The GDPR has been in place since 2018. Consumers are becoming more comfortable in exercising their rights of access, including requesting copies of their data and how this is used by businesses. In this article we aim to provide guidance on what steps to take should you receive a request for data. Am I required to respond to all requests for data ? No. The first thing to check is that the person making the request is authorized to do so. This is vital as providing personal data to someone who is not the subject is not only a breach of the GDPR/Data Protection Act, but can result in you being liable for compensation, a fine, or both. The first thing to do is to check the identity of the person making the request. Unless you are sufficiently familiar with the person to identify them from their voice or email, this should include obtaining proof of identity. If the person making the request is not the subject of the data, you should make sure that they are authorized to make the request. We strongly recommend obtaining written permission from the data subject specifically for the request or a general power of attorney. What do I have to provide? This can be split into two categories. The first is confirmation as to the types of data you hold and how you use it. For most members that will be the customer’s name and address, any payment data, and details either of the goods purchased or of the work undertaken to their vehicle. Most of the time this information will be held as part of the contract for accounting purposes and to assist with any future enquiries. Some members will also use the information for marketing purposes. Where possible any response to a subject access request should include this information. The second category is the actual data held. You are required to provide any data you hold that identifies the person concerned and any information about them. This can be invoices, data base entries or CCTV footage. Do I have to provide everything with a person’s name on? No. Whilst a person’s name will be personal data, this does not mean the whole content of any document becomes their personal data. There is no need to disclose the whole of an email, or any document just because they are addressed to an individual. Any content not related to an individual is not personal data and can be withheld/redacted. Here is an example straight from the Information Commissioner’s Office:- “An employee makes a SAR for all of the information you hold about them. During your search for their personal data, you find 2000 emails which the employee is copied into as a recipient. Other than their name and email address, the content of the emails does not relate to the employee or contain the employee’s personal data. You do not have to provide the employee with a copy of each email (with the personal information of third parties redacted). Since the only personal data which relates to them is their name and email address, it is sufficient to advise them that you identified their name and email address on 2000 emails and disclose to them the name contained on those emails, e.g. John Smith, and the email address contained on those emails, e.g. JohnSmith@org.co.uk . Alternatively, you could provide one email with other details redacted as a sample of the 2000 emails you hold. You should also clearly explain to the individual why this is the only information they are entitled to under the UK GDPR, but remember to provide them with supplementary information concerning the processing, e.g. retention periods for the emails. However, if any of the content within the email relates to the individual, you should provide them with a copy of the email itself, redacted if necessary.” What if the information I hold includes other people’s data? Where possible you should not disclose other people’s data in a subject access request. If you do not have the other person’s permission to disclose their data, we would not advise a disclosure. It is likely you hold a duty of confidentiality to that person as well as a duty under the GDPR/DPA regarding their data. If you cannot get consent and it is not reasonable to provide the information without it, then you should redact the other person’s information. How long do I have to respond? You are required to respond to a request for data within 30 days. However, it should be noted that this starts to run from when you hold sufficient information regarding the request. As such, if you need to obtain further identification or clarification as to the nature of the request the time limit will not start until you receive the substantive response. This time limit can be extended by a further 2 months if the request is particularly complex or part of a series of responses. However, this is the exception rather than the rule. Any responses that can be made within 30 days should be. Can I refuse a request for information? It is very unlikely that a request for information can be refused entirely. However, a request can be refused if it is excessive or if it is unfounded or unreasonable or vexatious. A request is not excessive just because a large amount of data has been asked. A request is likely to be excessive only if a person makes a number of repetitive or overlapping requests. it repeats or overlaps other recent requests. A request is likely to be unfounded or unreasonable or vexatious if you have reasonable grounds to believe the person making the request has no real interest in obtaining the information they have asked for and is only making the request to harass or cause expense to your business. For example, a request is made as part of a negotiation for compensation, and they offer to withdraw it if you settle their complaint. Can I charge a fee for providing the information? No. In Conclusion Whilst the GDPR / Data Protection Act 2018 require you to confirm what personal data you hold, how you process it and to provide a copy upon request within 30 days, this does not give a data subject a right to anything and everything with their name on it, or to make multiple requests for the same information. Data protection can be difficult to deal with. As always, this advice is general in nature and will need to be tailored to any one particular situation. As an RMI member you have access to the RMI Legal advice line, as well as a number of industry experts for your assistance. Should you find yourself in the situation above, contact us at any stage for advice and assistance as appropriate.