Course Outline
Introduction to Subject Access Requests (SARs)
- What is a Subject Access Request?
- Legal basis and importance of SARs
- Overview of key regulations (GDPR, CCPA, etc.)
Legal Framework and Compliance Requirements
- Rights of data subjects under GDPR and other laws
- Timeframes and deadlines for responding
- Penalties for non-compliance
Processing a Subject Access Request
- Validating and verifying the requester's identity
- Locating and compiling requested data
- Ensuring secure data transmission
Handling Third-Party and Sensitive Data
- Identifying third-party information in SARs
- Applying redaction and anonymization techniques
- Balancing data access rights with privacy laws
Exemptions and Limitations
- When can an organization refuse a SAR?
- Exemptions for security, confidentiality, and legal privilege
- Managing excessive or unreasonable SARs
Best Practices for SAR Management
- Developing an internal SAR policy
- Creating a streamlined SAR response process
- Using technology to automate SAR handling
Case Studies and Practical Exercises
- Reviewing real-world SAR cases
- Simulating a SAR request and response
- Group discussion on SAR challenges and solutions
Summary and Next Steps
Requirements
- Basic understanding of data protection and privacy laws
- Familiarity with organizational data management policies
- Experience in handling customer or employee data (recommended)
Audience
- Data protection officers (DPOs)
- Compliance officers
- Legal and HR professionals
- IT and data management teams
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 1600 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (3)
Really enjoyed the topics covered and the way that the trainer ran the session
Richard
Course - BCS Practitioner Certificate in Data Protection
I generally enjoyed the knowledge of the trainer.
Eddyfi Technologies
Course - GDPR Workshop
I enjoyed the interaction and facts gained / learn.