The subject access code of practice explains the rights that individuals have to access their personal data, and sets out the obligations of data controllers. This code is intended to help you provide subject access in accordance with the law and good practice. It aims to do this by explaining how to recognise a subject access request and by offering practical advice about how to deal with, and respond to, such a request. It provides guidance on the limited circumstances in which personal data is exempt from subject access. The code also explains how the right of subject access can be enforced when things go wrong.
We are consulting on the draft version of the subject access code of practice to gather the views of individuals, stakeholders and organisations who process personal data. These views will inform the final published version of the code of practice. The consultation will play an important role in ensuring the new code achieves the right balance between the protection of individuals’ privacy and proportionate obligations for organisations.