Right of Access Requests – what do I have to do as a controller?
15th August 2023
Right of Access Requests – what do I have to do as a controller?
Article 15 GDPR gives data subjects the right to ‘request’ a copy of personal data held on them by a Controller. These Data Subject Access Requests (DSAR) can be very time-consuming and there has been a lot of uncertainty over potential ‘grey areas’, for example in terms of what must be included, whether the request is justified, when is a request disproportionate and whether a charge can be made for the request (in most cases, you can’t).
Earlier this year, the European Data Protection Board (EDPB) finalised its after a comprehensive public consultation. These guidelines aim to provide a practical understanding of the right of access and its varied implementation across different contexts. They are not binding here in the UK but they do provide a useful summary of ‘helpful guidance on certain issues’ – ICO.
The primary goal of the right of access is to provide data subjects with transparent and easily accessible information about their stored data to allow them to ensure information held on them is accurate and has been processed lawfully, this should be irrespective of the technology or storage mediums employed. The EDPB guidelines dissect all facets of the right of access, response protocols, and compliance measures to help clarify those grey areas:-
Definition of Personal Data
The guidelines underscore that the right of access is bounded by the definition of personal data. It solely applies to personal data. Data not processed by automated means or not intended for an electronic or manual filing system, remains exempt.
Scope of Right of Access
Data subjects hold the right to access a copy of all processed data linked to them, or pertinent sections as requested. The data controller must disclose all data, unless a subset of data is specifically requested by the data subject, in which case the data controller may focus solely on that segment.
CASE LAW
In a notable decision dated 4 May 2023 by the European Court of Justice, Case C-487/21 F.F. v Österreichische Datenschutzbehörde, a key judgment was made regarding the notion of “copy” in relation to Article 15(3).
The applicant requested their data from a credit checking firm and upon receipt of a summary of their data rather than a ‘full copy’ filed a complaint to the Austrian DPA which eventually led to the Austrian court. The outcome in that case, was that controllers are not ‘universally obliged to provide full copies of documents or databases’.
To put this into context, it is often much more convenient for a Controller simply to photocopy or screenshot records, such as an HR record, but where references are made to other Data Subjects, rather than redact, it is permissible to extract the personal data into a separate document.
Ensuring Access by Data Controllers
While some scenarios make the right of access straightforward, complexities arise in intricate data processing activities. a DSAR does not just cover data held in a filing cabinet or main company CRM, but potentially any software or platform in which personal data is stored. Word and Excel files, emails, cloud services and even backups and archives. A growing area of concern is the use of Shadow IT systems, for example, employees using instant messaging platforms likes WhatsApp and Slack to have ‘off the record’ conversations which have not been approved by the Controller. Any personal information shared in these platforms may still need to be disclosed if a DSAR request is received.
You can see that mapping of data sources is crucial and organisational policies should make the Controller’s position on use of these Shadow IT systems very clear. Half of the battle is not the discovery of information but the management of the potential thousands or tens of thousands of records that it will produce.
Limiting the Right of Access
As previously stated, the sole purpose of an access request is for an individual to ensure that their data is being processed lawfully and is accurate. It is not meant to be used as a weapon to harm the Controller. That said, requests are, on the surface, purpose blind and Controllers should not ask why the request is being made. However, a request can be labelled “manifestly unfounded” if Article 15 of GDPR requirements are blatantly unmet. Factors like data alteration frequency, data nature, processing intent, and similarity to previous requests are vital considerations. Recent case law suggests that if the Right of Access request is proven to be a malicious fact-finding expedition, then their entitlement to right of access will be limited.
Ensuring Compliance
To help you to comply with your Data Subject Access Request obligations we suggest the following top-level steps:
- Evaluate Processes: Scrutinise current right of access processes against the UK GDPR Subject Access Request (SAR) guidelines which can be found here.
- Revise Internal Policies: Revisit internal policies, including data protection and Subject Access Request (SAR) policies. Ensure they reflect the best practices.
Implementation
Enhance staff training regarding DSARs. Update training materials to encompass the latest insights on recognising, handling, and responding to SARs compliantly.
Everything is not black and white surrounding Data Subject Access Requests yet . .but the more we learn from case law, along with the guidelines from Europe . . . a clearer, less grey picture is emerging.
If you need any help regarding managing, Data Subject Access Requests or training staff in how to manage them, get in touch. Please do take advantage of your complimentary thirty minute consultation with one of our data governance specialists: Book yours here.
Thank you to Liberius Legal for the Case Law examples.