Anonymity's facade: Data controllers obscuring transparency, burying subjects' rights

The Troubling Trend of Data Controllers Undermining Subject Access Requests

Subject access requests · Transparency · Accountability

A subject access request should not become a controlled narrative exercise. The right of access is meant to help a person understand how their personal information is used. Where a response is narrow, heavily redacted, processor-led or difficult to challenge, the accountability question is whether the controller can show a lawful route from request, to search, to review, to reason, to response.

Category
Data protection
Jurisdiction
United Kingdom
Reading time
c. 12 minutes
Last reviewed
4 July 2026
By-line
Legal Lens

Publication snapshot

This article examines how subject access requests can lose practical force when responses are framed around the controller's preferred account rather than the data subject's right of access. It focuses on search scope, personal information, redactions, exemptions, processor involvement, clarification, complaint routes and the evidence a requester should preserve when challenging an opaque SAR response.

Reader note: this article is public-interest commentary and practical legal education. References to SAR handling, controller conduct, redactions, processor involvement, complaint routes and regulatory oversight are criticism and analysis. They should not be read as findings of misconduct, dishonesty, unlawful concealment, data misuse, regulatory failure or professional wrongdoing by any named person, organisation, controller, processor, regulator or public body unless established by a competent court, tribunal, regulator, ombudsman, inquiry, audit report or official decision.

The right of access

The right of access allows a person to obtain a copy of their personal information and supplementary information about how that information is being used. It is a practical transparency right. It helps the person understand what is held, why it is held, who receives it, how long it is retained, and whether the organisation's use of that information can be checked.

That purpose matters because many SARs are made when trust has already broken down. The request may arise during an employment dispute, a complaint, a legal services dispute, a professional regulation issue, a landlord dispute, a safeguarding matter, a data breach concern or a conflict with an organisation that controls the relevant records.

The right is not unlimited. A SAR is not the same as litigation disclosure, freedom of information or a general demand for every document. The requester is entitled to personal information, not every record that exists. But where the response is incomplete, heavily redacted or difficult to understand, the controller should be able to explain the route it took.

Narrative control

A recurring concern in SAR disputes is narrative control. The requester asks for their data, but the response appears to preserve the organisation's version of events. Material that supports the controller's account is disclosed clearly. Material that may test that account is absent, redacted, described generally or said to fall outside scope.

That does not prove bad faith. A controller may lawfully withhold information because it is not personal data, relates to other people, is privileged, falls within an exemption, cannot be found after a reasonable and proportionate search, or requires clarification before it can be identified. But those concepts should not be used as labels without an audit trail.

The stronger question is not whether the requester suspects manipulation. It is whether the controller can show the route from request, to search, to review, to redaction, to exemption, to response.

Request

What was asked for, when was it received, and was identity or authority genuinely in issue?

Search

Which systems, people, periods, files and categories of personal information were considered?

Reason

What explains each omission, redaction, exemption, refusal or search limitation?

Scope is often where the dispute begins. A controller may say a document is not personal data, that the request is too broad, that searches would be disproportionate, or that further clarification is needed. Some of those points may be legitimate. The issue is whether they are being applied carefully.

Current guidance reflects the need for reasonable and proportionate searches. That does not permit a controller to avoid obvious sources. It means the controller should be able to show why the search was reasonable in the circumstances: the systems searched, the custodians considered, the date range used, the terms applied, the archived material checked and the reason any wider search was not proportionate.

Clarification is also a controlled tool. A controller may ask for further information where reasonably required to identify the personal information or processing activity to which the SAR relates. But clarification should not be requested on a blanket basis or used as a delay mechanism. The controller should explain why clarification is needed, keep a record of the request, and calculate any pause to the time limit properly.

Redaction and exemptions

Redaction can be necessary. A SAR may include information about other people, legally privileged material, confidential references, management information, regulatory material, health information, social work information, negotiations or material covered by a specific exemption. The problem is not the existence of exemptions. The problem is blanket use.

Exemptions should be considered case by case. They should not be relied on routinely or applied in a blanket fashion. If a controller relies on an exemption, it should document the reasons and be able to justify the position. Where a refusal is made, the requester should usually be told why, told about the right to complain to the controller and the ICO, and told about the ability to enforce rights through the courts.

Some reasons may need to be general where fuller explanation would defeat the exemption. But even then, the internal record should show what was withheld, why it was withheld, who considered it and how the decision was checked.

01

Identify the basis

Is the material withheld because it is not personal information, concerns another person, is privileged or falls within an exemption?

02

Apply it narrowly

Has the controller considered the actual information, rather than applying a broad category label?

03

Record the reason

Can the controller later justify each refusal, omission, redaction or exemption decision?

Processors and law firms

Controllers may use processors to help with SARs. That may be sensible where the request is large, technical, litigation-sensitive or requires secure review. A processor may help retrieve records, apply search terms, prepare review batches, propose redactions or assemble a response pack.

But processor involvement does not transfer responsibility. The controller remains responsible for complying with SARs and deciding how to deal with the request. The processor must be contractually required to help the controller meet its SAR obligations, including by allowing the controller to obtain the information needed for the response.

Law firms require particular care because roles can overlap. A law firm may advise the controller, act in the underlying dispute, review privilege, assist with SAR processing, draft the response or correspond with the requester. Those roles can be legitimate. They should also be clear. Where the adviser is close to the disputed facts, the controller should consider whether independent review, role separation or tighter supervision is needed.

The complaint route

Many requesters experience the complaint route as uneven because the controller holds the systems, search logs, internal reasoning and review records. The requester usually sees only the response. That imbalance can make a complaint feel frustrating, especially where the requester believes material has been withheld or selectively explained.

The practical answer is evidence discipline. A complaint is stronger when it identifies the SAR, the deadline, the likely data sources, the missing records, the redactions in issue, the exemption relied on, the reason it appears inadequate, and any inconsistency between the controller's account and documents already known to exist.

General allegations that a controller manipulated the narrative may express the frustration, but they rarely provide the route. The stronger formulation is narrower: this information appears to be personal information; this system or person likely held it; this record is missing or redacted; this exemption has not been explained; this is why the response does not show a reasonable and proportionate search or a case-by-case exemption decision.

The SAR evidence map

The practical tool is a SAR evidence map. It prevents a complex SAR dispute from becoming a general complaint that everything has been hidden. It also prevents the controller from treating uncertainty as if it were proof that no further data exists.

The map starts with the request. What was asked for, when was it sent, how was it delivered, and how did the controller respond? It then identifies the expected data sources: email accounts, case files, HR systems, complaint files, case-management systems, invoices, calendars, meeting notes, call recordings, audit logs, portal records and third-party correspondence.

The next step is comparison. What was disclosed? What was missing? What was redacted? What exemption was relied on? What supplementary information was supplied? What complaint route was given? What evidence shows that the missing material likely exists or that the redaction may be too broad?

01

Request. Record the date, wording, delivery method, acknowledgement and deadline calculation.

02

Sources. Identify people, systems, files and time periods likely to hold personal information.

03

Response. List what was disclosed, withheld, redacted, refused, explained or not addressed.

04

Gap. State the precise missing-data, redaction, exemption, processor or search concern.

Reform and practice

Realising the right of access requires more than formal compliance. Controllers should treat SAR handling as a governance issue: trained staff, clear ownership, documented searches, redaction logs, exemption reasons, processor controls, prompt clarification and intelligible responses.

Regulatory oversight also depends on usable records. If a requester complains, the controller should be able to reconstruct the response. If it cannot, the issue is no longer only whether a document was missing. It is whether the controller kept a record sufficient to demonstrate accountability.

The same applies to requesters. The stronger challenge is not broad accusation. It is a structured record showing what was requested, what should have existed, what was supplied, what was withheld, and why the explanation is inadequate.

Source anchors

These sources support the legal and regulatory framework used in this article. They do not prove any disputed complaint, breach, redaction issue, SAR failure, regulatory failure or organisation-specific misconduct.

The Legal Lens point

A SAR response should not leave the data subject guessing whether the controller searched properly, redacted lawfully, relied on exemptions selectively, used a processor appropriately or controlled the narrative of a dispute.

The strongest response to an opaque SAR is not louder accusation. It is better structure. Identify the request, the likely data sources, the disclosed material, the missing records, the redactions, the exemptions, the processor role and the specific accountability gap.

The right of access is weakened when it becomes a one-sided explanation managed by the controller. It is strengthened when both sides can see the route from request, to search, to review, to reason, to response.

SAR evidence and accountability map

If a SAR response appears incomplete, over-redacted or shaped by a disputed narrative, Legal Lens can help structure the request, response, evidence gaps and complaint route before escalation or specialist review.

Identify the SAR issue

Clarify whether the concern is missing data, narrow search, redaction, exemption, delay or processor role.

Map the evidence

Connect expected records, disclosed material, redactions and correspondence to the precise accountability gap.

Choose the route

Separate controller complaint, ICO complaint, legal advice, processor concern and any public commentary issue.

Issue map

Search, redaction, exemption, processor role, missing records and complaint route.

Evidence schedule

Requests, responses, known sources, missing records, chronology and next questions.

Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors' firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

Legal Lens publishes public-interest commentary and practical legal education. This article is not legal advice. SAR disputes may involve data protection, legal professional privilege, confidentiality, litigation strategy, professional conduct, limitation, costs, regulatory complaints and public commentary issues.

Leave a Reply

Your email address will not be published. Required fields are marked *

Skip to toolbar