DPO Programme – Module 2 (Virtual)
October 14 @ 9:30 am - 12:30 pm
Number of capacity: 15
Summary
This operational workshop provides a structured governance model for handling Subject Access Requests (SARs) and related data subject rights within General Practice.
It is workflow-driven, defensibility-focused, and designed to reduce ICO escalation risk.
A 3-hour SAR lifecycle workshop covering:
- Valid SAR recognition and statutory clock start
- One-month deadline discipline
- Identity verification proportionality
- Record search and extraction scope
- Redaction governance and documentation
- Clinical harm exemption
- Rectification vs annotation
- Refusal defensibility
- ICO escalation pathway
- SAR governance model for GP practice
Mapped to NHS DSPT Standards 1–3.
Course Content
- SAR validity and statutory timing
- Search scope and extraction governance
- Redaction and exemption decision-making
- Litigation interface and escalation management
- SAR logging architecture and oversight model
Expected Outcome
- Operate a compliant and defensible SAR workflow
- Apply exemptions proportionately and lawfully
- Maintain SAR documentation capable of regulatory scrutiny