Close Menu
    What's Hot

    About Us

    Purchase Our Services

    Can personal data be processed outside of the UK and EU?

    LinkedIn X (Twitter)
    GDPR Subject Access Request HelpGDPR Subject Access Request Help
    • The ICO
    • About Us
    • Purchase
    LinkedIn X (Twitter)
    CONTACT
    • Home
    • Business

      Can personal data be processed outside of the UK and EU?

      Are there correct ways to respond to a GDPR subject access request?…

      When can a SAR be refused in full or in part?

      Do all businesses need to be compliant with the UK GDPR?

      Should you register your company with the ICO?

    • Personal

      Will the UK police respond to a GDPR subject access request?

      What does the UK GDPR mean for individuals?

      I don’t live in the UK or EU, what are my rights under GDPR?

      A company has not responded to my GDPR subject access request, what can I do?

      Dealing with unwanted and nuisance calls…

    • Technology

      A faulty server could be considered a breach of the GDPR…

      A glossary and explanation of GDPR terms

      Significant fines and breaches in the news…

      Why IT Security is at the core of good GDPR practice…

    • Purchase Our Services
    GDPR Subject Access Request HelpGDPR Subject Access Request Help
    Home » What you shouldn’t do when responding to a SAR…
    Business

    What you shouldn’t do when responding to a SAR…

    Martin Kayes, CISSPBy Martin Kayes, CISSPUpdated:April 15, 20242 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    When responding to a SAR you must consider whether the information you hold includes the personal details of, or infers the involvement or actions of any other parties, the GDPR says that when responding to a SAR;

    “The right to obtain a copy… …shall not adversely affect the rights and freedoms of others”.

    and

    “The right of access is not absolute – organisations can refuse or limit their response to SARs in some circumstances where exemptions may apply.”

    These are two extremely important points that should not be overlooked.

    A SAR is a request for a copy that individual’s personal data and their personal data alone, a response should not include anything that can identify another person, or imply any actions taken by another person (this second point is extremely important in relation to safeguarding and or legal action).

    Some examples of what you would not include in a SAR response:

    1. Any other person’s name, email address, telephone number, home or work address and so forth – i.e. anything that could identify another person. There are some occasions however, where sharing some data relating to another person is necessary, in which case you should seek that person’s express permission.

    2. Another person’s image, voice recordings or biometric information. CCTV is a good example of this – any other persons appearing in a video, or stills, would have to be obscured (censored) before it can be shared, or released to the public, so that other persons are not identifiable.

    3. Actions taken or information given that would identify others. For example, in a safeguarding situation if the other person is known to the individual (Data Subject) then you should not including descriptions of actions that the other person made. It is possible that the Data Subject may not have been previously aware of those actions, i.e. “…she then filed a complaint with the police”.

    4. There are also reasons relating to national security, public safety, prevention or detection or investigation of crime and also if the Data Subject is a minor or legally incapacitated.

    We have seperate post on this site which explains the specific, legal reasons that the GDPR allows a company to refuse a SAR request, or part thereof.

    business News
    Martin Kayes, CISSP
    • Website

    Related Posts

    Can personal data be processed outside of the UK and EU?

    Are there correct ways to respond to a GDPR subject access request?…

    When can a SAR be refused in full or in part?

    Do all businesses need to be compliant with the UK GDPR?

    Should you register your company with the ICO?

    What does the UK GDPR mean for organisations?

    Don't Miss
    Business

    Can personal data be processed outside of the UK and EU?

    By Martin Kayes, CISSP

    Yes, data can be processed internationally under the UK GDPR (General Data Protection Regulation). Under…

    Are there correct ways to respond to a GDPR subject access request?…

    When can a SAR be refused in full or in part?

    Will the UK police respond to a GDPR subject access request?

    Stay In Touch
    • LinkedIn
    • Twitter
    Specialist Investigations
    About Us
    About Us

    A trading style of Cobalt ICT Limited

    Providing affordable, professional help with GDPR, Subject Access Requests, Data Privacy and Cyber Essentials.

    Offering services and consultancy with PAYG and Monthly Retainer options

    Based in London

    We are based in London but for security reasons we do not publish our physical address.

    Our registered office is:
    c/o Kinnair & Company
    Aston House, 21 Redburn Road
    Newcastle Upon Tyne
    NE5 1NB

    A registered company in England and Wales. Registration Number 05484135

    Business Hours

    Monday - Friday
    9am - 5pm
    Terms and Conditions

    LinkedIn X (Twitter)
    • Home
    • Business
    • Personal
    • Technology
    • Fines & Breaches
    • GDPR News
    • Privacy Policy
    © 2025 Cobalt ICT Limited.

    Type above and press Enter to search. Press Esc to cancel.