Learning 3 - Individual rights and accountability

Site: MyStudentSite Moodle
Course: UK Data Protection Interactive SCORM
Book: Learning 3 - Individual rights and accountability
Printed by: Guest user
Date: Tuesday, 4 August 2026, 11:46 PM

1. Section 3: Individual rights and accountability

UK data protection learning

Section 3: Individual rights and accountability

Turning legal rights into workable organisational processes.

Learning outcomes

By the end of this section, you should be able to:

  • describe the main rights available to individuals;
  • recognise a subject access request even when informal wording is used;
  • outline a reasonable and proportionate SAR response process;
  • explain privacy notices, retention schedules and data protection by design;
  • identify when a DPIA is required; and
  • describe key controller–processor responsibilities.

Rights give people meaningful control and transparency. Accountability requires organisations to build processes capable of recognising and responding to those rights.


Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.

1.1. 3.1 The rights of individuals

UK data protection learning

3.1 The rights of individuals

The main rights people can exercise over their personal information.

RightWhat it means in practice
To be informedReceive clear privacy information about how personal data is used.
AccessObtain personal data and related information through a subject access request.
RectificationCorrect inaccurate data and complete incomplete data where appropriate.
ErasureRequest deletion in specified circumstances. This is not an absolute right.
RestrictionLimit the use of data in specified circumstances.
Data portabilityReceive certain data in a structured, commonly used, machine-readable format.
ObjectObject to specified processing. An objection to direct marketing must be honoured.
Automated decisions and profiling safeguardsReceive protection and safeguards in relation to relevant solely automated decisions and profiling.
Rights are context-dependent. Whether a right applies can depend on the lawful basis, purpose, exemptions and facts. Staff should escalate rather than reject a request from memory.

Knowledge checkpoint

Answer each question before opening the suggested answer.

1. Which right allows a person to correct an inaccurate address?

Suggested answer: The right to rectification.

2. Which right is absolute for direct marketing?

Suggested answer: The right to object to direct marketing.

3. Is erasure always required whenever a person asks?

Suggested answer: No. The right to erasure applies only in defined circumstances and can be limited by lawful retention needs or exemptions.


Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.

1.2. 3.2 Subject access requests

UK data protection learning

3.2 Subject access requests

Recognising, searching for and securely disclosing personal data.

Recognising a SAR

A SAR does not need to use legal language, cite legislation or arrive on a special form. A message such as “Please send me the notes you hold about my performance” may be a valid request.

A practical response workflow

  1. Recognise and log: record the date received and route the request promptly.
  2. Verify identity proportionately: ask only for information reasonably needed to confirm identity.
  3. Clarify where permitted and useful: clarification can help focus the request, but should not be used to create unnecessary delay.
  4. Search reasonably and proportionately: identify relevant systems, mailboxes, paper records and processors.
  5. Review: separate the requester's personal data from third-party information and consider exemptions.
  6. Respond securely: normally within one calendar month, using an appropriate delivery method.
  7. Document: retain evidence of searches, decisions, redactions and communications.
Current search standard: The organisation is expected to carry out a reasonable and proportionate search. It should be able to explain what it searched and why.

Time and extensions

The normal response period is one calendar month. In suitable cases involving complexity or multiple requests, an extension may be available, but the individual must be informed within the initial period and given reasons.

Activity: Recognise and scope a SAR

Read the request: “Send me all emails, Teams messages, notes and disciplinary documents about me from the last two years.”

  1. Which teams, systems and people may hold responsive information?
  2. What identity check, if any, is proportionate?
  3. What search terms and date ranges should be recorded?
  4. What third-party information might require review?
  5. How will the response be sent securely?
Open the answer guidance
A documented search plan may include HR systems, line-manager files, email, collaboration platforms, case-management tools and relevant processors. Identity checks should be proportionate. Third-party information must be considered carefully rather than disclosed automatically.

Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.

1.3. 3.3 Accountability, transparency and privacy by design

UK data protection learning

3.3 Accountability, transparency and privacy by design

The records, controls and design choices that demonstrate compliance.

Demonstrating compliance

Accountability measures may include:

  • records of processing activities and data inventories;
  • privacy notices and communication records;
  • lawful-basis and legitimate-interest assessments;
  • retention schedules and deletion procedures;
  • training, role-based access and confidentiality controls;
  • incident and breach records;
  • contracts with processors;
  • DPIAs and risk decisions; and
  • audit, monitoring and governance reporting.

Privacy notices

Privacy information should be concise, transparent, intelligible, easily accessible and written in clear language. It normally explains the controller, purposes, lawful bases, recipients, transfers, retention, rights and complaint routes.

Storage limitation and retention

“Keep everything just in case” is not an acceptable retention strategy. Organisations should define evidence-based retention periods, review data and securely delete or anonymise it when no longer needed.

Data protection by design and default

Privacy and security should be considered early enough to influence system design, procurement, forms, permissions, default settings, testing and deployment. Default settings should use the minimum data needed for the purpose.

Knowledge checkpoint

Answer each question before opening the suggested answer.

1. What is the difference between compliance and accountability?

Suggested answer: Compliance means meeting the requirements; accountability also means taking responsibility and being able to demonstrate how they are met.

2. Why is a retention schedule useful?

Suggested answer: It links categories of records to justified retention periods, review points and disposal actions.

3. When should privacy be considered in a project?

Suggested answer: From the earliest planning and design stages, not after deployment.


Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.

1.4. 3.4 DPIAs, processors and international transfers

UK data protection learning

3.4 DPIAs, processors and international transfers

Assessing high-risk processing and managing external suppliers.

Data protection impact assessments

A DPIA is required before processing that is likely to result in a high risk to individuals. It helps an organisation describe the processing, assess necessity and proportionality, identify risks and select measures to reduce those risks.

Potential high-risk indicators include systematic monitoring, large-scale use of special category data, innovative technology, significant automated decisions, vulnerable people or combining datasets in unexpected ways.

Timing matters: A DPIA must be early enough to change or stop the proposed processing.

Using processors

A controller must use processors that provide sufficient guarantees. A written contract must address the required Article 28 matters, including documented instructions, confidentiality, security, sub-processors, assistance with rights and breaches, return or deletion, and audit information.

Restricted international transfers

Where a restricted transfer is made outside the UK, the organisation must use an available legal route, such as adequacy regulations or appropriate safeguards, and complete any required transfer risk assessment. The general principles, transparency and security requirements continue to apply.

Activity: DPIA screening

A college proposes an AI-assisted monitoring system that analyses learner behaviour, attendance, online activity and welfare indicators to predict disengagement.

  1. Identify at least five possible privacy risks.
  2. Explain why a DPIA is likely to be required.
  3. List the groups that should be consulted.
  4. Suggest measures that could reduce risk.
  5. Identify questions to ask the supplier about data, models, security, deletion and human oversight.
Open the answer guidance

Risks may include unfair or inaccurate profiling, excessive collection, special category inferences, opaque decisions, over-reliance by staff, data breaches, function creep, discrimination and chilling effects.

Possible controls include clear purposes, data minimisation, human review, accuracy testing, access controls, retention limits, transparency, challenge routes, supplier assurance and regular monitoring.


Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.