DSARs, redaction and data-access accountability
A subject access request is meant to help a person understand what personal data is held about them, how it is being used, and whether the processing is lawful. In practice, the right can become difficult to enforce where responses are selective, heavily redacted, delayed, narrowed or explained in language that the requester cannot meaningfully test.
Publication snapshot
- A DSAR, also known as a subject access request or SAR, is a practical tool for obtaining a copy of personal data and related information about how that data is being used.
- The right is not absolute. Controllers may rely on exemptions, third-party rights, clarification, proportionality, privilege or manifestly unfounded/excessive grounds in appropriate cases.
- The public-interest problem arises where those limits are used as blanket language rather than properly evidenced reasons.
- The practical answer is source discipline: define the scope, keep the correspondence trail, demand a redaction schedule where appropriate, and separate legal exemptions from tactical obstruction.
Why DSARs matter
The right of access is one of the most practical rights in data protection law. It allows a person to ask whether an organisation is using or storing their personal data and to obtain a copy of that data. It can help expose inaccurate records, undisclosed internal notes, decision-making trails, correspondence about the person, complaint handling, employment history, customer data, housing files, financial records or professional-service files.
That distinction matters. A DSAR is not a general disclosure exercise in litigation. It is not a substitute for civil disclosure, a freedom of information request, a complaint appeal or a fishing expedition for every document connected to a dispute. But it can still be powerful because personal data often sits inside emails, logs, notes, case-management systems, complaints files and internal communications.
The public lesson is simple. A DSAR works only if the controller searches properly, explains the response clearly, applies exemptions carefully and gives the data subject enough information to test what has been withheld.
The core access question
Has the controller provided the personal data the requester is entitled to receive, or has the response been narrowed, delayed, redacted or refused in a way that cannot be properly tested?
Selective disclosure
The first practical problem is selective disclosure. A controller may provide some information but omit the records that matter most to the requester: internal emails, complaint notes, audit logs, decision records, payment records, correspondence with advisers or documents held in less obvious systems.
That does not automatically prove concealment. A controller may have searched the wrong system, misunderstood the scope, applied an exemption, treated material as not personal data, or missed records through poor information governance. The safer criticism is not to assume motive. The safer criticism is to test the search.
Evidence turns confusion into an argument. The requester should identify the missing category, explain why it is likely to exist, refer to dates, names, account numbers or events, and ask the controller to confirm whether those locations were searched.
Emails, notes, call logs, complaint records, metadata, case files, payment records, SAR correspondence or internal messages.
Link the missing material to known dates, meetings, decisions, letters, phone calls, invoices, complaints or account activity.
Identify likely systems, teams, inboxes, portals, external advisers, archives, ticketing tools or case-management platforms.
Ask for confirmation of search locations, search terms, date ranges and the reason for any omitted category.
Redaction and privilege
Redaction is sometimes lawful and necessary. A response may include information about other people, confidential material, privileged legal advice or information covered by a statutory exemption. The problem arises when redaction becomes so broad that the requester cannot understand what has been withheld or why.
Legal professional privilege is a real protection. Third-party privacy is also real. But neither should be used as a decorative label. A controller relying on exemptions or third-party rights should be able to explain the category of material withheld, the basis for the withholding, and why disclosure could not be made in a more limited or anonymised form.
The procedural gateway still matters. The requester may not be entitled to every document they want. But they are entitled to a response that is intelligible enough to understand the basis of the controller’s position and decide whether to challenge it.
Names, identifiers or personal details of other individuals may need to be withheld or anonymised where disclosure is not justified.
Privileged material may be withheld, but the assertion should be specific enough to distinguish privilege from ordinary embarrassment.
The Data Protection Act framework contains exemptions, but they need to be applied to the facts rather than used as boilerplate.
A redaction or withholding schedule can help identify the category, reason and legal basis without disclosing protected content.
Law-firm involvement
Controllers sometimes involve solicitors or external advisers in DSAR responses, particularly where the request overlaps with a dispute, complaint, employment issue, regulatory concern or litigation risk. That is not automatically improper. Legal advice may be needed to assess privilege, third-party rights, exemptions, proportionality and risk.
The transparency issue is narrower. If an external law firm processes personal data for the controller, the controller should be clear about who controls the data, who is acting as processor or adviser, what data has been shared, what security applies, and whether the involvement of lawyers has delayed or narrowed the response.
The practical point is not to object to legal review as such. The practical point is to ask whether the controller remains accountable for the DSAR and whether the requester has received an intelligible response, not merely a legally managed response.
The controller remains responsible for the DSAR response and should not use external advisers to obscure responsibility.
A law firm may advise on privilege, exemptions, litigation overlap, third-party rights and response wording.
The requester may reasonably ask how their data was shared, protected and processed during external review.
If the response is incomplete or opaque, challenge the controller’s reasoning before escalating to the ICO or court.
Scope, delay and refusal
Scope disputes are common. A controller may ask for clarification where it processes a large amount of information and the request is unclear. It may also extend time where the request is complex or where the individual has made a number of requests. Those routes can be legitimate.
The problem arises where scope is narrowed without a proper basis, clarification is used to stall, or a request is dismissed as manifestly unfounded or excessive without adequate reasons. A broad DSAR can be difficult to manage. But broad does not automatically mean abusive, excessive or invalid.
That distinction matters. A requester who asks for “everything” may receive a large and unfocused response, and the controller may need clarification. A requester who gives dates, names, systems, issues and categories makes it harder for the controller to hide behind vagueness.
The controller may ask for clarification where it processes a large amount of information and cannot identify what is sought.
Complexity and multiple requests may justify extra time, but the reason should be explained promptly.
Manifestly unfounded or excessive grounds should be justified by evidence, not used as a routine shield.
Data should be provided in a usable format where possible; an unreadable dump can defeat the purpose of access.
The ICO route
The Information Commissioner’s Office is the UK regulator for data protection complaints. The ICO can consider concerns about how an organisation handled a DSAR. That does not mean every complaint will lead to enforcement action, a full investigation or an order in the requester’s preferred terms.
The supplied draft criticises delay, superficiality and perceived controller preference. That criticism should be framed carefully. A person may reasonably feel that an ICO complaint did not engage with the strongest point. But a finding of bias, bad faith or institutional preference would require decision data, internal material, comparative analysis or formal findings.
The stronger article point is practical. An ICO complaint should be evidence-led. It should identify the request, the deadline, the response, the missing data, the challenged exemption, the redaction problem, the follow-up correspondence and the remedy sought.
Keep the original DSAR, proof of sending, identity verification correspondence and date calculations.
Mark what was provided, what was withheld, what was redacted, what format was used and what explanation was given.
Before escalating, ask the controller to correct omissions, explain exemptions and revisit excessive redactions.
Submit a concise complaint with dates, documents, disputed issues and the practical outcome requested.
A practical evidence test
The answer is not to assume every poor DSAR response is a cover-up. The answer is to force the response into an evidence structure. Which data was requested? Which systems should have been searched? Which documents were provided? Which categories are missing? Which exemptions were relied on? Which redactions are unintelligible? Which dates prove delay?
That structure is useful whether the next step is a controller challenge, ICO complaint, court application, regulator complaint, civil disclosure request, employment dispute, housing dispute or public-interest article. It separates evidence from suspicion.
Use names, dates, account numbers, complaint references, systems, document categories and preferred format.
Create a short table showing what was requested, what was received, what is missing and what was withheld.
Ask the controller to explain search scope, redactions, exemptions, withheld categories and delay before involving the ICO.
The final point is direct. DSAR disputes are won less by outrage than by audit. A careful request, a clean chronology and a precise missing-data schedule make the controller’s response easier to test and harder to obscure.
Official legal and regulatory source spine
Source anchors
These sources separate the right of access, controller obligations, exemptions, refusal grounds, ICO complaint route and statutory framework from the article’s public-interest criticism. They do not prove that any particular controller, DPO, law firm or regulator acted improperly.
Official public guidance on making a SAR, what to include, response expectations and what to do if unhappy.
Open ICO public guide 02 Controller guidance ICO: guide to subject accessOfficial organisational guidance on recognising, responding to, searching for, supplying and refusing SAR material.
Open ICO guide 03 Detailed guidance ICO: right of accessDetailed guidance for DPOs and data-protection staff on right-of-access handling and relevant exemptions.
Open right-of-access guide 04 UK GDPR Article 15 Right of access by the data subjectPrimary legal source for the right of access and the information a data subject may be entitled to receive.
Open Article 15 05 DPA 2018 exemptions Data Protection Act 2018, Schedule 2Primary statutory source for several exemptions and restrictions relevant to subject access responses.
Open Schedule 2 06 Complaint route ICO: make a complaintOfficial starting point for raising data-protection concerns with the regulator after dealing with the organisation.
Open complaint routeUse these anchors to verify the framework. Any specific allegation that a controller, DPO, law firm or public body deliberately concealed data, misused privilege, destroyed records, acted unlawfully or misled the ICO requires the request, response, redaction schedule, search evidence, correspondence, legal basis, complaint file, decision material and any right-of-reply response.
Closing point
A DSAR is not a magic key to every document. But it is not a courtesy either. It is a legal right of access to personal data, subject to defined limits. The practical challenge is to make those limits visible, reasoned and testable. Where a response is selective, delayed, opaque or over-redacted, the answer is not simply to accuse. The answer is to audit the response and force the controller to explain its position.
DSAR response audit
Get a free written assessment of the access route
Legal Lens can turn a DSAR problem, over-redacted disclosure, missing-data issue, controller complaint or ICO escalation into a structured chronology, response audit, redaction challenge or evidence schedule. The assessment separates what was requested, what was provided, what is missing, what exemption was claimed and which route can realistically address it.
Identify the request date, scope, account references, data categories, systems, people and preferred format.
Separate provided data, missing categories, redactions, exemptions, delay, clarification and refusal grounds.
Convert the issue into a controller challenge, ICO complaint, court route note, regulator complaint or publication-safe summary.
Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors' firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

