[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fg1tvyziQgjEq1iQxAJVk7jzBXayBDg1dpUdKiZmUqXw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"c4e6c2aa-dc80-41e2-91bc-27d543c2f3c3","reform-uk-faces-gdpr-representative-action-over-dsar-failures","73c55161-acb6-4866-b277-7554785c17cf","Reform UK Faces GDPR Representative Action Over DSAR Failures","Reform UK failed to substantively respond to Data Subject Access Requests (DSARs) submitted by 51 individuals prior to the 2024 UK general election, triggering a landmark representative legal action under UK GDPR and the Data Protection Act 2018. The root cause is a failure to implement adequate processes for handling statutory data subject rights requests within the legally mandated one-month response window. This case matters because it demonstrates that political organisations are fully subject to data protection law, and that collective representative actions can now be brought even without individual claimants proving identical harm. The court's refusal to strike out the claim signals that regulators and courts will not tolerate procedural dismissal of GDPR obligations, raising the stakes for any organisation that ignores subject rights requests.","**Immediate actions:**\n- Establish a dedicated DSAR intake and tracking register to log every request with receipt date, deadline, and assigned owner.\n- Audit all outstanding or unanswered data subject rights requests and issue substantive responses within the statutory one-month deadline.\n\n**Process & Governance improvements:**\n- Appoint or designate a Data Protection Officer (or equivalent responsible person) with clear authority to manage and escalate DSARs and objections to processing.\n- Implement a documented DSAR workflow with templated responses, legal review checkpoints, and escalation paths for complex or bulk requests.\n- Train all staff who handle personal data on UK GDPR data subject rights obligations, including DSARs, objections, and erasure requests.\n\n**Detection & Monitoring measures:**\n- Deploy a compliance calendar or automated ticketing system that flags DSAR deadlines 7 and 14 days before expiry to prevent missed responses.\n- Conduct quarterly internal audits of data subject rights request handling to identify gaps before they become regulatory or litigation risks.",[12,13,14,15,16,17,18,19,20,21,22],"UK GDPR Article 15 (Right of Access)","UK GDPR Article 12 (Transparent Information and Communication)","UK GDPR Article 21 (Right to Object)","UK Data Protection Act 2018 Part 2","GDPR Recital 59 (Facilitating Data Subject Rights)","ICO DSAR Guidance (UK Information Commissioner's Office)","NIST SP 800-53 IP-1 (Individual Access)","NIST SP 800-53 IP-2 (Individual Access)","CIS Control 3: Data Protection","ITIL Service Management — Request Fulfilment Process","ISO\u002FIEC 27701:2019 Section 7.3 (Privacy Rights of Data Subjects)","published","2026-06-24T08:20:35.845181+00:00","2026-06-24T08:20:35.722+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=EWHC_(UK)_-_KB-2025-001120&diff=51967&oldid=0","ewhc-uk-kb-2025-001120-b74b1d","EWHC (UK) - KB-2025-001120",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]