Blindfolded by Bureaucracy
Illustration: Legal Lens (AI-generated)

The ICO’s Ineffectiveness in Handling My GDPR Complaint: What Comes Next

Data protection · SAR enforcement · ICO accountability

A Subject Access Request is not a favour. It is a legal right. When a controller fails to respond and the regulator’s response feels limited, the question is not only whether one request has been mishandled. It is whether individual data rights are being enforced with enough practical force to maintain public confidence.

Category
Data protection
Jurisdiction
United Kingdom
Reading time
c. 8 minutes
Last reviewed
1 June 2026
By-line
Legal Lens

Publication snapshot

  • Core issue: whether the ICO’s handling of an individual SAR complaint gives enough practical protection when a controller fails to respond.
  • Case context: the author says Balliol Property Services failed to respond to a SAR submitted in April 2024.
  • Practical focus: ICO complaint handling, controller compliance, court route, compensation, escalation and evidential discipline.
  • Risk point: criminal-law allegations should not be used unless the evidence supports them. SAR non-compliance is serious, but it is not automatically fraud.
Reader note: this article is public-interest commentary and practical legal education based on the author’s account of a data-protection dispute. References to weak enforcement, regulatory inconsistency, SAR non-compliance or possible escalation are criticism and analysis. They should not be read as findings of unlawful conduct, dishonesty, fraud, criminality, bad faith or regulatory failure by BPS, the ICO, any solicitor, employee, adviser, public body or individual unless established by a competent court, tribunal, regulator, ombudsman or official decision.

Why this matters

On 12 August 2024, my ongoing experience with the Information Commissioner’s Office left me concerned about the practical effectiveness of data-protection enforcement for individual complaints.

The issue began with a Subject Access Request to Balliol Property Services. I submitted the request in April 2024, seeking access to personal data held about me. According to my account, BPS did not respond despite follow-up. I then complained to the ICO, expecting the regulator to secure compliance with the right of access.

The ICO’s response recognised the complaint but did not, from my perspective, produce the enforcement outcome needed. The concern is not that every individual complaint should automatically produce a fine or formal enforcement notice. The concern is whether a controller can fail to respond to a SAR and still leave the requester without a timely, effective route to the data.

The accountability question: when a controller fails to respond to a SAR, what practical remedy does the individual actually have — and how quickly can it be made effective?

What happened

According to my account, I submitted a SAR to BPS in April 2024 and followed up when no response was received. I then complained to the ICO. The ICO accepted that there had been a failure to respond, but the practical outcome appeared limited: BPS was contacted or prompted to respond, and I was left uncertain about what would happen if BPS continued not to comply.

That is where the frustration lies. A SAR is supposed to be a clear access right. If the controller does not respond, the individual should not have to navigate multiple stages of complaint, escalation and possible litigation simply to obtain a response to a statutory request.

This type of case exposes a structural problem. The ICO may prioritise complaints according to seriousness, harm, wider impact and regulatory value. That triage model may be understandable from a regulatory-resources perspective. But from the individual’s perspective, a non-response to a SAR can be a direct and practical denial of access to personal data.

Author’s account

A SAR was submitted to BPS in April 2024 and no substantive response was received after follow-up.

Regulatory issue

The ICO complaint process appeared to recognise non-compliance but did not provide the immediate enforcement response the author expected.

Practical question

The issue is whether the individual has an effective route to compel access when the controller remains non-responsive.

What the ICO route can and cannot do

The ICO complaint route matters. It can assess complaint material, triage cases, ask an organisation to do more work, ask for clearer explanations, and in some cases take wider regulatory action. It can also use complaint information to identify trends and inform regulatory priorities.

But the ICO route has limits. The ICO cannot award compensation. It may decide that a complaint does not require detailed investigation. It may take a light-touch approach where the organisation appears to be taking steps to respond, where the issue is already known, or where the complaint does not meet the threshold for more intensive involvement.

That creates a difficult gap. The ICO may be acting consistently with its complaint-handling framework, while the individual remains without the data. That is why complainants should frame escalation precisely: not simply “the ICO has failed”, but “the controller has not complied, the data remains outstanding, the harm or practical impact is continuing, and the ICO should explain what further step it will take or why it will not.”

1

Show the SAR chronology

Request date, follow-up dates, response deadline, any ID request, any reply, and what remains outstanding.

2

Show the continuing impact

Explain why access matters, what harm or disadvantage is caused, and whether the data is needed for a live dispute or decision.

3

Ask for a specific ICO position

Ask whether the ICO will make further enquiries, require clearer action from the controller, or explain why no further step is proportionate.

4

Preserve alternative remedies

If the SAR remains unresolved, consider direct correspondence, a court route, compensation, or legal advice.

The court route

If a controller fails to comply with a SAR, the individual may need to consider direct action against the controller. That route should be separated from an ICO complaint.

The ICO can give an opinion and may take regulatory action, but compensation is not awarded by the ICO. If compensation is sought for material damage or distress, the route is against the organisation alleged to have broken data-protection law. If the objective is access to data rather than compensation alone, the remedy must be framed carefully around the specific right and the order sought.

A court route should not be approached as a campaigning step. It requires evidence, legal basis, remedy, defendant, chronology and proportionality. The strongest foundation is the SAR itself, proof of service, follow-up correspondence, non-response or inadequate response, ICO correspondence, and a clear statement of what data or remedy is still sought.

ICO route

Regulatory complaint

Use to ask the regulator to assess the complaint, press the organisation, explain its approach, or consider wider action.

Controller route

Direct compliance

Use to put the controller on notice of the outstanding SAR, the deadline history, the breach alleged and the remedy sought.

Court route

Order or compensation

Use where access remains unresolved or where breach-related damage or distress is alleged and evidence supports escalation.

Why criminal language needs care

The original frustration also raised thoughts about fraud, unjust enrichment, conspiracy to defraud, money laundering, forgery and perverting the course of justice. Those are serious legal concepts. They should not be used as ordinary pressure words in a SAR dispute.

A controller’s failure to respond to a SAR may be unlawful, unreasonable or damaging. It may justify complaint, litigation or compensation. But it does not automatically mean fraud, money laundering, forgery or perverting the course of justice. Those allegations require very different evidential foundations.

The safer and stronger approach is to describe the conduct precisely. Was there a missed SAR deadline? Was there no response? Was the response incomplete? Was an ID request unreasonable? Were records withheld? Were documents altered? Was a false statement made? Was there evidence of coordinated dishonesty? Each question points to a different route.

Unsafe framing

“BPS’s failure to respond may amount to fraud, money laundering, forgery or perverting the course of justice.”

Safer and stronger framing

“If evidence emerges of deliberate falsification, concealment, dishonest coordination or improper destruction of documents, the issue may require specialist legal advice beyond ordinary SAR enforcement.”

That distinction protects the complaint. Overstated allegations can distract from the strongest point: the controller has to comply with data-protection law and should be held to the access-right process.

The enforcement gap

The wider concern is whether the ICO’s approach leaves individual complainants feeling that their rights matter less than large-scale or high-profile cases.

High-profile cyber and security cases understandably attract visible regulatory attention, especially where sensitive personal data, health records, large numbers of people or critical services are involved. That does not mean smaller individual SAR failures are unimportant. A SAR may be crucial to one person’s ability to understand decisions made about them, challenge a process, protect their position in a dispute or uncover what has happened to their data.

The problem is not that the ICO should treat every case identically. Different cases require different regulatory responses. The problem is confidence. If an individual receives confirmation that a controller has not complied but still cannot obtain timely access, the system may look ineffective even if the regulator can justify its triage model.

Consistency does not mean identical treatment

The better test is whether the ICO’s approach gives individuals a clear, timely and realistic route to resolution when their access rights are not honoured.

Next steps

The next step is to move from general frustration to a structured escalation route. The strongest approach is to identify what remains unresolved, what evidence proves non-compliance, what impact the failure is having, and what action is requested.

An escalation to the ICO should ask for a specific review of the handling of the complaint and the current status of BPS’s compliance. A direct letter to BPS should identify the SAR, the missed deadline, the outstanding data and the intended next step if compliance is not achieved. Any court route should be prepared with the right defendant, remedy, evidence and legal basis.

The aim is not only to secure access to data. It is also to make the enforcement gap visible: where an individual right exists on paper but requires disproportionate effort to make effective in practice.

For the ICO

Ask for a review of what further action will be taken if the controller remains non-responsive, and how the complaint framework has been applied.

For BPS

Send a focused compliance letter identifying the SAR, the chronology, the outstanding response and the remedy sought.

For court or advice

Prepare the evidence bundle before escalation: SAR, proof of sending, follow-ups, ICO correspondence and any evidence of harm or distress.

Source anchors

These source anchors help separate the legal framework, the ICO complaint route and the article’s public-interest criticism.

Closing point

The right of access is only meaningful if it can be enforced in practice. If a controller does not respond and the individual is left to escalate, chase, complain and potentially litigate, the legal right can feel weaker than it appears on paper.

The ICO cannot litigate every individual grievance and should not be expected to treat every complaint as a major enforcement case. But where the complaint is simple — a SAR was made, the deadline passed, and no response was provided — the regulatory system should give the individual a clear path to resolution.

The public-confidence issue is therefore precise. Individual SAR breaches may not make headlines, but they still matter. A data-protection framework that protects only the most visible cases will not command the confidence of the people it exists to protect.

Decision support before ICO review, claim or escalation

Legal Lens helps complainants turn SAR disputes into structured, evidence-led next steps. The aim is practical: map the SAR chronology, identify the missed evidence, separate regulatory complaint from court route, and avoid allegations that outrun the documents.

SAR chronology ICO review Court route Wording risk

What we assess

SAR request, proof of sending, follow-ups, ICO complaint, response gaps, harm evidence, legal route and wording risk.

When to use it

Requesting ICO review, sending a letter before action, filing a claim, publishing criticism or alleging misconduct against a named organisation.

What you get

A concise written view on the strongest next step, missing evidence, escalation route and whether solicitor review is needed.

Independent Legal Lens consultancy. This is not a regulated solicitors’ firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

This article is general legal information and public-interest commentary. It is not legal advice or a finding of wrongdoing. SAR disputes, ICO complaints, compensation claims, court orders, criminal-law allegations and publication about named organisations require evidence-specific assessment and, where appropriate, regulated legal advice.

Leave a Reply

Comments are public. Please do not include details of your own case — use the contact form instead.

Your email address will not be published. Required fields are marked *