Skip to main content

Subject Access Request (SAR) Toolkit

  • September 2, 2026
  • 0 replies
  • 2 views

Reading time 3 mins

Introduction

The Subject Access Request (SAR) Toolkit provides a structured, auditable workflow to receive, triage, process and close SARs (including Right to Be Forgotten/erasure requests) in health and social care settings. It balances individual access rights with safeguarding, confidentiality and public‑interest exemptions; supports lawful identity verification, proportionate redaction and robust audit trails; and links SAR activity into governance, safeguarding and patient‑safety processes.

Legislative Requirements

  • Care Act 2014 — not an information‑rights statute, but creates duties (promoting wellbeing, preventing deterioration, safeguarding) that shape SAR handling. Providers must ensure disclosures do not expose adults at risk to harm, distress, coercion or abuse, and that SARs are coordinated with safeguarding processes where records reveal concerns (possible s.42 thresholds).
  • Mental Capacity Act 2005 — where SARs are made by representatives or capacity is in doubt, document authority or capacity assessments and make best‑interest decisions. Lack of capacity must never be used to withhold lawful access without recorded legal justification.
  • Data Protection Act 2018 / UK GDPR — SARs are governed by UK GDPR: identify lawful basis (Article 6), any special‑category conditions (Article 9), apply data‑minimisation, verify identity, apply proportionate redaction and exemptions, document lawful time extensions, and maintain secure audit trails. Data protection cannot be used as a blanket barrier to legitimate access.
  • Right to Be Forgotten (Erasure) — recognises grounds for erasure (data no longer necessary, withdrawn consent, inaccurate or unlawfully processed), but is not absolute. Refusals are lawful where retention is required for legal obligations, public interest, freedom of expression, research, or public health.

Regulatory Guidance

  • CQC (England) — no standalone SAR regulation, but SAR handling intersects with fundamental standards (Reg.12 safe care, Reg.17 good governance, Reg.18 staffing). Providers must evidence safe, timely handling, staff competence, auditable records, and escalation where disclosure reveals safeguarding or patient‑safety risks.
  • Care Inspectorate (Scotland) — expects transparent, auditable SAR processes aligned with rights‑based practice, information‑sharing duties and inspection readiness.
  • Care Inspectorate Wales (CIW) — requires accurate, lawful disclosure, consistent processes and systems that prevent delay or misuse of information.

Statutory Guidance

  • Accountability — organisations must be able to demonstrate compliance via records, decision rationales (redaction/exemption), and governance oversight.
  • Duty of Candour — where SAR failures contribute to harm or reveal system failures, openness obligations apply.
  • Safeguarding — SAR content may identify harm; organisations must be able to escalate and share information lawfully to protect adults at risk.
  • Reporting — there is no statutory obligation to report SARs themselves, but reporting duties arise when SAR handling results in a personal data breach, safeguarding referral, or regulatory non‑compliance.

HealthCare Guidance

  • DHSC / National Standards — expects SARs to be recognised in any format, logged immediately, processed within statutory timeframes (one calendar month with lawful extensions), supported by identity verification, and communicated transparently.
  • Scottish & Welsh frameworks — require SAR processing aligned with information‑governance frameworks and adult protection duties; emphasise auditable, consistent handling across boards and services.
  • NICE — while not SAR‑specific, NICE guidance emphasises reducing psychological harm and treating people with dignity; this informs how sensitive disclosures should be communicated.
  • NHS Scotland IG framework — treats SARs as core statutory functions requiring lawful processing, clear accountability and full auditability.

Evidence Based Practice

  • Log SARs immediately on receipt (date/time, channel, requester identity or representative) and provide timely acknowledgement with expected timescales and complaints/escalation routes.
  • Verify identity and authority proportionately; where information is withheld from a representative, record rationale and legal basis.
  • Apply a documented redaction process: assess necessity, balance rights (requester vs third parties), consider risk of serious harm, and record justification for each redaction or exemption relied upon.
  • Maintain secure, auditable disclosure packs (export/print logs, redaction overlays, reviewer sign‑offs) and retain evidence of lawful extensions and communications.
  • Integrate SAR workflow with safeguarding, complaints and incident systems so relevant signals trigger timely partner referrals or PSIRF‑relevant reviews.
  • Train staff on SAR law, MCA interactions, trauma‑informed communication and secure transfer methods (e.g., encrypted email / secure portals).

Clinical governance and Safety (NHS)

  • Include SAR metrics in governance reporting: volumes, time to acknowledge, time to complete, number of redactions, lawful extensions used, complaints and breach notifications arising from SAR handling.
  • Assign clear executive and operational leads for SAR assurance and ensure delegated sign‑off thresholds are documented (for sensitive disclosures, safeguarding‑linked records or complex redaction decisions).
  • Train managers to apply MCA principles where capacity is in question and to escalate complex or high‑risk disclosures for legal/IG advice before release.
  • Audit sample disclosures for quality of redaction, adequacy of justification, timeliness and evidence of secure delivery to the requester.

PSIRF

SAR failures that cause or reveal patient safety incidents (delayed disclosures leading to harm, disclosure of traumatic information without support, or administrative failures producing safeguarding consequences) should be triaged under PSIRF principles. Use systems thinking to determine contributory factors (process, staffing, training, IT) and select proportionate learning responses (structured review, thematic review or local improvement actions).

Using the Toolkit — Practical Steps

  1. Receive & Log — capture SAR receipt (reference, date/time, channel, requester type: data subject / representative / third party) and acknowledgement timeline.
  2. Verify & Clarify — confirm identity/authority, request scope clarification (date ranges, record types, specific services) and record verification evidence.
  3. Triage — classify by sensitivity and risk (routine, mixed‑sensitivity, high‑sensitivity e.g., safeguarding, mental‑health notes, third‑party data) and determine likely redaction/exemption needs.
  4. Search & Collect — identify relevant systems (EHRs, case notes, emails, procurement logs), capture exports with metadata and preserve integrity (hashing/versioning where appropriate).
  5. Review & Redact — apply proportionate redaction using a documented checklist (third‑party identifiers, special‑category references, risk of serious harm). Record legal basis/exemption for each withheld item and obtain senior/IG sign‑off for contested decisions.
  6. Decide on Erasure — for Right to Be Forgotten requests, assess erasure eligibility against retention requirements, legal obligations and public‑interest exemptions; document rationale for erasure or refusal.
  7. Communicate & Deliver — respond within statutory timelines (or record lawful extension), provide copies in a secure manner, include explanation of redactions/exemptions and advise complaint routes.
  8. Escalate — where disclosures reveal safeguarding concerns, potential breaches, or residual high risk, escalate immediately to safeguarding leads, IG/legal teams and, where required, regulators.
  9. Close & Learn — record completion evidence, retention actions (for erasure or rectification), and feed themes into governance and staff training. Archive audit trail for inspection.

Templates & Data Fields (recommended)

  • Reference number, status (received/acknowledged/in progress/closed), priority, date/time received and assigned owner.
  • Requester type (data subject / representative / solicitor), identity verification evidence, proof of authority and contact preferences.
  • Scope: date ranges, record types (clinical, administrative, emails, CCTV), preferred format for disclosure, any exclusions requested.
  • Triage classification: routine / mixed‑sensitivity / high‑sensitivity / erasure request.
  • Systems searched and export metadata (system, record IDs, timestamps, extractor, checksum/hash where used).
  • Redaction log: item reference, redaction reason, legal basis/exemption cited, reviewer name, sign‑off timestamp.
  • Erasure log: items identified for deletion, legal basis for retention/refusal, action owner, deletion evidence.
  • Communications log: acknowledgements, extension notices, disclosure cover letters, refusal letters and appeal/complaint correspondence.
  • Safeguarding/breach linkage: safeguarding referral reference, incident reference, regulator/commissioner notifications, PSIRF review links.
  • Data protection fields: lawful basis (Article 6), Article 9 condition if special category, retention decision, access controls and disclosure audit trail.

Monitoring, Audit and Reporting

  • Maintain a SAR dashboard showing volumes by channel, time to acknowledge, time to final response, number of redactions, erasure outcomes and outstanding high‑risk items.
  • Report aggregated SAR themes and exceptions to IG Committees, Quality & Safety Committees and Boards, with evidence of remedial actions and training needs.
  • Audit sample disclosures for correct identity verification, lawful redaction, MCA/best‑interest application, timeliness and adequacy of communications.
  • Capture lessons (recurring sensitive record types, system gaps, staff competence shortfalls) and convert to targeted improvements (process change, system queries, staff training).

Value Proposition

  • Delivers a single auditable workflow to manage SARs and erasure requests consistently across services, reducing legal and regulatory risk.
  • Balances rights‑based access with safeguarding and safety obligations, ensuring disclosures do not cause avoidable harm.
  • Integrates SAR activity with safeguarding, incident and governance systems so information‑rights signals drive timely protection and organisational learning.
  • Provides assurance to inspectors and commissioners through clear evidence of lawful decision‑making, redaction rationale and secure disclosure practice.

References

  • Care Act 2014
  • Mental Capacity Act 2005
  • Department of Health & Social Care (DHSC)
  • NHS Scotland information governance framework
  • Health & Social Services Group (Wales)
  • CQC Regulations (2014)
  • Care Inspectorate — Health and Social Care Standards (Scotland)
  • Care Inspectorate Wales (CIW) — National Minimum Standards
  • NICE guidance (England/Wales)
  • ICO guidance on Subject Access Requests and Erasure
  • NHS clinical safety standards
  • Patient Safety Incident Response Framework (PSIRF)
  • UK GDPR / Data Protection Act 2018

Disclaimer

Radar Healthcare provides configuration templates and implementation guidance to support effective use of the platform. Any data protection examples or references are for general guidance only and do not constitute legal or compliance advice. Radar Healthcare acts as a data processor under customer instruction. The customer, as data controller, remains responsible for assessing and managing data protection risks, determining lawful processing, and ensuring compliance with applicable regulations.

 

This topic has been closed for replies.