A subject access request should be a straightforward route to personal data. In practice, where a dispute is live and lawyers are involved, the process can become slow, defensive and difficult to challenge. The public-interest issue is whether individuals can enforce data rights without being exhausted by delay, over-redaction and procedural resistance.
Publication snapshot
- This article examines how SARs can become obstructed in contentious disputes.
- It distinguishes lawful verification, privilege and exemptions from conduct that may raise transparency concerns.
- It sets out practical steps for preserving the record, challenging redactions and escalating non-compliance.
Why subject access requests matter
A subject access request is not a favour. It is a legal right to obtain a copy of personal data and related information about how that data is being used. For individuals in disputes with landlords, employers, public bodies, service providers or legally represented organisations, a SAR may be the only practical way to uncover records, correspondence, decision-making trails and internal handling notes.
That is why obstruction matters. A delayed or incomplete SAR can prevent someone from understanding what has happened, testing the accuracy of allegations, identifying decision-makers, challenging unfair treatment or preparing a complaint or claim.
Organisations may have legitimate reasons to verify identity, clarify a request, apply exemptions or protect third-party data. But those mechanisms should not become tools for delay, opacity or tactical advantage.
The key distinction
Lawful SAR management is not the same as obstruction. The concern arises where verification, redaction, privilege, delay or delegation is used in a way that prevents the requester from obtaining data they are entitled to receive.
Why organisations may resist SARs
SARs can be difficult for organisations to handle, particularly where records are dispersed across email systems, case files, portals, archived documents, external advisers and historic correspondence. Some delay may be administrative rather than malicious.
The difficulty is that in contentious cases, the organisation may also have a defensive incentive. Disclosure may reveal inconsistency, poor record-keeping, inaccurate internal assumptions, mishandled complaints, weak evidential foundations or material that could assist the requester in a separate legal dispute.
Common pressure points
- Resource pressure: the organisation may lack systems to retrieve and review data efficiently.
- Legal exposure: disclosure may reveal records relevant to a complaint, claim or regulatory issue.
- Poor understanding: staff may misunderstand the difference between personal data, documents, disclosure and litigation privilege.
- Defensive legal handling: lawyers may advise caution, redaction or privilege claims where the data intersects with a dispute.
- Fragmented responsibility: controllers, processors, solicitors and agents may each point to the other while the requester remains without a complete response.
None of these explanations automatically proves wrongdoing. They do, however, explain why SARs can become contested and why requesters should keep a precise documentary record from the outset.
Case-study concerns: verification, delegation and silence
In the author’s experience, a SAR made during a dispute with an organisation became difficult once a law firm connected to that dispute became involved in the handling of the request. The concern is that a process intended to provide access to personal data became a defensive exercise in delay, control and non-disclosure.
One issue was repeated identity verification. Organisations are entitled to satisfy themselves about the requester’s identity where needed. However, repeated requests for ID may become questionable if the organisation or its solicitors already hold adequate identification and do not explain why further verification is necessary.
A second issue was delegation. Where a controller involves lawyers, agents or other third parties in handling a SAR, the requester is entitled to ask who is processing the request, in what capacity, on what legal basis, and whether the controller remains responsible for the response. The concern is sharper where the law firm has acted against the requester in an underlying dispute.
A third issue was silence. When questions about verification, delegation or redactions are met with no meaningful answer, the requester is left unable to test whether the SAR is being handled lawfully.
-
1The request is made.
The individual asks for their personal data and expects a clear, time-limited response.
-
2Verification or clarification is repeated.
The organisation asks for further information, sometimes without explaining why existing information is insufficient.
-
3Lawyers or agents become involved.
The requester may not know who is acting as controller, processor, adviser or representative.
-
4Redactions or silence follow.
The response may become difficult to understand, incomplete or heavily withheld without adequate explanation.
The ICO: important route, limited practical remedy
Escalation to the ICO is often the first external step when a SAR is mishandled. The ICO may assess compliance, issue guidance, identify poor practice or take regulatory action in appropriate cases.
The practical frustration is that an ICO complaint does not always produce the outcome the requester needs. A finding or indication that an organisation should have handled a SAR differently may not secure immediate disclosure, compensation or a full explanation of withheld material.
This creates a public-confidence problem. If an organisation can delay, narrow, over-redact or mishandle a SAR and the practical consequence remains limited, the right of access becomes harder to enforce for ordinary individuals.
The accountability gap
A data right is only meaningful if the individual can enforce it in real time. A delayed complaint outcome may confirm that something went wrong, but still leave the requester without the data they needed when it mattered.
Court enforcement: powerful but costly
Where a SAR continues to be mishandled, court enforcement may be considered. That can include seeking an order requiring compliance, and in some cases compensation. This is a significant step and should be assessed carefully because litigation can be costly, technical and slow.
A common concern is that by the time enforcement is pursued, records may have been lost, overwritten, deleted, reclassified or said to be irretrievable. That risk makes early preservation steps important. If data is likely to be relevant to a dispute, the requester should put the organisation on notice that the data must be preserved and should keep a record of that notice.
Preservation is separate from access
A SAR asks for access to personal data. A preservation request asks the organisation not to delete, alter or lose relevant material while the dispute, complaint or enforcement route is ongoing. Both should be recorded clearly.
How to protect yourself when a SAR is obstructed
The most effective response is to become methodical. Do not rely on broad allegations. Build a clean record that shows what was requested, when, from whom, what was received, what was missing and what explanation was given.
Make the request clearly
- Identify yourself and the data you are seeking.
- Send the SAR to the controller and any relevant data-protection contact.
- Keep proof of delivery, timestamps and attachments.
- Ask for electronic disclosure in a usable format where appropriate.
Track deadlines
- Record the date the SAR was received.
- Record any ID request and whether it was necessary.
- Record any clarification request and what it relates to.
- Follow up promptly if the response is late or incomplete.
Challenge redactions
- Ask for the basis of each category of redaction.
- Distinguish third-party data from legal privilege and other exemptions.
- Ask whether less intrusive redaction could allow disclosure.
- Request a schedule explaining what has been withheld and why.
Escalate cleanly
- Send a focused chaser before complaining externally.
- Complain to the ICO with a chronology and evidence bundle.
- Consider advice before threatening court action.
- Avoid publishing personal data or unsupported allegations while the matter is live.
It may also be appropriate to send separate SARs to different controllers where each holds personal data about you. However, sending a SAR to a law firm does not automatically require disclosure of all litigation documents. The response may engage privilege, third-party data and controller-capacity issues. Those points should be challenged precisely, not assumed away.
A call for greater accountability
The right of access is a cornerstone of data protection. It allows individuals to understand how information about them is being held, shared and used. Where organisations or their legal advisers treat that right as a litigation risk to be managed rather than a legal duty to be complied with, public confidence is damaged.
Reform should focus on practical enforceability. Individuals need clearer explanations for redactions, stronger consequences for unjustified delay, better routes to preserve data, and more transparent handling where solicitors or other third parties become involved in SAR processing.
Reform priorities
- Clearer redaction duties: organisations should explain the legal basis for withholding data in plain terms.
- Stronger preservation safeguards: disputed data should not disappear while a SAR complaint is ongoing.
- Controller accountability: organisations should remain visibly responsible even when lawyers assist with the response.
- Better ICO follow-up: where mishandling is identified, the focus should be whether the requester actually receives a lawful response.
- Practical court access: enforcement routes should be understandable and proportionate for individuals, not only for organisations with legal teams.
Until those reforms are achieved, individuals need to protect themselves through discipline: precise requests, clean records, deadline tracking, redaction challenges and careful escalation.
The closing point
Data rights are not meaningful if they can be worn down by delay, silence or overbroad confidentiality claims. A SAR should open the record, not become another battleground in which the individual is forced to fight for basic transparency.

