Skip to Primary Navigation

DSARs: How to understand your obligations beyond data

Personal data has been pixelated). A doctor prepares a prescription on a computer screen for a patient.
Photo: Adam Berry/Getty Images

UK and EU courts are increasingly saying that it’s not enough to point to a privacy notice to satisfy the extra GDPR requirements.

What matters

Controllers should understand when they have to disclose individual recipients of data, extra requirements for complex technical data, and explanations of automated decision-making, to know when they can rely on a privacy notice alone.

What matters next

Organizations can get ahead by updating privacy notices and processing records,

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience