Pallas27 Posted November 5, 2018 Posted November 5, 2018 An ICO Case Officer has stated that an expemption does not necessaily have to be quoted to the data subject when data is whithheld and/or shared without consent. Is this lawful? Opinions welcome especially if you can back it up with a link. Many thanks.
rom1984 Posted November 6, 2018 Posted November 6, 2018 Was it a SAR request or a FOI request? If it's a SAR then my understanding is that you should tell the data subject why the decision was refused. See... https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-of-access/ The section under "What should we do if we refuse the request" says that you should give the data subject the reason why you are refusing the request. If it was a FOI request then there is an exemption for people requesting personal data via the FOI right. In this case you can refuse to confirm or deny that you hold the information and point them towards the correct procedure. This is because the FOI request is for the world to see so merely by confirming you hold personal data could be a breach within its self. See - https://ico.org.uk/media/for-organisations/documents/1206/neither_confirm_nor_deny_in_relation_to_personal_data_and_regulation_foi_eir.pdf 1
GrumbleDook Posted November 6, 2018 Posted November 6, 2018 Just following up on @rom1984 explanation ... the case officer may have presumed you already point out where you inform data subjects of where you don’t apply the rights of the data subject within the Privacy Notice. If you do this, then just point to the PN. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now