Trust Us to Hide It
Illustration: Legal Lens (AI-generated)

Exposed: How the Legal Ombudsman Shields Secrets from Public Eyes!

Subject access requests – Legal Ombudsman – data transparency

A subject access request can expose how an organisation used a person’s data, but it is not an unrestricted right to every document on a complaint file. The Legal Ombudsman may withhold information where disclosure would likely prejudice its statutory complaint-handling function, protect another person’s information or preserve legal privilege. The accountability question is whether each restriction was applied narrowly, explained properly and limited to the information that genuinely required protection.

Category
Data protection
Jurisdiction
United Kingdom; E&W ombudsman context
Reading time
c. 15 minutes
Last reviewed
15 July 2026
By-line
John Barwell

Snapshot

This article examines a disputed subject access response from the Legal Ombudsman. It explains the current right of access, the complaint-function exemption under the Data Protection Act 2018, the role of prejudice, partial disclosure and redaction, current response times, and the difference between access to personal data and disclosure of a complete complaint file. The supplied case remains an allegation-led account because the SAR, response, withheld-material schedule and internal-review decision were not provided.

Reader note: this article is public-interest commentary and practical legal education. References to the Legal Ombudsman, Burnetts Solicitors and alleged withholding, delay or lack of transparency are analysis based on the supplied draft. They should not be read as findings of unlawful data processing, bad faith, concealment, bias or misconduct.

Access is not general disclosure

A complaint file may contain correspondence, internal analysis, third-party information, legal advice, administrative material and records that do not relate to the requester personally. A subject access request does not create a general right to inspect that entire file.

The right of access is directed to personal data. It entitles a person to confirmation that their information is being processed, a copy of that personal information and supplementary information about matters such as purpose, recipients, retention and complaint rights. The organisation may provide copies of documents where that is the clearest way to communicate the data, but the legal entitlement is to the information rather than to every original document in its complete form.

This distinction matters when a requester seeks internal notes or correspondence with a legal service provider. Some content may be the requester’s personal data. Other passages may concern staff reasoning, the provider, another individual or legal advice. The response should identify and disclose the requester’s information unless a lawful restriction applies. It need not provide unrelated material merely because it appears in the same email or note.

Core distinction. A SAR is a right to personal information and prescribed context. It is not a substitute for litigation disclosure, freedom of information or a complete explanation of the merits of an ombudsman decision.

The current access framework

The UK right of access sits within the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. The ICO’s current guidance states that organisations must make a reasonable and proportionate search for the requested personal information.

That standard does not permit an organisation to ignore inconvenient locations or search only the obvious inbox. It requires reasonable efforts measured against the circumstances, the volume and accessibility of information, the difficulty of retrieval and the fundamental importance of the right. The controller must be able to justify why any further search would be unreasonable or disproportionate.

The amended framework also permits clarification where it is reasonably required to identify the information or processing activity concerned. The response clock can pause while necessary clarification is awaited. The requester cannot, however, be forced to abandon a broad request. If clarification is refused, the organisation must still conduct reasonable searches.

Personal information

Identify information relating to the requester, including information embedded within wider documents.

Reasonable search

Search proportionately across relevant systems, files, recordings and accessible archives.

Supplementary information

Explain purposes, recipients, retention, source and relevant data rights.

Intelligible response

Provide enough context for the requester to understand the information and its use.

The ombudsman-function exemption

The Data Protection Act contains an exemption for personal information used in considering complaints under Part 6 of the Legal Services Act 2007. That is the statutory framework under which the Legal Ombudsman handles complaints about legal services.

The existence of the exemption does not mean that the entire complaint file is automatically outside the right of access. The ICO’s guidance states that it applies only to the extent that compliance would be likely to prejudice the performance of the relevant function. If the organisation can respond partially without creating that prejudice, it must do so.

The exemption is therefore functional rather than institutional. It protects the complaint-handling process where disclosure would likely undermine it. It does not permit information to be withheld merely because it was produced by an ombudsman, appears in an internal note or concerns communications with a service provider.

The relevant question is what harm disclosure of the specific information would cause. Depending on the facts, the concern may involve the fairness or independence of an active investigation, confidential information supplied for the complaint process, the position of another participant or the ability to obtain candid evidence. A general preference for privacy or administrative convenience is not enough.

The prejudice test

Where an exemption depends on prejudice, the controller should identify a clear and direct link between disclosure and the harm said to follow. The ICO describes the required prejudice as actual, real and of substance rather than trivial or speculative.

That analysis should be information-specific. An active complaint may justify withholding an investigator’s confidential line of inquiry at one stage, while the same risk may have diminished after the case has closed. A communication containing mixed information may justify withholding one passage but not the remainder.

The controller should record the particular function being protected, the nature of the harm, why disclosure would likely cause it and why a narrower response would not avoid the risk. That record supports accountability even where the public explanation must remain general to avoid defeating the exemption itself.

Protected function

Which complaint-handling activity or statutory responsibility is said to be at risk?

Specific information

Which passage, category or data item would create the risk if disclosed?

Likely harm

How would disclosure compromise, undermine or unfairly restrict the function?

Narrower alternative

Could redaction, extraction, delay or partial disclosure avoid the prejudice?

Redaction and partial disclosure

Redaction is often useful, but it is not a universal answer. The controller may remove a third party’s name while leaving enough context to identify them. A paragraph may be so interwoven with another person’s confidential information that extraction would distort the requester’s data. In other cases, names, contact details or unrelated passages can be removed while the substance is disclosed.

The ICO’s guidance emphasises that an organisation must provide as much requested information as it can. Where third-party data is involved, disclosure may be required if the other person consents or if it is reasonable to disclose without consent. Relevant factors include the nature of the information, duties of confidence, the importance of the data to the requester and what the requester already knows.

Partial disclosure is therefore not a failure in itself. It becomes questionable where the controller uses a broad label for a whole document without considering whether the requester’s information can be separated. A response should show that the material was reviewed at a sufficiently granular level.

Defensible restriction

The response identifies the relevant exemption, considers each category and discloses unaffected personal data with necessary context.

Accountability concern

Whole classes of material are withheld through generic wording without an intelligible link to prejudice, privilege or third-party rights.

Provider communications and internal notes

Correspondence between the Legal Ombudsman and a law firm may contain the complainant’s personal data, the firm’s explanation, information about staff or clients and material supplied in confidence. The fact that the communication came from the provider does not remove the complainant’s right of access to their own information within it.

The Legal Ombudsman’s current privacy notice says that evidence relied upon during an investigation is usually shared with the parties because openness and fairness require it. It also identifies circumstances in which evidence may not be shared, including legal restrictions, third-party data, confidential documents and information accepted in confidence.

A SAR is not identical to evidential disclosure within the complaint process. A document not relied upon may still contain personal data accessible through a SAR. Conversely, a document used during the investigation may contain protected third-party or privileged material. Each route asks a different question.

Internal notes require the same discipline. A staff member’s opinion about the requester may be their personal data if it relates to them. The requester is not automatically entitled to all surrounding operational discussion. The response should separate the requester’s data from material that is unrelated or lawfully exempt.

Time limits and extensions

An organisation must normally respond to a SAR without undue delay and within one month. It may extend the deadline by a further two months where the request is complex or the same person has made a number of rights requests.

The extension must be notified within the original one-month period and reasons must be given. A large volume of information can contribute to complexity, but size alone does not automatically justify an extension. The controller should be able to explain what made the particular request complex: sensitive exemptions, extensive unstructured records, technical retrieval difficulties or specialist work required to provide an intelligible response.

The source draft records that an internal-review date of 1 May 2024 was moved to 30 May 2024 without a substantive explanation. That chronology may support criticism of communication, but it does not establish a breach of the statutory SAR deadline without the original request date, identity checks, scope, extension notice and nature of the internal review.

Internal review is not itself a universal statutory stage for every SAR dispute. The legally relevant record should distinguish the original SAR response, any request for reconsideration, any service complaint and any later ICO complaint.

Reasons and accountability

Where an organisation refuses all or part of a SAR, it must normally tell the requester why, explain the right to complain to the controller and the ICO, and identify the possibility of court enforcement. The controller must be able to demonstrate that the exemption applies.

The explanation may sometimes need to remain general. Revealing the exact reason for withholding information could itself compromise the protected function. That limitation should not become a formula that prevents meaningful scrutiny. The response can usually identify the legal category, the type of prejudice or competing right and whether the withheld material was assessed for partial disclosure.

A useful response also separates the grounds relied upon. The complaint-function exemption, third-party information and legal professional privilege are different restrictions with different tests. Combining them into a single broad statement makes it difficult to know what was actually decided.

Scope

What systems, date range and categories of information were searched?

Restriction

Which exemption or competing right applies to each withheld category?

Application

Why would disclosure create prejudice, breach confidence or reveal another person’s data?

Challenge

How can the requester seek reconsideration, complain to the ICO or apply to court?

The Legal Ombudsman case study

The supplied draft says that a SAR sought communications between the Legal Ombudsman and Burnetts Solicitors, together with internal communications and notes. It says that some information was disclosed and other material was withheld by reference to paragraph 10 of Schedule 2 to the Data Protection Act 2018, confidentiality and the rights of others. It also says that an internal-review response was delayed.

Those assertions require the underlying correspondence before the response can be judged. The SAR would show what information and date range were requested. The disclosure bundle would show what was supplied. The refusal letter should identify the exemptions and reasons. A withheld-material schedule or properly structured description would show whether the decision was document-wide or passage-specific.

The complaint-function exemption may be legally available because the Legal Ombudsman considers complaints under Part 6 of the Legal Services Act 2007. Availability is not the same as correct application. The decisive question is whether disclosure of the particular personal data would likely have prejudiced that function and whether unaffected data could have been provided.

The Legal Ombudsman may contend that confidential exchanges, third-party information or the integrity of its complaint process required restriction. The requester may contend that the response was too broad, that the complaint had closed, or that redaction could have protected legitimate interests. Both positions must be tested against the actual documents and chronology.

How to audit the response

A strong challenge does not demand every unredacted document as a single proposition. It reconstructs what was requested, what was found, what was supplied and why each category was withheld.

The audit should identify missing searches, unexplained gaps, documents known to exist and redactions that appear wider than necessary. It should also distinguish information the requester wants because it is evidentially useful from information that is legally their personal data. A SAR is not expanded by the requester’s motive, even where the material may assist another dispute.

Where the concern is prejudice, the challenge can ask whether the complaint was active or closed, which function remained at risk and whether delayed disclosure would address the concern. Where third-party rights are relied upon, it can ask whether personal identifiers could be removed. Where privilege is claimed, it can ask whether the communication falls within legal advice or litigation privilege rather than ordinary operational correspondence.

Define the request

Record the wording, date range, systems, people and categories of personal information sought.

Inventory the response

List the files, extracts, recordings, supplementary information and redacted categories supplied.

Test each restriction

Identify the exemption, protected interest, prejudice and narrower disclosure option.

Select the correction route

Seek clarification or reconsideration, complain to the ICO, or obtain advice on court enforcement.

Challenge routes

The first step is normally to write to the controller, identify the omitted or over-redacted material and ask for the decision to be reconsidered. The challenge should be precise and attach evidence that the information exists, such as references within disclosed emails or the organisation’s own chronology.

The ICO advises that a complaint should generally be raised within three months of the requester’s last meaningful contact with the organisation. The ICO can consider the complaint and use regulatory powers where appropriate, but it does not act as the requester’s representative or award compensation.

The courts can order compliance with the right of access and can determine a compensation claim where a breach caused damage or distress. Court proceedings introduce limitation, evidence and costs issues and require separate legal assessment.

The Legal Ombudsman’s privacy notice confirms that data requests can be made through its contact route and that a person dissatisfied with the response may complain to the ICO. A service complaint about communication or handling should be kept distinct from the legal challenge to the SAR decision itself.

Source anchors

These official sources support the current access-right framework. They do not determine whether the disputed Legal Ombudsman response was lawful or whether any withheld document should be disclosed.

The closing point

Transparency does not require the Legal Ombudsman to disclose every document without restriction. It requires the organisation to identify the requester’s personal data, make reasonable searches, apply exemptions narrowly, disclose unaffected information and explain enough of its reasoning for the decision to be challenged.

A lawful exemption can protect complaint handling, confidentiality and other people. A generic exemption label cannot replace the required analysis. The record must show what was withheld, what interest was protected and why a narrower response would not have worked.

Access rights are strongest when the dispute is reduced to documents, categories and legal tests rather than a broad allegation of secrecy.

Subject access decision point

Legal Lens can structure a preliminary written review of a SAR response: the requested data, search scope, withheld categories, exemptions, reasons, chronology and available correction route.

Disclosure map

Separate personal data, third-party data, privileged material, complaint-function information and unrelated content.

Route selection

Identify whether the next step is reconsideration, service complaint, ICO complaint or specialist court advice.

Assessment outputs

SAR audit

Scope, searches, data categories, exemptions, reasons and missing information.

Evidence schedule

Known records, disclosure gaps, challenge points and route-specific documents.

Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors’ firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

Legal Lens provides public-interest legal analysis and practical case-structure support. This article is general information, not legal advice on any individual data request, ombudsman complaint or court claim.

Leave a Reply

Comments are public. Please do not include details of your own case — use the contact form instead.

Your email address will not be published. Required fields are marked *