Criminal fraud language should be used carefully. A mishandled Subject Access Request may raise data-protection, regulatory or civil issues. It only enters criminal-law territory if the documents point to something more serious: dishonest agreement, deliberate deception, and an intention to gain, cause loss or expose someone to a risk of loss.
Publication snapshot
- Core issue: when SAR obstruction or document-handling concerns move from data-protection dispute into potential criminal-law territory.
- Case context: the author’s concern relates to Balliol Property Services and the handling of a Subject Access Request.
- Practical focus: separating suspicion, regulatory breach, civil claim, criminal allegation and evidence capable of supporting escalation.
- Bottom line: conspiracy to defraud is serious language. It should not be used as a label for poor compliance unless the documents support dishonest agreement and intended gain, loss or risk of loss.
Why this matters
On 11 August 2024, the issue of possible fraud language arose in the continuing dispute about the handling of my Subject Access Request to Balliol Property Services. The immediate concern was not an abstract legal theory. It was whether the handling of the SAR, if deliberately obstructive, could reveal something more serious than poor administration or data-protection non-compliance.
That question has to be approached with discipline. A failed or delayed SAR can be serious. It may justify complaint to the Information Commissioner, a request for review, a claim for compensation, a court application, or regulatory escalation. But it does not automatically mean fraud, conspiracy or criminal conduct.
The correct approach is to separate three things: what is known, what is suspected, and what the documents would need to show before criminal language could responsibly be used.
The practical distinction: a data-protection breach may show non-compliance. A fraud allegation requires a much higher threshold: dishonesty, intentional wrongdoing, and evidence capable of being tested.
Why criminal language needs care
Conspiracy to defraud is a serious criminal-law concept. In broad terms, it concerns an alleged agreement between two or more people to act dishonestly so as to prejudice another person’s rights or economic interests. The focus is not simply poor behaviour. It is dishonest agreement.
That distinction matters in a SAR dispute. An organisation may miss a deadline, misunderstand the request, mishandle identity verification, apply an exemption wrongly, or respond defensively because litigation is in the background. Those matters may be unlawful, unfair or unreasonable. They may still fall short of criminal fraud.
Responsible public-interest criticism should therefore avoid jumping from “BPS failed to handle my SAR properly” to “BPS conspired to defraud me” unless there is a document trail showing an agreement, dishonest purpose and intended gain, loss or risk of loss.
Unsafe framing
“BPS conspired to defraud me by obstructing my SAR.”
Safer and stronger framing
“If documents showed a coordinated and dishonest plan to obstruct access rights for advantage or to cause loss, the issue could move beyond ordinary SAR non-compliance.”
The BPS context
The concern in the BPS dispute is whether the SAR process was handled transparently and lawfully. If the organisation failed to respond, withheld information without proper basis, relied on unjustified delay, or allowed the SAR to be shaped by litigation considerations, those matters may justify serious scrutiny.
However, the legal route depends on what the evidence shows. A controller’s failure to comply with the UK GDPR is not the same as proof of criminal conspiracy. A complaint may properly say that the SAR process appears obstructive, conflicted or inadequately explained. It should avoid asserting fraud unless the evidence supports that conclusion.
The strongest position is to focus first on the documents: the SAR, the deadline, the responses, any refusal, any identity-verification correspondence, any internal inconsistency, and any evidence suggesting that disclosure decisions were coordinated for an improper purpose.
The dispute concerns the handling of a SAR and whether BPS complied with access-right obligations.
The author is concerned that the handling may have been coordinated or obstructive rather than merely delayed.
Criminal fraud language requires evidence of dishonest agreement and intended gain, loss or risk of loss.
What the documents would need to show
The practical test is not whether the conduct felt dishonest. It is whether documents, communications or witness evidence show a coordinated plan that crosses the line from poor compliance into dishonest conduct.
In a SAR dispute, that might include evidence that people agreed to conceal records, falsify search results, misstate whether data existed, invent a reason for delay, destroy or alter documents, or use the SAR process to gain an improper advantage in related proceedings. Even then, the precise legal characterisation would require specialist advice.
Identify the act
What exactly happened: missed deadline, refusal, redaction, withholding, failure to search, misleading statement, altered record or unexplained deletion?
Identify the people involved
Who made the decision, who knew about it, who approved it, and who communicated it externally?
Identify the agreement
Is there evidence of coordination, instruction, shared purpose or deliberate alignment between two or more people?
Identify the dishonest purpose
Does the material show an intent to deceive, gain advantage, cause loss, or expose another person to a risk of loss?
Without that pathway, the safer and stronger route is to frame the matter as SAR non-compliance, inadequate transparency, possible misuse of process, or a failure of controller accountability.
Legal routes
The available route depends on the evidence and the remedy sought. If the issue is access to personal data, the immediate route is usually data-protection enforcement: complaint, review, direct correspondence with the controller, and possible civil action where loss or distress has been caused.
If the concern is deliberate document manipulation, false records, destruction of documents, or coordinated deception, the matter may require a different strategy. That could include preserving evidence, obtaining legal advice, considering whether a criminal report is appropriate, and avoiding public allegations that cannot yet be proved.
Fraud language should not be used to strengthen a weak evidential record. It should be reserved for cases where the factual pattern, documentary material and legal advice support it.
SAR enforcement
Use where the main issue is delay, incomplete disclosure, unreasonable ID checks, refusal or failure to search properly.
Claim or court application
Use where a controller’s breach has caused loss or distress, or where court intervention is needed to enforce access rights.
Specialist advice first
Use where there is evidence of dishonest agreement, falsification, destruction, deception or intended gain, loss or risk of loss.
Corporate governance point
Even where criminal thresholds are not met, the governance issue remains important. Organisations that handle personal data should have clear systems for SAR compliance, escalation, record retention, searches, redactions, exemptions and response deadlines.
Where a SAR arises during a dispute, those systems become more important, not less. The organisation should be able to show that data-protection compliance was handled separately from litigation advantage, reputational concern or internal defensiveness.
Clear SAR ownership
One person or team should be responsible for compliance, deadline control and audit trail.
Documented searches
The organisation should record what systems were searched, by whom, when, and with what search terms.
Separated dispute handling
Legal disputes should not contaminate the fairness or completeness of a statutory access process.
Escalation discipline
Where fraud, falsification or concealment is suspected, allegations should be preserved, evidenced and legally reviewed before escalation.
Source anchors
These source anchors help separate SAR compliance, fraud law, prosecution thresholds and public-interest criticism.
Closing point
The possibility of fraud should not be dismissed where documents genuinely suggest dishonest coordination. But criminal language must be earned by evidence. It is not enough that a SAR was delayed, obstructed or mishandled.
The immediate task is therefore practical: preserve the documents, map the decision chain, identify who knew what and when, and separate regulatory non-compliance from any possible dishonest agreement.
If the evidence only shows poor SAR handling, the route is data-protection enforcement and civil accountability. If it shows coordinated deception, the matter may require a different response. Either way, the strongest position is precise, evidenced and legally disciplined.
Decision support before alleging fraud, issuing a claim or escalating
Get a free written assessment before using criminal fraud language
Legal Lens helps complainants turn serious concerns into structured, evidence-led routes. The aim is practical: separate SAR non-compliance from dishonesty allegations, map the documents, identify the correct forum, and avoid wording that weakens an otherwise legitimate complaint.
What we assess
SAR history, correspondence, missed deadlines, decision chain, suspected concealment, evidential gaps, forum choice and wording risk.
Use it before
Alleging fraud, sending a letter before action, escalating to a regulator, making a criminal report, or publishing criticism of a named organisation.
What you get
A concise written view on the safest route, the strongest evidence, wording to avoid and whether solicitor review is needed.
Independent Legal Lens consultancy. This is not a regulated solicitors’ firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

