Your Data Their Secrets

The Hidden Struggles of Accessing Personal Data: A Follow-Up on Law Firms Obstructing SARs

Subject access requests · Data rights · Accountability

A subject access request should be a straightforward route to personal data. In practice, where a dispute is live and lawyers are involved, the process can become slow, defensive and difficult to challenge. The public-interest issue is whether individuals can enforce data rights without being exhausted by delay, over-redaction and procedural resistance.

Category
Data protection
Jurisdiction
United Kingdom
Reading time
c. 8 minutes
Last reviewed
5 June 2026
By-line
Legal Lens

Publication snapshot

  • This article examines how SARs can become obstructed in contentious disputes.
  • It distinguishes lawful verification, privilege and exemptions from conduct that may raise transparency concerns.
  • It sets out practical steps for preserving the record, challenging redactions and escalating non-compliance.
Reader note: this article is public-interest commentary based on the author’s experience and the materials available at the time of writing. References to alleged obstruction, defensive handling, over-redaction, privilege misuse and regulatory weakness are made as criticism and analysis, and should not be read as findings of unlawful conduct unless established by a court, tribunal, regulator, ombudsman or other competent authority.

Why subject access requests matter

A subject access request is not a favour. It is a legal right to obtain a copy of personal data and related information about how that data is being used. For individuals in disputes with landlords, employers, public bodies, service providers or legally represented organisations, a SAR may be the only practical way to uncover records, correspondence, decision-making trails and internal handling notes.

That is why obstruction matters. A delayed or incomplete SAR can prevent someone from understanding what has happened, testing the accuracy of allegations, identifying decision-makers, challenging unfair treatment or preparing a complaint or claim.

Organisations may have legitimate reasons to verify identity, clarify a request, apply exemptions or protect third-party data. But those mechanisms should not become tools for delay, opacity or tactical advantage.

The key distinction

Lawful SAR management is not the same as obstruction. The concern arises where verification, redaction, privilege, delay or delegation is used in a way that prevents the requester from obtaining data they are entitled to receive.

Why organisations may resist SARs

SARs can be difficult for organisations to handle, particularly where records are dispersed across email systems, case files, portals, archived documents, external advisers and historic correspondence. Some delay may be administrative rather than malicious.

The difficulty is that in contentious cases, the organisation may also have a defensive incentive. Disclosure may reveal inconsistency, poor record-keeping, inaccurate internal assumptions, mishandled complaints, weak evidential foundations or material that could assist the requester in a separate legal dispute.

Common pressure points

  • Resource pressure: the organisation may lack systems to retrieve and review data efficiently.
  • Legal exposure: disclosure may reveal records relevant to a complaint, claim or regulatory issue.
  • Poor understanding: staff may misunderstand the difference between personal data, documents, disclosure and litigation privilege.
  • Defensive legal handling: lawyers may advise caution, redaction or privilege claims where the data intersects with a dispute.
  • Fragmented responsibility: controllers, processors, solicitors and agents may each point to the other while the requester remains without a complete response.

None of these explanations automatically proves wrongdoing. They do, however, explain why SARs can become contested and why requesters should keep a precise documentary record from the outset.

Case-study concerns: verification, delegation and silence

In the author’s experience, a SAR made during a dispute with an organisation became difficult once a law firm connected to that dispute became involved in the handling of the request. The concern is that a process intended to provide access to personal data became a defensive exercise in delay, control and non-disclosure.

One issue was repeated identity verification. Organisations are entitled to satisfy themselves about the requester’s identity where needed. However, repeated requests for ID may become questionable if the organisation or its solicitors already hold adequate identification and do not explain why further verification is necessary.

A second issue was delegation. Where a controller involves lawyers, agents or other third parties in handling a SAR, the requester is entitled to ask who is processing the request, in what capacity, on what legal basis, and whether the controller remains responsible for the response. The concern is sharper where the law firm has acted against the requester in an underlying dispute.

A third issue was silence. When questions about verification, delegation or redactions are met with no meaningful answer, the requester is left unable to test whether the SAR is being handled lawfully.

  1. 1
    The request is made.

    The individual asks for their personal data and expects a clear, time-limited response.

  2. 2
    Verification or clarification is repeated.

    The organisation asks for further information, sometimes without explaining why existing information is insufficient.

  3. 3
    Lawyers or agents become involved.

    The requester may not know who is acting as controller, processor, adviser or representative.

  4. 4
    Redactions or silence follow.

    The response may become difficult to understand, incomplete or heavily withheld without adequate explanation.

The ICO: important route, limited practical remedy

Escalation to the ICO is often the first external step when a SAR is mishandled. The ICO may assess compliance, issue guidance, identify poor practice or take regulatory action in appropriate cases.

The practical frustration is that an ICO complaint does not always produce the outcome the requester needs. A finding or indication that an organisation should have handled a SAR differently may not secure immediate disclosure, compensation or a full explanation of withheld material.

This creates a public-confidence problem. If an organisation can delay, narrow, over-redact or mishandle a SAR and the practical consequence remains limited, the right of access becomes harder to enforce for ordinary individuals.

The accountability gap

A data right is only meaningful if the individual can enforce it in real time. A delayed complaint outcome may confirm that something went wrong, but still leave the requester without the data they needed when it mattered.

Court enforcement: powerful but costly

Where a SAR continues to be mishandled, court enforcement may be considered. That can include seeking an order requiring compliance, and in some cases compensation. This is a significant step and should be assessed carefully because litigation can be costly, technical and slow.

A common concern is that by the time enforcement is pursued, records may have been lost, overwritten, deleted, reclassified or said to be irretrievable. That risk makes early preservation steps important. If data is likely to be relevant to a dispute, the requester should put the organisation on notice that the data must be preserved and should keep a record of that notice.

Preservation is separate from access

A SAR asks for access to personal data. A preservation request asks the organisation not to delete, alter or lose relevant material while the dispute, complaint or enforcement route is ongoing. Both should be recorded clearly.

How to protect yourself when a SAR is obstructed

The most effective response is to become methodical. Do not rely on broad allegations. Build a clean record that shows what was requested, when, from whom, what was received, what was missing and what explanation was given.

Make the request clearly

  • Identify yourself and the data you are seeking.
  • Send the SAR to the controller and any relevant data-protection contact.
  • Keep proof of delivery, timestamps and attachments.
  • Ask for electronic disclosure in a usable format where appropriate.

Track deadlines

  • Record the date the SAR was received.
  • Record any ID request and whether it was necessary.
  • Record any clarification request and what it relates to.
  • Follow up promptly if the response is late or incomplete.

Challenge redactions

  • Ask for the basis of each category of redaction.
  • Distinguish third-party data from legal privilege and other exemptions.
  • Ask whether less intrusive redaction could allow disclosure.
  • Request a schedule explaining what has been withheld and why.

Escalate cleanly

  • Send a focused chaser before complaining externally.
  • Complain to the ICO with a chronology and evidence bundle.
  • Consider advice before threatening court action.
  • Avoid publishing personal data or unsupported allegations while the matter is live.

It may also be appropriate to send separate SARs to different controllers where each holds personal data about you. However, sending a SAR to a law firm does not automatically require disclosure of all litigation documents. The response may engage privilege, third-party data and controller-capacity issues. Those points should be challenged precisely, not assumed away.

A call for greater accountability

The right of access is a cornerstone of data protection. It allows individuals to understand how information about them is being held, shared and used. Where organisations or their legal advisers treat that right as a litigation risk to be managed rather than a legal duty to be complied with, public confidence is damaged.

Reform should focus on practical enforceability. Individuals need clearer explanations for redactions, stronger consequences for unjustified delay, better routes to preserve data, and more transparent handling where solicitors or other third parties become involved in SAR processing.

Reform priorities

  • Clearer redaction duties: organisations should explain the legal basis for withholding data in plain terms.
  • Stronger preservation safeguards: disputed data should not disappear while a SAR complaint is ongoing.
  • Controller accountability: organisations should remain visibly responsible even when lawyers assist with the response.
  • Better ICO follow-up: where mishandling is identified, the focus should be whether the requester actually receives a lawful response.
  • Practical court access: enforcement routes should be understandable and proportionate for individuals, not only for organisations with legal teams.

Until those reforms are achieved, individuals need to protect themselves through discipline: precise requests, clean records, deadline tracking, redaction challenges and careful escalation.

The closing point

Data rights are not meaningful if they can be worn down by delay, silence or overbroad confidentiality claims. A SAR should open the record, not become another battleground in which the individual is forced to fight for basic transparency.

Legal Lens supports litigants in person, whistleblowers, consumers, campaigners and public-interest accountability work. Contact Legal Lens.

This article is public-interest commentary and general information. It is not legal advice. SAR disputes, privilege claims, ICO complaints and court enforcement are fact-sensitive and should be assessed against the documents and current law.

Leave a Reply

Your email address will not be published. Required fields are marked *

Skip to toolbar