Data protection
A subject access request is not a shortcut to every document in a regulator's file. It is a route to personal data and the information needed to understand how that data has been processed. Where a response contains heavy redactions, a requester needs a disciplined way to test whether the answer is lawful, intelligible and transparent without assuming that every withheld line proves a breach.
Publication snapshot
A SAR dispute is won or lost on the distinction between documents and personal data
The source draft describes a subject access request to the Solicitors Regulation Authority concerning a report and supporting material said to relate to an assessment of alleged conflict of interest and misconduct. The complainant says the response disclosed some material but applied extensive redactions, leaving the decision-making route difficult to understand.
This version preserves the core concern but avoids treating the redactions as proof of unlawful processing. The publication-safe question is narrower and stronger: did the response provide the requester’s personal data, enough context to make that data intelligible, the required supplementary information, and an adequate explanation for any refusal, redaction or exemption?
Why the distinction matters
The right of access is a fundamental transparency tool. It allows a person to ask whether an organisation is processing their personal information, to receive a copy of that personal information, and to receive supplementary information explaining matters such as purposes, categories, recipients, retention, source and rights.
But a SAR is not the same as civil disclosure, freedom of information, regulatory disclosure or a right to the complete original file. That distinction matters most when the requester asks for a report, assessment, investigation file, complaint file or decision record. The document may contain the requester’s personal data, third-party data, ordinary non-personal information, confidential material, privileged material or material outside the scope of the request.
The practical issue is therefore not simply whether the whole document was disclosed. The question is whether the controller identified the personal data, supplied it in an intelligible form, provided enough context for the requester to understand how it was being used, and explained any withholding in a way that can be tested.
The SRA case study
The source draft says an individual requested the full report and supporting documentation behind an SRA assessment relating to alleged conflict of interest and misconduct. The purpose of the request was to understand the decision-making process and the basis on which conclusions had been drawn.
The draft says the response disclosed certain documents but applied extensive redactions, and that the SRA stated the right of access did not entitle the requester to full copies of original documents. It also says the SRA maintained that redactions were limited to material that did not constitute the requester’s personal data, and that no personal data had been exempted from disclosure.
Those assertions require the actual SAR, response, redacted documents, correspondence and any review outcome before firm conclusions can be reached. The safer article does not say the SRA was wrong. It asks how a requester should analyse a response of that kind and what questions should be raised if the redactions make the processing difficult to understand.
What a SAR should answer
A good SAR response should answer more than the narrow question of whether a name appears on a page. It should leave the requester able to understand the processing route.
What personal data was processed?
The response should identify the personal data being supplied, including where it appears in reports, notes, correspondence, logs, assessments or decisions.
Why was it processed?
The requester should be able to understand the purpose of processing and, where relevant, how the data was used in an assessment or decision.
Who received it?
The response should address recipients or categories of recipients where required, including internal teams, decision-makers, advisers or external bodies where applicable.
What was withheld?
Where information is removed or withheld, the requester needs a clear route to understand whether the issue is third-party data, privilege, confidentiality, exemption or non-personal information.
This is not a demand for every document in every case. It is a demand for a response that is intelligible enough to let the requester see how their personal data has been handled.
Redactions and third-party data
Redaction is not automatically improper. In many regulatory, employment, legal and complaint files, a document may contain personal data about several people. It may also include confidential information, privileged communications, information about witnesses, internal analysis or material that does not relate to the requester at all.
The difficulty arises when the redaction is so extensive that the personal data supplied is no longer intelligible. A requester may receive fragments of a report that mention them but do not show what the document is, why the information was used, who relied on it or what conclusion it fed into. That does not prove unlawful processing, but it does justify focused questions.
The correct challenge is not simply: “send me the full document.” It is: “please identify what personal data has been supplied, what material has been withheld, what basis has been applied, whether third-party information could have been protected by narrower redaction, and what contextual information is necessary for the disclosed data to be intelligible.”
The evidence map
A SAR challenge should be built around a clear record. Broad frustration rarely helps. A focused issue map does.
The request
Keep the original SAR, date sent, wording used, categories requested, documents identified and any clarification provided.
The response
Record what was provided, what format was used, whether supplementary information was supplied, and whether the response was within time.
The redaction schedule
List each heavily redacted document, the missing context, any stated exemption and why the remaining material is said to be unintelligible.
The missing personal data
Identify specific categories believed to be missing, such as assessment notes, decision records, correspondence, source material, logs or internal summaries.
The escalation record
Keep the follow-up complaint, controller reply, ICO complaint, key documents and any explanation of why the response remains inadequate.
This approach also protects the requester. It avoids asking the ICO, court or controller to guess what is missing. The issue becomes specific: which data, which document, which redaction, which explanation, and which route remains unresolved?
The escalation route
If a requester is unhappy with a SAR response, the first practical step is usually to go back to the controller with a focused complaint. The complaint should identify the missing personal data, the unclear redactions, the lack of supplementary information, the failure to explain an exemption, or the reasons the response is not intelligible.
The ICO route is then available where the issue remains unresolved, but expectations should be realistic. The ICO can consider complaints about data protection rights and decide what steps are appropriate. It is not the requester’s representative and it does not award compensation. Court enforcement and civil remedies are separate routes and usually need legal advice.
Route discipline matters
A SAR complaint should not be used as a substitute appeal against every regulatory decision. It should focus on personal data, intelligibility, supplementary information, redactions, exemptions and accountability for processing.
Source anchors
These source anchors support the SAR and data-protection framework discussed in this article. They do not prove any contested allegation about the SRA, any SAR response, any redaction, any regulatory assessment or any data protection breach.
ICO public guidance
Getting copies of your information
The ICO explains subject access requests, what to include, response times and the practical route for individuals.
Response guidance
Getting a response to your SAR
The ICO explains what should be sent back, partial documents, redaction and supplementary information.
Right of access
What is the right of access?
The detailed ICO guidance explains copies of personal information, supplementary information and information about other people.
Intelligibility
How can information be supplied?
The ICO explains mixed documents, context, intelligibility and why full documents may sometimes be the clearest route.
Third-party data
Information about other people
The ICO explains the rights-of-others exemption, consent, reasonableness and third-party personal information.
Escalation
What to do if you are unhappy
The ICO explains follow-up complaints, missing information, unexplained blacking-out and when to complain to the ICO.
The closing point
The source draft is right to connect SARs with transparency and accountability. The refined point is that transparency does not always mean disclosure of every document. It means giving the requester their personal data, the necessary context, the required supplementary information and an explanation for what has been withheld.
Where a regulator or any other organisation relies on redactions, the response should still be capable of being understood. If the personal data has been reduced to fragments, the next step is not rhetoric. It is a precise challenge: what personal data was processed, what has been withheld, why was it withheld, and what further context is needed to make the answer intelligible?
SAR route check
Get a free written assessment of the route
Legal Lens can help structure a subject access, redaction or regulator data-response concern into a clear issue map before the next step.
Separate personal data, full-document disclosure, redactions, exemptions, supplementary information and complaint-route issues.
Turn the SAR, response, redacted material, correspondence and chronology into a reviewable record.
Identify whether the next step is clarification, internal complaint, ICO complaint, regulator service complaint or civil advice.
SAR, ICO, regulator, complaint and civil routes.
Key documents, redactions, chronology and missing records.
Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors' firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

