WAJD Learning

Module 2 of 2 · 40 minutes

Access requests, retention and sharing with other organisations

By the end of this module you will be able to

  • Handle a subject access request end to end, including redaction
  • Apply a retention schedule and justify it
  • Share data with another organisation lawfully
  • Recognise when a DPIA is required

Work through it

1 interactive for this module, built on the WAJD Teach engine. Nothing moves until you ask it to, and every one has a written version if you would rather read it.

Amara A daughter has asked for everything we hold about her mother. Where do I start?

Nadia With the clock, because it has already started. One month from receipt. Extendable by two more if it is complex or there are several, but only if you tell her inside the first month and say why.

Amara Can I ask her to prove who she is?

Nadia Yes, proportionately. And be careful here, because asking for excessive proof to buy time is itself a breach. The clock only pauses while you wait for identification you genuinely needed.

Amara Where do I search?

Nadia Everywhere the data actually lives, which is always more places than the official system. Email. Shared drives. Handover sheets. The manager's notebook. The messaging group the team uses.

Amara The messaging group is not official.

Nadia It is still your data, and honestly, discovering it exists is often the more serious finding. A request has a way of surfacing every unofficial place information has been living.

Amara Can I tidy the records up first?

Nadia No. And I want to be very precise about this one, because people do it instinctively and think they are being helpful.

Amara Go on.

Nadia Amending or deleting a record because somebody has asked to see it is a criminal offence under section 173 of the Data Protection Act 2018. Routine deletion under a schedule you already had can carry on. Tidying, cannot.

Amara Redaction. There are other people mentioned throughout.

Nadia Then redact the third party detail and disclose the rest. What you must not do is withhold the whole record because parts of it mention somebody else, which is the standard overreaction.

Amara Is it always redacted?

Nadia It is a balance, not a blanket rule. Another service user, yes. A professional acting in their working capacity, often not, because they were doing their job and their name is part of the account.

Amara How do I redact a PDF?

Nadia Properly, and this catches organisations out expensively. A black box drawn over text is not redaction if the text is still underneath and can be copied out. Flatten the document, or redact on paper before scanning.

Amara Let us do retention. We keep everything, which feels safest.

Nadia It feels safest and it is a breach. Storage limitation says no longer than necessary, and keeping everything forever also means any future incident is much larger than it needed to be.

Amara But care records are needed years later.

Nadia They are, and the periods are genuinely long for exactly that reason. The point is not to keep less than you should. It is to have a schedule, to be able to justify each period, and to actually apply it.

Amara What if we have a schedule and ignore it?

Nadia That is worse than having none, because you have documented that you knew what you should have been doing and did not.

Amara Last thing. We are about to start sharing data with a local NHS team.

Nadia Routine sharing wants a written data sharing agreement. What is shared, why, the lawful basis, how it is transferred, how long each side keeps it, and what happens if there is a breach.

Amara And urgent one off sharing?

Nadia No agreement needed. Lawful basis, minimum necessary, and a record of what you shared, with whom, and why.

Amara Is there anything else I should have done and probably have not?

Nadia A DPIA, almost certainly. It is required before processing likely to be high risk: large scale special category data, systematic monitoring, new technology, or processing about vulnerable people.

Amara That is us on at least three counts.

Nadia It is most care services on at least three counts, and very few have ever done one. And note the word before. A DPIA written after the system went live is a document, not an assessment.

The written material

Running a subject access request

One month from receipt, extendable by two further months for complex or numerous requests provided you tell the person inside the first month and explain why. Normally no fee. You may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, and that bar is high.

You may ask for identification, but only what is proportionate, and asking for excessive proof to delay the clock is itself a breach. The clock pauses only while you await genuinely necessary identification.

Search everywhere the data actually lives, which is more places than the official system: email, shared drives, handover notes, the manager's notebook, and the messaging app the team uses. Data in an unofficial place is still your data, and its existence is often the more serious finding.

Redaction, which is where people go wrong

Third party personal data within the record must generally be redacted unless that person consents or it is reasonable to disclose without consent. That is a balance, not a blanket rule, and the identity of professionals acting in their working capacity is often disclosable.

What you must not do is withhold the entire record because parts mention somebody else, which is the standard overreaction. Redact the third party detail and disclose the rest.

Redact properly. A black box drawn over text in a PDF is not redaction if the text remains underneath and can be copied out, and organisations have been fined for exactly that. Flatten the document, or redact before scanning.

Retention, and why keeping everything is not the safe option

Storage limitation requires that personal data is kept no longer than necessary. Keeping everything forever feels cautious and is a breach, as well as increasing the harm of any future incident.

Have a schedule, apply it, and be able to justify each period. In care, retention periods are longer than people expect because records may be needed as evidence years later, and NHS and adult social care records management guidance sets out the usual periods.

The two things that matter in an audit: that a schedule exists, and that it is actually applied. A schedule nobody follows is worse than none, because it documents that you knew what you should have been doing.

Sharing with other organisations, and DPIAs

Routine sharing between organisations should sit under a written data sharing agreement: what is shared, why, the lawful basis, how it is transferred, how long each party keeps it, and what happens on breach.

One off sharing in an urgent situation does not need an agreement. It needs a lawful basis, proportionality, and a record of what was shared, with whom and why.

A Data Protection Impact Assessment is required before processing likely to result in a high risk to individuals: large scale special category data, systematic monitoring, new technology, automated decisions with significant effects, or processing about vulnerable people. Care services frequently tick several of those and have never done one.

  • Routine sharing: written data sharing agreement
  • Urgent one off sharing: lawful basis, minimum necessary, and a record
  • DPIA before high risk processing, not after it has gone live
  • Vulnerable data subjects are themselves a DPIA trigger

Knowledge check

The knowledge check and your certificate need a free account, so that your progress and results can be saved as evidence.

Create a free account Sign in

The learning itself stays free and open. You are reading all of it right now without an account.