Individual Rights Procedure PR14

In accordance with the UK GDPR, individuals are granted certain rights regarding their personal data. The Organisation must comply with the Data Protection Act 2018 (DPA 18) and the UK General Data Protection Regulations (UKGDPR)

Handling Information Rights Requests Procedure

1. Introduction

In accordance with the UK GDPR, individuals are granted certain rights regarding their personal data. Requests from individuals to exercise these rights are referred to a 'Information Rights Requests'.

This procedure sets out how we ensure a consistent and effective approach is in place for responding to Information Rights Requests. All personal data processed by us is within the scope of this procedure.

This document must be viewed alongside City Family's (the 'Organisation's') suite of Information governance policies

2. Roles & Responsibilities

This procedure applies to all employees (staff, volunteers, contractors) who are responsible for responding to an Information Rights Request and you are responsible for reading and understanding this procedure.

All employees are responsible for recognising an Information Rights Request, logging the request and reporting it immediately to the Privacy Officer/Chief Executive Officer.

3. Background - Information Rights

The UK GDPR provides the following rights in law to individuals. These are not absolute and may not apply in all circumstances:

  • Information about how information relating to them is being used (right to be informed);
  • Access to personal data relating to them (right of access)
  • Right to request their data is shared to another provider (right of data portability);
  • Erasure of their personal data (right of erasure or right to be forgotten);
  • Rectification of incorrect or incomplete information (right of rectification);
  • To have any or all processing of their personal data restricted (right of restriction of processing);
  • To object to processing of their data (right to object);
  • To not be subject to a decision based solely on automated processing, including profiling, which produces legal effects similarly significant affects on him or her (right to not be subject to automated decision making);
  • To withdraw consent where consent is the lawful grounds for processing (right to withdraw consent).

Individuals also have the right to withdraw their consent to the processing of their data (where this is the lawful basis for processing) and the right to complain to the Information Commissioner's Office if they are not happy with the way we process their data.

4. Initial Procedural Steps

4.1 Identifying an Information Rights Request

The organisation shall ensure employees receive appropriate training to enable them to recognise and handle Information Rights Requests.

4.2 Reacting to a request

Anyone receiving an Information Rights Request should forward it to the Privacy Officer/Chief Executive Officer without delay.

If it is a verbal request (e.g. via the phone, in person, recorded message or voice mail) the requestor's name, contact details (e.g. phone number and/or email address), and details of the request should be recorded and this information should be conveyed to the Privacy Officer/Chief Executive Officer without delay.

It is the responsibility of the employee initially receiving the request to ensure that it has been received by the Privacy Officer/Chief Executive Officer. Simply forwarding a request onto another person is not sufficient – employees are responsible for taking active steps to verify that a suitable person has received the request.

4.3 Logging requests

When becoming aware of an Information Rights Request the Privacy Officer/Chief Executive Officer shall create an entry in the Information Rights Request Register with all relevant information.

4.4 Assignment

The Privacy Officer/Chief Executive Officer shall determine whether to delegate actions to other individuals regarding the request and shall nominate an individual to manage the request where appropriate – the "Request Handler" – which shall be marked up in the request register.

Requests must be responded to within one month of receipt (except where an extension applies).

4.5 Identity verification

The Request Handler shall engage with the requestor where appropriate to validate their identity and contact details to ensure that personal data are not disclosed to the wrong person. The 'clock' can be paused while waiting for this information. The register will be updated to reflect this.

Acceptable methods of identity verification include requesting and reviewing documentary evidence such as a valid passport, driving license etc.

The Request Handler must be satisfied that the person making the request has appropriate authority to exercise the rights requested before the request can be further processed. Once the identity of the requestor has been satisfactorily confirmed the 'clock' will start again. The register will be updated to reflect the new response date.

If the requestor fails to verify their identity within 14 working days, the Request Handler shall inform the Privacy Officer/Chief Executive Officer and the requestor that the request will not be taken further until they have satisfactorily verified their identity and that the request will be closed.

4.6 Clarification

The Request Handler shall engage with the requestor to clarify the request as necessary. This might be in order to narrow the search to specific information systems or date ranges to enable a prompt response. They shall also agree how the requestor would like the response (e.g. digitally or in hard copy format).

If the requestor fails to respond the request must still be responded to and all data relating to the data subject must be considered to fall in scope of the request.

4.7 Qualification

The Request Handler shall review the request to determine if it is a valid request made under the UK GDPR or Data Protection Act 2018. The Request Handler shall review and apply the qualification criteria set out in the Appendix to determine if each request is valid seeking advice as necessary.

Valid requests shall be handled in accordance with the procedures set out below.

4.8 Information Search

The Request Handler shall initiate an information search by issuing to all relevant employees instructions to search specified information systems for information meeting the search criteria.

The search criteria shall be defined in such a way as to provide the maximum opportunity for personal data relating to the requestor and falling within the scope of the search to be found.

The instruction shall set out a deadline for responding.

Employees receiving an information search instruction shall ensure that they carry out the search as instructed and follow the relevant actions, such as shall collating all of the information found in an information search and securely passing this to the Request Handler. The Request Handler shall be responsible for compiling all of the results of the information search that they receive from employees and create a register of every document found in the information search.

5. Secondary Procedural Steps

The Request Handler shall take the following procedural steps in the case of each type of request.

  • A rectification request shall follow the rectification request procedure;
  • An erasure request shall follow the erasure request procedure;
  • A portability request shall follow the portability request procedure;
  • A subject access request shall follow the DSAR procedure;
  • An objection shall follow the objection procedure;
  • A restriction request shall follow the restriction procedure.

5.1 Rectification request procedure

The Request Handler shall review the information returned from the information search to establish if any of it differs from the information provided by the requestor as being "accurate".

Where the information provided by the requestor differs from that returned from the information search, the Request Handler shall determine whether the information being processed is inaccurate and/or incomplete through consulting with colleagues or external agencies as necessary.

The Request Handler shall either issue instructions to correct and/or update information relating to the request or shall determine that the request will not be upheld and follow the Request Refusal Procedure.

Employees receiving information correction instructions shall execute them within 24 hours and shall verify in writing to the Request Handler the action that they have taken.

Where the personal data have been made public and the rectification request has been upheld, the Request Handler shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure of any links to, or copy or replication of, those personal data.

Where an opinion is recorded on an individual's record, this must be clearly marked to show it is an opinion. Where the data subject disagrees with the opinion recorded, this does not necessarily mean it must be rectified if a request for rectification is received. The Privacy Officer/Chief Executive Officer will advise if required.

5.2 Erasure requests

The Request Handler shall review the information returned from the information search to establish if any of it is subject to the erasure request by determining whether any of the following conditions apply:

  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2) of the UK GDPR, and where there is no other legal ground for the processing;
  • the data subject objects to the processing pursuant to Article 21(1) of the UK GDPR and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2) of the UK GDPR;
  • the personal data have been unlawfully processed;
  • the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
  • the personal data have been collected in relation to the offer of information society services referred to in Article 8(1) of the UK GDPR.

Additionally, the person managing the request shall consider if any of the exemptions provided for in Article 17(3) of the UK GDPR shall apply to the extent that processing is necessary:

  • for exercising the right of freedom of expression and information;
  • for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  • for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3) of the UK GDPR;
  • for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of the UK GDPR in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
  • for the establishment, exercise or defence of legal claims.

The Request Handler shall either issue instructions to erase information relating to the request or shall determine that the request will not be upheld and follow the Request Refusal Procedure. They may consult with colleagues or external agencies regarding the erasure request.

Where it is determined that the information being processed must be erased, the Request Handler shall issue instructions to erase information to all relevant individuals (including employees and data processors) via a written instruction.

Employees receiving information correction instructions shall execute them within 24 hours and shall verify in writing to the Request Handler the action that they have taken.

Where the personal data have been made public and the erasure request has been upheld, the Request Handler shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure of any links to, or copy or replication of, those personal data.

The Request Handler shall liaise with the Privacy Officer/Chief Executive Officer to obtain the approval of the response to the requestor prior to releasing the response to the requestor via the requestor's preferred method and ensuring that the disclosure is made securely. The Request Handler shall update the data subject rights register with all relevant information describing how the request has been handled and any resulting actions.

5.4 Portability Requests

The Request Handler shall review the information returned from the information search to establish if any of it is subject to the portability request by determining whether any of the following conditions apply:

  • The data subject provided the information to the organisation in the first place; and
  • The processing is carried out by automated means; and
  • the processing is based on consent or a contract between the data subject and the organisation.

The Request Handler shall review the criteria above and determine if the request is to be upheld or not. If the request is not to be upheld the Request Refusal Procedure shall be followed.

Where the request is upheld the Request Handler shall review liaise with the data subject to determine:

  • the format in which the data are to be transmitted
  • the contact details of the person they are to be transmitted to,
  • the secure method of transmission.

The Request Handler shall ensure that the redacted information is transferred to the nominated person in the nominated format via the nominated method.

5.5 Subject Access Requests

The Request Handler shall review the information returned from the information search to establish if any of it should be redacted or is subject to an exemption. Where redaction is required the Request Handler shall arrange for the redaction of any information which must not be released to the requestor (e.g. other people's personal data).

The Request Handler shall review whether any exemptions provided for in the DPA18 are to be applied to the information returned from the information search and shall compile a list of all such cases of applying exemptions and the information that is not to be released due to reliance on an exemption. The Request Handler shall redact any exempt information if it is contained within a document or remove entire documents if the document is subject to an exemption.

The Request Handler shall discuss decisions about redaction and exemptions with appropriate people as necessary including from an external source such as a lawyer or data protection practitioner where they feel this is necessary.

The Request Handler shall draft a response to the requestor and prepare all of the information that is to be released including:

Confirmation as to whether or not personal data concerning the requestor are being processed, and, where that is the case, the following information:

  • the purposes of the processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  • the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
  • the right to lodge a complaint with a supervisory authority;
  • where the personal data were not collected from the data subject, any available information as to their source;
  • the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the requestor.
  • where personal data are transferred to a third country or to an international organisation, details of the appropriate safeguards pursuant relating to the transfer.
  • a copy of the personal data undergoing processing that has been redacted and to which exemptions have been applied.

The Request Handler shall liaise with the Privacy Officer/Chief Executive Officer to obtain the approval of the response to the requestor prior to releasing the response to the requestor via the requestor's preferred method and ensuring that the disclosure is made securely. The Request Handler shall update the Data Subject Rights Register with all relevant information describing how the request has been handled and any resulting actions.

5.6 Objections to processing

The Request Handler shall consult with relevant employees to establish whether personal data relating to the requestor are being processed in the manner and for the purposes that they are objecting to and shall determine if the processing:

  • is based on a legitimate interest or a public task or official authority, or
  • is for scientific or historical research purposes or statistical purposes pursuant to Article 89(1) of the UK GDPR.

In the case of (a) above, where the data processing activities have another legal basis, the Request Handler shall inform the requestor that the objection request is not valid and the decision rationale.

Where it is not possible to demonstrate another legal basis the Request Handler shall determine if the data are required for the establishment, exercise or defence of legal claims. If this is the case the Request Handler shall inform the requestor that their request has not been upheld.

If it is not the case then the person managing the request shall perform a balancing test to determine if the organisation is able to demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the requestor.

If the objection is to automated individual decision making (including profiling) the Request Handler shall consider and document the effects of the decision making.

The Request Handler shall ensure a comprehensive written statement is maintained describing and detailing the processes applied to the handling of the request.

The Request Handler shall issue instructions to all relevant people to cease processing the personal data falling within the scope of a restriction or objection and shall ensure that where processing has been restricted, the personal data within the scope of the restriction shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the UK.

The Request Handler shall liaise with the Privacy Officer/Chief Executive Officer to obtain the approval of the response to the requestor prior to releasing the response to the requestor via the requestor's preferred method and ensuring that the disclosure is made securely. The Request Handler shall update the Data Subject Rights Register with all relevant information describing how the request has been handled and any resulting actions.

5.7 Restriction requests

Where the requestor has requested a restriction of processing the Request Handler shall determine if any of the following circumstances apply:

  • the accuracy of the personal data is contested by the requestor;
  • the processing is unlawful and the requestor opposes the erasure of the personal data and requests the restriction of their use instead;
  • we no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;
  • the requestor has objected to processing under 4.6.e above.

In the case of (a) above the Request Handler shall verify the accuracy of the personal data and then take action as appropriate in accordance with section 5.1 above;

In the case of (b) above the Request Handler shall make an assessment as to the lawfulness of the processing and, if there is no lawful basis, shall liaise with the requestor to determine the nature of the restriction that they require and issue a "Stop Now" instruction to relevant people to implement the requestor's instructions. If the Request Handler finds that there is a valid lawful basis they shall handle the request in accordance with the Objection Procedure. The Request Handler may be required to undertake a legitimate interest test and in any event shall fully document the decisions and investigation that they undertake.

In the case of (c) above, the Request Handler shall issue a "Stop Now" instruction ensuring that the instruction also contains instructions to retain the personal data so that the requestor is able to rely on it for the establishment, exercise or defence of legal claims which may or may not be against the organisation.

In the case of (d) above the Request Handler shall handle the request in accordance with Objection Procedure.

The Request Handler shall ensure that appropriate records are maintained of the restriction and sufficient that the restriction is communicated to relevant people including maintaining a commentary of each request to provide an audit trail of decisions made and action taken in respect of each request.

The Privacy Officer/Chief Executive Officer shall ensure that the requestor is informed in writing before the restriction of processing is lifted.

5.2 Request Refusal Procedure

Where it is determined that the request will not be upheld, the Request Handler will draft a suitable response to the requestor. This will be approved by the Privacy Officer/Chief Executive Officer prior to issue.

6. Document Control

The Privacy Officer/Chief Executive Officer owns this procedure and is responsible for ensuring that it is reviewed on a regular basis. A current version of this procedure is available to all employees.

This procedure was approved by the Chief Executive Officer on 25 May 2024 and is issued on a version-controlled basis under his/her signature.

8. Approval

This policy has been approved by the undersigned and will be reviewed at least annually.

NameT Poore
Approval Date25/5/24
Review Date9/7/25
Next reviewJuly 2026
City Family Logo

City Family CIC | Socata House I 543-545 London Road I Westcliff On Sea I Essex I SS0 9LJ

Community Fund
Southend-on-Sea City Council

Thank You To Our Partners...

Rochford District Council
A Better Start Southend

© 2023 City Family CIC | Company number 14356630 | City Family CIC, DadsConnect and Talking Transitions are registered Trademarks, in the UK belonging to City Family CIC

Registered at Socata House I 543-545 London Road I Westcliff On Sea I Essex I SS0 9LJ

As part of the Women in the Workplace project, funded by DHSC and run by Pregnant Then Screwed and Best Beginnings, we are excited to share that we have received an Accreditation for the Empowered Foundations training with a focus on women's reproductive health in the workplace. As part of the training, our managers accessed modules based on the topics of pregnancy loss, fertility, flexible working and eliminating bias to better understand the use of language, ways to support members of staff and increase knowledge base around these specific topics. Here at City Family we are striving to improve the support available for the women in our workplace

Website by ionic.

Privacy Overview

When you visit our website, it may store or retrieve information on your browser, mostly in the form of cookies, which are mostly used to make the site work as you expect it to and give you a more personalised web experience.

They also help us understand how easy it is for users to find information so that we can make improvements.

Please click here to read our Privacy Policy