Policy

GDPR Procedure

Purpose

"This document defines the process by which RGA responds to data subject rights requests under the UK GDPR and Data Protection Act 2018."

Scope

The procedure applies to all personal data processed by the consultancy and all data subjects including clients, suppliers, employees, contractors, and other individuals.

Data Subject Rights Covered

RGA supports:

  • Right of access (Subject Access Request – SAR)
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object
  • Rights related to automated decision-making (where applicable)

Roles and Responsibilities

The Data Protection Lead acts as primary contact, assesses validity and scope of requests, coordinates responses, and maintains documentation. Staff must promptly forward requests to this individual.

Requests may arrive via email, written correspondence, or verbal communication. "All staff must treat any expression of a data subject right as a valid request, even if informal."

Request Handling Process

  1. Log the request with date, type, requestor details, and deadline
  2. "Confirm the identity of the requestor before releasing or modifying data"
  3. Assess which right is being exercised and identify relevant systems
  4. "Retrieve relevant personal data securely" and review for exemptions
  5. Final response reviewed by Data Protection Lead, delivered securely
  6. Update logs and retain correspondence

Timeframes

"Requests are responded to within one calendar month of receipt" with possible extensions up to two additional months for complex cases.

Refusals and Limitations

Requests may be refused where manifestly unfounded, excessive, legally prohibited, or containing third-party information. "All refusals must be documented and justified."

Data Security

"All data is processed securely and confidentially" with access restricted to authorised personnel using secure storage and transmission methods.

Record Keeping

Maintained records include request logs, identity verification evidence, internal assessments, and response copies.

Training and Awareness

"All staff receive periodic awareness training on GDPR data subject rights."

Review and Maintenance

"This procedure is reviewed annually or following regulatory change."

← Back to Policies