{"id":172454,"date":"2022-07-21T07:32:51","date_gmt":"2022-07-21T06:32:51","guid":{"rendered":"https:\/\/legalvision.co.uk\/?p=172454"},"modified":"2022-07-25T03:37:58","modified_gmt":"2022-07-25T02:37:58","slug":"safely-handle-sar","status":"publish","type":"post","link":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/","title":{"rendered":"Four Tips to Safely Handle Subject Access Requests in England"},"content":{"rendered":"\n<p>Your business will likely handle a significant amount of data relating to employees, customers and suppliers. Therefore, you must comply with data protection requirements to avoid fines. The <a href=\"https:\/\/www.google.com\/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=&amp;cad=rja&amp;uact=8&amp;ved=2ahUKEwiGgL7Z-JL5AhWe0XMBHTgvBOoQFnoECAcQAQ&amp;url=https%3A%2F%2Fgdpr-info.eu%2F&amp;usg=AOvVaw1akHzzz224Oq1yU0pd6qSw\">General Data Protection Regulation<\/a> (GDPR) contains many data protection rules, including the right for an individual to file a Subject Access Request (SAR). These are also known as data subject access requests or DSARs. This article will explain the nature of a SAR and provide four tips for your business on safely handling them.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is a Subject Access Request?<\/h2>\n\n\n\n<p>SARs came into existence prior to the GDPR. However, <a href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/how-does-gdpr-affect-my-business\/\">the GDPR reduces the time<\/a> your company has to address the SAR.\u00a0Under a SAR, all individuals who have <a href=\"https:\/\/legalvision.co.uk\/ecommerce-online-business\/personal-data-e-commerce\/\">data<\/a> relating to them within your organisation have the right to:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>to be informed of the specific data you hold about them;\u00a0<\/li><li>receive a copy of this data; and\u00a0<\/li><li>be told who else has access to that information.<\/li><\/ul>\n\n\n\n<div  class=\"box box--icon box--warning\">\n    <p>Your organisation has one calendar month to respond to the SAR. Usually, you must do so in writing.<\/p>\n<\/div>\n\n\n\n<p>Under old data protection laws, your company was able to charge a small fee for performing this task. However, under the new rules, your business cannot usually request payment. Although, there is an exemption where the SAR is &#8216;excessive&#8217; or the individual seeks multiple copies. Here, you may charge a reasonable fee.\u00a0\u00a0<\/p>\n\n\n\n<p>Let us explore four tips to help your company safely handle SARs.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">1. Acknowledge Receipt<\/h2>\n\n\n\n<p>It is good practice to respond to the sender of the SAR and confirm a receipt of their request. This also enables your company note the deadline to respond (one calendar month from the date of receipt).<\/p>\n\n\n\n<p>So, if you receive a SAR from an employee by email on 2nd May, your first step would be to acknowledge it by return email. Additionally, you might note that 2nd June is the final day to provide them with the necessary materials.<\/p>\n\n\n\n\n<a href=\"#content-next\"\n   class=\"block p-4 mt-10 text-xl font-bold text-center text-white no-underline bg-gray-800 rounded-t-xl\">\n    Continue reading this article below the form\n    <i class=\"text-xl fa-regular fa-arrow-down\"><\/i>\n<\/a>\n<div class=\"px-6 pt-10 pb-12 mb-10 text-center bg-gray-100 rounded-b-xl sm:px-12 test\">\n    <div class=\"mb-8 text-2xl font-bold text-orange\">\n        Need legal advice?\n        <br>\n        <span class=\"text-lg not-prose\">\n                            Call <a href=\"tel:+448081968584\" class=\"not-prose\">0808 196 8584<\/a> for urgent assistance.\n                <br>\n                Otherwise, complete this form, and we will contact you within one business day.\n                    <\/span>\n    <\/div>\n\n    \n\n<div class=\"not-prose flex justify-center text-left gform_input_bg_white    \">\n    <script>\nvar gform;gform||(document.addEventListener(\"gform_main_scripts_loaded\",function(){gform.scriptsLoaded=!0}),document.addEventListener(\"gform\/theme\/scripts_loaded\",function(){gform.themeScriptsLoaded=!0}),window.addEventListener(\"DOMContentLoaded\",function(){gform.domLoaded=!0}),gform={domLoaded:!1,scriptsLoaded:!1,themeScriptsLoaded:!1,isFormEditor:()=>\"function\"==typeof InitializeEditor,callIfLoaded:function(o){return!(!gform.domLoaded||!gform.scriptsLoaded||!gform.themeScriptsLoaded&&!gform.isFormEditor()||(gform.isFormEditor()&&console.warn(\"The use of gform.initializeOnLoaded() is deprecated in the form editor context and will be removed in Gravity Forms 3.1.\"),o(),0))},initializeOnLoaded:function(o){gform.callIfLoaded(o)||(document.addEventListener(\"gform_main_scripts_loaded\",()=>{gform.scriptsLoaded=!0,gform.callIfLoaded(o)}),document.addEventListener(\"gform\/theme\/scripts_loaded\",()=>{gform.themeScriptsLoaded=!0,gform.callIfLoaded(o)}),window.addEventListener(\"DOMContentLoaded\",()=>{gform.domLoaded=!0,gform.callIfLoaded(o)}))},hooks:{action:{},filter:{}},addAction:function(o,r,e,t){gform.addHook(\"action\",o,r,e,t)},addFilter:function(o,r,e,t){gform.addHook(\"filter\",o,r,e,t)},doAction:function(o){gform.doHook(\"action\",o,arguments)},applyFilters:function(o){return gform.doHook(\"filter\",o,arguments)},removeAction:function(o,r){gform.removeHook(\"action\",o,r)},removeFilter:function(o,r,e){gform.removeHook(\"filter\",o,r,e)},addHook:function(o,r,e,t,n){null==gform.hooks[o][r]&&(gform.hooks[o][r]=[]);var d=gform.hooks[o][r];null==n&&(n=r+\"_\"+d.length),gform.hooks[o][r].push({tag:n,callable:e,priority:t=null==t?10:t})},doHook:function(r,o,e){var t;if(e=Array.prototype.slice.call(e,1),null!=gform.hooks[r][o]&&((o=gform.hooks[r][o]).sort(function(o,r){return o.priority-r.priority}),o.forEach(function(o){\"function\"!=typeof(t=o.callable)&&(t=window[t]),\"action\"==r?t.apply(null,e):e[0]=t.apply(null,e)})),\"filter\"==r)return e[0]},removeHook:function(o,r,t,n){var e;null!=gform.hooks[o][r]&&(e=(e=gform.hooks[o][r]).filter(function(o,r,e){return!!(null!=n&&n!=o.tag||null!=t&&t!=o.priority)}),gform.hooks[o][r]=e)}});\n<\/script>\n\n                <div class='gf_browser_gecko gform_wrapper gravity-theme gform-theme--no-framework lawyer-form_wrapper gplaceholder_wrapper form-with-labels-no-asterisks_wrapper has-new-validation-error-styling_wrapper' data-form-theme='gravity-theme' data-form-index='0' id='gform_wrapper_2453' style='display:none'><div id='gf_2453' class='gform_anchor' tabindex='-1'><\/div><form method='post' enctype='multipart\/form-data' target='gform_ajax_frame_2453' id='gform_2453' class='lawyer-form gplaceholder form-with-labels-no-asterisks has-new-validation-error-styling' action='\/api\/wp\/v2\/posts\/172454#gf_2453' data-formid='2453' novalidate>\n                        <div class='gform-body gform_body'><div id='gform_fields_2453' class='gform_fields top_label form_sublabel_below description_below validation_below'><div id=\"field_2453_1000\" class=\"gfield gfield--type-honeypot gform_validation_container field_sublabel_below gfield--has-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_1000'>Email<\/label><div class='ginput_container'><input name='input_1000' id='input_2453_1000' type='text' value='' autocomplete='new-password'\/><\/div><div class='gfield_description' id='gfield_description_2453_1000'>This field is for validation purposes and should be left unchanged.<\/div><\/div><div id=\"field_2453_1\" class=\"gfield gfield--type-text gfield--input-type-text gf_left_half gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_1'>First Name<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_text'><input name='input_1' id='input_2453_1' type='text' value='' class='medium'     aria-required=\"true\" aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_2453_12\" class=\"gfield gfield--type-text gfield--input-type-text gf_right_half gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_12'>Last Name<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_text'><input name='input_12' id='input_2453_12' type='text' value='' class='medium'     aria-required=\"true\" aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_2453_2\" class=\"gfield gfield--type-email gfield--input-type-email gf_left_half gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_2'>Email Address<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_email'>\n                            <input name='input_2' id='input_2453_2' type='email' value='' class='medium'    aria-required=\"true\" aria-invalid=\"false\"  \/>\n                        <\/div><\/div><div id=\"field_2453_3\" class=\"gfield gfield--type-phone gfield--input-type-phone gf_right_half gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_3'>Phone<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_phone'><input name='input_3' id='input_2453_3' type='tel' value='' class='medium'   aria-required=\"true\" aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_2453_14\" class=\"gfield gfield--type-select gfield--input-type-select gfield--width-full custom-select gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_14'>Number of Employees in Your Business<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_select'><select name='input_14' id='input_2453_14' class='large gfield_select'    aria-required=\"true\" aria-invalid=\"false\" ><option value='' selected='selected'>Select ...<\/option><option value='0' >0<\/option><option value='1' >1-5<\/option><option value='6' >6-20<\/option><option value='21' >21-50<\/option><option value='51' >51-250<\/option><option value='250' >250+<\/option><\/select><\/div><\/div><div id=\"field_2453_4\" class=\"gfield gfield--type-textarea gfield--input-type-textarea gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_4'>Tell us about your enquiry<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_textarea'><textarea name='input_4' id='input_2453_4' class='textarea medium'     aria-required=\"true\" aria-invalid=\"false\"   rows='10' cols='50'><\/textarea><\/div><\/div><div id=\"field_2453_5\" class=\"gfield gfield--type-html gfield--input-type-html gfield_html gfield_html_formatted gfield_no_follows_desc field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  >By submitting this form, you agree to receive emails from LegalVision and can unsubscribe at any time. View our <a href=\"https:\/\/legalvision.co.uk\/privacy-notice\/\" target=\"_blank\">Privacy Policy<\/a>. <\/div><div id=\"field_2453_8\" class=\"gfield gfield--type-hidden gfield--input-type-hidden gform_hidden field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><div class='ginput_container ginput_container_text'><input name='input_8' id='input_2453_8' type='hidden' class='gform_hidden'  aria-invalid=\"false\" value='http:\/\/legalvision.co.uk\/api\/wp\/v2\/posts\/172454' \/><\/div><\/div><div id=\"field_2453_13\" class=\"gfield gfield--type-hidden gfield--input-type-hidden gform_hidden field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><div class='ginput_container ginput_container_text'><input name='input_13' id='input_2453_13' type='hidden' class='gform_hidden'  aria-invalid=\"false\" value='generic_form' \/><\/div><\/div><fieldset id=\"field_2453_999\" class=\"gfield gfield--type-checkbox gfield--type-choice gfield__uk-marketo-opt-in field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><legend class='gfield_label gform-field-label screen-reader-text' ><\/legend><div class='ginput_container ginput_container_checkbox'><div class='gfield_checkbox ' id='input_2453_999'><div class='gchoice gchoice_2453_999_1'>\n\t\t\t\t\t\t\t\t<input class='gfield-choice-input' name='input_999.1' type='checkbox'  value='1'  id='choice_2453_999_1'   \/>\n\t\t\t\t\t\t\t\t<label for='choice_2453_999_1' id='label_2453_999_1' class='gform-field-label gform-field-label--type-inline'>By submitting this form, you agree to receive content and event invitations from us to help you grow your business. If you do not want to receive such messages, tick here.<\/label>\n\t\t\t\t\t\t\t<\/div><\/div><\/div><\/fieldset><\/div><\/div>\n        <div class='gform-footer gform_footer top_label'> <button type=\"submit\" id=\"gform_submit_button_2453\" class=\"gform_button button\" onclick=\"gform.submission.handleButtonClick(this);\" data-submission-type=\"submit\"><span class=\"gform_submit_button__text\">Submit Now<\/span><\/button> <input type='hidden' name='gform_ajax' value='form_id=2453&amp;title=&amp;description=&amp;tabindex=0&amp;theme=gravity-theme&amp;hash=ec2463697d0d9cef7b71236ae60964c7' \/>\n            <input type='hidden' class='gform_hidden' name='gform_submission_method' data-js='gform_submission_method_2453' value='iframe' \/>\n            <input type='hidden' class='gform_hidden' name='gform_theme' data-js='gform_theme_2453' id='gform_theme_2453' value='gravity-theme' \/>\n            <input type='hidden' class='gform_hidden' name='gform_style_settings' data-js='gform_style_settings_2453' id='gform_style_settings_2453' value='' \/>\n            <input type='hidden' class='gform_hidden' name='is_submit_2453' value='1' \/>\n            <input type='hidden' class='gform_hidden' name='gform_submit' value='2453' \/>\n            \n            <input type='hidden' class='gform_hidden' name='gform_currency' data-currency='GBP' value='W+5MD\/6AKocBBBJ0sjOygT6L7GAErSKPoiXXGObn62yVVB0+SrhnVKDeNajmMhNhtLG2OBCXlGyPfRoycl3mdEXyDeTmMqmk4Vp\/fmHjViHvtSU=' \/>\n            <input type='hidden' class='gform_hidden' name='gform_unique_id' value='' \/>\n            <input type='hidden' class='gform_hidden' name='state_2453' value='WyJ7XCIxNFwiOltcIjIyODY0N2ViMWU3NTcxZjA4YTY4NGJmMDcwMTk3Y2I0XCIsXCJiMzk3YmQ1MDBmMmFjNjk1ODE4MzdmNTBhYTA2MzQ0OFwiLFwiNGYyNGZkZGEwMzlkNDUxMWFhZGE1NGYwZmQwZmNiZTdcIixcIjUyMmJkMDE2M2I2ZmEwOTI3NDZhZjU5YTg0ZmM1NDk5XCIsXCIzODRlNjk1YjQxMTAzMWFiYmQ2ODEyMGYyZWFhMDYyNlwiLFwiYjkzNDcwNTE2MjkxOGRjZWViMjQzNzRjNmE0NGVmNTlcIixcIjQxMTliODZhMzVjYzJiMWViNDZiMmQ4NjRlNGUzZmNjXCJdfSIsIjQ3MjNiMzA2ZDIyZGVkODA2N2YyMjYyOThkYzI1ODVmIl0=' \/>\n            <input type='hidden' autocomplete='off' class='gform_hidden' name='gform_target_page_number_2453' id='gform_target_page_number_2453' value='0' \/>\n            <input type='hidden' autocomplete='off' class='gform_hidden' name='gform_source_page_number_2453' id='gform_source_page_number_2453' value='1' \/>\n            <input type='hidden' name='gform_field_values' value='' \/>\n            \n        <\/div>\n                        <\/form>\n                        <\/div>\n\t\t                <iframe style='display:none;width:0px;height:0px;' src='about:blank' name='gform_ajax_frame_2453' id='gform_ajax_frame_2453' title='This iframe contains the logic required to handle Ajax powered Gravity Forms.'><\/iframe>\n\t\t                <script>\ngform.initializeOnLoaded( function() {gformInitSpinner( 2453, 'https:\/\/legalvision.co.uk\/wp-content\/themes\/legalv-v6\/img\/spinner.svg', true );jQuery('#gform_ajax_frame_2453').on('load',function(){var contents = jQuery(this).contents().find('*').html();var is_postback = contents.indexOf('GF_AJAX_POSTBACK') >= 0;if(!is_postback){return;}var form_content = jQuery(this).contents().find('#gform_wrapper_2453');var is_confirmation = jQuery(this).contents().find('#gform_confirmation_wrapper_2453').length > 0;var is_redirect = contents.indexOf('gformRedirect(){') >= 0;var is_form = form_content.length > 0 && ! is_redirect && ! is_confirmation;var mt = parseInt(jQuery('html').css('margin-top'), 10) + parseInt(jQuery('body').css('margin-top'), 10) + 100;if(is_form){form_content.find('form').css('opacity', 0);jQuery('#gform_wrapper_2453').html(form_content.html());if(form_content.hasClass('gform_validation_error')){jQuery('#gform_wrapper_2453').addClass('gform_validation_error');} else {jQuery('#gform_wrapper_2453').removeClass('gform_validation_error');}setTimeout( function() { \/* delay the scroll by 50 milliseconds to fix a bug in chrome *\/ jQuery(document).scrollTop(jQuery('#gform_wrapper_2453').offset().top - mt); }, 50 );if(window['gformInitDatepicker']) {gformInitDatepicker();}if(window['gformInitPriceFields']) {gformInitPriceFields();}var current_page = jQuery('#gform_source_page_number_2453').val();gformInitSpinner( 2453, 'https:\/\/legalvision.co.uk\/wp-content\/themes\/legalv-v6\/img\/spinner.svg', true );jQuery(document).trigger('gform_page_loaded', [2453, current_page]);window['gf_submitting_2453'] = false;}else if(!is_redirect){var confirmation_content = jQuery(this).contents().find('.GF_AJAX_POSTBACK').html();if(!confirmation_content){confirmation_content = contents;}jQuery('#gform_wrapper_2453').replaceWith(confirmation_content);jQuery(document).scrollTop(jQuery('#gf_2453').offset().top - mt);jQuery(document).trigger('gform_confirmation_loaded', [2453]);window['gf_submitting_2453'] = false;wp.a11y.speak(jQuery('#gform_confirmation_message_2453').text());}else{jQuery('#gform_2453').append(contents);if(window['gformRedirect']) {gformRedirect();}}jQuery(document).trigger(\"gform_pre_post_render\", [{ formId: \"2453\", currentPage: \"current_page\", abort: function() { this.preventDefault(); } }]);        if (event && event.defaultPrevented) {                return;        }        const gformWrapperDiv = document.getElementById( \"gform_wrapper_2453\" );        if ( gformWrapperDiv ) {            const visibilitySpan = document.createElement( \"span\" );            visibilitySpan.id = \"gform_visibility_test_2453\";            gformWrapperDiv.insertAdjacentElement( \"afterend\", visibilitySpan );        }        const visibilityTestDiv = document.getElementById( \"gform_visibility_test_2453\" );        let postRenderFired = false;        function triggerPostRender() {            if ( postRenderFired ) {                return;            }            postRenderFired = true;            gform.core.triggerPostRenderEvents( 2453, current_page );            if ( visibilityTestDiv ) {                visibilityTestDiv.parentNode.removeChild( visibilityTestDiv );            }        }        function debounce( func, wait, immediate ) {            var timeout;            return function() {                var context = this, args = arguments;                var later = function() {                    timeout = null;                    if ( !immediate ) func.apply( context, args );                };                var callNow = immediate && !timeout;                clearTimeout( timeout );                timeout = setTimeout( later, wait );                if ( callNow ) func.apply( context, args );            };        }        const debouncedTriggerPostRender = debounce( function() {            triggerPostRender();        }, 200 );        if ( visibilityTestDiv && visibilityTestDiv.offsetParent === null ) {            const observer = new MutationObserver( ( mutations ) => {                mutations.forEach( ( mutation ) => {                    if ( mutation.type === 'attributes' && visibilityTestDiv.offsetParent !== null ) {                        debouncedTriggerPostRender();                        observer.disconnect();                    }                });            });            observer.observe( document.body, {                attributes: true,                childList: false,                subtree: true,                attributeFilter: [ 'style', 'class' ],            });        } else {            triggerPostRender();        }    } );} );\n<\/script>\n<\/div>\n<\/div>\n<div id=\"content-next\"><!-- scroll anchor --><\/div>\n<h2 class=\"wp-block-heading\">2. Ask for Further Information <\/h2>\n\n\n\n<p>Make sure you know exactly what the individual wants to receive. For example, while they may ask for all information about themselves, they may only be interested in information on a particular subject or relating to a certain matter. If you have a significant amount of information about an individual, it is good practice to ask for further information to narrow your scope of search.<\/p>\n\n\n\n<p>For example, suppose an individual asks for all information about them. Yet, upon being asked for the particular materials sought, they are only requesting emails between themselves and an individual they are in dispute with. In that case, you can potentially limit your search to those emails alone. This prevents your organisation from organising and sending every mention of the individual on your system.<\/p>\n\n\n\n<div  class=\"box box--icon box--info\">\n    <p>You can &#8216;pause&#8217; the one-month deadline while waiting for the individual to provide further information. So, if you wait three days for a response, your deadline to fully handle the SAR becomes one month and three days.<\/p>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">3. Search and Redact Information<\/h2>\n\n\n\n<p>Once you know what the individual is seeking, you can search your relevant systems. Depending on the nature of the SAR, this may involve checking:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>your IT system;<\/li><li>your email server;<\/li><li>personnel files;&nbsp;<\/li><li>written materials (for example, within filing cabinets); or<\/li><li>digital messages and files on work devices.<\/li><\/ul>\n\n\n\n<p>Sometimes a document may mention the requester alongside other individuals. In that case, you should redact the names and information belonging to others. Redacting information involves placing a large black bar over other individuals&#8217; data, so someone else cannot read it, thus protecting their confidentiality. Some business owners seek legal advice on when they can and cannot redact confidential information.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">4. Respond in One Month<\/h2>\n\n\n\n<p>Usually, your business will have one calendar month to respond to a SAR. This is subject to being able to &#8216;pause&#8217; the clock whilst awaiting additional information, as mentioned above. However, your organisation may also extend the one calendar month deadline in the following situations:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>a complex SAR; or<\/li><li>receiving several <a href=\"https:\/\/legalvision.co.uk\/corporations\/complying-with-gdpr\/\">GDPR related requests<\/a> from the same individual simultaneously (such as an employee who requests two SARs and makes an application for erasure).<\/li><\/ul>\n\n\n\n<div  class=\"box box--icon box--info\">\n    <p>Many business owners wish to explore the tactic of labelling a SAR as &#8216;complex&#8217; and buying more time. In reality, this is a limited exemption for exceptionally complicated SAR requests. Simply stating the SAR is complex without good reason is a breach of data protection rules and exposes your company to ICO fines.<\/p>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">An Example<\/h2>\n\n\n\n<p>Let us say you receive a written SAR from an employee on 5th July. In this case, the employee is asking for all personal information held about them. Your company should acknowledge receipt and then ask for further information as to the reason for the request and what particular documents they are looking for.<\/p>\n\n\n\n<p>Five days later, the employee returns to explain that they are looking for payment and pension information to help them with an ongoing dispute with their pension provider. The five days waiting for a response means that your organisation now has one month and five days to respond, extending the deadline to 10th August.&nbsp;<\/p>\n\n\n\n<p>Now that you know they are looking for documents to support a pension dispute, you can confirm with the individual that you intend to provide them with documents for this purpose. This means your company can limit its search to payment, invoice and pension information. Meanwhile, you may exclude other emails, telephone call recordings and other materials relating to their actual work.<\/p>\n\n\n\n<p>Your organisation may likely provide them with a copy of their: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>employment contract; <\/li><li>any pension policies or pension information leaflets; and <\/li><li>all emails on the work system between the employee and pension provider.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Key Takeaways<\/h2>\n\n\n\n<p>Your business must safely handle an SAR to avoid breaching data protection law. This will also prevent your business from receiving a non-compliance fine from the <a href=\"https:\/\/www.google.com\/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=&amp;cad=rja&amp;uact=8&amp;ved=2ahUKEwjhqe_7gJP5AhX84XMBHbj7C-MQFnoECB4QAQ&amp;url=https%3A%2F%2Fico.org.uk%2F&amp;usg=AOvVaw0fd0zwJUih5t8Qr5gDI_uT\">Information Commissioner&#8217;s Office<\/a> (ICO). Some business owners obtain legal assistance to ensure they fully comply with data protection rules. Although, this depends on the complexity of the SAR request. Additionally, you may require assistance if the individual has lodged it to assist in an active legal claim against the organisation.<\/p>\n\n\n\n<p>If you need help to handle an SAR you have received, our experienced <a href=\"https:\/\/legalvision.co.uk\/it-lawyers-lp\/\">Data, Privacy and IT lawyers<\/a> can assist as part of our LegalVision membership. For a low monthly fee, you will have unlimited access to lawyers to answer your questions and draft and review your documents. Call us today on <a href=\"tel:+448081968584\" class=\"AVANSERnumber dynamic-number\">0808 196 8584<\/a> or visit our <a href=\"https:\/\/legalvision.co.uk\/membership\/\">membership page<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1658382220999\"><strong class=\"schema-faq-question\"><strong>Can my company refuse if an employee is only using a SAR to help a Tribunal action?<\/strong><\/strong> <p class=\"schema-faq-answer\">No. The SAR&#8217;s purpose is irrelevant, and your company must carry it out whether its relationship with the requester is positive or negative.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1658382243629\"><strong class=\"schema-faq-question\"><strong>Can my business charge any form of fee for carrying out a SAR?<\/strong><\/strong> <p class=\"schema-faq-answer\">It can only do so in limited circumstances. Fees are limited to requests which are &#8216;excessive&#8217; (for example, insisting on wanting 40 years&#8217; worth of records when only in dispute with you over the last 6 months) or where the individual requests multiple copies.<\/p> <\/div> <\/div>\n","protected":false},"excerpt":{"rendered":"<p>Your business will likely handle a significant amount of data relating to employees, customers and suppliers. Therefore, you must comply with data protection requirements to avoid fines. The General Data Protection Regulation (GDPR) contains many data protection rules, including the right for an individual to file a Subject Access Request (SAR). These are also known<a href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/\">Continue reading <span class=\"sr-only\">&#8220;Four Tips to Safely Handle Subject Access Requests in England&#8221;<\/span><\/a><\/p>\n","protected":false},"author":13349,"featured_media":3133,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"1790,3678,1611,2650,172007,2537","_relevanssi_noindex_reason":"","editor_notices":[],"footnotes":""},"categories":[27],"tags":[20,21,366,642,746,799],"class_list":["post-172454","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-privacy-it","tag-small-business","tag-medium-business","tag-data-privacy","tag-gdpr-complicance","tag-ico","tag-subject-access-request"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to Safely Handle a Subject Access Request (SAR) | LegalVision UK<\/title>\n<meta name=\"description\" content=\"This article provides tips for your business to safely handle and respond to a subject access request (SAR) and avoid fines.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Safely Handle a Subject Access Request (SAR) | LegalVision UK\" \/>\n<meta property=\"og:description\" content=\"This article provides tips for your business to safely handle and respond to a subject access request (SAR) and avoid fines.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/\" \/>\n<meta property=\"og:site_name\" content=\"LegalVision UK\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/LegalVision\" \/>\n<meta property=\"article:published_time\" content=\"2022-07-21T06:32:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-07-25T02:37:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121628\/business-image-052274.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1089\" \/>\n\t<meta property=\"og:image:height\" content=\"726\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Thomas Sutherland\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@LegalVision_law\" \/>\n<meta name=\"twitter:site\" content=\"@LegalVision_law\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Thomas Sutherland\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/\"},\"author\":{\"name\":\"Thomas Sutherland\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/#\\\/schema\\\/person\\\/46d22f7d1b4ba321fe5b1cdc648cc5d2\"},\"headline\":\"Four Tips to Safely Handle Subject Access Requests in England\",\"datePublished\":\"2022-07-21T06:32:51+00:00\",\"dateModified\":\"2022-07-25T02:37:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/\"},\"wordCount\":1075,\"image\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/img.legalvision.com.au\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2022\\\/05\\\/24121628\\\/business-image-052274.jpg\",\"keywords\":[\"small business\",\"medium business\",\"data privacy\",\"gdpr complicance\",\"ICO\",\"subject access request\"],\"articleSection\":[\"Data, Privacy and IT Articles\"],\"inLanguage\":\"en-GB\"},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/\",\"url\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/\",\"name\":\"How to Safely Handle a Subject Access Request (SAR) | LegalVision UK\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/img.legalvision.com.au\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2022\\\/05\\\/24121628\\\/business-image-052274.jpg\",\"datePublished\":\"2022-07-21T06:32:51+00:00\",\"dateModified\":\"2022-07-25T02:37:58+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/#\\\/schema\\\/person\\\/46d22f7d1b4ba321fe5b1cdc648cc5d2\"},\"description\":\"This article provides tips for your business to safely handle and respond to a subject access request (SAR) and avoid fines.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/#faq-question-1658382220999\"},{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/#faq-question-1658382243629\"}],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/#primaryimage\",\"url\":\"https:\\\/\\\/img.legalvision.com.au\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2022\\\/05\\\/24121628\\\/business-image-052274.jpg\",\"contentUrl\":\"https:\\\/\\\/img.legalvision.com.au\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2022\\\/05\\\/24121628\\\/business-image-052274.jpg\",\"width\":1089,\"height\":726,\"caption\":\"What Are Share Capital Requirements for Small Businesses? | LegalVision UK\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/legalvision.co.uk\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data, Privacy and IT Articles\",\"item\":\"https:\\\/\\\/legalvision.co.uk\\\/category\\\/data-privacy-it\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Four Tips to Safely Handle Subject Access Requests in England\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/#website\",\"url\":\"https:\\\/\\\/legalvision.co.uk\\\/\",\"name\":\"LegalVision UK\",\"description\":\"LegalVision is a commercial law firm in the UK with a commitment to innovation\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/legalvision.co.uk\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/#\\\/schema\\\/person\\\/46d22f7d1b4ba321fe5b1cdc648cc5d2\",\"name\":\"Thomas Sutherland\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2022\\\/05\\\/cropped-Thomas-Sutherland-96x96.jpg\",\"url\":\"https:\\\/\\\/legalvision.co.uk\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2022\\\/05\\\/cropped-Thomas-Sutherland-96x96.jpg\",\"contentUrl\":\"https:\\\/\\\/legalvision.co.uk\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2022\\\/05\\\/cropped-Thomas-Sutherland-96x96.jpg\",\"caption\":\"Thomas Sutherland\"},\"description\":\"Tom is an Expert Legal Contributor for LegalVision. He has particular expertise in Commercial and Employment litigation, as well as data protection and privacy regulations. He is a qualified Solicitor in England and Wales and has a decade of legal experience, including advocacy within civil courts and Tribunals. Tom specialises in civil and employment litigation. He has extensive experience in advising employers and companies as to the requirements of employment law and data protection rules, as well as day-to-day advice on smooth running from a commercial perspective. Qualifications: Professional Skills Course - Law, University of Law; Legal Practice Course - Law, College of Law; Bachelor of Laws, University of Southampton.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/tom-sutherland-72b4509b\\\/\"],\"url\":\"https:\\\/\\\/legalvision.co.uk\\\/author\\\/thomassutherland\\\/\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/#faq-question-1658382220999\",\"name\":\"Can my company refuse if an employee is only using a SAR to help a Tribunal action?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. The SAR's purpose is irrelevant, and your company must carry it out whether its relationship with the requester is positive or negative.\",\"inLanguage\":\"en-GB\"},\"inLanguage\":\"en-GB\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/safely-handle-sar\\\/#faq-question-1658382243629\",\"name\":\"Can my business charge any form of fee for carrying out a SAR?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It can only do so in limited circumstances. Fees are limited to requests which are 'excessive' (for example, insisting on wanting 40 years' worth of records when only in dispute with you over the last 6 months) or where the individual requests multiple copies.\",\"inLanguage\":\"en-GB\"},\"inLanguage\":\"en-GB\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Safely Handle a Subject Access Request (SAR) | LegalVision UK","description":"This article provides tips for your business to safely handle and respond to a subject access request (SAR) and avoid fines.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/","og_locale":"en_GB","og_type":"article","og_title":"How to Safely Handle a Subject Access Request (SAR) | LegalVision UK","og_description":"This article provides tips for your business to safely handle and respond to a subject access request (SAR) and avoid fines.","og_url":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/","og_site_name":"LegalVision UK","article_publisher":"https:\/\/www.facebook.com\/LegalVision","article_published_time":"2022-07-21T06:32:51+00:00","article_modified_time":"2022-07-25T02:37:58+00:00","og_image":[{"width":1089,"height":726,"url":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121628\/business-image-052274.jpg","type":"image\/jpeg"}],"author":"Thomas Sutherland","twitter_card":"summary_large_image","twitter_creator":"@LegalVision_law","twitter_site":"@LegalVision_law","twitter_misc":{"Written by":"Thomas Sutherland","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/#article","isPartOf":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/"},"author":{"name":"Thomas Sutherland","@id":"https:\/\/legalvision.co.uk\/#\/schema\/person\/46d22f7d1b4ba321fe5b1cdc648cc5d2"},"headline":"Four Tips to Safely Handle Subject Access Requests in England","datePublished":"2022-07-21T06:32:51+00:00","dateModified":"2022-07-25T02:37:58+00:00","mainEntityOfPage":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/"},"wordCount":1075,"image":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/#primaryimage"},"thumbnailUrl":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121628\/business-image-052274.jpg","keywords":["small business","medium business","data privacy","gdpr complicance","ICO","subject access request"],"articleSection":["Data, Privacy and IT Articles"],"inLanguage":"en-GB"},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/","url":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/","name":"How to Safely Handle a Subject Access Request (SAR) | LegalVision UK","isPartOf":{"@id":"https:\/\/legalvision.co.uk\/#website"},"primaryImageOfPage":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/#primaryimage"},"image":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/#primaryimage"},"thumbnailUrl":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121628\/business-image-052274.jpg","datePublished":"2022-07-21T06:32:51+00:00","dateModified":"2022-07-25T02:37:58+00:00","author":{"@id":"https:\/\/legalvision.co.uk\/#\/schema\/person\/46d22f7d1b4ba321fe5b1cdc648cc5d2"},"description":"This article provides tips for your business to safely handle and respond to a subject access request (SAR) and avoid fines.","breadcrumb":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/#faq-question-1658382220999"},{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/#faq-question-1658382243629"}],"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/#primaryimage","url":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121628\/business-image-052274.jpg","contentUrl":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121628\/business-image-052274.jpg","width":1089,"height":726,"caption":"What Are Share Capital Requirements for Small Businesses? | LegalVision UK"},{"@type":"BreadcrumbList","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/legalvision.co.uk\/"},{"@type":"ListItem","position":2,"name":"Data, Privacy and IT Articles","item":"https:\/\/legalvision.co.uk\/category\/data-privacy-it\/"},{"@type":"ListItem","position":3,"name":"Four Tips to Safely Handle Subject Access Requests in England"}]},{"@type":"WebSite","@id":"https:\/\/legalvision.co.uk\/#website","url":"https:\/\/legalvision.co.uk\/","name":"LegalVision UK","description":"LegalVision is a commercial law firm in the UK with a commitment to innovation","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/legalvision.co.uk\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/legalvision.co.uk\/#\/schema\/person\/46d22f7d1b4ba321fe5b1cdc648cc5d2","name":"Thomas Sutherland","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/legalvision.co.uk\/wp-content\/uploads\/sites\/4\/2022\/05\/cropped-Thomas-Sutherland-96x96.jpg","url":"https:\/\/legalvision.co.uk\/wp-content\/uploads\/sites\/4\/2022\/05\/cropped-Thomas-Sutherland-96x96.jpg","contentUrl":"https:\/\/legalvision.co.uk\/wp-content\/uploads\/sites\/4\/2022\/05\/cropped-Thomas-Sutherland-96x96.jpg","caption":"Thomas Sutherland"},"description":"Tom is an Expert Legal Contributor for LegalVision. He has particular expertise in Commercial and Employment litigation, as well as data protection and privacy regulations. He is a qualified Solicitor in England and Wales and has a decade of legal experience, including advocacy within civil courts and Tribunals. Tom specialises in civil and employment litigation. He has extensive experience in advising employers and companies as to the requirements of employment law and data protection rules, as well as day-to-day advice on smooth running from a commercial perspective. Qualifications: Professional Skills Course - Law, University of Law; Legal Practice Course - Law, College of Law; Bachelor of Laws, University of Southampton.","sameAs":["https:\/\/www.linkedin.com\/in\/tom-sutherland-72b4509b\/"],"url":"https:\/\/legalvision.co.uk\/author\/thomassutherland\/"},{"@type":"Question","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/#faq-question-1658382220999","name":"Can my company refuse if an employee is only using a SAR to help a Tribunal action?","acceptedAnswer":{"@type":"Answer","text":"No. The SAR's purpose is irrelevant, and your company must carry it out whether its relationship with the requester is positive or negative.","inLanguage":"en-GB"},"inLanguage":"en-GB"},{"@type":"Question","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/#faq-question-1658382243629","name":"Can my business charge any form of fee for carrying out a SAR?","acceptedAnswer":{"@type":"Answer","text":"It can only do so in limited circumstances. Fees are limited to requests which are 'excessive' (for example, insisting on wanting 40 years' worth of records when only in dispute with you over the last 6 months) or where the individual requests multiple copies.","inLanguage":"en-GB"},"inLanguage":"en-GB"}]}},"_links":{"self":[{"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/posts\/172454","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/users\/13349"}],"replies":[{"embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/comments?post=172454"}],"version-history":[{"count":21,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/posts\/172454\/revisions"}],"predecessor-version":[{"id":172757,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/posts\/172454\/revisions\/172757"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/media\/3133"}],"wp:attachment":[{"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/media?parent=172454"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/categories?post=172454"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/tags?post=172454"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}