The data processor/controller must ensure that any rectification, erasure, and restricting of processing data requests made by a data subject are properly communicated to all parties that had access to the data subject’s data.
The data processor/controller may be exempt from this requirement if notifying all such parties would require a disproportionate effort. The data subject must be informed of all these parties that had access to their data if they request such information.
The DPA contains several limitations to data subjects’ rights as they are provided under the UK GDPR. One such exception aims to protect the national security and defense of the country. Accordingly, the rights of data subjects do not apply if the exemption is required to safeguard national security or defense purposes, however, only in relation to manual unstructured data held by FOI public authorities.