Policy

Subject Access Request (SAR) Policy

Handling requests from patients and staff to access their personal data under the UK General Data Protection Regulation - verifying identity, meeting the one-month timescale, applying exemptions and managing third-party, unfounded or excessive requests

Ref BS-GOV-POL-017See a sample (PDF) →
£54.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This policy is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Purpose
  • 2. Scope
  • 3. Policy statement and principles
  • 4. Definitions
  • 5. What a Subject Access Request entitles the requester to receive
  • 6. Receiving and recognising a request
  • 7. Verifying the requester's identity
  • 8. Timescales for responding
  • 9. Locating and compiling the information
  • 10. Third-party data
  • 11. Exemptions
  • 12. Health data and the serious harm test
  • 13. Requests made on behalf of others, for children and for deceased patients
  • 14. Manifestly unfounded or excessive requests, and fees
  • 15. Providing the response
  • 16. Refusing a request and the right to complain
  • 17. Staff Subject Access Requests
  • 18. Roles and responsibilities
  • 19. Training
  • 20. Monitoring, audit and review
  • 21. Related documents
  • 22. Glossary
  • 23. References

Legislation & standards it maps to

  • UK General Data Protection Regulation (UK GDPR) - in particular Article 12 (transparent information and modalities), Article 15 (right of access) and Article 23 (restrictions)
  • Data Protection Act 2018 - in particular Part 2, Schedule 2 and Schedule 3 (exemptions from the right of access)
  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 - in particular Regulation 9 (Person-centred care), Regulation 10 (Dignity and respect), Regulation 12 (Safe care and treatment) and Regulation 17 (Good governance)
  • Care Quality Commission (Registration) Regulations 2009 - in particular Regulation 20 (Notification of other incidents)
  • Access to Health Records Act 1990 - access to the records of deceased patients
  • Access to Medical Reports Act 1988 - access to medical reports supplied for employment or insurance purposes
  • Human Rights Act 1998 - in particular Article 8 (right to respect for private and family life)
  • Equality Act 2010 - reasonable adjustments in the handling of requests

Who it applies to

All directors, the registered manager, the Data Protection Officer or nominated data protection lead, clinical and administrative staff, receptionists, practitioners, managers, locums, students, volunteers, contractors and third-party processors of [Organisation Name]

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyMental Capacity Act & DoLS Policy£54.99
PolicyRecords Management & Retention Policy£54.99
PolicyData Protection & Confidentiality Policy£54.99
PolicyReasonable Adjustments Policy£54.99

Need the whole set?

Buy a complete sector bundle and save versus buying documents individually.

Browse bundles