Access to Personal Data
The Data Protection Act provides a formal procedure for an individual to ask an organisation for access to, or copies of, personal data that the organisation might hold about him/herself. This is called a Subject Access Request [SAR]. A Court of Appeal decision on 8th December 2003 has substantially amended the operation of the Act with respect to SARs - see seperate entry in this A to Z Guide.
The Data Protection Act also requires an organisation that processes any personal data to have in place procedures to control access to that data. The procedures may cover authorisation, authentication, plus the purpose and consent for the processing