This practical workshop, will look at managing Subject Access Requests and what you need to consider to comply with legislation and upholding individuals rights to access personal and sensitive information held about them. This will enable delegates to look at case studies and have the confidence to respond to requests.
“The right of individuals to access information that organisations hold on them is one that is vital for transparency, and is enshrined in law. What we’re seeing now is that many employers are misunderstanding the nature of subject access requests, or underestimating the importance of responding to requests. For example, employers may be unaware that requests can be submitted informally, such as over social media, or do not have to contain the words ‘subject access request’ in order to qualify as a legally binding request. Similarly, employers may not realise that there is a strict time frame for responding to requests, and this must be kept to.”
Elanor McCombe, Policy Group Manager at the Information Commissioner’s Office
In 2018 both the General Data Protection Regulation and a new Data Protection Act were introduced in the UK, requiring health and social care bodies, by the nature of their work, to respond to Subject Access requests. There is, to a certain extent, relatively clear guidance in the legislation as to what this requires organisations to do. This course, however, facilitated by an experienced Information Governance & Health Records Manager, undertakes to highlight how to practically implement the requirements, introducing a practical approach to Subject Access Requests.
Within Health and Social Care (inc. third sector); Data Protection Officers, Deputy Data Protection Officers, Information Governance Professionals and Line Managers of any of the above should attend this masterclass.
In May 2023, the ICO published a new guide on responding to subject access requests Read in full here
Key Learning Objectives include understanding:
Background and Legal Basis
Definitions
Working with others in the organisation: Information Asset Owners, Health Records Manager, Data Protection Officer, Caldicott Guardian, Senior Information Risk Owner
How to Manage a Subject Access Request: Identifying a valid request, Excessive & Unfounded request, Locating the information requested, Collating, Redacting & Disclosure, Exemptions
Requests from 3rd Parties: Solicitors, Insurance Companies, Police, Others, Requests from Staff
Complaints
Complex requests - Case studies
Information Commissioners Office - Audits and Enforcement
FACILITATOR
Tania Palmariellodiviney, Director and Founder of the award winning Data Privacy Simplified, is an experienced and highly skilled Information Governance and Data Protection Specialist with an extensive track record of working in all areas of the health and social care and education sector.
She has worked for NHS England at strategic and operational level and is a Trustee Board member and DPO support for local Bedford Charity Carers in Bedfordshire.
With a BCS Practitioner Certificate in Data Protection, a Master’s in Health Information Governance and as a member of the International Association of Privacy Professionals (IAPP), Tania is a regular attendee and speaker at national conferences discussing national and international data protection legislation as well as current issues and resolutions within the industry.
Tania is the Co-founder of DPS & BJM IG & Privacy training, delivering high quality Information Governance teaching and accreditation across the Health and Care Sector.
Data Privacy Simplified are leading providers and experts in Information Governance and Data Protection legislation, aiming to support organisations to thrive, whilst ensuring legal compliance within data protection legislation.