Practical tips for dealing with Data Subject Access Requests

Поделиться
HTML-код
  • Опубликовано: 12 сен 2024

Комментарии • 19

  • @martycrow
    @martycrow Год назад +1

    Good explanation and well balanced between the needs of a 'data controller' and 'data subject'. This is a vital topic that more people need to understand in order to create more transparent data architecture. Let the light in, I say!

  • @philbrown4930
    @philbrown4930 2 года назад +1

    Regardless of how well you might know or preach about a subject, there is always more to learn - thanks Rich

  • @catherinemclean1116
    @catherinemclean1116 2 года назад +2

    Thanks so much Rich, really useful to hear this

    • @iSTORMDiaries
      @iSTORMDiaries  2 года назад +2

      Thank you for the inspiration for the episode! :)

  • @JimmyHendrixJR
    @JimmyHendrixJR Год назад +1

    Excellent explanation!

  • @chinthamansharmila1779
    @chinthamansharmila1779 2 года назад +1

    I loved the video, so insightful!

  • @Amelia-qm6bk
    @Amelia-qm6bk 2 года назад +1

    Many thanks Rich > appreciated

  • @anniewilson2116
    @anniewilson2116 Год назад +1

    I was refused my SARS from the care home my mother was in. The CEO of the we care group told me I know nothing about the law and will only deal with me through solicitors. I told him what I was entitled to and they have 28 days to respond which they had not.

    • @iSTORMDiaries
      @iSTORMDiaries  Год назад +1

      As long as you had either appropriate power of attorney or written permission to act on your mothers behalf, the request should not have been refused. In instances such as this, I always recommend being clear, providing what documentation you have and if all else fails, talking to the ICO as they can help you.

  • @yagmursahin8832
    @yagmursahin8832 2 года назад

    Thank you.

  • @AuditingGlasgow
    @AuditingGlasgow 8 месяцев назад +1

    How do i get all data held on record held about me examples prison doctors work schools etc

    • @iSTORMDiaries
      @iSTORMDiaries  8 месяцев назад

      You need to do a subject access request to each organization. You can send the same letter. Keep it simple, provide your details and explain that you’d like a copy of your records under as per your right under the GDPR. They may ask for confirmation of ID or dates. I’d also title your email Subject Access Request. Good luck

  • @GailJonesPolymerClay
    @GailJonesPolymerClay Год назад +1

    If the data I require is from a third person ( ie a colleague) will they know?

    • @iSTORMDiaries
      @iSTORMDiaries  Год назад

      It very much depends on the circumstances. Most searches in an employment context are carried out without people knowing but if the data relates to an opinion or comment formed about you by someone else, there are situations where that persons consent may be sought before it is released to you.

    • @lishkaheaney7324
      @lishkaheaney7324 Год назад

      ​@@iSTORMDiaries can you tell me what stops an employee from deleting the texts/emails after you've asked for data subject access?

    • @martycrow
      @martycrow Год назад

      @@lishkaheaney7324 My understanding is that it is illegal for a company/an organisation to delete data collected in the course of its normal business, even (or maybe especially!) once in receipt of a DSAR. I got this info from the ICO website which is user-friendly, in plain English and informative. It is prudent to remind the entity who holds the info when requesting DSAR and refer them to the IOC website. The requirement for a company to hold records is also a requirement under Company Law, so that may need a gentle reminder too. Good luck!