Regulatory accountability
When a person complains to the Information Commissioner’s Office, the practical issue is not whether the complainant can recite the UK GDPR. It is whether the regulator tests the evidence against the duties that actually matter: security, accountability, individual rights, breach handling and risk assessment. This article uses one complaint concerning Burnetts Solicitors as a public-interest case study in how a narrow regulatory response can leave serious questions unanswered.
Publication snapshot
The public-confidence issue
The complaint was not merely about a private disagreement with a firm of solicitors. It raised a wider question: what happens when a complainant identifies apparent weaknesses in records, access rights, audit trails, breach procedures and data protection governance, but receives a regulatory answer that does not appear to engage with those points in substance?
The concern is that the ICO’s complaint-handling process can appear to treat a response from an organisation as an answer in itself, rather than testing whether that response deals with the underlying evidence. That distinction matters because data protection rights are only meaningful if they can be enforced through a regulator that explains its reasoning clearly.
Why this complaint matters
The Information Commissioner’s Office is not a private mediator between a complainant and an organisation. It is the UK’s data protection regulator. Its function in an individual complaint is not to provide a full civil remedy, award compensation or act as the complainant’s solicitor. But it is expected to assess information-rights concerns through the lens of the law and to explain, in practical terms, why it does or does not consider further regulatory action appropriate.
That makes the quality of reasoning critical. A complainant may have no internal access to an organisation’s records, systems, audit trails, breach logs, policies or risk assessments. The regulator may be the only body with enough institutional authority to ask targeted questions. Where the response is superficial, the complainant is left with a formal outcome but no meaningful answer.
This article considers a complaint made about Burnetts Solicitors. The complaint raised concerns about reliance on paper audit logs, alleged absence of digital records, subject access handling, data subject rights, record-keeping, breach procedures and the absence of clear evidence of data protection impact assessment where one was said to be necessary. The ICO’s response, according to the complainant, rejected the complaint without addressing the substance of those issues.
The public-interest point is not that every complaint should result in enforcement. It is that every serious complaint should be handled through a visible reasoning process. If the concern is wrong, the regulator can say why. If the evidence is incomplete, it can identify what is missing. If the organisation’s explanation is accepted, the regulator can explain the basis on which it is accepted. What undermines trust is a conclusion that appears to bypass the evidential questions that made the complaint serious in the first place.
The five questions the regulator had to ask
A data protection complaint of this kind is not properly assessed by asking a single broad question: did the organisation say it complied? The practical question is whether the organisation can demonstrate compliance in relation to the specific processing activities under challenge.
Security
Were the technical and organisational measures appropriate to the risk, including the way audit trails, access controls and paper records were stored, retrieved, redacted and monitored?
Accountability
Could the firm show, by records and governance material rather than assertion, how it complied with the data protection principles?
Individual rights
Were subject access and related rights capable of being exercised effectively where records were said to be paper-based, incomplete or difficult to redact?
Breach handling
Was there a documented procedure for identifying, recording, risk-assessing and reporting personal data breaches where required?
Risk assessment
Had the firm considered whether the processing activity required structured risk assessment, including a DPIA where the legal threshold was engaged?
Those questions are not technical decoration. They go to the core of modern data protection law. The UK GDPR is built around principles, but those principles are made practical through systems, records, explanations and demonstrable governance. A controller that cannot show how it protects data, manages requests or records decisions may be compliant in language but weak in proof.
The Burnetts case study
The complaint described a set of linked concerns arising from the complainant’s dealings with Burnetts Solicitors and a subject access request connected to a landlord dispute. The complainant says that Burnetts relied heavily on paper audit logs which could not easily be redacted and that digital equivalents were absent or not disclosed. If accurate, that would create a practical difficulty: a firm cannot confidently assure a data subject that it can identify, retrieve, redact and explain processing activity if the underlying records are fragmented or inaccessible.
The complaint also raised concerns about data subject rights. The issue was not simply whether a policy existed. The issue was whether the policy could work in practice where the records needed to respond to access, rectification, erasure or restriction requests were said to be incomplete, paper-based or not capable of being interrogated in a reliable way.
There was also an accountability concern. The complainant says the absence of adequate digital logs made it difficult to understand who accessed data, when they accessed it, for what purpose and under what authority. In a regulated legal environment, those questions are not peripheral. Law firms handle client, opponent, witness, financial and sometimes highly sensitive information. A credible governance system should be capable of explaining how access and disclosure decisions are controlled.
A further concern concerned the handling of a subject access request. The complainant says a solicitor who was involved in the underlying dispute responded to a request in circumstances that appeared to create a conflict risk. The article does not assert that this was unlawful. The narrower point is that the complaint put the ICO on notice of a governance issue: whether the person handling information-rights correspondence was sufficiently independent from the dispute in which the data was being used.
Finally, the complainant says that Burnetts later introduced additional compliance resource, including a compliance coordinator and assistant. That fact, if accurately recorded, does not prove earlier non-compliance. Organisations can strengthen compliance for many reasons. But it may be relevant context where the earlier position presented to the regulator was that existing systems were already adequate.
Why the ICO response raises concern
The complainant’s central criticism is that the ICO took around eight months to respond and then concluded that Burnetts were compliant without addressing the main evidential points. The difficulty with that kind of response is not only delay. It is opacity.
If the ICO reviewed the paper audit logs issue, the response needed to explain what had been checked and why the paper-based system did not create a compliance problem. If it accepted Burnetts’ explanation, the response needed to identify the explanation and the reason it was sufficient. If the issue fell outside the ICO’s scope, the response needed to say so. A complainant cannot test the fairness of the regulatory outcome if the reasoning does not engage with the complaint actually made.
The same applies to data subject rights. If the complaint alleged that access and redaction could not be handled properly because of record-keeping limitations, the regulatory answer needed to go beyond a general statement that policies existed. A policy is relevant, but it is not the same as operational compliance. The practical question is whether the policy could be applied to the records, systems and processing activity under challenge.
There is also a wider public-confidence problem. Regulators risk losing legitimacy when their decisions appear to depend on institutional confidence rather than evidence. A complainant does not need every point upheld. But they are entitled to expect a route of analysis: allegation, evidence, organisation response, regulator assessment and reasoned conclusion.
The oversight gap
The oversight gap in cases like this sits between two positions. On one side, the regulator is not a court and cannot be expected to conduct a trial of every factual dispute. On the other, it cannot properly discharge its public function by treating unresolved evidence as though it does not matter.
What a narrow review can do
It can confirm that the organisation has provided a response, point the complainant to general rights and close the matter without making findings on contested evidence.
What a robust review should do
It should identify the specific legal duties engaged, test the organisation’s explanation against the complaint evidence and explain why further action is or is not justified.
The distinction is especially important in professional-services settings. Solicitors’ firms hold data in circumstances shaped by duties of confidentiality, litigation, privilege, opponent correspondence and client instructions. That does not make them immune from data protection duties. It means the analysis may need to be more careful, not less.
A weak regulatory answer also shifts pressure back onto the complainant. The individual may then be forced to consider civil proceedings, a fresh complaint, a judicial review route, an ombudsman route, a professional conduct complaint or public-interest publication. Each route carries cost, limitation, jurisdiction and evidence risks. A clear regulatory answer can narrow those issues. An opaque answer can multiply them.
What reform requires
The answer is not to require the ICO to enforce every complaint. That would be unrealistic and legally unsound. The answer is to require better issue discipline in complaint handling.
Issue-by-issue reasoning
Where a complaint identifies security, access, accountability, breach handling or DPIA concerns, each should be recorded and answered separately.
Evidence traceability
Regulatory responses should show what evidence was considered, what was not considered and whether the organisation’s explanation was tested.
Clear limits of scope
If the ICO does not determine a factual dispute, award compensation or examine professional conduct, it should say that clearly and direct the complainant to the correct route where appropriate.
Accountability for closure decisions
Closing a complaint should not mean avoiding the hard points. It should mean explaining why, on the evidence and within the regulator’s remit, no further regulatory step is justified.
That approach would not prejudge organisations. It would protect them from vague allegations by requiring the complaint to be structured. It would also protect complainants from dismissive outcomes by requiring the regulator to answer the case actually put. Proper reasoning benefits both sides.
The broader lesson is simple. Data protection law depends on accountability. If a controller must be able to demonstrate compliance, a regulator assessing a complaint should be able to demonstrate how it assessed that compliance. Public confidence does not require perfect outcomes. It requires reasons that can be understood.
Source anchors
These source anchors support the legal and regulatory framework used in this article. They do not prove any contested allegation about the complaint, Burnetts Solicitors or the ICO’s handling of the complaint.
ICO guidance
UK GDPR data protection principles
The principles include lawfulness, fairness, transparency, purpose limitation, data minimisation, security and accountability.
ICO guidance
Security and Article 32
The ICO explains the need for appropriate technical and organisational measures, risk analysis and security governance.
ICO guidance
Individual rights
The guidance sets out access, rectification, erasure, restriction, portability, objection and automated decision-making rights.
ICO guidance
Personal data breach handling
The ICO explains reporting thresholds, the 72-hour reporting standard, individual notification and record-keeping.
ICO guidance
Data Protection Impact Assessments
The guidance explains when DPIAs are needed and how organisations should assess risks to individuals.
The closing point
The issue raised by this complaint is larger than one firm and one regulatory outcome. It is about whether data protection rights remain practical when a complainant has to rely on the regulator to test the evidence.
If the ICO’s answer to a detailed complaint is only a conclusion, the public is asked to trust the result without seeing the reasoning. That is not enough for a rights-based regime. The regulator does not have to agree with every complainant. But it should be able to show that it understood the complaint, tested the relevant duties and explained why the outcome followed.
Data protection route check
Get a free written assessment of the route
Legal Lens can help structure a data protection complaint, regulator response or escalation pack into a clear issue map before the next procedural step.
Separate what the documents prove from what remains contested, inferred or dependent on disclosure.
Identify whether the next step is regulatory, civil, ombudsman, professional conduct, judicial review or publication-led.
Turn the complaint, response, SAR material, policies and chronology into a practical review bundle.
Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors' firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

