How long do I have to respond to subject access requests?
Under GDPR, you have a month to respond to any request. In that time, you should make sure you have positively confirmed the request is genuinely from the person who made the request, then respond. If they’re requesting data, then collate and send the information (you might need to ‘redact’ or blank out certain bits that affect the privacy of others). Remember that you have to include any information that your data processors are also storing about that person.
For requests to erase or amend information it’s pretty similar. You have a month to respond - which is why it’s important to have a good understanding of where all your organisation’s personal data is being stored and have contracts in place that require data processors to respond promptly.
GDPR subject access request template
Astrid provides a training module for staff, with individual videos and questions addressing the key aspects of data protection and GDPR including subject access requests.
We know it can be hard to train staff in the detailed requirements of data requests so we also provide a special subject access request template form that guides you through the right process and keeps a record of the decisions you’ve made and responses you provide to requests.
Subscribe to Astrid today and receive all the guidance you need to protect personal data and become GDPR compliant.