Data Deception

Navigating GDPR Challenges: My Experience with a Subject Access Request

Data protection · Subject access · Transparency

A subject access request is one of the most practical rights in data protection law. It allows a person to ask what personal data is being processed, why it is being used, who has received it, and whether the processing can be understood. But the right only works if organisations respond on time, explain redactions properly, and avoid treating disclosure as a controlled negotiation rather than a legal entitlement.

Category
Data protection
Jurisdiction
England & Wales
Reading time
c. 8 minutes
Last reviewed
1 June 2026
By-line
Legal Lens

Publication snapshot

  • This article uses a personal SAR experience as a practical case study in data transparency.
  • The central concerns are delay, partial disclosure, heavy redaction, privilege reliance, external-adviser involvement and unclear controller responsibility.
  • Legal professional privilege and third-party rights may justify withholding some material, but the reasoning should be clear enough to test.
  • The practical lesson is to create a structured SAR challenge: request, deadline, search, disclosure, redaction, exemption, controller role and complaint route.
Reader note: this article is public-interest commentary and practical legal education. References to delayed SAR handling, redactions, privilege, external advisers, alleged conflict, alleged property-related harm or alleged lack of transparency are criticism and analysis unless established by a competent court, regulator, ombudsman, formal admission or primary document.

The core point: SARs are accountability tools

The UK data protection framework gives individuals a practical route to understand how their personal data is being used. A subject access request is not just a way of obtaining documents. It is a way of testing transparency, accuracy, sharing, purpose and accountability.

This article concerns a SAR submitted in April 2024 to a prominent chartered surveyors and commercial property consultancy in Newcastle. The concern is that the response process was delayed, only partly answered at first, heavily redacted, and insufficiently clear about exemptions, external advisers and the basis on which material was withheld.

The wider lesson is straightforward: where a SAR response is difficult to understand, the data subject should not be left guessing. The organisation should explain what it searched, what it disclosed, what it withheld, why it withheld it, and what complaint or enforcement route remains available.

Understanding the right of access

The right of access allows individuals to obtain a copy of their personal data and supplementary information about how that data is being processed. It helps people understand what information is held about them, why it is being used, who it has been shared with and whether the processing appears lawful.

A SAR does not need formal legal wording. The important question is whether the person is clearly asking for their own personal data. Once that is clear, the organisation should recognise the request and manage it through a compliant process.

1

Access

The individual should receive a copy of their personal data unless a valid limit applies.

2

Explanation

The response should explain key processing information in a concise and intelligible way.

3

Timing

The response should be given without undue delay and normally within one month.

4

Accountability

Where material is withheld, the organisation should identify the reason and the route to challenge it.

The timeline: partial response and delayed final disclosure

The stated chronology is that the SAR was submitted on 4 April 2024. An initial partial response was provided on 29 April 2024. A final response was then provided on 28 June 2024.

If that chronology is correct, the question is not merely whether the organisation sent something within one month. The sharper questions are whether the initial response was meaningful, whether any extension was properly explained, whether the request was sufficiently complex to justify further time, and whether the final response allowed the requester to understand what had been disclosed and withheld.

4 Apr 2024

SAR submitted

The starting point is the wording of the request, delivery evidence, recipient details and any identity or scope correspondence.

29 Apr 2024

Partial response received

The issue is whether this was a substantive response, an interim disclosure, or a partial response that left key matters unresolved.

28 Jun 2024

Final response received

The issue is whether the extended timetable was justified, explained and supported by a compliant disclosure process.

Identified issues in the response

The experience raised several issues that often appear in contested SAR responses: timing, exemptions, redactions, third-party involvement, conflict concerns and incomplete signposting of rights.

Delay and partial disclosure

The response pattern raised the question of whether the organisation complied within the required period, whether any extension was available, and whether delay was properly explained.

Privilege and exemptions

Legal professional privilege may justify withholding some material, but the explanation should be specific enough to understand the category of information withheld and the basis relied upon.

External advisers

Where external legal advisers are involved, the organisation should make clear who is acting as controller, processor, joint controller, legal adviser or another role.

Conflict concern

If a person directly involved in the underlying dispute handles or controls the SAR process, the concern is whether the search and disclosure process remains objective and complete.

Rights information

A response should explain the route to complain to the ICO or enforce rights through the courts where the requester disputes the response.

Heavily redacted emails

Where critical emails are heavily redacted, the requester should be able to understand what exemption is relied upon and how the redaction decision was made.

The redaction test: how to make the dispute clear

Redaction is not automatically improper. A SAR response may need to protect privileged information, third-party personal data, confidential material or material covered by a statutory exemption. The difficulty arises when the explanation is too broad to test.

A stronger challenge does not simply say “the redactions are excessive”. It identifies each redacted item, the apparent subject matter, the exemption relied upon, the explanation given and why that explanation is disputed.

The practical redaction audit

A structured schedule turns a general objection into a clear data-rights challenge.

A

Which email or document was redacted?

B

What type of information appears to be withheld?

C

What exemption or restriction was cited?

D

What explanation was given for withholding?

E

Why is the explanation disputed?

Routes taken after the disputed response

After receiving a disputed SAR response, the practical route is usually staged. The first step is to give the organisation a clear opportunity to explain or correct the response. The next step may be an ICO complaint. In some cases, legal advice may be needed about court enforcement, compensation, confidentiality, privilege or connected civil proceedings.

DPO

Formal complaint to the organisation

Set out the delay, redactions, exemption concerns, missing categories, controller issues and remedy requested.

ICO

Complaint to the Information Commissioner

Use a structured bundle: request, response, timeline, redaction schedule, explanations given and unresolved issues.

Review

Request for internal or independent review

Ask the organisation to reconsider searches, exemptions, privilege claims, redaction decisions and controller responsibilities.

Advice

Legal advice where needed

Seek advice where court enforcement, compensation, privilege, litigation strategy or connected property issues may arise.

Lessons learned and practical recommendations

The experience highlights the need for organisations to treat SARs as rights-based processes, not administrative inconvenience. It also shows why individuals should keep a clear record from the outset.

For organisations

Respond clearly and on time

Maintain a process for recognising SARs, verifying identity promptly, searching reasonably and explaining any delay or extension.

For organisations

Explain withholding

Apply exemptions carefully and provide reasons that allow the requester to understand the basis of the decision.

For individuals

Keep the request precise

Save the SAR, delivery evidence, response letters, redacted material, rights information and any extension correspondence.

For individuals

Build a challenge schedule

Separate delay, search scope, missing categories, redactions, exemptions, third-party data and controller-role issues.

Source anchors

These anchors support the SAR and data-rights framework. They do not verify the organisation-specific chronology, redaction decisions, property-related allegations, external-adviser status or any disputed facts from the underlying matter.

Closing point

SARs are powerful because they turn abstract privacy rights into practical accountability. They allow individuals to see how their data has been used, who has handled it, and whether an organisation’s explanations withstand scrutiny.

Where a response is late, partial, heavily redacted or unclear about external advisers, the answer is structure. The requester needs a timeline, a redaction schedule, a controller map, an exemption analysis and a clear complaint route.

The Legal Lens point is simple: transparency is not achieved by sending a bundle. It is achieved by sending a response that can be understood, tested and challenged.

SAR response, redaction audit and complaint route

Legal Lens can help turn a confusing SAR response into a structured challenge. The assessment can separate missed deadlines, partial disclosure, redactions, privilege claims, third-party controller questions, ICO route and the evidence needed to make the complaint clear.

Deadline analysis Redaction audit Controller route Complaint structure
01 What was requested?

Original SAR, wording, delivery proof, scope and any identity checks.

02 What was withheld?

Redactions, privilege explanations, third-party data and missing categories.

03 Which route applies?

DPO complaint, ICO complaint, review request, legal advice or connected civil issue.

Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors’ firm or data-protection consultancy. A preliminary assessment is not a substitute for regulated legal advice, specialist data-protection advice, urgent court advice or representation where that is needed.

This article is general legal information and public-interest commentary. It is not legal advice, data-protection advice, or a finding that any organisation, adviser, controller, processor, regulator or individual acted unlawfully or improperly.

Leave a Reply

Your email address will not be published. Required fields are marked *

Skip to toolbar