All MRS websites use cookies to help us improve our services. Any data collected is anonymised. If you continue using this site without accepting cookies you may experience some performance issues. Read about our cookies here.
To enlarge video please either pause the video and then press the F key on your keyboard or select full screen button option located on the bottom right of the video.
You are currently not logged in. Any progress made will be lost.
New individual rights
The key new individual rights are:
Strengthened individual rights
The strengthened individual rights are:
o Contact details of Data Protection Officers (if applicable)
o Data retention periods
o Contact details of data processors, controllers and third parties
o Purpose for collecting personal data
o Whether personal data is transferred
o Categories of personal data collected
One way to communicate this information is via Data Protection Policies, notices and also recruitment documentation.
All of these rights need to be promoted and proactively communicated to individuals (via recruitment documentation for example), and how individuals can easily exercise their rights.
Individuals have the right to access their personal data. This is commonly referred to as subject access. Individuals can make a subject access request verbally or in writing. You have one month to respond to a request. You cannot charge a fee to deal with a request in most circumstances.
If the data subject is physically unable to make the request in writing then an exception can be made to accept a verbal request under the Disability Discrimination Act 1995. Even if the data subject does not explicitly mention the Data Protection Act you must still treat their request as a valid claim if it is clear they are asking for their personal data.
Individuals have the right to confirmation that you are processing their personal data; a copy of their personal data; and other relevant information such as the purposes of the processing, recipients of the data, retention periods, categories of data being collected (e.g. special category data); plus the right to complain to the ICO, have the data rectified (if wrong), erased or restricted.
An individual is only entitled to their own personal data and not to other people's data (unless they are making the request on someone else's behalf). If an individual makes a request electronically you should provide the information in a commonly used digital format, unless the individual requests another format i.e. paper copies.
If sending participant data electronically remember the information must be sent securely e.g. using SFTP.
Transparency requirements
In order to be prepared for meeting any request for these rights you should consider for example:
Resources