Opaque Privilege

My Battle for UK GDPR Compliance: Challenging Muckle LLP’s Handling of Subject Access Requests

Data protection case commentary

Subject Access Requests are meant to give people practical access to their personal data. This case study concerns a SAR dispute involving Muckle LLP and the difficulties a data subject says they faced when trying to understand what had been searched, what had been withheld, why privilege was relied on, and how concerns about public accountability were characterised in correspondence.

Category
Case commentary
Jurisdiction
UK data protection
Reading time
c. 9 minutes
Last reviewed
1 June 2026
By-line
Legal Lens

Publication snapshot

  • This article examines a data subject’s account of a disputed Subject Access Request involving Muckle LLP.
  • The issues raised include redaction, legal professional privilege, legitimate interests, search scope, security information and tone of correspondence.
  • The central accountability question is whether the SAR response allowed the requester to understand what personal data had been disclosed, what had been withheld, and why.
  • The wider point is practical: SAR compliance depends not only on technical legal answers, but on clear reasoning, transparent search explanations and respectful engagement.

Why this matters

A Subject Access Request, often shortened to SAR, is one of the most practical rights in UK data protection law. It allows a person to ask what personal data is being processed, obtain a copy of that data, and receive supplementary information about how it is being used.

That right matters especially where the data sits inside legal correspondence, matter files, complaint handling, internal emails, advice notes, call records, decision documents or communications between professional firms. A response may be formally lengthy but still difficult to test if key context is withheld or if exemption explanations are too general.

The practical question: can the requester understand what has been searched, what personal data has been disclosed, what has been withheld, and the reason for any withholding?

Case background

The complainant says their SAR experience with Muckle LLP raised concerns about how legal-sector organisations handle data access requests when the underlying matter is contested. The concerns included whether correspondence had been withheld, whether redactions were properly explained, whether legal professional privilege had been applied too broadly, and whether the search had covered all likely sources of personal data.

The complainant also says there were similarities between SAR responses from two organisations, raising a question about whether Muckle LLP had a wider role in drafting or shaping another response. Similarity of wording does not prove improper coordination. It may reflect template wording, shared legal language or ordinary professional input. But where the requester’s personal data may have been shared or discussed, it is reasonable to ask what role each organisation played and what data was processed.

What is established by the draft

The draft raises a personal account of a disputed SAR process involving Muckle LLP, with references to correspondence between 17 and 26 July 2024.

What remains contested

The adequacy of the response, the scope of search, the basis for privilege, and the meaning of any similar wording would depend on the underlying correspondence and disclosure bundle.

What the reader should focus on

The wider lesson is not simply whether one response was right or wrong, but how SAR responses should be explained so a data subject can meaningfully understand them.

Why the legal sector matters

Law firms often hold sensitive, disputed and context-heavy personal data. That makes careful SAR handling especially important.

Redactions and privilege

The complainant says the response relied on legal professional privilege to withhold significant material. Legal professional privilege can be a valid reason for withholding personal data in a SAR response. It protects confidential legal communications in defined circumstances, including legal advice privilege and litigation privilege.

The concern in this case study is not that privileged material must always be disclosed. The concern is whether the explanation was specific enough to allow the data subject to understand the categories of material withheld and why privilege was said to apply. A response that simply invokes privilege without meaningful context can leave the requester unable to test whether the exemption has been applied to the facts of the request.

The key distinction

The right question is not whether a law firm can ever rely on privilege. It can. The stronger question is whether the privilege position is explained with enough clarity, discipline and accountability to show that it has not been used as a blanket answer.

1

Identify the category

The response should, where possible, explain whether the withheld material is legal advice, litigation material, third-party data or another protected category.

2

Explain the basis

The controller should be able to identify the exemption or basis relied on and show why it applies to the relevant material.

3

Avoid blanket language

General wording may sometimes be necessary, but routine or blanket reliance on exemptions weakens transparency.

4

Preserve accountability

The organisation should keep an internal record of its reasoning so the response can be defended if challenged.

Legitimate interests and transparency

The complainant says they asked for more information about the legitimate interests relied on in the processing of their personal data and were told there was no legal obligation to provide the legitimate interest assessment itself. That issue needs careful separation.

A controller may not always be required to disclose an internal assessment document in full. However, where legitimate interests are relied on as a lawful basis, transparency still matters. A data subject should be able to understand the purpose of processing, the nature of the interest relied on, and how their rights and interests have been considered.

Formal position

An organisation may say it is not required to provide a full internal assessment document as part of a SAR response.

Transparency concern

The requester may still reasonably ask for a clear explanation of the interest relied on and how the processing was assessed.

Practical standard

A clear summary may assist compliance by showing that the organisation has considered the data subject’s position rather than relying on formulaic wording.

Search scope and security information

The complainant says the initial response appeared to limit the search to emails and matter files. That raised a concern about whether other sources of personal data had been considered. In many organisations, personal data may sit across case-management systems, billing records, call notes, internal messaging, archived files, document-management systems, complaints records and correspondence with third parties.

A SAR response is stronger when it explains the search logic. The requester does not need every internal operational detail, but they should be able to understand whether the organisation looked in the obvious places and whether any limitation on search scope was reasonable.

The complainant also says the firm referred to privacy-policy and third-party compliance material when asked about security measures. In data protection practice, security is not only a policy statement. It includes technical and organisational measures appropriate to the risk. A response does not have to disclose sensitive security detail that could create risk, but it should give enough information to explain how personal data is protected at a meaningful level.

Search locations

Emails and matter files may be central, but the response should consider whether other systems are likely to hold personal data.

Archived records

Historic or closed matter records may still contain personal data if they remain accessible or within retention systems.

Third-party correspondence

Where another organisation was involved, the requester may ask what personal data was shared and for what purpose.

Security explanation

Security responses should balance useful reassurance with the need not to reveal sensitive operational details.

Tone and accountability

The complainant says that when they raised concerns about possible public disclosure of their experience, the response characterised this as a threat and as akin to blackmail under section 21 of the Theft Act 1968. That is a serious characterisation. In a data-rights dispute, language of that kind can change the whole tone of the exchange.

There is an important difference between improper pressure and a person saying that they may speak publicly about a regulatory or rights-based concern. Organisations are entitled to protect their position, challenge unfair allegations and object to improper conduct. But professional engagement is stronger when it addresses the substance of the concern before escalating the language of the dispute.

What escalates the dispute

Characterising rights-based concern as improper pressure without first giving a clear explanation of the SAR position can make the process feel defensive and adversarial.

What improves accountability

A clearer response explains the search, exemptions, privilege position, complaints route and any limits on what can safely be disclosed.

Practical lessons

This case study points to practical lessons for organisations handling SARs and for data subjects challenging responses. The best SAR process is not simply legally defensive. It is structured, intelligible and capable of being checked.

1

Explain the search

Identify the obvious systems considered and explain any limits on the search scope in clear terms.

2

Use exemptions carefully

Apply privilege, third-party data and other exemptions to the facts of the request, not as a general shield.

3

Summarise where full disclosure is not possible

Where a document cannot be disclosed, a careful category explanation may still improve transparency.

4

Keep the tone professional

Rights-based concern should be answered with substance, not treated as a personal affront.

5

Preserve the record

Data subjects should keep the SAR, response bundle, redaction explanations, follow-up correspondence and any complaint outcome.

Source anchors

These sources help separate the right of access, exemption framework, security context, professional standards and criminal-law reference point:

Closing point

The right of access works only when a person can understand the response. Legal professional privilege, third-party data, security concerns and confidentiality may all justify limits on disclosure in the right case. But the process still needs explanation, discipline and proportionality. In a legal-sector SAR, the standard should be practical transparency: enough clarity for the requester to understand the answer, enough reasoning for the controller to justify it, and enough professionalism to keep the dispute focused on the data rights at stake.

Legal Lens decision support

If a SAR response relies on privilege, gives limited search detail, redacts heavily, or avoids explaining the lawful basis for processing, the next step should be structured. A focused review can help turn a confusing response into a clear list of issues to raise.

What the assessment can organise

Legal Lens can help identify the response gaps, separate privilege from search-scope issues, build a concise chronology, and prepare a practical follow-up route for the organisation or the ICO.

Redaction pattern Privilege explanation Search scope Legitimate interests Security response ICO escalation pack

Best for

Data subjects facing incomplete disclosure, unexplained redactions, privilege claims or unclear SAR search responses.

What you get

A structured issue map showing what appears missing, what needs clarification and what evidence supports escalation.

Practical output

A cleaner route for follow-up: targeted questions, document schedule, ICO complaint structure or correspondence plan.

Independent Legal Lens consultancy. A preliminary assessment is decision support designed to help you organise the documents, issues and next step.

This article is Legal Lens public-interest commentary and practical legal education. It is based on the issues and materials described by the author and is intended to support clearer discussion of data rights, SAR handling and professional accountability.

Leave a Reply

Your email address will not be published. Required fields are marked *

Skip to toolbar