Compliments and Complaints
Policy and Procedure
Purpose of the Policy
This policy sets out the procedure for handling Subject Access Requests (SARs) in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The purpose of this policy is to ensure you, or a third party you authorise, are able to exercise you right of access to your personal data. The policy also protects the confidentiality of third parties and maintaining the integrity of clinical records.
Scope
This policy applies to all personal data held by Journey of You, including:
- Client records
- Administrative records
- Electronic communications
- Assessment forms
- Session dates and attendance records
- Correspondence
This policy applies to all staff, contractors, and therapists working on behalf of Journey of You.
Definition of a Subject Access Request
A SARs is a request made by an individual, or an authorised third party, for access to their personal data held by the organisation.
A SARs request can be made via any means (form, phone, message, email, in-session, etc.). You don’t have to give a reason for wanting to see your information, and you don’t need to use the term "Subject Access Request" for the request to be valid.
Making a Subject Access Request
When making a SARs, regardless of the format used, it’s helpful to include if you:
- want a copy of your information as well as to see it (if you want to see them we can go through them during a regularly scheduled appointment, or book one specifically to go through them)
- want all or just part of it
- would like your information to be given to you in a specific format that meets your needs, and I will endeavour to meet your request
- if you request your records to be emailed, then we will secure you or your representative’s agreement (in writing or by email) that they accept the risk of sending unencrypted information via email
- you may also need to provide proof of your identity. I have a duty of care to ensure that any information provided for the client can be verified
Responsibility
The Data Controller, Kirsty Woodhead, is responsible for responding to Subject Access Requests.
Timeframe
I will deal with the SAR without undue delay and in any event within one month of receipt of your request.
If the work involved is particularly complex, or if numerous requests are made, then I may extend this period by up to two additional months. In this case, I will inform you about the extension and explain the reasons.
Identification
When I receive a SAR I will first check that I have enough information to be sure of the data subject identity. Often, I will have no reason to doubt a person’s identity, for example, if I have regular sessions with them. However, if I have good cause to doubt a person’s identity, I can ask for any evidence I reasonably need to confirm the identity.
If the request comes from a third party I will always check with my client and require identification of the third party.
No information will be released until identity has been confirmed.
Information That Will Be Provided
I will provide personal data that the individual is entitled to receive, which may include:
- Confirmation that their data is being processed
- Dates of attendance
- Type of service provided
- Copies of assessment forms completed by the client
- Administrative correspondence relating to the client
- Session notes
Supervision Notes
Supervision notes are the personal working notes of the therapist and are not routinely disclosed. Supervision notes:
- Are intended as clinical processing tool or the therapist
- Contain professional and personal observations, reflections, and hypotheses
- Include references to third parties
- May contain information that could cause serious harm to the physical or mental health of the client or another person if disclosed
Under the Data Protection Act 2018 and UK GDPR, exemptions may apply where disclosure could:
- Cause serious harm to the physical or mental health of the data subject or another person
- Breach the confidentiality of a third party
- Include information that is not the personal data of the requester
Therefore, Journey of You does not provide copies of supervision session notes to ensure I comply with both our legal and ethical obligations.
Where appropriate, a summary of information may be provided instead.
Third Party Information
Information that identifies another person will not be disclosed without their consent, unless it is reasonable to do so. Such information may be:
- Redacted
- Withheld
Exemptions
Journey of You reserves the right to withhold information where permitted under the Data Protection Act 2018, including but not limited to:
- Risk of serious harm
- Third party confidentiality
Method of Disclosure
The information will be provided in a concise, transparent and easily accessible format. It may be provided
- Electronically or
- During session or
- By secure postal delivery
Fee
I will not charge a fee for dealing with a SAR request unless it is:
- Manifestly unfounded, or
- Excessive, or
- Repetitive
If the above applies, a reasonable fee will be charged.
Record Keeping
I will keep a record of what steps have been taken when dealing with the request. Including, but not limited to:
- The request
- Identity verification
- Information provided
- Date of response
Complaints
If you’re not satisfied with my actions, you can submit a complaint. If you remain dissatisfied, you have the right to refer the matter to the Information Commissioner.
If you would like to know more or have any concerns about how your personal data is being processed, please contact:
Kirsty Woodhead
Tel: 07476906257
Email: kirsty@journeyofyou.uk
For complaints about data protection and your data subject rights, the Information Commissioner can be contacted at:
Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow
Cheshire
SK9 5AF
Tel: 0303 123 1113 (local rate) or 01625 545 745 (national rate)
or via the ICO complaints tool: Data protection and personal information complaints tool | ICO
Modified 08.09.26
