Transparency unveils truth, even for the powerful institutions

Navigating the Challenges of Data Access: A Case Study with the Solicitors Regulation Authority (SRA)

Data protection

A subject access request is not a shortcut to every document in a regulator's file. It is a route to personal data and the information needed to understand how that data has been processed. Where a response contains heavy redactions, a requester needs a disciplined way to test whether the answer is lawful, intelligible and transparent without assuming that every withheld line proves a breach.

Category
Data protection
Jurisdiction
United Kingdom
Reading time
c. 9 minutes
Last reviewed
3 July 2026
By-line
John Barwell

Publication snapshot

A SAR dispute is won or lost on the distinction between documents and personal data

The source draft describes a subject access request to the Solicitors Regulation Authority concerning a report and supporting material said to relate to an assessment of alleged conflict of interest and misconduct. The complainant says the response disclosed some material but applied extensive redactions, leaving the decision-making route difficult to understand.

This version preserves the core concern but avoids treating the redactions as proof of unlawful processing. The publication-safe question is narrower and stronger: did the response provide the requester’s personal data, enough context to make that data intelligible, the required supplementary information, and an adequate explanation for any refusal, redaction or exemption?

Why the distinction matters

The right of access is a fundamental transparency tool. It allows a person to ask whether an organisation is processing their personal information, to receive a copy of that personal information, and to receive supplementary information explaining matters such as purposes, categories, recipients, retention, source and rights.

But a SAR is not the same as civil disclosure, freedom of information, regulatory disclosure or a right to the complete original file. That distinction matters most when the requester asks for a report, assessment, investigation file, complaint file or decision record. The document may contain the requester’s personal data, third-party data, ordinary non-personal information, confidential material, privileged material or material outside the scope of the request.

The practical issue is therefore not simply whether the whole document was disclosed. The question is whether the controller identified the personal data, supplied it in an intelligible form, provided enough context for the requester to understand how it was being used, and explained any withholding in a way that can be tested.

The SRA case study

The source draft says an individual requested the full report and supporting documentation behind an SRA assessment relating to alleged conflict of interest and misconduct. The purpose of the request was to understand the decision-making process and the basis on which conclusions had been drawn.

The draft says the response disclosed certain documents but applied extensive redactions, and that the SRA stated the right of access did not entitle the requester to full copies of original documents. It also says the SRA maintained that redactions were limited to material that did not constitute the requester’s personal data, and that no personal data had been exempted from disclosure.

Those assertions require the actual SAR, response, redacted documents, correspondence and any review outcome before firm conclusions can be reached. The safer article does not say the SRA was wrong. It asks how a requester should analyse a response of that kind and what questions should be raised if the redactions make the processing difficult to understand.

What a SAR should answer

A good SAR response should answer more than the narrow question of whether a name appears on a page. It should leave the requester able to understand the processing route.

What personal data was processed?

The response should identify the personal data being supplied, including where it appears in reports, notes, correspondence, logs, assessments or decisions.

Why was it processed?

The requester should be able to understand the purpose of processing and, where relevant, how the data was used in an assessment or decision.

Who received it?

The response should address recipients or categories of recipients where required, including internal teams, decision-makers, advisers or external bodies where applicable.

What was withheld?

Where information is removed or withheld, the requester needs a clear route to understand whether the issue is third-party data, privilege, confidentiality, exemption or non-personal information.

This is not a demand for every document in every case. It is a demand for a response that is intelligible enough to let the requester see how their personal data has been handled.

Redactions and third-party data

Redaction is not automatically improper. In many regulatory, employment, legal and complaint files, a document may contain personal data about several people. It may also include confidential information, privileged communications, information about witnesses, internal analysis or material that does not relate to the requester at all.

The difficulty arises when the redaction is so extensive that the personal data supplied is no longer intelligible. A requester may receive fragments of a report that mention them but do not show what the document is, why the information was used, who relied on it or what conclusion it fed into. That does not prove unlawful processing, but it does justify focused questions.

The correct challenge is not simply: “send me the full document.” It is: “please identify what personal data has been supplied, what material has been withheld, what basis has been applied, whether third-party information could have been protected by narrower redaction, and what contextual information is necessary for the disclosed data to be intelligible.”

The evidence map

A SAR challenge should be built around a clear record. Broad frustration rarely helps. A focused issue map does.

The request

Keep the original SAR, date sent, wording used, categories requested, documents identified and any clarification provided.

The response

Record what was provided, what format was used, whether supplementary information was supplied, and whether the response was within time.

The redaction schedule

List each heavily redacted document, the missing context, any stated exemption and why the remaining material is said to be unintelligible.

The missing personal data

Identify specific categories believed to be missing, such as assessment notes, decision records, correspondence, source material, logs or internal summaries.

The escalation record

Keep the follow-up complaint, controller reply, ICO complaint, key documents and any explanation of why the response remains inadequate.

This approach also protects the requester. It avoids asking the ICO, court or controller to guess what is missing. The issue becomes specific: which data, which document, which redaction, which explanation, and which route remains unresolved?

The escalation route

If a requester is unhappy with a SAR response, the first practical step is usually to go back to the controller with a focused complaint. The complaint should identify the missing personal data, the unclear redactions, the lack of supplementary information, the failure to explain an exemption, or the reasons the response is not intelligible.

The ICO route is then available where the issue remains unresolved, but expectations should be realistic. The ICO can consider complaints about data protection rights and decide what steps are appropriate. It is not the requester’s representative and it does not award compensation. Court enforcement and civil remedies are separate routes and usually need legal advice.

Route discipline matters

A SAR complaint should not be used as a substitute appeal against every regulatory decision. It should focus on personal data, intelligibility, supplementary information, redactions, exemptions and accountability for processing.

Source anchors

These source anchors support the SAR and data-protection framework discussed in this article. They do not prove any contested allegation about the SRA, any SAR response, any redaction, any regulatory assessment or any data protection breach.

The closing point

The source draft is right to connect SARs with transparency and accountability. The refined point is that transparency does not always mean disclosure of every document. It means giving the requester their personal data, the necessary context, the required supplementary information and an explanation for what has been withheld.

Where a regulator or any other organisation relies on redactions, the response should still be capable of being understood. If the personal data has been reduced to fragments, the next step is not rhetoric. It is a precise challenge: what personal data was processed, what has been withheld, why was it withheld, and what further context is needed to make the answer intelligible?

SAR route check

Legal Lens can help structure a subject access, redaction or regulator data-response concern into a clear issue map before the next step.

Issue definition

Separate personal data, full-document disclosure, redactions, exemptions, supplementary information and complaint-route issues.

Evidence structure

Turn the SAR, response, redacted material, correspondence and chronology into a reviewable record.

Route selection

Identify whether the next step is clarification, internal complaint, ICO complaint, regulator service complaint or civil advice.

Route map

SAR, ICO, regulator, complaint and civil routes.

Evidence schedule

Key documents, redactions, chronology and missing records.

Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors' firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

Legal Lens publishes public-interest commentary, practical legal education and evidence-led analysis. This article is not legal advice. Anyone facing live proceedings, limitation, confidentiality duties, privilege issues, regulatory escalation, data protection disputes or a disputed regulator decision should obtain appropriate legal advice before taking action.

Leave a Reply

Your email address will not be published. Required fields are marked *