Data Subject Access Requests (DSAR)¶
| Field | Value |
|---|---|
| Reference | PROC-004 |
| Type | Procedure |
| Version | 1.00 |
| Status | Approved |
| Owner | Data Protection Lead |
| Approver | Board |
| Approval Reference | MIN-2026-08-02 |
| Effective Date | 2026-08-05 |
| Next Review | 2027-08-05 |
| Review Requirements | As defined in STD-001 |
| Classification | Public |
Purpose¶
To explain how to exercise your UK GDPR data protection rights with BRSA, and what happens after you do.
Scope¶
Applies to anyone whose personal data BRSA holds - members and non-members alike.
If you'd like to know what personal data the British Rabbit Smallholders Association (BRSA) holds about you, or wish to exercise any of your other data protection rights, here's how.
How to make a request¶
Email [dsar@brsauk.co.uk] with:
- Your full name and the email address associated with your membership (if applicable)
- A clear description of what you're requesting (e.g. "a copy of all personal data you hold about me," "deletion of my account," "correction of my name on file")
We may need to verify your identity before processing certain requests, to protect your data from being disclosed to the wrong person.
What happens next¶
We will acknowledge your request promptly and respond in full within one calendar month of receipt, as required by UK GDPR. If your request is complex, we may extend this by a further two months, and will explain why if so.
What this covers¶
You can request:
- A copy of the personal data we hold about you
- Correction of inaccurate or incomplete data
- Deletion of your data, where applicable (note: some data may need to be retained for legal or financial record-keeping reasons even after a deletion request)
- Restriction of how we process your data
- A copy of your data in a portable format, where applicable
If you're not satisfied¶
If you're unhappy with our response, you can contact our Data Protection Lead directly, or escalate to the Information Commissioner's Office (ICO) at ico.org.uk.
Related Documents¶
- POL-001 Data Protection Policy
- POL-004 Privacy Policy
- PROC-003 Data Breach and Incident Response
Review Requirements¶
As defined in STD-001.
Change History¶
| Version | Date | Author | Summary |
|---|---|---|---|
| 0.10 | 2026-07-23 | DC | Initial draft |
| 0.50 | 2026-07-24 | DC | Version -> 0.50; Status -> Review |
| 0.50 | 2026-08-05 | DC | Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05 |
| 0.50 | 2026-08-05 | DC | Approval Reference -> MIN-2026-08-02 |
| 1.00 | 2026-08-05 | DC | Version -> 1.00; Approval Reference -> MIN-2026-08-02; Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05 |