Why the Right of Access is broken DSARs are an overly onerous and often pointless exercise There’s been murmuring for years about the ‘weaponisation’ of the right of access. Individuals submitting Data Subject Access Requests in an effort to try and ‘dig up dirt’ for another matter. Maybe during an unfair dismissal claim, a disciplinary case, employment tribunal, an ongoing complaint or prior to litigation. Organisations sometimes believe the person is submitting a DSAR just to be downright awkward and find themselves unable to meet the threshold to refuse the request (in part, or in full) as ‘manifestly’ unfounded or excessive. Businesses are spending excessive amounts of time responding to more tricky requests. We’re told we need to be prepared and have enough resources to handle requests. But is it reasonable to expect small-to-medium sized organisations to have teams on standby for 6-7 requests a year? Often one or two people have to dedicate hours… days, to respond by the statutory deadline. This can be a whole calendar month where they’ve done little else. We also know countless local councils, police services, NHS trusts and other public bodies have been on the receiving end of official ICO reprimands for failing to address their massive backlogs of requests. Something needs to change. It’s getting worse not better. Anecdotally, I’m hearing the number of requests is steadily increasing. No one is immune. Companies that have never received a DSAR have had the horror of their first one from a disgruntled ex-employee. Charities, housing associations, travel operators, retailers, publishers are all in the firing line. The problem. Fulfilling this right is often not straightforward. The ICO’s guidance is over 100 pages long. I can deliver a whole day’s DSAR training session and not cover every nuanced consideration. The specific circumstances of a request can throw up new challenges. Yes, we can always improve our procedures and make efficiencies. But ultimately, with difficult requests there will always be time-consuming issues which can’t be automated. There may be brilliant software available to streamline the process. But many small-to-medium sized companies and charities, with limited budgets, will struggle to justify the cost of new technology when the volume of requests is not very high, and fluctuates significantly. Some redaction technology can almost make things worst by over-redacting. Then, after all our efforts are people happy with what they receive? It seems not. While I can’t find the most recently figures, the ICO’s 2023/24 Annual Report reveals nearly 40,000 complaints were received by the regulator. A staggering 39% of these concerned DSARs. Those submitting requests are clearly further disgruntled with what they receive. By June 2026 UK organisations will be legally required to have a data protection complaints procedure. And yes, this will inevitably mean a percentage of the DSARs you get out the door, will come straight back in as a formal complaint. More time and effort, while the individual’s frustration grows. I fear we’ll see public bodies not just being accused of failing to address a massive backlog of DSARs, but a massive backlog of unresolved data protection complaints too. Of course, we’re not all saints. Some organisations do a bad job with DSARs. I’ve seen cases where individuals have been provided with reams of overly redacted documents which make no sense. Some organisations blatantly ignore requests. A Care Home manager has been personally fined for deliberately destroying and withholding information, when faced with a DSAR. There are the cases where bad practices can be exposed. There are the high-profile cases. Nigel Farage successfully revealed via a DSAR that NatWest had closed his Coutts account due to his political opinions. And then via a second request exposed how NatWest employees had made disparaging comments about him. But I like to believe there are plenty of organisations trying their very best to do the right thing. I work with some who spend painstaking hours retrieving, assessing and redacting, only to look at what they’re providing and think ‘is this of any value to the person?’ Often, a DSAR seems far from the most suitable route for the individual to get the information or resolution they’re seeking. If we take a step back to why this right exists in data protection law it seldom feels like DSARs are being submitted in the spirit of what legislators intended. GDPR states: The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data… Recital 63 gives us further clarification: A data subject should have the right of access to personal data which have been collected concerning him or her, and to exercise that right easily and at reasonable intervals, in order to be aware of, and verify, the lawfulness of the processing. For its part the ICO says: It is a fundamental right for individuals. It helps them understand how and why you are using their data and check you are doing it lawfully. In reality? The times when an individual is actually expressing an interest in the ‘lawfulness of processing’ are, in my experience, exceptionally rare. In the past twenty years, I can’t think of any case I’ve dealt with where the requestee has stated an interest in this. So, my interest was piqued by a proposal in the European Commission’s Digital Omnibus, which is looking at amending aspects of GDPR. It suggests requests could be rejected, or a fee charged, if a controller considers the request is being used by someone for other purposes than the ‘protection of their personal data’. On the face of it, this seems a good idea. An attempt to take the right of access back to what the legislation originally intended it to be. But the devil will be in the detail. How would organisations make this judgement call? Will people just get smart and add new wording to make sure their requests meet the bar? If the EU does proceed with significant changes, I would encourage the UK Government to follow suit. Others in my field may gasp and shake their heads, but I was disappointed the UK Data (Use and Access) Act only clarified in law right of access matters which already happen in established practice. I wish it had gone further. There are other areas which could be looked at. When an individual insists they want all their personal data, should organisations really be under an obligation to include information the individual already has? Is the timescale too short? Could we at least not have to count bank holidays! Can the threshold for manifestly unfounded or excessive be lowered, or changed? As it stands, I believe some but not all DSARs are too onerous for organisations to fulfil, and often provide no meaningful benefit for the individual. No one seems to win, and complaints grow. Please can something change. Unfortunately, as the law is unlikely to be amended any time soon, either in the EU or UK, I’ll leave you with a few quick tips: A DSAR is not a right to documentation. It’s a person’s right to receive a copy of their personal data and other supplementary information. A request for specific information isn’t a DSAR just because it includes personal data – in fact treating a specific request like a DSAR can be to the individual’s detriment and create an unnecessary burden on resources. Managing expectations right from the start can help to reduce complaints. People often have a flimsy grasp of what the right actually entitles them too. Talking with the requestee can often resolve much more than relying on emails. I’ve written more about managing employee related requests and do check out the ICO’s helpful employee DSAR Q&A.
The Little Book of Data Protection Nuggets
Managing Employee DSARs Right of Access: Data Subject Access Request (DSAR / SAR) Your heart sinks. It’s a DSAR. It’s from a fellow employee. There’s an ongoing grievance case. You know it’s going to be tricky. Nuanced. Time-consuming. It’s even worse than someone cooking fish in the office microwave. Current and former employees don’t tend to submit requests when they’re happy. There’s usually another issue at play – an unfair dismissal claim, an allegation of bullying or harassment, perhaps? Having seen a recent spike in employee-related requests, I thought it might be helpful to provide a refresher on some (but by no all means all) DSAR matters. Be prepared If you’re planning workplace changes, or any other activity likely to unsettle people, be sure to factor in the potential for this to cause an increase in DSARs. Be prepared, with the necessary skilled resources on standby. Awareness Do your people know what to do if they receive a request – verbally, by email or in the post? Do they know where this should be forwarded to, and pronto? I’ve known of DSARs to be left languishing in someone’s inbox for a couple of weeks. They aren’t going away. In fact they’ll lurk there, like an alien in a horror movie. Watching. Waiting to pounce. Okay, not really, but you get the drift. Be sure to raise awareness to try and avoid a last-minute panic to meet the statutory response timeframe. Reason People don’t have to explain why they’ve submitted a request. Nor do they have to explain how they intend to use the information you provide them with. They don’t have to give you a reason, and many won’t. You may suspect it’s a ‘fishing’ exercise linked to another issue, but this mustn’t be allowed to get in the way of fulfilling their request. A DSAR should be handled separately to other matters, to prevent bias and make sure the process is fair. Admittedly, this may be easier in practice for larger organisations than smaller ones. And don’t forget you still need to respond on time, even if the statutory response date falls while other matters (such as a grievance) are ongoing. Clarification You can always ask for clarification if a request is unclear, or is going to involve searching, assessing and/or providing a significant amount of information. For example, you can ask specifically what information they’re seeking, and the date range they’d like you to focus on. This can prove not just helpful for you, but also the individual themselves. However, ultimately, you can’t force the person to narrow their scope. If they want all of their personal data, they are entitled to it – as long as its ‘reasonable and proportionate.’ Reasonable and proportionate searches The scope of your searches may have to cover structured and unstructured data – such as emails and messaging apps. And I’m afraid there’s no magic wand to solve this one. It’s a classic example of ‘each case turns on its own merits.’ If you can demonstrate a search is clearly unreasonable or disproportionate, you may refuse it. You need to balance the importance of the information to the individual, the circumstances of the request and the difficulties involved in retrieving the information. As an example, it’s likely to be disproportionate to run a search just for someone’s initials in your email system, if this returns thousands of irrelevant results because it scoops up any word with those initials in it. But remember, the ICO says the burden of proof is on the organisation to justify why a search is unreasonable or disproportionate – which is why it’s difficult to provide a hard and fast rule. The Regulator also says organisations should design information management systems so personal data can be efficiently located, extracted and redacted. Remember, this is not a new right. Subject access requests were first introduced in the UK back in 1984, were enhanced by the Data Protection Act 1998, and further changes were then introduced in 2018 by GDPR. The shiny new Data (Use and Access) Act 2025 has clarified searches should be ‘reasonable and proportionate’, and the ICO is planning to publish updated ‘Right of Access’ guidance within the coming months. Here’s hoping we get further detail from the regulator on how this should be interpreted in practise. Some real-world examples would be nice. Not a right to documentation People are entitled to a copy of their personal data, but not entire documents, or indeed full email chains. Just because someone’s name or email address appears in a document or email doesn’t mean the rest of the content is their personal data. Especially if this relates to other routine ‘business as usual’ (BAU) matters. So there can be quite a painstaking process to sift the personal data you need to provide from the information you don’t need or wish to include. You can take steps to exclude BAU correspondence, which is highly unlikely to include additional personal data other than the individual’s email address and name. Social media If your organisation has corporate pages on social media platforms like Facebook, Instagram, WhatsApp or X you’ll be the controller of any information posted, so they’re potentially in scope depending on the nature of the request. Also potentially in scope, are any posts shared with you, for example by other colleagues. Recordings and transcripts If you record and or use an AI tool to transcribe meetings – these are likely to capture personal data, so depending on the nature of the request may well be in scope. When is it okay to transcribe meetings? Information they already have Information the requester already has in their possession (or has access to) is within scope. For example, letters or other documents previously shared directly with them. They may of course, confirm they are okay for these to be excluded, if you ask. Information about others The Data Protection Act 2018 provides an exemption which says you don’t have to comply with a request, if doing so means disclosing information which identifies another individual, unless, the other individual has given their consent, or it’s reasonable to disclose without their consent. Routinely this won’t mean you don’t have to comply with the request in full, but rather that the protecting others is considered with respect to some of the information that’s been collated. Often with employee requests searches will retrieve some information which relates to other people. Sometimes it will be reasonable to disclose with or without consent, sometimes it will be possible to apply redaction, so other individuals are no longer identifiable. Alternatively, you might choose to extract only the pertinent personal information relating to the requester. Where it’s not possible to render another person unidentifiable, where you have a duty of confidence and/or a real concern this will infringe on the other person’s rights and freedoms, you may decide not to disclose. Negotiations with the individual If you have a record of your intentions in any negotiations with the requester, this would be exempt from the right of access if this could prejudice the negotiation. The ICO stresses this exemption is only likely to apply while negotiations are ongoing and may be difficult to apply once they’ve ended. In short, anything you write might ‘be taken down and given in evidence’ (ahem!). Non-disclosure or settlement agreements The ICO says people have the right to a copy of their personal information, and this right cannot be overridden by a settlement or non-disclosure agreement. In other words, even if it’s written into an agreement that the individual is not permitted to submit a DSAR, the Regulator says this element of any agreement is likely to be unenforceable. It’s quite possible someone might willingly withdraw their DSAR as part of a settlement, but this doesn’t render them barred from submitting one again in future. So, finally… To sum up, there’s no easy way to handle an employee related DSAR. It requires an eye for detail and an understanding of the rules and principles behind the legislation. Is there anything that might make DSARs more straightforward? Having a robust DSAR procedure and a robust approach to data retention – only keeping what’s necessary, so there’s less data to trawl through when you get a request. And just to say if a DSAR is especially delicate or complex, it may be a wise to seek legal advice where you’re unsure.