SlideShare a Scribd company logo
1 of 7
Download to read offline
Nothing in this presentation may be construed as Legal Advice.




                                    Subject                                    How to
                                                                              achieve a
                                     Access                                  devastating
                                    Request                                     effect


  www.dataprotectionofficer.com ||| info@dataprotectionofficer.com




SAR   SAR can be requested here   Evidence likely to be tampered with   Evidence less likely to be tampered with
The truth about Subject Access
                        Request (SAR)
      • When you make a SAR                            SAR


           – Your request may not ask the right questions from the
             right sources , therefore the information may be
           –       Tampered with
                 • The organisation may deny the existence of the information
                   required leaving your request less effective as an evidence.
      • This guide will provide you information about the
        depth of information that can be requested
        capable of preventing tamper
      • The request needs to get to areas of an
        organisation that is more difficult to tamper with

SAR   SAR can be requested here   Evidence likely to be tampered with   Evidence less likely to be tampered with
Overview of the process


 Subject has                                         With an official               Notification of            Decision and
                     An issue has arisen
 a complain                                          or department                  management                documentation


                       Issue                             Official(s)                Management                   Decision
                                                                        SAR
                                                                                                       SAR
                      Incident
                                                                                                               communication
                         Act                               Officer(s)                Management

                      Meeting
                                                      Department                          HR                   Documentation
                      Decision
Subject                                            SAR
                                                                              SAR                       SAR
                       Event

                     Allegation

                    Negligence


SAR   SAR can be requested here            Evidence likely to be tampered with            Evidence less likely to be tampered with
Issue arises with
                                                          the subject




                                                                              Subject




                    Incident
                                  Meeting


     Decision
                                                      Officer or subject
                                                        communicates
                                                      with the subject or




                            Email


Report
              Meeting
                                          Telephone
                                                        Management
                                                                              Communication




                                                      Audit of the issue
                                                      is communicated




                                          PC
                            Laptop


Witness
                                                       via the network
                                                                              Network




              Telephone
                                                         All electronic
                                                       traffic is logged
                                                                              Servers




                                                         and tracked
     Traffic logs
                                  Server logs
                    Backup logs




                                                       Audit logs on all
                                                      computer systems
                                                                              Audits




                                                       provide evidence
                                  PC Audit
                    Web Audit
     Email Audit
                                                                                              Target organisation layout




                                                       All decisions are
                                                        required to be
                                  HR files
                    Records




                                                         documented
                                                                            Decision &
                                                                            documents
SAR points of impact
                                               Mobile phone
                                                                     Audit, logs & servers

                                                                                        SAR
                                                              SAR



                                             Email server
                         Laptops
                                                               SAR

      Issue
                              SAR                                                    SAR
                                                               SAR


                                            Web logs
                  computers                                    SAR

                                             Telephone
                                                                                        SAR
                              SAR
                                                               SAR


SAR    SAR can be requested here            Witness

      Evidence likely to be tampered with

      Evidence less likely to be tampered with
The overall objective


• An in-depth request that is
                                       The strategy               • Make it difficult for the
  harder to repudiate                                               respondent to deny the
                                • Target areas that will reveal     existence of the information
                                  information that the            • Request information from
                                  respondent cant tamper            areas that the respondent
                                  with & that will reveal           cant easily tamper
                                  detrimental information


            The SAR                                                        End result
Contact details
www.dataprotectionofficer.com


Ben Oguntala, LLB Hons, LLM

• Ben.oguntala@dataprotectionofficer.com

Telephone

• (+44) (0)7812039867

More Related Content

More from Ben Omoakin Oguntala, developingafrica(dot)net

More from Ben Omoakin Oguntala, developingafrica(dot)net (17)

Developing Africa Ode Remo brochure
Developing Africa Ode Remo brochureDeveloping Africa Ode Remo brochure
Developing Africa Ode Remo brochure
 
Developing Africa - Ode Remo
Developing Africa - Ode RemoDeveloping Africa - Ode Remo
Developing Africa - Ode Remo
 
Thisday story with Oguntala
Thisday story with OguntalaThisday story with Oguntala
Thisday story with Oguntala
 
Africa secretariat - The Home of African raw materials
Africa secretariat - The Home of African raw materials Africa secretariat - The Home of African raw materials
Africa secretariat - The Home of African raw materials
 
Data Leakage Prevention
Data Leakage PreventionData Leakage Prevention
Data Leakage Prevention
 
Risk Assessment And Risk Treatment
Risk Assessment And Risk TreatmentRisk Assessment And Risk Treatment
Risk Assessment And Risk Treatment
 
Data Protection Compliance In Economically Depressing Times
Data Protection Compliance In Economically Depressing TimesData Protection Compliance In Economically Depressing Times
Data Protection Compliance In Economically Depressing Times
 
Privacy Impact Assessment Final
Privacy Impact Assessment FinalPrivacy Impact Assessment Final
Privacy Impact Assessment Final
 
Managing Information Asset Register
Managing Information Asset RegisterManaging Information Asset Register
Managing Information Asset Register
 
Fraud Monitoring Solution
Fraud Monitoring SolutionFraud Monitoring Solution
Fraud Monitoring Solution
 
Conformidad De Seguridad De InformacióNv2
Conformidad De Seguridad De InformacióNv2Conformidad De Seguridad De InformacióNv2
Conformidad De Seguridad De InformacióNv2
 
Iso 27001 Audit Evidence Acquisitionv3
Iso 27001 Audit Evidence Acquisitionv3Iso 27001 Audit Evidence Acquisitionv3
Iso 27001 Audit Evidence Acquisitionv3
 
Iso 27001 Audit Evidence Acquisition
Iso 27001 Audit Evidence AcquisitionIso 27001 Audit Evidence Acquisition
Iso 27001 Audit Evidence Acquisition
 
Gprs/3G Troubleshooter
Gprs/3G TroubleshooterGprs/3G Troubleshooter
Gprs/3G Troubleshooter
 
Pci V2
Pci V2Pci V2
Pci V2
 
FoI
FoIFoI
FoI
 
Dpa V3
Dpa V3Dpa V3
Dpa V3
 

How to make a Subject Access Request effective

  • 1. Nothing in this presentation may be construed as Legal Advice. Subject How to achieve a Access devastating Request effect www.dataprotectionofficer.com ||| info@dataprotectionofficer.com SAR SAR can be requested here Evidence likely to be tampered with Evidence less likely to be tampered with
  • 2. The truth about Subject Access Request (SAR) • When you make a SAR SAR – Your request may not ask the right questions from the right sources , therefore the information may be – Tampered with • The organisation may deny the existence of the information required leaving your request less effective as an evidence. • This guide will provide you information about the depth of information that can be requested capable of preventing tamper • The request needs to get to areas of an organisation that is more difficult to tamper with SAR SAR can be requested here Evidence likely to be tampered with Evidence less likely to be tampered with
  • 3. Overview of the process Subject has With an official Notification of Decision and An issue has arisen a complain or department management documentation Issue Official(s) Management Decision SAR SAR Incident communication Act Officer(s) Management Meeting Department HR Documentation Decision Subject SAR SAR SAR Event Allegation Negligence SAR SAR can be requested here Evidence likely to be tampered with Evidence less likely to be tampered with
  • 4. Issue arises with the subject Subject Incident Meeting Decision Officer or subject communicates with the subject or Email Report Meeting Telephone Management Communication Audit of the issue is communicated PC Laptop Witness via the network Network Telephone All electronic traffic is logged Servers and tracked Traffic logs Server logs Backup logs Audit logs on all computer systems Audits provide evidence PC Audit Web Audit Email Audit Target organisation layout All decisions are required to be HR files Records documented Decision & documents
  • 5. SAR points of impact Mobile phone Audit, logs & servers SAR SAR Email server Laptops SAR Issue SAR SAR SAR Web logs computers SAR Telephone SAR SAR SAR SAR SAR can be requested here Witness Evidence likely to be tampered with Evidence less likely to be tampered with
  • 6. The overall objective • An in-depth request that is The strategy • Make it difficult for the harder to repudiate respondent to deny the • Target areas that will reveal existence of the information information that the • Request information from respondent cant tamper areas that the respondent with & that will reveal cant easily tamper detrimental information The SAR End result
  • 7. Contact details www.dataprotectionofficer.com Ben Oguntala, LLB Hons, LLM • Ben.oguntala@dataprotectionofficer.com Telephone • (+44) (0)7812039867