Skip to main content

The Open Subject Access Standard 1.0

Status
Draft

Abstract

OSAS is an open standard for how an organisation handles a subject access request, from the ease of making one to the quality of the answer. It sets out testable criteria, grouped into domains under five principles, at three cumulative conformance levels: Level 1, Level 2, and Level 3.

Status of this document

This is a draft of version 1.0, published for comment. The criteria and their numbers may still change before 1.0 is final, so do not yet rely on them as stable. To comment on a criterion, contact us. For a plain-English introduction to OSAS, see the overview.

Reachable

Finding and Making a Request

A1 A Findable Privacy Notice

Level 1

Every page of the organisation's website links to its privacy notice.

Understanding A1

A2 A Signposted Route

Level 1

The privacy notice explains how to make a subject access request, including where to send it.

Understanding A2

A3 No Account Required

Level 1

Making a request does not require creating an account where the person does not already hold one.

Understanding A3

A4 No Mandated Route

Level 1

The organisation does not require a subject access request to be made through one particular route, such as a single form or online portal.

Understanding A4

A5 A Request in Any Form

Level 1

The organisation treats a request as valid however it is made, including verbally, and does not require it to use particular wording or to cite the law.

Understanding A5

A6 A Named Contact

Level 2

The privacy notice names a data-protection contact and a direct way to reach them.

A7 A Choice of Routes

Level 2

At least two routes exist to make a request, one of which is an email address for subject access requests or the data-protection contact.

A8 A Proportionate Request Form

Level 2

Where the organisation provides a request form, it asks for nothing beyond what is needed to identify the person and locate their data.

A9 A Request Made on Someone's Behalf

Level 2

The organisation accepts a request made by someone the person has authorised to act for them.

A10 The Right Explained

Level 3

The privacy notice explains what the right of access lets a person do, not only that the right exists.

A11 No Discouragement

Level 3

No step in making a request presents a message or question that urges the person to reconsider, narrow, or withdraw it.

Responsive

Acknowledgement and Timeline

B1 A Response Within the Time Limit

Level 1

The response is provided within one month of the request, or within an extended time limit the organisation has notified.

B2 An Extension Notified in Time

Level 1

Where the organisation extends the time limit, it tells the person within one month of the request.

B3 An Extension Explained

Level 1

Where the organisation extends the time limit, it states why the extension is needed.

B4 Acknowledgement of Receipt

Level 2

The organisation confirms to the person that it has received the request.

B5 A Stated Response Date

Level 2

The acknowledgement states the date by which the organisation will respond.

Identity Verification

C1 Verification Only on Reasonable Doubt

Level 1

The organisation requests identity verification only where it has a reasonable doubt about the identity of the person making the request.

C2 Proportionate Verification

Level 1

Where the organisation requests identity verification, it asks only for what is necessary to confirm the person's identity.

C3 Verification Explained

Level 2

Where the organisation requests identity verification, it states why the verification is needed.

C4 The Effect on the Time Limit Stated

Level 2

Where the organisation requests identity verification, it states how this affects the time limit for responding.

C5 Verification Data Not Retained

Level 3

The organisation states that identity information provided for verification is used only to confirm identity and is not kept afterward.

Complete

Completeness and Scope

D1 Confirmation of Processing

Level 1

The response states whether or not the organisation processes the person's personal data.

D2 A Copy of the Data

Level 1

Where the organisation processes the person's personal data, the response includes a copy of it.

D3 The Systems Searched

Level 2

The response states which systems or records the organisation searched for the person's personal data.

D4 The Period Searched

Level 2

The response states the date range the search covered.

D5 Any Limit on the Search

Level 2

Where the organisation limited the scope of its search, the response states what it did not search, and why.

D6 A Request Not Narrowed Without Agreement

Level 2

Where the organisation asks the person to specify what they want, it does not treat the request as withdrawn or narrowed if the person does not reply.

D7 Unstructured Records Included

Level 3

The response states whether the search covered unstructured records, such as emails and documents, and not only structured databases.

Supplementary Information

E1 The Purposes

Level 1

The response states the purposes for which the organisation processes the person's personal data.

E2 The Categories of Data

Level 1

The response states the categories of the person's personal data that the organisation processes.

E3 The Recipients

Level 1

The response states the recipients, or categories of recipient, to whom the organisation has disclosed or will disclose the person's personal data.

E4 The Retention Period

Level 1

The response states how long the organisation will keep the person's personal data, or the criteria it uses to decide.

E5 The Person's Other Rights

Level 1

The response states the person's rights to rectification, erasure, restriction, and objection.

E6 The Right to Complain

Level 1

The response states that the person can complain to the Information Commissioner's Office.

E7 The Source of the Data

Level 1

Where the organisation did not collect the personal data from the person, the response states any available information about its source.

E8 Automated Decision-Making

Level 1

The response states whether the organisation makes solely automated decisions about the person, including profiling.

E9 The Logic Explained

Level 1

Where the organisation makes solely automated decisions about the person, the response gives meaningful information about the logic involved, and the significance and likely consequences for the person.

E10 Safeguards for Transfers Abroad

Level 1

Where the organisation transfers the person's personal data outside the UK, the response states the safeguards it relies on for the transfer.

E11 Recipients Named

Level 2

The response names the actual recipients of the person's personal data, not only categories of recipient, unless naming a recipient is not possible.

E12 Written for the Person

Level 2

The supplementary information describes how the organisation processes the person's own data, not only what its general privacy notice says.

E13 A Specific Retention Period

Level 3

Where a retention period can be determined, the response gives that period, not only the criteria for deciding it.

Intelligible

Intelligibility

F1 Codes and Terms Explained

Level 1

Where the response or the copy uses codes, abbreviations, or technical terms, the response explains what they mean.

F2 What Each Part Is

Level 1

The response identifies what each part of the copy is.

F3 Organised to Navigate

Level 2

The response is organised so the person can find their way through it, rather than presented as an undifferentiated bundle.

F4 Clear to a Child

Level 2

Where the response is addressed to a child, it uses language the child can understand.

F5 A Guide to the Response

Level 3

The response includes a short guide to what it contains and how it is arranged.

F6 Plain Language

Level 3

A person without specialist knowledge of the organisation's systems or of data-protection law can understand the response.

Format and Delivery

G1 Provided Free

Level 1

The organisation provides the response free of charge.

G2 Electronic by Default

Level 1

Where the person made the request by electronic means, the response is provided in a commonly used electronic form, unless the person asked for another form.

G3 Delivered Securely

Level 1

The organisation delivers the response by a means that protects it from being read by anyone other than the person.

G4 A Usable Format

Level 2

The response is provided in a format the person can open and reuse with commonly available software, not as images of the personal data or a file locked against reuse.

G5 No Barrier to Collection

Level 2

Receiving the response does not require creating an account where the person does not already hold one, or using one particular portal.

G6 An Accessible Format on Request

Level 2

Where the person needs the response in an accessible format, the organisation provides it in that format.

G7 Accessible by Default

Level 3

The response meets recognised accessibility standards, so a person using assistive technology can read it without having to ask for an alternative.

Accountable

Redaction and Exemptions

H1 Refusal Explained

Level 1

Where the organisation refuses a request in whole or in part, the response states the reasons.

H2 How to Challenge a Refusal

Level 1

Where the organisation refuses a request in whole or in part, the response tells the person they can seek a remedy from the Information Commissioner's Office or a court.

H3 Redaction Shown

Level 1

Where the organisation redacts information from the copy, the response shows that something has been redacted.

H4 The Ground Stated

Level 2

For each redaction, the response states the ground relied on.

H5 Third-Party Data Limited

Level 2

Where the organisation redacts another person's personal data, it redacts only that, and not the person's own personal data alongside it.

H6 Exemptions Applied Narrowly

Level 2

Where an exemption covers only part of a record, the organisation discloses the rest.

H7 A Charge or Rejection Justified

Level 2

Where the organisation charges a fee, or rejects the request as manifestly unfounded or excessive, the response states why.

H8 The Reason Explained

Level 3

Where the organisation relies on an exemption, the response explains why it applies to the redacted data, not only which exemption it is.

Glossary

Each term below has one meaning across the whole standard, and every criterion uses it verbatim. Where a term has a common name in law or practice, that name is noted but not used in the criteria.

acknowledgement
The organisation's confirmation to the person that it has received the request.
copy
The reproduction of the person's personal data that the organisation provides in the response, as distinct from the supplementary information about it.
data-protection contact
The person or team the organisation identifies as responsible for data-protection matters, including requests. Where the organisation has appointed a Data Protection Officer, the data-protection contact is that officer.
exemption
A legal ground on which the organisation may withhold some personal data from the response.
extension
An addition to the time limit that the law allows where a request is complex, or where the organisation has received a number of requests from the same person. An extension can be up to two further months.
identity verification
Steps the organisation takes to confirm that the person making the request is who they say they are. The information the organisation asks for to do this is the person's identity information.
the organisationalso known as controller
The body that determines the purposes and means of processing the personal data, and to which the request is made.
the personalso known as data subject
The identified or identifiable individual the personal data is about, who is exercising the right of access.
personal data
Information relating to the person, from which they can be identified directly or indirectly.
privacy notice
The public document in which the organisation explains how and why it processes personal data, and how a person can exercise their rights.
recipient
A person or organisation to whom the organisation discloses the person's personal data.
redaction
The removal or obscuring of information from the copy, such as another person's data or material an exemption covers.
request form
A form the organisation provides for making a request.
the response
What the organisation provides in answer to the request: confirmation of whether it processes the person's data, a copy of that data, and the supplementary information about the processing.
the right of access
The person's right to obtain from the organisation confirmation that their personal data is being processed, a copy of that data, and the supplementary information about the processing. It is set out in Article 15 of the UK GDPR.
route
A means by which the person can make a request, such as an email address, a form, a postal address, or a feature within an account.
The steps the organisation takes to find the person's personal data across its systems and records, structured and unstructured alike.
subject access requestalso known as SAR, DSAR
A request by the person to the organisation to exercise the right of access. Shortened to the request throughout this standard.
supplementary information
The information about the processing that the response includes alongside the copy of personal data: the purposes, the categories of data, the recipients, the retention period, the person's rights, the source of the data, and any automated decision-making.
time limit
The period within which the organisation provides the response: one month from the day the request is received, unless extended as the law allows.