In accordance with the UK GDPR, individuals are granted certain rights regarding their personal data. The Organisation must comply with the Data Protection Act 2018 (DPA 18) and the UK General Data Protection Regulations (UKGDPR)
In accordance with the UK GDPR, individuals are granted certain rights regarding their personal data. Requests from individuals to exercise these rights are referred to a 'Information Rights Requests'.
This procedure sets out how we ensure a consistent and effective approach is in place for responding to Information Rights Requests. All personal data processed by us is within the scope of this procedure.
This document must be viewed alongside City Family's (the 'Organisation's') suite of Information governance policies
This procedure applies to all employees (staff, volunteers, contractors) who are responsible for responding to an Information Rights Request and you are responsible for reading and understanding this procedure.
All employees are responsible for recognising an Information Rights Request, logging the request and reporting it immediately to the Privacy Officer/Chief Executive Officer.
The UK GDPR provides the following rights in law to individuals. These are not absolute and may not apply in all circumstances:
Individuals also have the right to withdraw their consent to the processing of their data (where this is the lawful basis for processing) and the right to complain to the Information Commissioner's Office if they are not happy with the way we process their data.
The organisation shall ensure employees receive appropriate training to enable them to recognise and handle Information Rights Requests.
Anyone receiving an Information Rights Request should forward it to the Privacy Officer/Chief Executive Officer without delay.
If it is a verbal request (e.g. via the phone, in person, recorded message or voice mail) the requestor's name, contact details (e.g. phone number and/or email address), and details of the request should be recorded and this information should be conveyed to the Privacy Officer/Chief Executive Officer without delay.
It is the responsibility of the employee initially receiving the request to ensure that it has been received by the Privacy Officer/Chief Executive Officer. Simply forwarding a request onto another person is not sufficient – employees are responsible for taking active steps to verify that a suitable person has received the request.
When becoming aware of an Information Rights Request the Privacy Officer/Chief Executive Officer shall create an entry in the Information Rights Request Register with all relevant information.
The Privacy Officer/Chief Executive Officer shall determine whether to delegate actions to other individuals regarding the request and shall nominate an individual to manage the request where appropriate – the "Request Handler" – which shall be marked up in the request register.
Requests must be responded to within one month of receipt (except where an extension applies).
The Request Handler shall engage with the requestor where appropriate to validate their identity and contact details to ensure that personal data are not disclosed to the wrong person. The 'clock' can be paused while waiting for this information. The register will be updated to reflect this.
Acceptable methods of identity verification include requesting and reviewing documentary evidence such as a valid passport, driving license etc.
The Request Handler must be satisfied that the person making the request has appropriate authority to exercise the rights requested before the request can be further processed. Once the identity of the requestor has been satisfactorily confirmed the 'clock' will start again. The register will be updated to reflect the new response date.
If the requestor fails to verify their identity within 14 working days, the Request Handler shall inform the Privacy Officer/Chief Executive Officer and the requestor that the request will not be taken further until they have satisfactorily verified their identity and that the request will be closed.
The Request Handler shall engage with the requestor to clarify the request as necessary. This might be in order to narrow the search to specific information systems or date ranges to enable a prompt response. They shall also agree how the requestor would like the response (e.g. digitally or in hard copy format).
If the requestor fails to respond the request must still be responded to and all data relating to the data subject must be considered to fall in scope of the request.
The Request Handler shall review the request to determine if it is a valid request made under the UK GDPR or Data Protection Act 2018. The Request Handler shall review and apply the qualification criteria set out in the Appendix to determine if each request is valid seeking advice as necessary.
Valid requests shall be handled in accordance with the procedures set out below.
The Request Handler shall initiate an information search by issuing to all relevant employees instructions to search specified information systems for information meeting the search criteria.
The search criteria shall be defined in such a way as to provide the maximum opportunity for personal data relating to the requestor and falling within the scope of the search to be found.
The instruction shall set out a deadline for responding.
Employees receiving an information search instruction shall ensure that they carry out the search as instructed and follow the relevant actions, such as shall collating all of the information found in an information search and securely passing this to the Request Handler. The Request Handler shall be responsible for compiling all of the results of the information search that they receive from employees and create a register of every document found in the information search.
The Request Handler shall take the following procedural steps in the case of each type of request.
The Request Handler shall review the information returned from the information search to establish if any of it differs from the information provided by the requestor as being "accurate".
Where the information provided by the requestor differs from that returned from the information search, the Request Handler shall determine whether the information being processed is inaccurate and/or incomplete through consulting with colleagues or external agencies as necessary.
The Request Handler shall either issue instructions to correct and/or update information relating to the request or shall determine that the request will not be upheld and follow the Request Refusal Procedure.
Employees receiving information correction instructions shall execute them within 24 hours and shall verify in writing to the Request Handler the action that they have taken.
Where the personal data have been made public and the rectification request has been upheld, the Request Handler shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure of any links to, or copy or replication of, those personal data.
Where an opinion is recorded on an individual's record, this must be clearly marked to show it is an opinion. Where the data subject disagrees with the opinion recorded, this does not necessarily mean it must be rectified if a request for rectification is received. The Privacy Officer/Chief Executive Officer will advise if required.
The Request Handler shall review the information returned from the information search to establish if any of it is subject to the erasure request by determining whether any of the following conditions apply:
Additionally, the person managing the request shall consider if any of the exemptions provided for in Article 17(3) of the UK GDPR shall apply to the extent that processing is necessary:
The Request Handler shall either issue instructions to erase information relating to the request or shall determine that the request will not be upheld and follow the Request Refusal Procedure. They may consult with colleagues or external agencies regarding the erasure request.
Where it is determined that the information being processed must be erased, the Request Handler shall issue instructions to erase information to all relevant individuals (including employees and data processors) via a written instruction.
Employees receiving information correction instructions shall execute them within 24 hours and shall verify in writing to the Request Handler the action that they have taken.
Where the personal data have been made public and the erasure request has been upheld, the Request Handler shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure of any links to, or copy or replication of, those personal data.
The Request Handler shall liaise with the Privacy Officer/Chief Executive Officer to obtain the approval of the response to the requestor prior to releasing the response to the requestor via the requestor's preferred method and ensuring that the disclosure is made securely. The Request Handler shall update the data subject rights register with all relevant information describing how the request has been handled and any resulting actions.
The Request Handler shall review the information returned from the information search to establish if any of it is subject to the portability request by determining whether any of the following conditions apply:
The Request Handler shall review the criteria above and determine if the request is to be upheld or not. If the request is not to be upheld the Request Refusal Procedure shall be followed.
Where the request is upheld the Request Handler shall review liaise with the data subject to determine:
The Request Handler shall ensure that the redacted information is transferred to the nominated person in the nominated format via the nominated method.
The Request Handler shall review the information returned from the information search to establish if any of it should be redacted or is subject to an exemption. Where redaction is required the Request Handler shall arrange for the redaction of any information which must not be released to the requestor (e.g. other people's personal data).
The Request Handler shall review whether any exemptions provided for in the DPA18 are to be applied to the information returned from the information search and shall compile a list of all such cases of applying exemptions and the information that is not to be released due to reliance on an exemption. The Request Handler shall redact any exempt information if it is contained within a document or remove entire documents if the document is subject to an exemption.
The Request Handler shall discuss decisions about redaction and exemptions with appropriate people as necessary including from an external source such as a lawyer or data protection practitioner where they feel this is necessary.
The Request Handler shall draft a response to the requestor and prepare all of the information that is to be released including:
Confirmation as to whether or not personal data concerning the requestor are being processed, and, where that is the case, the following information:
The Request Handler shall liaise with the Privacy Officer/Chief Executive Officer to obtain the approval of the response to the requestor prior to releasing the response to the requestor via the requestor's preferred method and ensuring that the disclosure is made securely. The Request Handler shall update the Data Subject Rights Register with all relevant information describing how the request has been handled and any resulting actions.
The Request Handler shall consult with relevant employees to establish whether personal data relating to the requestor are being processed in the manner and for the purposes that they are objecting to and shall determine if the processing:
In the case of (a) above, where the data processing activities have another legal basis, the Request Handler shall inform the requestor that the objection request is not valid and the decision rationale.
Where it is not possible to demonstrate another legal basis the Request Handler shall determine if the data are required for the establishment, exercise or defence of legal claims. If this is the case the Request Handler shall inform the requestor that their request has not been upheld.
If it is not the case then the person managing the request shall perform a balancing test to determine if the organisation is able to demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the requestor.
If the objection is to automated individual decision making (including profiling) the Request Handler shall consider and document the effects of the decision making.
The Request Handler shall ensure a comprehensive written statement is maintained describing and detailing the processes applied to the handling of the request.
The Request Handler shall issue instructions to all relevant people to cease processing the personal data falling within the scope of a restriction or objection and shall ensure that where processing has been restricted, the personal data within the scope of the restriction shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the UK.
The Request Handler shall liaise with the Privacy Officer/Chief Executive Officer to obtain the approval of the response to the requestor prior to releasing the response to the requestor via the requestor's preferred method and ensuring that the disclosure is made securely. The Request Handler shall update the Data Subject Rights Register with all relevant information describing how the request has been handled and any resulting actions.
Where the requestor has requested a restriction of processing the Request Handler shall determine if any of the following circumstances apply:
In the case of (a) above the Request Handler shall verify the accuracy of the personal data and then take action as appropriate in accordance with section 5.1 above;
In the case of (b) above the Request Handler shall make an assessment as to the lawfulness of the processing and, if there is no lawful basis, shall liaise with the requestor to determine the nature of the restriction that they require and issue a "Stop Now" instruction to relevant people to implement the requestor's instructions. If the Request Handler finds that there is a valid lawful basis they shall handle the request in accordance with the Objection Procedure. The Request Handler may be required to undertake a legitimate interest test and in any event shall fully document the decisions and investigation that they undertake.
In the case of (c) above, the Request Handler shall issue a "Stop Now" instruction ensuring that the instruction also contains instructions to retain the personal data so that the requestor is able to rely on it for the establishment, exercise or defence of legal claims which may or may not be against the organisation.
In the case of (d) above the Request Handler shall handle the request in accordance with Objection Procedure.
The Request Handler shall ensure that appropriate records are maintained of the restriction and sufficient that the restriction is communicated to relevant people including maintaining a commentary of each request to provide an audit trail of decisions made and action taken in respect of each request.
The Privacy Officer/Chief Executive Officer shall ensure that the requestor is informed in writing before the restriction of processing is lifted.
Where it is determined that the request will not be upheld, the Request Handler will draft a suitable response to the requestor. This will be approved by the Privacy Officer/Chief Executive Officer prior to issue.
The Privacy Officer/Chief Executive Officer owns this procedure and is responsible for ensuring that it is reviewed on a regular basis. A current version of this procedure is available to all employees.
This procedure was approved by the Chief Executive Officer on 25 May 2024 and is issued on a version-controlled basis under his/her signature.
This policy has been approved by the undersigned and will be reviewed at least annually.
| Name | T Poore |
| Approval Date | 25/5/24 |
| Review Date | 9/7/25 |
| Next review | July 2026 |
City Family CIC | Socata House I 543-545 London Road I Westcliff On Sea I Essex I SS0 9LJ



Thank You To Our Partners...


© 2023 City Family CIC | Company number 14356630 | City Family CIC, DadsConnect and Talking Transitions are registered Trademarks, in the UK belonging to City Family CIC
Registered at Socata House I 543-545 London Road I Westcliff On Sea I Essex I SS0 9LJ
As part of the Women in the Workplace project, funded by DHSC and run by Pregnant Then Screwed and Best Beginnings, we are excited to share that we have received an Accreditation for the Empowered Foundations training with a focus on women's reproductive health in the workplace. As part of the training, our managers accessed modules based on the topics of pregnancy loss, fertility, flexible working and eliminating bias to better understand the use of language, ways to support members of staff and increase knowledge base around these specific topics. Here at City Family we are striving to improve the support available for the women in our workplace
Website by ionic.