Data Subject Rights Policy

Mission 

Kerv empowers every Data Subject to exercise their statutory rights over personal data held by the Kerv Group. We process Subject Requests lawfully, transparently, and without undue delay, safeguarding both the individual’s privacy and Kerv’s compliance posture. 

Kerv recognises that individuals have statutory rights in respect of their personal data and is committed to enabling those rights in accordance with applicable data protection legislation. 

Purpose 

This policy defines how Kerv recognises, validates, records, fulfils, and closes Subject Requests, including situations where Kerv is acting as either a Data Controller or Data Processor. It ensures compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy establishes the framework for responding to requests relating to: 

Scope 

This policy applies to: 

Where Kerv acts as a Data Processor on behalf of a client or partner organisation, any Subject Request received directly by Kerv will be logged and forwarded to the relevant Data Controller without undue delay. Kerv will support the Data Controller in fulfilling the request in accordance with contractual obligations and applicable legislation. 

Policy 

Recognising a Subject Request 

Any request from an individual to access, correct, erase, restrict, port, or object to the processing of their own personal data constitutes a valid Subject Request. The request does not need to reference legislation or use specific terminology in order to be valid. Employees must escalate any Subject Request received to Governance Operations immediately via subjectrequests@kerv.com
Verbal requests are valid. Where these are made, staff should invite the requester to confirm the request in writing, or document and confirm the details of the request with the individual prior to escalating to subjectrequests@kerv.com for action. 

Identity Verification 

Kerv will take reasonable and proportionate steps to verify the identity of the requester prior to disclosing personal data. Verification methods will be appropriate to the nature of the request and the sensitivity of the information involved. Wherever possible, verification will rely on information already known to Kerv, such as confirming known contact details, existing account information, or secure communication channels. 

Government-issued identification will only be requested where reasonable doubt exists regarding the identity of the requester or where the information requested is particularly sensitive. Kerv will avoid collecting excessive personal information for identity verification and will apply the principle of data minimisation. Where identification documents are collected, they will be used solely for verification and securely deleted following completion of the verification process. 

Third-party requests require signed authority from the data subject and identification for both the data subject and the authorised representative. 

If verification cannot be completed, the request will be paused until sufficient information is provided. 

Response Timeframes 

The response period begins when a complete and verifiable request is received. 

Where requests are complex or numerous, the response period may be extended by up to two additional months. Governance Operations must notify the requester within the first month if an extension is required and explain the reason for the extension. 

Types of Subject Requests 

Individuals have the right to obtain confirmation as to whether their personal data is being processed and to receive a copy of that data along with information about how it is being used. 

Individuals may request correction of inaccurate or incomplete personal data. Where rectification is required, relevant data owners must update the affected records without undue delay and ensure that any inaccurate information is corrected across relevant systems. 

Individuals may request deletion of personal data where the data is no longer necessary for the purposes for which it was collected, where consent has been withdrawn, where processing is unlawful, or where the individual has successfully objected to the processing. 

Requests for erasure will be assessed against legal, regulatory, contractual, and operational retention requirements. Where personal data cannot be erased due to a lawful obligation or legitimate interest, the requester will be informed of the basis for continued retention. 

Individuals may request that processing of their personal data be restricted where the accuracy of the data is contested, where the processing is unlawful but the individual prefers restriction rather than deletion, where the data is required for legal claims, or where an objection to processing is under review. Where restriction is applied, personal data will be retained but will not be actively processed unless permitted under applicable legislation. 

Individuals have the right to object to the processing of their personal data where the processing is based on legitimate interests or public task. Where an objection is received, Governance Operations and the CDPPO will assess whether compelling legitimate grounds exist to continue processing that override the interests, rights, and freedoms of the individual. Where the objection relates to direct marketing activities, processing will cease immediately. 

Where processing is based on consent or contract and carried out by automated means, individuals may request their personal data in a structured, commonly used and machine-readable format. Where technically feasible, the data may be transmitted directly to another controller at the request of the individual. 

Where personal data is used in automated decision-making processes that produce legal or similarly significant effects, individuals have the right to request human review of the decision and obtain meaningful information regarding the logic involved in the processing. 

Data Discovery and System Searches 

Data Owners are responsible for identifying and retrieving relevant personal data from systems under their control. This includes ensuring that appropriate searches are performed across systems, platforms, applications, and repositories where personal data may be stored, including structured systems, cloud services, collaboration platforms, archived records, and relevant backup environments where reasonably accessible. 

Governance Operations will coordinate system searches and ensure that relevant data owners and system administrators are engaged to support the fulfilment of requests. 

Form of Response 

Responses are delivered securely, typically via an encrypted OneDrive link. Paper copies or alternative formats may be provided upon request where feasible and appropriate. Where information is redacted, the response will clearly identify where information has been withheld in accordance with applicable exemptions. 

Third-Party Data & Exemptions 

Third-party personal data will be redacted unless consent has been provided or disclosure is considered lawful and reasonable. Statutory exemptions, including legal professional privilege, regulatory confidentiality, protection of third-party rights, prevention or detection of crime, or protection of ongoing investigations, will be assessed by the CDPPO and documented. 

Where data is withheld, an explanation will be provided unless doing so would prejudice the exemption itself. 

Manifestly Unfounded or Excessive Requests 

Kerv reserves the right to refuse or limit the scope of a Subject Request where the request is manifestly unfounded or excessive, including where requests are repetitive or clearly intended to cause disruption. Any decision to refuse or limit a request must be assessed by Governance Operations and approved by the CDPPO. Where a request is refused, the individual will be informed of the reasons for the decision and their right to lodge a complaint with the supervisory authority. 

Record-Keeping & Retention 

Each Subject Request will be assigned a unique reference. 
Governance Operations will log all key actions, communications, searches conducted, redactions applied, and decisions made during the fulfilment process. All Subject Request records will be retained securely for a six year period commencing from the date of request closure. 

Process Workflow 

Step Owner Key Actions 
Governance Operations Log request and acknowledge within 5 working days 
Governance Operations Verify identity where appropriate and record verification method 
Governance Operations + CDPPO Classify the request type (access / rectification / erasure / restriction / objection / portability) 
Data Owners Locate relevant data, perform system searches, redact third-party references and provide output 
CDPPO Confirm lawful basis, assess exemptions, review and approve response 
Governance Operations Send securely to requester using approved methods 
Governance Operations Log closure and retain records securely for 6 years 

Internal SAR Operatives 

Subject Request handlers within Governance Operations: 

Roles & Responsibilities 

Role Responsibilities 
CDPPO (Chief Data Privacy and Protection Officer) Policy owner; authorises redactions; leads on complex cases and exemptions 
Governance Operations Manages request intake, logging, coordination, and secure response 
Data Owners Retrieve, review, and validate personal data from their respective systems 
All Staff Identify and escalate Subject Requests without delay 
Legal Counsel Support with exemptions, litigation risk, and regulator engagement 

Complaints 

If the Data Subject is not satisfied with our actions, they may raise a complaint directly to the Kerv Group Limited Managing Director at complaints@kerv.com

The Managing Director will assess and handle any written complaint concerning the way a Subject Request has been handled and the information that has been disclosed. 

Requestors in the UK may further write to the Information Commissioner’s Office at casework@ico.org.uk or by post at: 

Wycliffe House 
Water Lane 
Wilmslow 
Cheshire 
SK9 5AF 

Annex A – Definitions 

Term Definition 
Data Subject A living individual identifiable from personal data. 
Personal Data Any data relating to an identified or identifiable individual. 
Controller Entity that determines the purposes and means of processing. 
Processor Entity that processes personal data on behalf of a controller. 
Processing Any operation on personal data (e.g., collection, storage, deletion). 
SAR Subject Access Request made under UK GDPR and DPA 2018. 

Annex B – Templated Acknowledgment 

Dear [Requester’s Name], 

Thank you for contacting Kerv. We acknowledge receipt of your Subject Access Request (SAR) submitted on [insert date]. 

Your request is currently being reviewed by our Governance Operations team under reference [insert SAR reference number]. In accordance with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, we aim to provide a full response within one calendar month, subject to identity verification and the completeness of your request. 

In the event we require any further information to confirm your identity or clarify your request, a member of the Governance Operations team will contact you shortly. Please note the statutory timeframe for our response will begin upon our receipt of all requested information  and completion/satisfaction of the required identity verification.  

If you have any questions or wish to provide additional details in support of your request, please reply to this email or contact us at subjectrequests@kerv.com. 

Kind regards, 
Governance Operations Team 
Kerv Group 
www.kerv.com 

Worth Digital

is now part of Kerv

worth & kerv collab

In a continued effort to ensure we offer our customers the very best in knowledge and skills, Kerv has acquired Worth Digital.

Netwrx

is now part of Kerv

netwrx-popup

In a continued effort to ensure we offer our customers the very best in knowledge and skills, Kerv has acquired Netwrx.

Inciper

is now part of Kerv

In a continued effort to ensure we offer our customers the very best in knowledge and skills, Kerv has acquired Inciper.