Data Subject Rights Policy
Mission
Kerv empowers every Data Subject to exercise their statutory rights over personal data held by the Kerv Group. We process Subject Requests lawfully, transparently, and without undue delay, safeguarding both the individual’s privacy and Kerv’s compliance posture.
Kerv recognises that individuals have statutory rights in respect of their personal data and is committed to enabling those rights in accordance with applicable data protection legislation.
Purpose
This policy defines how Kerv recognises, validates, records, fulfils, and closes Subject Requests, including situations where Kerv is acting as either a Data Controller or Data Processor. It ensures compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy establishes the framework for responding to requests relating to:
- Access to personal data
- Rectification of inaccurate personal data
- Erasure of personal data
- Restriction of processing
- Objection to processing
- Data portability
- Rights relating to automated decision making
Scope
This policy applies to:
- All Kerv entities and employees worldwide.
- Any Subject Request received verbally or in writing (letter, email, ticket, call, web form or other communication method).
- Personal data processed in any medium or system controlled or managed by Kerv.
Where Kerv acts as a Data Processor on behalf of a client or partner organisation, any Subject Request received directly by Kerv will be logged and forwarded to the relevant Data Controller without undue delay. Kerv will support the Data Controller in fulfilling the request in accordance with contractual obligations and applicable legislation.
Policy
Recognising a Subject Request
Any request from an individual to access, correct, erase, restrict, port, or object to the processing of their own personal data constitutes a valid Subject Request. The request does not need to reference legislation or use specific terminology in order to be valid. Employees must escalate any Subject Request received to Governance Operations immediately via subjectrequests@kerv.com.
Verbal requests are valid. Where these are made, staff should invite the requester to confirm the request in writing, or document and confirm the details of the request with the individual prior to escalating to subjectrequests@kerv.com for action.
Identity Verification
Kerv will take reasonable and proportionate steps to verify the identity of the requester prior to disclosing personal data. Verification methods will be appropriate to the nature of the request and the sensitivity of the information involved. Wherever possible, verification will rely on information already known to Kerv, such as confirming known contact details, existing account information, or secure communication channels.
Government-issued identification will only be requested where reasonable doubt exists regarding the identity of the requester or where the information requested is particularly sensitive. Kerv will avoid collecting excessive personal information for identity verification and will apply the principle of data minimisation. Where identification documents are collected, they will be used solely for verification and securely deleted following completion of the verification process.
Third-party requests require signed authority from the data subject and identification for both the data subject and the authorised representative.
If verification cannot be completed, the request will be paused until sufficient information is provided.
Response Timeframes
The response period begins when a complete and verifiable request is received.
- Acknowledgement of receipt will be issued within 5 working days.
- Kerv will respond to the request within one calendar month.
Where requests are complex or numerous, the response period may be extended by up to two additional months. Governance Operations must notify the requester within the first month if an extension is required and explain the reason for the extension.
Types of Subject Requests
- Access Requests
Individuals have the right to obtain confirmation as to whether their personal data is being processed and to receive a copy of that data along with information about how it is being used.
- Rectification Requests
Individuals may request correction of inaccurate or incomplete personal data. Where rectification is required, relevant data owners must update the affected records without undue delay and ensure that any inaccurate information is corrected across relevant systems.
- Erasure Requests
Individuals may request deletion of personal data where the data is no longer necessary for the purposes for which it was collected, where consent has been withdrawn, where processing is unlawful, or where the individual has successfully objected to the processing.
Requests for erasure will be assessed against legal, regulatory, contractual, and operational retention requirements. Where personal data cannot be erased due to a lawful obligation or legitimate interest, the requester will be informed of the basis for continued retention.
- Restriction of Processing
Individuals may request that processing of their personal data be restricted where the accuracy of the data is contested, where the processing is unlawful but the individual prefers restriction rather than deletion, where the data is required for legal claims, or where an objection to processing is under review. Where restriction is applied, personal data will be retained but will not be actively processed unless permitted under applicable legislation.
- Objection to Processing
Individuals have the right to object to the processing of their personal data where the processing is based on legitimate interests or public task. Where an objection is received, Governance Operations and the CDPPO will assess whether compelling legitimate grounds exist to continue processing that override the interests, rights, and freedoms of the individual. Where the objection relates to direct marketing activities, processing will cease immediately.
- Data Portability
Where processing is based on consent or contract and carried out by automated means, individuals may request their personal data in a structured, commonly used and machine-readable format. Where technically feasible, the data may be transmitted directly to another controller at the request of the individual.
- Automated Decision Making
Where personal data is used in automated decision-making processes that produce legal or similarly significant effects, individuals have the right to request human review of the decision and obtain meaningful information regarding the logic involved in the processing.
Data Discovery and System Searches
Data Owners are responsible for identifying and retrieving relevant personal data from systems under their control. This includes ensuring that appropriate searches are performed across systems, platforms, applications, and repositories where personal data may be stored, including structured systems, cloud services, collaboration platforms, archived records, and relevant backup environments where reasonably accessible.
Governance Operations will coordinate system searches and ensure that relevant data owners and system administrators are engaged to support the fulfilment of requests.
Form of Response
Responses are delivered securely, typically via an encrypted OneDrive link. Paper copies or alternative formats may be provided upon request where feasible and appropriate. Where information is redacted, the response will clearly identify where information has been withheld in accordance with applicable exemptions.
Third-Party Data & Exemptions
Third-party personal data will be redacted unless consent has been provided or disclosure is considered lawful and reasonable. Statutory exemptions, including legal professional privilege, regulatory confidentiality, protection of third-party rights, prevention or detection of crime, or protection of ongoing investigations, will be assessed by the CDPPO and documented.
Where data is withheld, an explanation will be provided unless doing so would prejudice the exemption itself.
Manifestly Unfounded or Excessive Requests
Kerv reserves the right to refuse or limit the scope of a Subject Request where the request is manifestly unfounded or excessive, including where requests are repetitive or clearly intended to cause disruption. Any decision to refuse or limit a request must be assessed by Governance Operations and approved by the CDPPO. Where a request is refused, the individual will be informed of the reasons for the decision and their right to lodge a complaint with the supervisory authority.
Record-Keeping & Retention
Each Subject Request will be assigned a unique reference.
Governance Operations will log all key actions, communications, searches conducted, redactions applied, and decisions made during the fulfilment process. All Subject Request records will be retained securely for a six year period commencing from the date of request closure.
Process Workflow
| Step | Owner | Key Actions |
| 1 | Governance Operations | Log request and acknowledge within 5 working days |
| 2 | Governance Operations | Verify identity where appropriate and record verification method |
| 3 | Governance Operations + CDPPO | Classify the request type (access / rectification / erasure / restriction / objection / portability) |
| 4 | Data Owners | Locate relevant data, perform system searches, redact third-party references and provide output |
| 5 | CDPPO | Confirm lawful basis, assess exemptions, review and approve response |
| 6 | Governance Operations | Send securely to requester using approved methods |
| 7 | Governance Operations | Log closure and retain records securely for 6 years |
Internal SAR Operatives
Subject Request handlers within Governance Operations:
- Receive annual training on UK GDPR and the Data Protection Act 2018.
- Sign confidentiality agreements.
- Use only secure and auditable tools for request fulfilment.
- Operate under least privilege and need-to-know access principles.
- Escalate any irregularities to the CDPPO within 24 hours of becoming aware of such issues.
Roles & Responsibilities
| Role | Responsibilities |
| CDPPO (Chief Data Privacy and Protection Officer) | Policy owner; authorises redactions; leads on complex cases and exemptions |
| Governance Operations | Manages request intake, logging, coordination, and secure response |
| Data Owners | Retrieve, review, and validate personal data from their respective systems |
| All Staff | Identify and escalate Subject Requests without delay |
| Legal Counsel | Support with exemptions, litigation risk, and regulator engagement |
Complaints
If the Data Subject is not satisfied with our actions, they may raise a complaint directly to the Kerv Group Limited Managing Director at complaints@kerv.com.
The Managing Director will assess and handle any written complaint concerning the way a Subject Request has been handled and the information that has been disclosed.
Requestors in the UK may further write to the Information Commissioner’s Office at casework@ico.org.uk or by post at:
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Annex A – Definitions
| Term | Definition |
| Data Subject | A living individual identifiable from personal data. |
| Personal Data | Any data relating to an identified or identifiable individual. |
| Controller | Entity that determines the purposes and means of processing. |
| Processor | Entity that processes personal data on behalf of a controller. |
| Processing | Any operation on personal data (e.g., collection, storage, deletion). |
| SAR | Subject Access Request made under UK GDPR and DPA 2018. |
Annex B – Templated Acknowledgment
Dear [Requester’s Name],
Thank you for contacting Kerv. We acknowledge receipt of your Subject Access Request (SAR) submitted on [insert date].
Your request is currently being reviewed by our Governance Operations team under reference [insert SAR reference number]. In accordance with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, we aim to provide a full response within one calendar month, subject to identity verification and the completeness of your request.
In the event we require any further information to confirm your identity or clarify your request, a member of the Governance Operations team will contact you shortly. Please note the statutory timeframe for our response will begin upon our receipt of all requested information and completion/satisfaction of the required identity verification.
If you have any questions or wish to provide additional details in support of your request, please reply to this email or contact us at subjectrequests@kerv.com.
Kind regards,
Governance Operations Team
Kerv Group
www.kerv.com