What's inside
This standard operating procedure is fully drafted and structured, ready to brand and complete for your service. It covers:
- 1. Purpose
- 2. Scope
- 3. Definitions
- 4. Rights of the data subject under a SAR
- 5. Responsibilities
- 6. Procedure
- 7. Timescales
- 8. Fees, and manifestly unfounded or excessive requests
- 9. Exemptions and redactions
- 10. Special cases
- 11. Secure delivery
- 12. Refusing a request
- 13. Records, monitoring and the SAR register
- 14. Complaints and the ICO
- 15. Training
- 16. Related documents
- 17. Document control and review
Legislation & standards it maps to
- UK General Data Protection Regulation (UK GDPR), Article 15
- Data Protection Act 2018
- Data (Use and Access) Act 2025
- Access to Health Records Act 1990
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, Regulation 17 (Good governance)
- Information Commissioner's Office – Right of access guidance
- Common Law Duty of Confidentiality
- Caldicott Principles (UK Caldicott Guardian Council)
- General Medical Council – Confidentiality: good practice in handling patient information (2017)
Who it applies to
All staff at [Organisation Name], with specific duties held by the [Data Protection Officer] and [Caldicott Guardian].
How it works
- Buy securely with Stripe - instant, no VAT, no account needed.
- Download your editable Word file from the link we email you straight away.
- Complete the placeholders for your service, then have it approved before use.
- Add the optional updates subscription and we keep it current as guidance changes.