Learning 3 - Individual rights and accountability
| Site: | MyStudentSite Moodle |
| Course: | UK Data Protection Interactive SCORM |
| Book: | Learning 3 - Individual rights and accountability |
| Printed by: | Guest user |
| Date: | Tuesday, 4 August 2026, 11:46 PM |
1. Section 3: Individual rights and accountability
Section 3: Individual rights and accountability
Turning legal rights into workable organisational processes.
Learning outcomes
By the end of this section, you should be able to:
- describe the main rights available to individuals;
- recognise a subject access request even when informal wording is used;
- outline a reasonable and proportionate SAR response process;
- explain privacy notices, retention schedules and data protection by design;
- identify when a DPIA is required; and
- describe key controller–processor responsibilities.
Rights give people meaningful control and transparency. Accountability requires organisations to build processes capable of recognising and responding to those rights.
Official reference points
- ICO: Individual rights
- ICO: Subject access requests
- ICO: Data protection impact assessments
- ICO: UK GDPR guidance and resources
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.
1.1. 3.1 The rights of individuals
3.1 The rights of individuals
The main rights people can exercise over their personal information.
| Right | What it means in practice |
|---|---|
| To be informed | Receive clear privacy information about how personal data is used. |
| Access | Obtain personal data and related information through a subject access request. |
| Rectification | Correct inaccurate data and complete incomplete data where appropriate. |
| Erasure | Request deletion in specified circumstances. This is not an absolute right. |
| Restriction | Limit the use of data in specified circumstances. |
| Data portability | Receive certain data in a structured, commonly used, machine-readable format. |
| Object | Object to specified processing. An objection to direct marketing must be honoured. |
| Automated decisions and profiling safeguards | Receive protection and safeguards in relation to relevant solely automated decisions and profiling. |
Knowledge checkpoint
Answer each question before opening the suggested answer.
1. Which right allows a person to correct an inaccurate address?
Suggested answer: The right to rectification.
2. Which right is absolute for direct marketing?
Suggested answer: The right to object to direct marketing.
3. Is erasure always required whenever a person asks?
Suggested answer: No. The right to erasure applies only in defined circumstances and can be limited by lawful retention needs or exemptions.
Official reference points
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.
1.2. 3.2 Subject access requests
3.2 Subject access requests
Recognising, searching for and securely disclosing personal data.
Recognising a SAR
A SAR does not need to use legal language, cite legislation or arrive on a special form. A message such as “Please send me the notes you hold about my performance” may be a valid request.
A practical response workflow
- Recognise and log: record the date received and route the request promptly.
- Verify identity proportionately: ask only for information reasonably needed to confirm identity.
- Clarify where permitted and useful: clarification can help focus the request, but should not be used to create unnecessary delay.
- Search reasonably and proportionately: identify relevant systems, mailboxes, paper records and processors.
- Review: separate the requester's personal data from third-party information and consider exemptions.
- Respond securely: normally within one calendar month, using an appropriate delivery method.
- Document: retain evidence of searches, decisions, redactions and communications.
Time and extensions
The normal response period is one calendar month. In suitable cases involving complexity or multiple requests, an extension may be available, but the individual must be informed within the initial period and given reasons.
Activity: Recognise and scope a SAR
Read the request: “Send me all emails, Teams messages, notes and disciplinary documents about me from the last two years.”
- Which teams, systems and people may hold responsive information?
- What identity check, if any, is proportionate?
- What search terms and date ranges should be recorded?
- What third-party information might require review?
- How will the response be sent securely?
Open the answer guidance
Official reference points
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.
1.3. 3.3 Accountability, transparency and privacy by design
3.3 Accountability, transparency and privacy by design
The records, controls and design choices that demonstrate compliance.
Demonstrating compliance
Accountability measures may include:
- records of processing activities and data inventories;
- privacy notices and communication records;
- lawful-basis and legitimate-interest assessments;
- retention schedules and deletion procedures;
- training, role-based access and confidentiality controls;
- incident and breach records;
- contracts with processors;
- DPIAs and risk decisions; and
- audit, monitoring and governance reporting.
Privacy notices
Privacy information should be concise, transparent, intelligible, easily accessible and written in clear language. It normally explains the controller, purposes, lawful bases, recipients, transfers, retention, rights and complaint routes.
Storage limitation and retention
“Keep everything just in case” is not an acceptable retention strategy. Organisations should define evidence-based retention periods, review data and securely delete or anonymise it when no longer needed.
Data protection by design and default
Privacy and security should be considered early enough to influence system design, procurement, forms, permissions, default settings, testing and deployment. Default settings should use the minimum data needed for the purpose.
Knowledge checkpoint
Answer each question before opening the suggested answer.
1. What is the difference between compliance and accountability?
Suggested answer: Compliance means meeting the requirements; accountability also means taking responsibility and being able to demonstrate how they are met.
2. Why is a retention schedule useful?
Suggested answer: It links categories of records to justified retention periods, review points and disposal actions.
3. When should privacy be considered in a project?
Suggested answer: From the earliest planning and design stages, not after deployment.
Official reference points
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.
1.4. 3.4 DPIAs, processors and international transfers
3.4 DPIAs, processors and international transfers
Assessing high-risk processing and managing external suppliers.
Data protection impact assessments
A DPIA is required before processing that is likely to result in a high risk to individuals. It helps an organisation describe the processing, assess necessity and proportionality, identify risks and select measures to reduce those risks.
Potential high-risk indicators include systematic monitoring, large-scale use of special category data, innovative technology, significant automated decisions, vulnerable people or combining datasets in unexpected ways.
Using processors
A controller must use processors that provide sufficient guarantees. A written contract must address the required Article 28 matters, including documented instructions, confidentiality, security, sub-processors, assistance with rights and breaches, return or deletion, and audit information.
Restricted international transfers
Where a restricted transfer is made outside the UK, the organisation must use an available legal route, such as adequacy regulations or appropriate safeguards, and complete any required transfer risk assessment. The general principles, transparency and security requirements continue to apply.
Activity: DPIA screening
A college proposes an AI-assisted monitoring system that analyses learner behaviour, attendance, online activity and welfare indicators to predict disengagement.
- Identify at least five possible privacy risks.
- Explain why a DPIA is likely to be required.
- List the groups that should be consulted.
- Suggest measures that could reduce risk.
- Identify questions to ask the supplier about data, models, security, deletion and human oversight.
Open the answer guidance
Risks may include unfair or inaccurate profiling, excessive collection, special category inferences, opaque decisions, over-reliance by staff, data breaches, function creep, discrimination and chilling effects.
Possible controls include clear purposes, data minimisation, human review, accuracy testing, access controls, retention limits, transparency, challenge routes, supplier assurance and regular monitoring.
Official reference points
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.