Shattered Trust

Exposing GDPR Non-Compliance: A Deep Dive into Mishandled Subject Access Requests

Subject access · Data transparency · England & Wales

A subject access request is not a courtesy request. It is a statutory route for understanding what personal data is being processed, why it is being used, who has received it, and whether the processing is lawful. Where a response is delayed, heavily redacted, or justified by broad references to privilege, the issue is not only disclosure. It becomes a question of transparency, accountability and trust.

Category
Data protection
Jurisdiction
England & Wales
Reading time
c. 8 minutes
Last reviewed
1 June 2026
By-line
Legal Lens

Publication snapshot

  • The article examines a disputed subject access request made to Naylors Gavin Black LLP in April 2024.
  • The central issue is whether the response was timely, intelligible, properly searched, securely disclosed and lawfully redacted.
  • Legal professional privilege may justify withholding some material, but it should be tied to a clear exemption analysis, not used as a blanket answer.
  • A strong SAR challenge should separate ICO issues, SRA conduct questions, civil/legal advice issues and the underlying property dispute.
Reader note: this article is public-interest commentary and practical legal education. References to Naylors Gavin Black LLP, Angus White, Muckle LLP, alleged SAR delay, alleged over-redaction, alleged conflict, alleged obstruction, alleged unlawful eviction context, alleged lack of transparency or alleged data-protection non-compliance are allegations and analysis unless established by a competent court, tribunal, regulator, ombudsman, inquiry, audit report, formal admission or primary document.

The core point: a SAR response should answer, not obscure

The concern raised in this article is that a subject access request made to Naylors Gavin Black LLP in April 2024 was met with delay, partial disclosure, heavy redaction and insufficient explanation about privilege, third-party sharing and the role of another firm.

A delayed or incomplete-looking SAR response may involve several possibilities: poor compliance, a legitimate exemption dispute, a disagreement about scope, a privilege issue, or a dispute about third-party data. That is why the strongest approach is to reduce the complaint to a clear set of accountability questions.

The public-interest point remains straightforward. Data rights are practical rights. They only work if organisations respond on time, explain what they have done, justify withholding, and avoid leaving the requester unable to understand how their personal data has been processed.

SAR framework: what the right of access is meant to do

The right of access allows an individual to obtain a copy of their personal data and supplementary information. It helps the individual understand how and why their data is being used, and whether that use is lawful.

A request does not need to use formal language. If it is clear that the individual is asking for their own personal data, the organisation should recognise it as a subject access request and deal with it through the correct process.

1

Recognise the request

Identify that the individual is asking for their own personal data, even if the request does not cite legislation.

2

Search reasonably

Carry out a reasonable search for personal data within the scope of the request.

3

Explain clearly

Provide the copy data and supplementary information in an accessible, concise and intelligible format.

4

Justify limits

Where material is withheld, identify the relevant exemption, restriction or basis for refusal.

The timeline issue: partial response, final response and delay

The stated chronology is that the SAR was submitted on 4 April 2024, that an initial partial response was provided on 29 April 2024, and that a final response was provided on 28 June 2024.

If those dates are correct, the key question is not simply whether any response arrived within one month. The sharper questions are whether the first response was meaningful, whether any extension was properly available, whether the extension was communicated, whether the request was complex, and whether the final disclosure allowed the requester to understand what had been withheld.

4 Apr 2024

SAR submitted

The starting point requires the request, recipient, wording, delivery evidence and any identity or authority correspondence.

29 Apr 2024

Partial response said to be provided

The issue is whether this was a meaningful SAR response, a holding response, an interim disclosure or an incomplete disclosure.

28 Jun 2024

Final response said to be provided

The issue is whether the extended timeframe was justified, explained and compliant with the applicable SAR rules.

Redactions, privilege and the danger of blanket explanations

The article raises concern about significant redactions and broad reliance on legal professional privilege. That may be an important issue. Legal professional privilege can justify withholding some material in the subject-access context, but it should not become a substitute for analysis.

A well-handled SAR response should allow the requester to understand the category of material withheld, the basis for withholding, and whether the organisation considered third-party information, confidentiality, privilege, legal advice or litigation context. It does not necessarily require disclosure of the privileged content itself.

The redaction audit

A redaction dispute is strongest when each withheld item is examined against a clear set of questions.

A

What document or email was redacted?

B

What category of data was withheld?

C

What exemption was relied upon?

D

What explanation was given?

Controller route: Naylors Gavin Black, Muckle LLP and direct access rights

The article raises concern that personal data was shared with Muckle LLP and that Muckle LLP was said to be a controller that would not engage unless authorised by Naylors Gavin Black LLP. That point needs careful separation because controller status, processor status, joint-controller status, agency, privilege and litigation context may all affect the route.

The practical question is not whether the requester was entitled to every document from every organisation on demand. The question is whether each organisation’s role was clearly explained, whether any direct SAR to a controller was recognised, and whether any refusal or redirection was properly justified.

Naylors Gavin Black route

Request the search scope, exemption basis, disclosure schedule, redaction explanation and any extension explanation.

Muckle LLP route

Clarify whether the firm was acting as controller, processor, joint controller, instructed solicitor or another role.

ICO route

Frame the complaint around delay, search, intelligibility, exemptions, third-party data, controller role and failure to explain.

SRA route

Use this only where the evidence raises a serious professional-conduct issue, not merely disagreement with a SAR response.

The accountability test: what a proper challenge should show

Strong language about transparency failure and obstruction is less effective than a well-structured challenge. The stronger route is to reduce the dispute to request, deadline, search, disclosure, redaction, exemption, controller role and remedy.

1

Identify the request

Keep the original SAR, proof of delivery, any identity checks and all correspondence about scope or clarification.

2

Test the deadline

Compare the request date, partial response, extension notice and final response against the one-month rule and any stated extension basis.

3

Audit the redactions

Build a schedule showing each redacted item, what appears to be withheld, the exemption relied upon and why the explanation is disputed.

4

Separate the routes

Keep ICO data-rights issues separate from SRA conduct issues, civil claims, professional negligence, property disputes and complaint handling.

5

Ask for a reasoned answer

The final question is simple: what was searched, what was disclosed, what was withheld, why was it withheld, and who was responsible for the data?

Source anchors

These anchors support the SAR and professional-framework discussion. They do not verify the Naylors Gavin Black-specific allegations, Angus White-specific criticism, Muckle LLP-specific role, alleged unlawful eviction, alleged misconduct, or any disputed case facts.

Closing point

A SAR dispute is not just about receiving documents. It is about whether the organisation has respected the requester’s right to understand how their personal data has been used.

Where a response is late, partial, heavily redacted or unclear about third-party sharing, the correct answer is structure: request, deadline, search, redaction, exemption, controller role, complaint route and remedy.

The Legal Lens point is simple: transparency is not delivered by disclosure alone. It is delivered by disclosure that can be understood, tested and, where necessary, challenged.

SAR dispute, redaction audit and escalation route

Legal Lens can help turn a confusing SAR response into a structured challenge. The assessment can separate missed deadlines, partial disclosure, redactions, privilege claims, third-party controller issues, ICO route, SRA conduct questions and the evidence needed to make the complaint clear.

Deadline analysis Redaction audit Controller route Evidence structure
01 What was requested?

Original SAR, wording, delivery proof, scope and any identity checks.

02 What was withheld?

Redactions, privilege explanations, third-party data and missing categories.

03 Which route applies?

ICO, SRA, civil advice, property dispute or formal complaint route.

Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors’ firm or data-protection consultancy. A preliminary assessment is not a substitute for regulated legal advice, specialist data-protection advice, urgent court advice or representation where that is needed.

This article is general legal information and public-interest commentary. It is not legal advice, data-protection advice or a finding that Naylors Gavin Black LLP, Angus White, Muckle LLP, any solicitor, firm, controller, regulator or public body acted unlawfully or improperly.

Leave a Reply

Your email address will not be published. Required fields are marked *

Skip to toolbar