For legal issues relating to Data Protection check this link...Lots of very useful info in understandable terms.
Data Protection | OUT-LAW.COM
it includes the following and much much more
Negotiating with the Data Subject (This should be important to Banks)
At this stage, it is advisable to negotiate with the data subject. The location information the data subject will have already given will give a clue as to what it is the data subject really wants to have information about. The benefit of the Data Protection Act 1998 is that it allows data controllers to negotiate with data subjects to get the data subject to specify the exact information he or she wishes to receive.
The data controller is entitled to ask for a fee of £10 and two further pieces of information. Firstly, the data controller must satisfy himself that the person making the request is, in fact, the data subject. The use of a
Subject access request
form is advised, since the greatest breach of a data controller's security is for the data controller to satisfy a
Subject access request
made by a person impersonating the data subject. The use of the form goes towards proving that the data controller has adequate identification and verification procedures in place. Secondly, the data controller is entitled to ask the data subject for further information to enable the data controller to locate the information which that person seeks.
When the last of these three pieces of information has been obtained, the forty day period starts to run. It is advisable to put procedures in place to ensure that the receipt of the request and the further information is correctly dated so that an organisation knows how long it has to satisfy the subject access request.
However, if the data subject is adamant that he or she wishes to receive a copy of everything the data controller holds on him or her, then there is very little the data controller can do about this, and a completely exhaustive search of the computerised and manually held data in the organisation will be required. (nice to know what you see in the Act is what you get)