On this page
- Introduction
- Scope
- Key Messages
- BCFT appointed Responsibilities
- Subject Access Requests.
- Rights to Erasure, Rectification, and Restriction
- Right to Data Portability
- Right to Object
- Automated Decision Making technology
- Accessing records about someone who has died
- Accepting Requests by Third Parties on Behalf of the Data Subject
- Data Protection Complaints
- Policy Review
- Appendix 1: Standard Costs to Be Used in the Calculation of Fees for Subject Access Requests under the General Data Protection Regulation (UK GDPR) and Data Protection Act (DPA) 2018.
- Appendix 2: Data Protection Rights Extension Authorisation Process Map
- Appendix 3: Information Governance Appeals Notice
1. Introduction
This policy forms part of Bradford Children Families Trust (BCFT) wider Information Governance Policy to ensure that BCFT complies with the provisions of the Data Protection Act 2018 (DPA) and the UK General Data Protection Regulation (UK GDPR).
The legislation states that data controllers are responsible for compliance with the six data protection Principles (the Principles) and must be able to demonstrate compliance to data subjects and regulatory bodies. The Information Governance Framework is the (BCFT) method to demonstrate compliance with these Principles. The Data Protection Rights Policy details how BCFT will comply with an individual’s data protection rights, including the right of access, and how BCFT will deal with Data Protection complaints and/or concerns. The policy is concerned with, in particular, the first data protection Principle:
Article 5(1)(a) Personal data should be processed lawfully, fairly, and in a transparent manner in relation to the data subject
Queries about this policy, or any policy in the Information Governance framework, should be directed to BCFT’s Data Protection Officer.
2. Scope
2.1 Who the policy applies to
This policy applies to all BCFT employees and any authorised agents working on behalf of BCFT, including temporary or agency staff, elected officials, volunteers, secondees and third-party contractors.
For the benefit of doubt this policy will refer to all individuals within scope of the policy as ‘Officers’. Officers who are found to knowingly or recklessly infringe this policy may face disciplinary action in accordance with BCFT’s disciplinary policies and procedures.
2.2 What the policy applies to
The Policy applies to information in all forms including, but not limited to:
- Hard copy of documents printed or written on paper;
- Information or data stored electronically, including scanned images;
- Communications sent by post/courier or using electronic means such as email, fax or electronic file transfer;
- Information or data stored on or transferred to removable media such as tape, CD, DVD, USB storage device or memory card;
- Information stored on portable computing devices including mobile phones, tablets, cameras and laptops;
- Speech, voice recordings and verbal communications, including voicemail;
- Published web content, for example intranet and internet;
- photographs and other digital images including CCTV.
In addition, the policy also covers information held by a third party on behalf of BCFT which is considered to be information held by BCFT and which may be required to be disclosed unless one of the exemptions/exceptions applies.
This policy does not include an individual’s ‘Right to be Informed’ as to how their data is being processed at BCFT. This is instead included in BCFT’s ‘Personal Privacy Policy’.
3. Key Messages
- Subject Access Requests are where a Data Subject, or legitimate representative of the Data Subject, can access any information that BCFT holds about them. This process is managed by the Information Governance Team, but directorates/service areas retain responsibility for ensuring requests are answered within the statutory time limits. Requests are subject to certain exemptions.
- Data subjects have the right to request that their personal data is erased, rectified or restricted. A number of considerations must be taken into account when addressing these requests. Where the request has been rejected, the data subject must be informed of this with an explanation. Where requests are upheld, the data subject must be given a certificate confirming this.
- Where BCFT is making use of Automated Decision Making technology, data subjects must be informed of its use and their rights in respect of this. Data subjects may make an outright objection or a partial objection to automate processing.
- Data subjects can request that BCFT provides them or another data controller with certain data which is processed by automated means in a machine-readable format. This applies where the processing was based on consent or contractual obligations.
- Where BCFT receives a request from an applicant regarding information relating to a deceased person, BCFT is bound by a Duty of Confidentiality. Such requests will be handled by the Information Governance Team due to the complexities in establishing right of access in these circumstances.
- Where a Data Protection request is received from an applicant on behalf of the data subject, BCFT must establish the applicant’s right to exercise the data protection request. Where a request is refused, a written explanation must be provided to the applicant.
- BCFT has an Information Governance complaints procedure in place to address concerns about how data protection requests have been handled. Complaints will be handled by the Data Protection Officer (DPO) alongside the corporate complaints process. If the complainant is still not satisfied, they may complain to the Information Commissioner’s Office (ICO). The Information Governance Team will act as a point of contact for the ICO.
4. BCFT appointed Responsibilities
BCFT is a data controller under UK GDPR (General Data Protection Regulation) and will remain accountable for protecting personal information.
In order that BCFT meets its obligatory requirements, it appoints the following responsibilities:
- The Senior Information Risk Officer (SIRO) is responsible for ensuring compliance with this policy and promoting openness and accountability.
- Senior Managers (e.g. Directors and Heads of Service) are responsible for ensuring that their business areas have processes and procedures in place that support this policy and comply with UK GDPR and the DPA 2018.
- Senior managers are responsible for ensuring that their business area has up to date privacy notices.
- Senior managers are responsible for ensuring that, when rights requests are made directly to contracted providers or agents who are processing personal data and providing services on behalf of BCFT, they are forwarded onto BCFT.
- Line managers must ensure that all staff who report to them are aware of the requirements of the legislations, and that all new staff receive an introductory briefing on the access to information procedures.
- All staff must recognise that all recorded information may be provided to the public/data subject, and that the law requires that there will be full and unconditional disclosure in every case unless one or more of the statutory exemptions / exceptions applies.
- Providers are also expected to support BCFT in responding to these rights request, in line with their responsibilities under UK GDPR.
- The Data Protection Officer (DPO) is responsible for the provision of advice relating to the release of any personal data as required.
5. Subject Access Requests
Data Protection Information Requests, known as Subject Access Requests (SAR), apply only to the personal information of the data subject – that is the person who the data is about. Only the data subject, someone legitimately acting on their behalf, a legally appointed advocate of the data subject, or a third party who has the explicit consent of the Data Subject should be permitted to access this data. The right of access is subject to certain exemptions.
5.1 Receiving a Request
Any officer, or contractor of BCFT could receive a request for personal data that is held by, or on behalf of, BCFT from an applicant at any time.
The DPA 2018 does not require SARs to be made in writing. However, applicants will be encouraged to complete the ‘Subject Access Request Form’ where possible to ensure BCFT understands the request and can more easily locate the requested information.
Requests that are received orally will be written down by the receiving officer and confirmed with the applicant by the receiving officer to ensure BCFT understands the applicant’s request.
All requests for personal information must be passed to the Information Governance Team. Each request received by BCFT will be acknowledged with the applicant within five working days by the receiving officer, a directorate representative, or the Information Governance Team. The Information Governance Team will log the request, provide a reference number and forward the request onto the responsible officer(s) to process.
BCFT must be satisfied as to the applicant’s identity. If the Information Governance Team is not certain of the applicant’s identity from existing BCFT records or involvement with the applicant, they may ask that that applicant produce:
- Valid photo ID (driver’s licence, passport etc);
- Proof of address (utility bill, council tax letter etc);
- Or sufficient information for BCFT to be satisfied of the applicant’s identity;
A list of accepted Identification Documents will be maintained and published on BCFT’s website. This list will be based on the Cabinet Office’s recommended list of recognised identification documents.
5.2 Fees
Generally, no fee may be charged for processing a subject access request. However, where a request is considered to be ‘Excessive’ or ‘Manifestly Unreasonable’ (as defined by Article 5 of the UK GDPR) or where the requested information has already been supplied, under Subject Access, to the applicant then BCFT may refuse a request outright or request a reasonable administrative fee.
SAR charges should be made in accordance with the Subject Access charging structure (Appendix 1).
5.3 Timescales
A request only becomes valid once BCFT is satisfied it has sufficient detail to respond to the request. Once a request is considered to be valid then BCFT has one calendar month to respond to the request. In most cases, for consistency, BCFT will interpret one calendar month to be 30 Calendar Days.
BCFT may apply a discretionary extension of up to two further calendar months to comply with the request if the requested information would take a considerable amount of time to collate, redact, and prepare for disclosure due to the complexity of the case (including volume of the information as an aspect of the complexity). If BCFT wishes to apply an extension they will inform the applicant of the extension within the first thirty days of receiving the request. This extension period will be kept to a minimum and will not be used as a way of managing heavy workloads. The DPO will approve and keep a record of all time extensions. A standard threshold, for applying an extension, will be maintained by the Data Protection Officer (Appendix 2).
These timescales also apply to Erasure, Rectification, and Restriction requests detailed in section 6.
5.4 Searching for Information
When locating information across BCFT filing systems, databases, and archives(electronic and manual) officers should take care to search name variations, initials, and nicknames. Officers should make a record of what search terms they have used and what systems were searched. The Data Protection Officer will provide BCFT officers with guidance as to how to search for information and how to keep records of such searches.
5.5 Exemptions and Third Party Information
There are a range of exemptions, in the Data Protection Act, which can be applied to some or all of the information being requested. A data subject’s right to their own data is very strong and BCFT will only apply exemptions when absolutely necessary.
Third Party data, that is data about a person other than the data subject, should also be withheld from the disclosure unless:
- the third party individual has given consent to disclosure,
- they are incapable of giving consent, or
- there is a reasonable expectation of disclosure (i.e. the third party is a BCFT officer or other professional working with the data subject);
The DPO will approve and keep a record of all exemptions applied to personal data disclosed under Subject Access.
5.6 Responding to Requests
SARs must be answered within the timeframes stipulated above.
Each directorate is responsible for responding to their own SARs. If the request is a cross-directorate request then the Information Governance Team will coordinate and send the response.
Whilst BCFT’s default position will be to transmit the requested information electronically by secure means, BCFT is obliged to send responses in the format preferred by the applicant. Every effort will be made to comply with this requirement. If an applicant requests the information in a specific format BCFT is not obliged to comply unless it is reasonable to do so. Where copy documents are requested there is no requirement to send a copy of the document to the applicant. In some cases it may be easier to extract the information from the document or to provide a digest.
Officers should take care to ensure redactions are permanent and cannot be reversed. The DPO will offer guidance to BCFT officers as to how to secure redactions effectively and efficiently.
Officers should also take care to transmit the requested personal data by secure means:
- Post: 1st class recorded or special courier
- Electronic Transmission: Galaxkey or through Sharepoint
6. Rights to Erasure, Rectification, and Restriction
As well as having the Right of Access to their personal data, data subjects may wish to exercise their rights to request that their personal data is erased, rectified, or restricted to one specific purpose.
It is the responsibility of the DPO, with the assistance of the relevant service area, to consider and respond to such requests.
6.1 Considering requests for Data Erasure
When considering a request for personal data to be erased from BCFT systems the following considerations must be addressed:
- Whether BCFT requires the information for a lawful and specified purpose or purposes, (including audit, archival, and research purposes)
- Whether the information was collected based on the consent of the data subject,
- Whether another legislative direction compels BCFT to retain or destroy the personal data,
- Whether the personal data is required by BCFT to establish, exercise, or defend legal claims of BCFT, or another individual,
- Whether erasing the data would jeopardise a record of decisions made by BCFT,
When rejecting a request for data erasure BCFT will, if it is appropriate to do so, explain the reasons for not complying with the applicant’s request. BCFT’s response must outline its lawful basis for processing the personal data and the retention period, or alternatively the criteria used to determine a retention period. BCFT will also contemplate whether, if erasing the data is not appropriate, rectifying or restricting the data would be more appropriate.
When upholding a request for data erasure BCFT will ensure that all BCFT systems, including archived records and electronic databases, will be cleansed. BCFT will inform the data subject when it expects this will be done and will provide the data subject with an assurance certificate stating the data has been erased.
The DPO will maintain a log of erasure requests and whether the request was upheld or rejected. If the request was upheld, the DPO will take care to ensure that their log, and corresponding records, does not include the information requested to be erased.
6.2 Considering requests for Data Rectification
When considering a request for personal data to be rectified the following considerations must be addressed:
- Whether the information held on BCFT systems is recorded as a fact, professional opinion, or statement made by a third party.
- Whether editing the data would jeopardise a record of decisions made by BCFT,
- Whether the Data Subject’s claims that the information is incorrect can be corroborated by other sources or professionals,
- Whether editing the data could lead to fraudulent activities.
When rejecting a request for data rectification BCFT will, if it is appropriate to do so, explain the reasons for not complying with the applicant’s request. BCFT will also contemplate whether it would be appropriate to attach the applicant’s request to the contested information so that future readers understand that the applicant contests the accuracy of the data.
When upholding a request for data rectification, BCFT will ensure that all BCFT systems, including archived records and electronic databases, will be updated. BCFT will inform the data subject when it expects this will be done and will provide the data subject with an assurance certificate stating the data has been erased. In some cases it may be more appropriate to annotate the record to reflect that the information is incorrect but that decisions have already been made based on the incorrect data.
The DPO will maintain a log of rectification requests and whether the request was upheld or rejected.
6.4 Considering requests for Data Restriction
As well as requesting that data be either erased or rectified, a data subject may ask BCFT to restrict their processing activities to limited purposes.
A request for restriction will be considered to be valid if:
- BCFT is verifying the accuracy of the data or the lawfulness of processing upon the data subject’s request,
- BCFT does not have a lawful basis for processing the data but the data subject has asked that BCFT does not delete the data,
- BCFT no longer requires the personal data other than for the establishment, exercising, or defence of legal claims.
Processing restrictions are not permanent and may be suspended if BCFT has either verified the accuracy of the data, the processing or the data, or a new lawful processing activity is required. BCFT will inform the data subject that the processing restriction has been suspended as soon as possible.
The DPO will maintain a log of restriction requests and whether the request was upheld or rejected.
7. Right to Data Portability
As well as the right of access to their personal data, data subjects can also request that BCFT provides them, or another controller of their choice, with certain data in a machine readable format. This is known as the right to Data Portability.
Data Portability will only apply if the processing was based on the consent of the data subject or based on contractual obligations. Data Portability will also only apply to data processed by automated means.
The DPO will maintain a log of such requests and will work with Technology Services to ensure that requests are processed within one calendar month.
8. Right to Object
Data subjects do have the right in certain circumstances to object to the processing of their personal data. Where direct marketing is involved, Data subjects have an absolute right to stop the processing of their data, however, in other cases it might be possible for BCFT to continue processing after the objection is received if there is a compelling reason for doing so.
The DPO will assist the service area in making a determination on what is appropriate in the circumstances. DPO will also maintain a log of such requests.
9. Automated Decision Making technology
For some processes BCFT may wish to utilise Automated Decision Making technology. If this is the case then BCFT must, in most cases, inform data subjects that the technology is in use and how, and if, the data subject is able to object to the use of the technology on their personal data.
9.1 Definition and Scope of Automated Decision Making Technology
The Information Commissioner’s Office defines Automated Decision Making as using automated algorithmic technology to make predictions or decisions about an individual based on data about their personality, behaviour, interests, or habits.
This policy does not apply to automated analysis processing where aggregated data is being used for research, to generate statistics, or to direct BCFT policy.
The policy also does not apply to processing where automated technology has been used for a calculation but there has been human review before a decision is made i.e. an assessment tool.
9.2 Informing Data Subjects
When BCFT does operate automated decision making technology it must inform data subjects that their personal data is, or may be, subject to the technology and decisions may be made about them as the result of the processing.
Data subjects will be informed through the utilisation of service level Privacy Notices. These notices are covered by BCFT’s ‘Personal Privacy Policy’.
9.3 Safeguards when using Automated Decision Making Technology
BCFT’s ‘Personal Privacy Policy’ will outline what measures will be implemented in order to safeguard the rights and freedoms of the data subject when using Automated Decision Making Technology.
10. Accessing records about someone who has died
We understand that requesting information about someone who has died may happen at a difficult or distressing time. This page explains how Bradford Children and Families Trust considers requests for records about a deceased person.
The UK GDPR and Data Protection Act 2018 only apply to living people. This means a request for records about someone who has died is not dealt with as a subject access request. However, this does not mean there is an automatic right of access to the person’s records. We must still consider confidentiality, the rights of living people, and whether any legal restrictions or exemptions apply.
Depending on the type of information requested, we may need to consider the request under other legal frameworks, including the Freedom of Information Act 2000, the Access to Health Records Act 1990 where relevant, and the common law duty of confidentiality. Each request will be considered on a case-by-case basis.
10.1 Who can request information?
We will usually only consider sharing records where the person requesting them can show they have a legal or legitimate basis for access.
This may include where you are:
- the deceased person’s personal representative, such as the executor or administrator of their estate;
- someone who held a relevant Lasting Power of Attorney or deputyship while the person was alive;
- someone with evidence of a legal claim arising from the person’s death;
- a solicitor or representative acting with written authority from someone entitled to request the information; or
- able to provide evidence that the deceased person would have agreed to the information being shared.
Being a relative or next of kin does not automatically give a right of access to records.
10.2 What we need from you
To help us consider your request, please provide:
- the full name of the deceased person;
- their date of birth, date of death and last known address, if known;
- details of the records or information you are asking for;
- proof that the person has died, such as a death certificate, grant of probate or letters of administration;
- proof of your identity and current address;
- evidence of your entitlement to request the information, such as probate, letters of administration, a will showing you as executor, LPA/deputyship documentation, legal claim documentation or written authority.
We may need to ask you for more information before we can consider your request.
10.3 How we consider requests
Each request is considered individually. We will consider:
- whether we hold the information requested;
- whether you have provided enough evidence of your identity and entitlement;
- whether the information is confidential or sensitive;
- whether the records include information about children, family members, carers, professionals or other living people;
- whether any information should be withheld or redacted;
- whether disclosure would be lawful, fair and appropriate;
- whether any exemption or legal restriction applies.
Records held by children’s services can be highly sensitive. They may include information about other people, including children and family members. Where information relates to living people, we must consider their data protection rights. This means we may not be able to provide all the information requested, or information may need to be redacted before it is shared.
Providing evidence does not guarantee that records will be disclosed.
10.4 How to make a request
Please send your request in writing to:
Email: DPO@Bradfordcft.org.uk
11. Accepting Requests by Third Parties on Behalf of the Data Subject
Where a Data Protection request has been received by an individual, who is acting on behalf of the data subject, then BCFT must establish the applicant’s right to exercise a data protection request.
The following table expresses what evidence must be examined before a request from a third party will be accepted:
| Applicant Type | Evidence Required |
| On behalf of: Child Under 12 Years Old (or older child lacking mental capacity) | Demonstrable evidence that you have parental responsibility for that child. |
| On behalf of: Child Over 12 | Your child may be asked to consent or agree to disclose data to you in certain circumstances. |
| On behalf of: an Adult | Official paperwork listing you as legal guardian of the data subject. |
| Solicitor or Agent acting on data subject’s behalf | A form of authority addressed specifically to BCFT and signed by the data subject or their legal representative. In some circumstances we may also request explicit consent from the data subject. |
| Other individual acting on data subject’s behalf | The data subject may be asked to consent or agree to disclose data to you in certain circumstances. |
Each data protection request will be decided on a case-by-case basis and will take in to account any exceptional factors.
When refusing a data protection request, due to no right of access being established, officers must highlight why a request has been refused and what the applicant can do to persuade BCFT to re-examine their request.
12. Data Protection Complaints
Unlike with the Freedom of Information Act 2000 and the Environmental Information Regulations 2004, the UK GDPR and DPA 2018 do not require BCFT to have a statutory internal review process. However, it is considered to be best practice to have a complaints procedure in place if a data subject:
- believes that exemptions have been applied incorrectly or information is missing from a response to a Subject Access Request,
- believes that other Data Protection Requests have not been handled appropriately or have not taken in to consideration all factors,
- believes that BCFT is processing their personal data unlawfully, unfairly, or in a manner not deemed to be secure.
BCFT will maintain and publish an Information Governance Appeals Document so that applicants understand the process (Appendix 3). The appeals document must be attached to all responses to Data Protection rights.
The DPO will be responsible for considering and answering such complaints. This will be in conjunction with BCFT’s corporate complaints process where required.
Data Protection internal reviews will be conducted and responded to within 30 Calendar Days.
If an applicant is not satisfied with the outcome of an internal review they may raise a concern with the ICO. The Information Governance Team, on the instruction of the DPO, will act as the point of contact for the ICO in respect of concerns raised.
13. Policy Review
This policy will be reviewed every two years unless there is a change in legislation, practice or procedure in which case the policy will be reviewed more frequently to ensure it remains accurate, relevant and up to date.
Appendix 1: Standard Costs to Be Used in the Calculation of Fees for Subject Access Requests under the General Data Protection Regulation (UK GDPR) and Data Protection Act (DPA) 2018
| Staff time [1] | £25.00 per hour |
| Printing and Photocopying Costs (per Sheet) | A4 (b/w) – 2p A4 (colour) – 10p A3 (b/w) – 4p A3 (colour) – 20p A0 (b/w) – £2.00 A0 (colour) – £10.00 |
| Postage Costs | 1st class at cost or original estimate, whichever is lesser |
| Other items such as relevant translation | At cost or original estimate, whichever is lesser |
CHARGING REGIME:
All charges will be calculated at time of request. The applicant will be advised of any charge and all payment must be settled prior to work commencing.
| Only applicable where a request is considered to be ‘Excessive’ or ‘Manifestly Unreasonable’ or where copies of information, already provided under Subject Access, have been requested | |
| Staff Time Required | Charge (£) (+VAT Where applicable [2]) |
| Less than half an hour | Disbursement costs only |
| At least half an hour, but less than one full hour | £12.50 + disbursements |
| One full hour | £25 + disbursements* |
| *A further £25 will be charged for each additional full hour required to identify the information requested (with a pro rata’d calculation for part hours) | |
[1] Activities taken into account when calculating staff time are locating, retrieving and extracting the information.
[2] VAT will be applied in addition to charges outlined should the information requested be available to the applicant from another source other than BCFT.
Appendix 2: Data Protection Rights Extension Authorisation Process Map
Each extension will be awarded on a case by case basis but the following diagram will be used as a standard

Appendix 3: Information Governance Appeals Notice
This document outlines the appeals process that services users can exercise if unhappy with the way in which a request for information has been handled. This document covers requests made under the Freedom of Information Act 2000, Environmental Information Regulations 2004, and Data Protection legislation.
Appeals regarding Freedom of Information (FOI) and Environmental Information Regulations (EIR) Requests
If you are dissatisfied in the way in which the BCFT has responded to your request for information under the FOI Act or EIR then you may request that BCFT conducts a statutory Internal Review. You may wish to request such a review if you:
- are dissatisfied with the way in which your request has been handled,
- do not agree with an exemption that has been applied to the information you have requested,
- believe that not all of the information has been provided to you.
Upon receipt the Information Governance Manager will appoint an officer to handle your complaint. Where possible the appointed officer will not have had any involvement in your original request and will have more seniority than the original responding officer. The reviewing officer will then examine your original request and the response that was sent to you and decide whether BCFT responded to your request appropriately according to legislative requirements. The reviewing officer will also decide whether to uphold or overturn decisions to withhold information.
BCFT will conduct FOI and EIR Internal Reviews within 20 Working Days.
If you are dissatisfied with the response to an Internal Review you may appeal to the Information Commissioner’s Office (see overleaf).
Appeals regarding Subject Access Requests (SAR) and other Data Protection requests or concerns
If you are dissatisfied in the way in which the BCFT has responded to your Subject Access Request or other Data Protection request/concern then you may request that BCFT conducts an Internal Review. Unlike with the FOI/EIR process this is not a statutory requirement but is instead a stage that BCFT has chosen to adopt. You may wish to request such a review if you:
- are dissatisfied with the way in which your request has been handled,
- do not agree with an exemption that has been applied to the information you have requested,
- believe that not all of the information has been provided to you.
Upon receipt the Information Governance Manager will appoint an officer to handle your complaint. Where possible the appointed officer will not have had any involvement in your original request and will have more seniority than the original responding officer. The reviewing officer will then examine your original request and the response that was sent to you and decide whether BCFT responded to your request appropriately according to legislative requirements. The reviewing officer will also decide whether to uphold or overturn decisions to withhold information.
BCFT will conduct Data Protection Internal Reviews within 30 Calendar Days.
If you are dissatisfied with the response to an Internal Review you may appeal to the Information Commissioner’s Office (see overleaf).
How to Request an Internal Review
To request that BCFT requests an Internal Review you should contact the Head of Governance and Risk on the below contact details:
Corporate Information Governance Team,
Sir Henry Mitchell House,
4 Manchester Road, Bradford,
West Yorkshire,
BD5 0QL
Email: dpo@bradfordcft.org.uk
When requesting an Internal Review you should supply the following information:
- Your name (so that we can identify you and your request)
- Your contact details (so that we can contact you with our response)
- Request reference number (this should have been provided to you when BCFT responded to your original request)
- Reasons why you are dissatisfied with the response to your request
The Information Governance Office will acknowledge your request for an internal review within 5 working days and advise you of timescales for responding.
Please be aware that Internal Reviews will not usually be conducted if 2 Calendar Months have passed since your request was responded to.
After BCFT has considered your appeal
If, following the completion of an internal review, you still remain dissatisfied with the way in which BCFT has handled your request then you may appeal to the Information Commissioner’s Office (ICO). The ICO is the UK’s Freedom of Information and Data Protection Regulator.
You can do this via the ICO’s website:
https://ico.org.uk/make-a-complaint/
ICO helpline: 0303 123 1113.
Normal opening hours are Monday to Friday between 9am and 5pm (excluding bank holidays).
If you are dissatisfied with the ICO’s response to your complaint, then you may be able to take your complaint to the information tribunal. The ICO will give you details about this when they issue their decision notice.
| Lead Author | Head of Governance and Risk | |
| Department | Information Governance | |
| Applies to | All BCFT employees and any authorised agents working on behalf of BCFT, including temporary or agency staff, elected officials, volunteers, secondees, and third-party contractors. | |
| Version | 1.0 | |
| Date Approved | 8th January 2026 | |
| Review Date | January 2027 | |
| Version History | ||