Subject access requests – Legal Ombudsman – data transparency
A subject access request can expose how an organisation used a person’s data, but it is not an unrestricted right to every document on a complaint file. The Legal Ombudsman may withhold information where disclosure would likely prejudice its statutory complaint-handling function, protect another person’s information or preserve legal privilege. The accountability question is whether each restriction was applied narrowly, explained properly and limited to the information that genuinely required protection.
Snapshot
This article examines a disputed subject access response from the Legal Ombudsman. It explains the current right of access, the complaint-function exemption under the Data Protection Act 2018, the role of prejudice, partial disclosure and redaction, current response times, and the difference between access to personal data and disclosure of a complete complaint file. The supplied case remains an allegation-led account because the SAR, response, withheld-material schedule and internal-review decision were not provided.
Reader note: this article is public-interest commentary and practical legal education. References to the Legal Ombudsman, Burnetts Solicitors and alleged withholding, delay or lack of transparency are analysis based on the supplied draft. They should not be read as findings of unlawful data processing, bad faith, concealment, bias or misconduct.
Access is not general disclosure
A complaint file may contain correspondence, internal analysis, third-party information, legal advice, administrative material and records that do not relate to the requester personally. A subject access request does not create a general right to inspect that entire file.
The right of access is directed to personal data. It entitles a person to confirmation that their information is being processed, a copy of that personal information and supplementary information about matters such as purpose, recipients, retention and complaint rights. The organisation may provide copies of documents where that is the clearest way to communicate the data, but the legal entitlement is to the information rather than to every original document in its complete form.
This distinction matters when a requester seeks internal notes or correspondence with a legal service provider. Some content may be the requester’s personal data. Other passages may concern staff reasoning, the provider, another individual or legal advice. The response should identify and disclose the requester’s information unless a lawful restriction applies. It need not provide unrelated material merely because it appears in the same email or note.
Core distinction. A SAR is a right to personal information and prescribed context. It is not a substitute for litigation disclosure, freedom of information or a complete explanation of the merits of an ombudsman decision.
The current access framework
The UK right of access sits within the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. The ICO’s current guidance states that organisations must make a reasonable and proportionate search for the requested personal information.
That standard does not permit an organisation to ignore inconvenient locations or search only the obvious inbox. It requires reasonable efforts measured against the circumstances, the volume and accessibility of information, the difficulty of retrieval and the fundamental importance of the right. The controller must be able to justify why any further search would be unreasonable or disproportionate.
The amended framework also permits clarification where it is reasonably required to identify the information or processing activity concerned. The response clock can pause while necessary clarification is awaited. The requester cannot, however, be forced to abandon a broad request. If clarification is refused, the organisation must still conduct reasonable searches.
Identify information relating to the requester, including information embedded within wider documents.
Search proportionately across relevant systems, files, recordings and accessible archives.
Explain purposes, recipients, retention, source and relevant data rights.
Provide enough context for the requester to understand the information and its use.
The ombudsman-function exemption
The Data Protection Act contains an exemption for personal information used in considering complaints under Part 6 of the Legal Services Act 2007. That is the statutory framework under which the Legal Ombudsman handles complaints about legal services.
The existence of the exemption does not mean that the entire complaint file is automatically outside the right of access. The ICO’s guidance states that it applies only to the extent that compliance would be likely to prejudice the performance of the relevant function. If the organisation can respond partially without creating that prejudice, it must do so.
The exemption is therefore functional rather than institutional. It protects the complaint-handling process where disclosure would likely undermine it. It does not permit information to be withheld merely because it was produced by an ombudsman, appears in an internal note or concerns communications with a service provider.
The relevant question is what harm disclosure of the specific information would cause. Depending on the facts, the concern may involve the fairness or independence of an active investigation, confidential information supplied for the complaint process, the position of another participant or the ability to obtain candid evidence. A general preference for privacy or administrative convenience is not enough.
The prejudice test
Where an exemption depends on prejudice, the controller should identify a clear and direct link between disclosure and the harm said to follow. The ICO describes the required prejudice as actual, real and of substance rather than trivial or speculative.
That analysis should be information-specific. An active complaint may justify withholding an investigator’s confidential line of inquiry at one stage, while the same risk may have diminished after the case has closed. A communication containing mixed information may justify withholding one passage but not the remainder.
The controller should record the particular function being protected, the nature of the harm, why disclosure would likely cause it and why a narrower response would not avoid the risk. That record supports accountability even where the public explanation must remain general to avoid defeating the exemption itself.
Which complaint-handling activity or statutory responsibility is said to be at risk?
Which passage, category or data item would create the risk if disclosed?
How would disclosure compromise, undermine or unfairly restrict the function?
Could redaction, extraction, delay or partial disclosure avoid the prejudice?
Redaction and partial disclosure
Redaction is often useful, but it is not a universal answer. The controller may remove a third party’s name while leaving enough context to identify them. A paragraph may be so interwoven with another person’s confidential information that extraction would distort the requester’s data. In other cases, names, contact details or unrelated passages can be removed while the substance is disclosed.
The ICO’s guidance emphasises that an organisation must provide as much requested information as it can. Where third-party data is involved, disclosure may be required if the other person consents or if it is reasonable to disclose without consent. Relevant factors include the nature of the information, duties of confidence, the importance of the data to the requester and what the requester already knows.
Partial disclosure is therefore not a failure in itself. It becomes questionable where the controller uses a broad label for a whole document without considering whether the requester’s information can be separated. A response should show that the material was reviewed at a sufficiently granular level.
The response identifies the relevant exemption, considers each category and discloses unaffected personal data with necessary context.
Whole classes of material are withheld through generic wording without an intelligible link to prejudice, privilege or third-party rights.
Provider communications and internal notes
Correspondence between the Legal Ombudsman and a law firm may contain the complainant’s personal data, the firm’s explanation, information about staff or clients and material supplied in confidence. The fact that the communication came from the provider does not remove the complainant’s right of access to their own information within it.
The Legal Ombudsman’s current privacy notice says that evidence relied upon during an investigation is usually shared with the parties because openness and fairness require it. It also identifies circumstances in which evidence may not be shared, including legal restrictions, third-party data, confidential documents and information accepted in confidence.
A SAR is not identical to evidential disclosure within the complaint process. A document not relied upon may still contain personal data accessible through a SAR. Conversely, a document used during the investigation may contain protected third-party or privileged material. Each route asks a different question.
Internal notes require the same discipline. A staff member’s opinion about the requester may be their personal data if it relates to them. The requester is not automatically entitled to all surrounding operational discussion. The response should separate the requester’s data from material that is unrelated or lawfully exempt.
Time limits and extensions
An organisation must normally respond to a SAR without undue delay and within one month. It may extend the deadline by a further two months where the request is complex or the same person has made a number of rights requests.
The extension must be notified within the original one-month period and reasons must be given. A large volume of information can contribute to complexity, but size alone does not automatically justify an extension. The controller should be able to explain what made the particular request complex: sensitive exemptions, extensive unstructured records, technical retrieval difficulties or specialist work required to provide an intelligible response.
The source draft records that an internal-review date of 1 May 2024 was moved to 30 May 2024 without a substantive explanation. That chronology may support criticism of communication, but it does not establish a breach of the statutory SAR deadline without the original request date, identity checks, scope, extension notice and nature of the internal review.
Internal review is not itself a universal statutory stage for every SAR dispute. The legally relevant record should distinguish the original SAR response, any request for reconsideration, any service complaint and any later ICO complaint.
Reasons and accountability
Where an organisation refuses all or part of a SAR, it must normally tell the requester why, explain the right to complain to the controller and the ICO, and identify the possibility of court enforcement. The controller must be able to demonstrate that the exemption applies.
The explanation may sometimes need to remain general. Revealing the exact reason for withholding information could itself compromise the protected function. That limitation should not become a formula that prevents meaningful scrutiny. The response can usually identify the legal category, the type of prejudice or competing right and whether the withheld material was assessed for partial disclosure.
A useful response also separates the grounds relied upon. The complaint-function exemption, third-party information and legal professional privilege are different restrictions with different tests. Combining them into a single broad statement makes it difficult to know what was actually decided.
What systems, date range and categories of information were searched?
Which exemption or competing right applies to each withheld category?
Why would disclosure create prejudice, breach confidence or reveal another person’s data?
How can the requester seek reconsideration, complain to the ICO or apply to court?
The Legal Ombudsman case study
The supplied draft says that a SAR sought communications between the Legal Ombudsman and Burnetts Solicitors, together with internal communications and notes. It says that some information was disclosed and other material was withheld by reference to paragraph 10 of Schedule 2 to the Data Protection Act 2018, confidentiality and the rights of others. It also says that an internal-review response was delayed.
Those assertions require the underlying correspondence before the response can be judged. The SAR would show what information and date range were requested. The disclosure bundle would show what was supplied. The refusal letter should identify the exemptions and reasons. A withheld-material schedule or properly structured description would show whether the decision was document-wide or passage-specific.
The complaint-function exemption may be legally available because the Legal Ombudsman considers complaints under Part 6 of the Legal Services Act 2007. Availability is not the same as correct application. The decisive question is whether disclosure of the particular personal data would likely have prejudiced that function and whether unaffected data could have been provided.
The Legal Ombudsman may contend that confidential exchanges, third-party information or the integrity of its complaint process required restriction. The requester may contend that the response was too broad, that the complaint had closed, or that redaction could have protected legitimate interests. Both positions must be tested against the actual documents and chronology.
How to audit the response
A strong challenge does not demand every unredacted document as a single proposition. It reconstructs what was requested, what was found, what was supplied and why each category was withheld.
The audit should identify missing searches, unexplained gaps, documents known to exist and redactions that appear wider than necessary. It should also distinguish information the requester wants because it is evidentially useful from information that is legally their personal data. A SAR is not expanded by the requester’s motive, even where the material may assist another dispute.
Where the concern is prejudice, the challenge can ask whether the complaint was active or closed, which function remained at risk and whether delayed disclosure would address the concern. Where third-party rights are relied upon, it can ask whether personal identifiers could be removed. Where privilege is claimed, it can ask whether the communication falls within legal advice or litigation privilege rather than ordinary operational correspondence.
Record the wording, date range, systems, people and categories of personal information sought.
List the files, extracts, recordings, supplementary information and redacted categories supplied.
Identify the exemption, protected interest, prejudice and narrower disclosure option.
Seek clarification or reconsideration, complain to the ICO, or obtain advice on court enforcement.
Challenge routes
The first step is normally to write to the controller, identify the omitted or over-redacted material and ask for the decision to be reconsidered. The challenge should be precise and attach evidence that the information exists, such as references within disclosed emails or the organisation’s own chronology.
The ICO advises that a complaint should generally be raised within three months of the requester’s last meaningful contact with the organisation. The ICO can consider the complaint and use regulatory powers where appropriate, but it does not act as the requester’s representative or award compensation.
The courts can order compliance with the right of access and can determine a compensation claim where a breach caused damage or distress. Court proceedings introduce limitation, evidence and costs issues and require separate legal assessment.
The Legal Ombudsman’s privacy notice confirms that data requests can be made through its contact route and that a person dissatisfied with the response may complain to the ICO. A service complaint about communication or handling should be kept distinct from the legal challenge to the SAR decision itself.
Source anchors
These official sources support the current access-right framework. They do not determine whether the disputed Legal Ombudsman response was lawful or whether any withheld document should be disclosed.
The current detailed framework for SAR scope, searches, timing, exemptions, redaction and enforcement.
The current approach to prejudice, complaint functions, privilege and reasons for refusal.
The consent, reasonableness, confidentiality and redaction analysis for mixed personal data.
The statutory exemption relevant to complaint functions under Part 6 of the Legal Services Act 2007.
Current information on complaint-file data, evidence sharing, access rights and ICO complaints.
Practical steps for challenging an incomplete, delayed or inadequately explained SAR response.
The closing point
Transparency does not require the Legal Ombudsman to disclose every document without restriction. It requires the organisation to identify the requester’s personal data, make reasonable searches, apply exemptions narrowly, disclose unaffected information and explain enough of its reasoning for the decision to be challenged.
A lawful exemption can protect complaint handling, confidentiality and other people. A generic exemption label cannot replace the required analysis. The record must show what was withheld, what interest was protected and why a narrower response would not have worked.
Access rights are strongest when the dispute is reduced to documents, categories and legal tests rather than a broad allegation of secrecy.
Subject access decision point
Get a free written assessment of the data route
Legal Lens can structure a preliminary written review of a SAR response: the requested data, search scope, withheld categories, exemptions, reasons, chronology and available correction route.
Separate personal data, third-party data, privileged material, complaint-function information and unrelated content.
Identify whether the next step is reconsideration, service complaint, ICO complaint or specialist court advice.
Assessment outputs
Scope, searches, data categories, exemptions, reasons and missing information.
Known records, disclosure gaps, challenge points and route-specific documents.
Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors’ firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

