Skip to main content

The Open Subject Access Standard 1.0

Status
Draft

Abstract

OSAS is an open standard for how an organisation handles a subject access request, from the ease of making one to the quality of the answer. It sets out testable criteria, grouped into domains under five principles, at three cumulative conformance levels: Level 1, Level 2, and Level 3.

Status of this document

This is a draft of version 1.0, published for comment. The criteria and their numbers may still change before 1.0 is final, so do not yet rely on them as stable. To comment on a criterion, contact us. For a plain-English introduction to OSAS, see the overview. The criteria are also published as JSON.

Reachable

Finding and Making a Request

A1 A Findable Privacy Notice

Level 1

Every page of the organisation's website links to its privacy notice.

Understanding A1

A2 A Signposted Route

Level 1

The privacy notice explains how to make a subject access request, including where to send it.

Understanding A2

A3 No Account Required

Level 1

Making a request does not require creating an account where the person does not already hold one.

Understanding A3

A4 No Mandated Route

Level 1

The organisation does not require a subject access request to be made through one particular route, such as a single form or online portal.

Understanding A4

A5 A Request in Any Wording

Level 1

The organisation treats a request as valid whatever wording it uses.

Understanding A5

A6 A Verbal Request

Level 1

The organisation treats a request made verbally as valid.

Understanding A6

A7 A Named Contact

Level 2

The privacy notice names a data-protection contact and a direct way to reach them.

Understanding A7

A8 A Choice of Routes

Level 2

At least two routes exist to make a request, one of which is an email address for subject access requests or the data-protection contact.

Understanding A8

A9 A Proportionate Request Form

Level 2 (judgement)

Where the organisation provides a request form, it asks for nothing beyond what is needed to identify the person and locate their data.

Understanding A9

A10 A Request Made on Someone's Behalf

Level 2

The organisation accepts a request made by someone the person has authorised to act for them.

Understanding A10

A11 The Right Explained

Level 3

The privacy notice explains what the right of access lets a person do, not only that the right exists.

Understanding A11

A12 No Discouragement

Level 3 (judgement)

No step in making a request presents a message or question that urges the person to reconsider, narrow, or withdraw it.

Understanding A12

Responsive

Acknowledgement and Timeline

B1 A Response Within the Time Limit

Level 1

The response is provided within one month of the request, or within an extended time limit the organisation has notified.

Understanding B1

B2 An Extension Notified in Time

Level 1

Where the organisation extends the time limit, it tells the person within one month of the request.

Understanding B2

B3 An Extension Explained

Level 1

Where the organisation extends the time limit, it states why the extension is needed.

Understanding B3

B4 Acknowledgement of Receipt

Level 2

The organisation confirms to the person that it has received the request.

Understanding B4

B5 A Stated Response Date

Level 2

The acknowledgement states the date by which the organisation will respond.

Understanding B5

Identity Verification

C1 No Verification on an Identified Route

Level 1

The organisation does not request identity verification where the request comes through a route that already identifies the person.

Understanding C1

C2 Proportionate Verification

Level 1 (judgement)

Where the organisation requests identity verification, it asks only for what is necessary to confirm the person's identity.

Understanding C2

C3 Verification Explained

Level 2

Where the organisation requests identity verification, it states why the verification is needed.

Understanding C3

C4 The Effect on the Time Limit Stated

Level 2

Where the organisation requests identity verification, it states how this affects the time limit for responding.

Understanding C4

C5 Verification Data Not Retained

Level 3

The organisation states that identity information provided for verification is used only to confirm identity and is not kept afterward.

Understanding C5

Complete

Completeness and Scope

D1 Confirmation of Processing

Level 1

The response states whether or not the organisation processes the person's personal data.

Understanding D1

D2 A Copy of the Data

Level 1

Where the organisation processes the person's personal data, the response includes a copy of it.

Understanding D2

D3 The Systems Searched

Level 2

The response states which systems or records the organisation searched for the person's personal data.

Understanding D3

D4 The Period Searched

Level 2

The response states the date range the search covered.

Understanding D4

D5 Whether the Search Was Limited

Level 2

The response states whether or not the organisation limited the scope of its search.

Understanding D5

D6 A Limit on the Search Explained

Level 2

Where the response states that the organisation limited the scope of its search, it states what was not searched, and why.

Understanding D6

D7 A Request Not Narrowed Without Agreement

Level 2

Where the organisation asks the person to specify what they want, it does not treat the request as withdrawn or narrowed if the person does not reply.

Understanding D7

D8 Data Held on the Organisation's Behalf

Level 2

The response states whether the search covered personal data held on the organisation's behalf by another organisation.

Understanding D8

D9 Unstructured Records Included

Level 3

The response states whether the search covered unstructured records, such as emails and documents, and not only structured databases.

Understanding D9

Supplementary Information

E1 The Purposes

Level 1 (judgement)

The response states the purposes for which the organisation processes the person's personal data.

Understanding E1

E2 The Categories of Data

Level 1 (judgement)

The response states the categories of the person's personal data that the organisation processes.

Understanding E2

E3 The Recipients

Level 1 (judgement)

The response states the recipients, or categories of recipient, to whom the organisation has disclosed or will disclose the person's personal data.

Understanding E3

E4 The Retention Period

Level 1 (judgement)

The response states how long the organisation will keep the person's personal data, or the criteria it uses to decide.

Understanding E4

E5 The Person's Other Rights

Level 1

The response states the person's rights to rectification, erasure, restriction, and objection.

Understanding E5

E6 The Right to Complain

Level 1

The response states that the person can complain to the Information Commissioner's Office.

Understanding E6

E7 The Source of the Data

Level 1

Where the organisation did not collect the personal data from the person, the response states any available information about its source.

Understanding E7

E8 Automated Decision-Making

Level 1

The response states whether the organisation makes solely automated decisions about the person, including profiling.

Understanding E8

E9 The Logic Explained

Level 1 (judgement)

Where the organisation makes solely automated decisions about the person, the response gives meaningful information about the logic involved.

Understanding E9

E10 The Consequences Explained

Level 1 (judgement)

Where the organisation makes solely automated decisions about the person, the response states the significance of those decisions and their likely consequences.

Understanding E10

E11 Safeguards for Transfers Abroad

Level 1

Where the organisation transfers the person's personal data outside the UK, the response states the safeguards it relies on for the transfer.

Understanding E11

E12 Recipients Named

Level 2

The response names the actual recipients of the person's personal data, not only categories of recipient, unless naming a recipient is not possible.

Understanding E12

E13 Written for the Person

Level 2 (judgement)

The supplementary information describes how the organisation processes the person's own data, not only what its general privacy notice says.

Understanding E13

E14 A Specific Retention Period

Level 3

The response gives a retention period for the person's personal data, rather than only the criteria for deciding one.

Understanding E14

Intelligible

Intelligibility

F1 Codes and Terms Explained

Level 1

Where the response or the copy uses codes, abbreviations, or technical terms, the response explains what they mean.

Understanding F1

F2 What Each Part Is

Level 1

The response identifies what each part of the copy is.

Understanding F2

F3 Organised to Navigate

Level 2 (judgement)

The response is organised so the person can find their way through it, rather than presented as an undifferentiated bundle.

Understanding F3

F4 Clear to a Child

Level 2 (judgement)

Where the response is addressed to a child, it uses language the child can understand.

Understanding F4

F5 A Guide to the Response

Level 3

The response includes a short guide to what it contains and how it is arranged.

Understanding F5

F6 Plain Language

Level 3 (judgement)

A person without specialist knowledge of the organisation's systems or of data-protection law can understand the response.

Understanding F6

Format and Delivery

G1 Provided Free

Level 1

The organisation provides the response free of charge.

Understanding G1

G2 Electronic by Default

Level 1

Where the person made the request by electronic means, the response is provided in a commonly used electronic form, unless the person asked for another form.

Understanding G2

G3 Delivered Securely

Level 1

The organisation delivers the response by a means that protects it from being read by anyone other than the person.

Understanding G3

G4 A Usable Format

Level 2

The response is provided in a format the person can open and reuse with commonly available software, not as images of the personal data or a file locked against reuse.

Understanding G4

G5 No Barrier to Collection

Level 2

Receiving the response does not require creating an account where the person does not already hold one, or using one particular portal.

Understanding G5

G6 An Accessible Format on Request

Level 2

Where the person needs the response in an accessible format, the organisation provides it in that format.

Understanding G6

G7 Accessible by Default

Level 3

The response meets recognised accessibility standards, so a person using assistive technology can read it without having to ask for an alternative.

Understanding G7

Accountable

Redaction and Exemptions

H1 Refusal Explained

Level 1

Where the organisation refuses a request in whole or in part, the response states the reasons.

Understanding H1

H2 How to Challenge a Refusal

Level 1

Where the organisation refuses a request in whole or in part, the response tells the person they can seek a remedy from the Information Commissioner's Office or a court.

Understanding H2

H3 Redaction Shown

Level 1

Where the organisation redacts information from the copy, the response shows that something has been redacted.

Understanding H3

H4 The Ground Stated

Level 2

For each redaction, the response states the ground relied on.

Understanding H4

H5 Redaction Limited to What Is Withheld

Level 2 (judgement)

Each redaction covers only the information withheld, and not the surrounding text, page, or record that contains it.

Understanding H5

H6 A Record Withheld in Full Explained

Level 2

Where the organisation withholds a record in full under an exemption, the response states why no part of it could be disclosed.

Understanding H6

H7 A Charge or Rejection Justified

Level 2

Where the organisation charges a fee, or rejects the request as manifestly unfounded or excessive, the response states why.

Understanding H7

H8 How to Complain to the Organisation

Level 2

The response states how the person can complain to the organisation about it.

Understanding H8

H9 The Reason Explained

Level 3 (judgement)

Where the organisation relies on an exemption, the response explains why it applies to the redacted data, not only which exemption it is.

Understanding H9

Glossary

Each term below has one meaning across the whole standard, and every criterion uses it verbatim. Where a term has a common name in law or practice, that name is noted but not used in the criteria.

acknowledgement
The organisation's confirmation to the person that it has received the request.
copy
The reproduction of the person's personal data that the organisation provides in the response, as distinct from the supplementary information about it.
data-protection contact
The person or team the organisation identifies as responsible for data-protection matters, including requests. Where the organisation has appointed a Data Protection Officer, the data-protection contact is that officer.
exemption
A legal ground on which the organisation may withhold some personal data from the response.
extension
An addition to the time limit that the law allows where a request is complex, or where the organisation has received a number of requests from the same person. An extension can be up to two further months.
identity verification
Steps the organisation takes to confirm that the person making the request is who they say they are. The information the organisation asks for to do this is the person's identity information.
the organisationalso known as controller
The body that determines the purposes and means of processing the personal data, and to which the request is made.
the personalso known as data subject
The identified or identifiable individual the personal data is about, who is exercising the right of access.
personal data
Information relating to the person, from which they can be identified directly or indirectly.
privacy notice
The public document in which the organisation explains how and why it processes personal data, and how a person can exercise their rights.
recipient
A person or organisation to whom the organisation discloses the person's personal data.
record
A single item the organisation holds in which the person's personal data appears, such as a file, an email, or an entry in a database.
redaction
The removal or obscuring of information from the copy, such as another person's data or material an exemption covers.
request form
A form the organisation provides for making a request.
the response
What the organisation provides in answer to the request: confirmation of whether it processes the person's data, a copy of that data, and the supplementary information about the processing.
the right of access
The person's right to obtain from the organisation confirmation that their personal data is being processed, a copy of that data, and the supplementary information about the processing. It is set out in Article 15 of the UK GDPR.
route
A means by which the person can make a request, such as an email address, a form, a postal address, or a feature within an account.
The steps the organisation takes to find the person's personal data across its systems and records, structured and unstructured alike.
subject access requestalso known as SAR, DSAR
A request by the person to the organisation to exercise the right of access. Shortened to the request throughout this standard.
supplementary information
The information about the processing that the response includes alongside the copy of personal data: the purposes, the categories of data, the recipients, the retention period, the person's rights, the source of the data, and any automated decision-making.
time limit
The period within which the organisation provides the response: one month from the day the request is received, unless extended as the law allows.