GDPR

GDPR Subject Access Request: authentication cannot be an afterthought

As the deadline approached last year, companies scrambled to update their data protection practices. As it happened, some companies did get fined for non-compliance. Following a long period of adjustment, however, GDPR requirements have become normalised into existing compliance programs.What many companies were ill-prepared for was the onslaught of consumers exercising their rights under the…


As the deadline approached last year, companies scrambled to update their data protection practices. As it happened, some companies did get fined for non-compliance. Following a long period of adjustment, however, GDPR requirements have become normalised into existing compliance programs.

What many companies were ill-prepared for was the onslaught of consumers exercising their rights under the new regime. Under GDPR, a consumer can file a Subject Access Request (SAR) with an organisation to determine if that organisation is processing personal data concerning him or her, and, if the information has been shared, along with the names of the parties with which it has been shared. 

In fact, these are only but a few of the searching questions that the user, as the data subject, can demand answers to. Further, once the SAR has been dispatched to the organisation, it is legally obligated to comply with the request, retrieve the information, and formally respond to the data subject – all within a month.  

  • Satya Nadella calls for global GDPR
  • Majority of companies still aren’t GDPR-compliant
  • The ramifications of GDPR

Subject Access Request

SARs hav

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

GDPR

GDPR wasn’t designed for AI and that’s a security problem

The Security Think Tank explores the intersection of GDPR and artificial intelligence, considering how data protection standards in the UK and Europe are changing in this new paradigm…

The Security Think Tank explores the intersection of GDPR and artificial intelligence, considering how data protection standards in the UK and Europe are changing in this new paradigm…
Read More

Continue Reading
GDPR

When the intern has admin rights: GDPR in the agentic age

The Security Think Tank explores the intersection of GDPR and artificial intelligence, considering how data protection standards in the UK and Europe are changing in this new paradigm…

The Security Think Tank explores the intersection of GDPR and artificial intelligence, considering how data protection standards in the UK and Europe are changing in this new paradigm…
Read More

Continue Reading
GDPR

Nigel Farage wants to scrap ‘suffocating’ UK GDPR

Reform UK’s leader proposes ‘light-touch’ alternative, although rival politicians say plans are sparsely detailed and inconsistent with reality…

Reform UK’s leader proposes ‘light-touch’ alternative, although rival politicians say plans are sparsely detailed and inconsistent with reality…
Read More

Continue Reading
GDPR

Tech Tuesday: Data privacy and synthetic data generation tools

Data has become simultaneously the most valuable asset most organisations own and the most heavily regulated one. GDPR fines exceeded €4.5 billion cumulatively by early 2026. The EU AI Act’s classification of training data quality as a high-risk system requirement has made data provenance a legal obligation rather than a best practice…

Data has become simultaneously the most valuable asset most organisations own and the most heavily regulated one. GDPR fines exceeded €4.5 billion cumulatively by early 2026. The EU AI Act’s classification of training data quality as a high-risk system requirement has made data provenance a legal obligation rather than a best practice…
Read More

Continue Reading