Legal services · Subject access requests · Client trust
A law firm’s data protection duties cannot be separated from its professional duties. When a subject access request arises from a dispute involving former-client information, adverse interests or a possible conflict, the question is not only whether the firm can point to a GDPR process. It is whether the response preserves transparency, confidentiality, independence and public confidence.
Publication snapshot
This article examines the overlap between subject access requests, legal-sector confidentiality, former-client information and conflict-of-interest concerns. It is framed for England and Wales legal services and UK data protection practice. The core point is practical: where a SAR is connected to a dispute involving a law firm, the firm should be able to show a clean route from request, to role allocation, to search, to exemption or redaction, to response, while preserving client confidentiality and professional independence.
Reader note: this article is public-interest commentary and practical legal education. References to SAR handling, law-firm governance, conflicts, former-client confidentiality, professional standards and data protection are criticism and analysis. They should not be read as findings of misconduct, dishonesty, data misuse, unlawful conduct, professional wrongdoing or regulatory failure by any named person, firm, controller, processor, regulator or public body unless established by a competent court, tribunal, regulator, ombudsman, inquiry, audit report or official decision.
Legal-sector data trust
Legal services depend on trust. A client gives a solicitor information that may be commercial, financial, personal, strategic, privileged, confidential or highly sensitive. The client does so because the firm is expected to protect the information, act independently, avoid improper conflicts and maintain professional standards.
Data protection does not replace those duties. It sits alongside them. A law firm handling personal information must understand its UK GDPR obligations, but it must also understand the professional context in which that information was obtained. A client file is not just a dataset. It may also contain confidential instructions, advice, litigation strategy, family circumstances, health material, financial vulnerability, business assets and information about other people.
That is why subject access requests in the legal sector require more than administrative processing. They require role clarity, confidentiality analysis, privilege review, conflict checking, redaction discipline and a record capable of explaining why the response was handled in the way it was.
The right of access
The ICO describes the right of access as a fundamental right that gives people the right to obtain a copy of their personal information and supplementary information. It helps people understand how and why their information is being used and check whether it is being used lawfully.
That purpose is especially important where trust has broken down. A former client, employee, tenant, complainant or opposing party may use a SAR to understand what information a firm holds, what has been shared, who has received it, whether the file is complete, whether the response to a dispute is consistent with the underlying records, and whether personal information has been handled properly.
A SAR is not general disclosure. The requester is not automatically entitled to every document, every privileged communication or every record mentioning their name. But the controller should be able to show how it identified personal data, searched relevant systems, considered exemptions, applied redactions and provided supplementary information.
Search
Which systems, files, custodians, dates and categories of personal data were considered?
Review
Who reviewed the material for personal data, third-party data, confidentiality, privilege and exemptions?
Response
What was disclosed, withheld, redacted, explained, refused or left for complaint review?
Law firms as controllers
A controller decides why and how personal data is processed. A processor acts on a controller’s behalf and on documented instructions. In legal-sector SAR disputes, those roles need careful analysis because a law firm may be acting as an independent controller for its own client files, a processor for another controller, a legal adviser in an underlying dispute, or a combination of roles in different parts of the same factual background.
The ICO’s right of access guidance makes the controller’s responsibility clear. Controllers are responsible for complying with SARs. If they use a processor, they need a contractual arrangement that enables them to deal with SARs properly, and the processor must help them meet their SAR obligations. The controller remains responsible for deciding how to deal with SARs.
That matters where a firm or adviser becomes involved in a SAR connected to a wider dispute. The person receiving the response should not be left guessing whether the firm is the controller, an adviser, a processor, a reviewer, a privilege gatekeeper or a tactical representative in the underlying dispute. Each role has different implications for independence, confidentiality and accountability.
Conflict and confidentiality
The SRA Principles require solicitors to uphold the rule of law and proper administration of justice, uphold public trust and confidence, act with independence, honesty and integrity, encourage equality, diversity and inclusion, and act in each client’s best interests. Those principles give the data protection issue a professional frame.
The SRA Code of Conduct also addresses conflicts, confidentiality and disclosure. It states that solicitors must not act where there is an own-interest conflict or significant risk of one. It also restricts acting where there is a client conflict or significant risk unless the code’s conditions are met. Those conditions include informed consent given or evidenced in writing, effective safeguards for confidential information where appropriate, and the solicitor being satisfied that it is reasonable to act for all clients.
Former-client information is particularly sensitive. The code requires solicitors to keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents. It also restricts acting for a client whose interest is adverse to another current or former client where the firm holds material confidential information, unless the code’s protective conditions are met.
SAR handling in disputes
A SAR connected to a legal dispute should not become an informal litigation tactic, a defensive narrative exercise or a way of obscuring role boundaries. It may be perfectly proper for a firm to consider privilege, confidentiality, third-party data and exemptions. It may also be proper to take legal advice before responding. The problem arises when the process becomes opaque and the requester cannot see who is responsible for what.
Where a SAR is handled by someone close to the disputed facts, the firm should consider whether that creates a perception or reality of conflict. The question is not only whether the person has enough technical knowledge to respond. It is whether their involvement undermines confidence in the independence, objectivity or confidentiality of the process.
A disciplined response identifies the controller, the decision-maker, the reviewer, the legal adviser, the processor if any, and the escalation route. It also records what was searched, which exemptions were considered, why redactions were applied, what was withheld and who approved the final response.
Separate roles
Distinguish data protection handling from litigation strategy, complaint defence, privilege review and client advice.
Record decisions
Keep the search plan, review notes, redaction basis, exemption reasoning and approval route.
Preserve confidence
Consider independent review or tighter safeguards where the reviewer is close to the disputed facts.
Redaction, exemptions and privilege
Redaction is not automatically suspicious. SAR responses may legitimately withhold or redact information where it is not the requester’s personal data, relates to other people, is legally privileged, falls within an exemption, or cannot be disclosed without prejudicing a protected function. In legal-sector files, privilege and duties owed to other clients may be central.
The ICO guidance on exemptions is clear that exemptions should be considered case by case. They must not be applied routinely or in blanket fashion, and the controller should document the reasons for relying on an exemption and be able to justify it. If a controller refuses to comply with a request, it must usually give reasons, explain the right to complain to the controller and the ICO, and refer to the ability to seek enforcement through the courts.
The legal professional privilege exemption requires careful analysis. The ICO guidance explains that personal information may be exempt if legal professional privilege or the confidentiality of communications in Scotland may be maintained, or where a professional legal adviser owes a duty of confidentiality to their client. The exemption does not automatically cover every process a law firm carries out. The review still has to connect the withheld material to the proper basis for withholding it.
Individual conduct and firm systems
When a SAR goes wrong, attention often turns to the individual who handled the request. That may be necessary where a person acted outside authority, accessed material they should not have accessed, failed to escalate a conflict or mishandled confidential information. But individual conduct should not obscure the wider systems question.
A well-run firm should have SAR processes that do not depend on improvisation. It should know who can receive a SAR, who verifies identity, who conducts searches, who reviews privileged material, who handles former-client confidentiality, who approves exemptions, who signs off the response and who records the audit trail. It should also know when a matter must be escalated to a data protection lead, COLP, COFA, senior risk officer or independent reviewer.
The professional issue is therefore both personal and institutional. A single mishandled response may reveal a training issue. It may reveal a supervision issue. It may reveal inadequate digital audit trails, unclear file-closing practice, weak conflict controls, poor processor governance or an absence of practical ownership. The record should make it possible to identify which.
The evidence route
For a requester, the strongest route is evidence structure rather than accusation. The SAR should be kept with proof of delivery, acknowledgement, identity checks, clarification exchanges, response dates, disclosed material, redaction examples, missing-record list, complaint correspondence and any evidence showing that particular records likely exist.
For a firm, the equivalent discipline runs in the opposite direction. The firm should be able to reconstruct the response: receipt, triage, role allocation, conflict check, search plan, systems searched, reviewer access, privilege analysis, third-party data review, exemption reasoning, response approval and complaint route.
The practical question is not whether a requester dislikes the response. The question is whether the firm can show a lawful, professional and accountable route from the SAR to the decision. If that route cannot be reconstructed, the problem is no longer only the missing document. It is the missing governance trail.
For requesters
Keep the SAR, response, missing-record list, redactions, complaint trail and evidence that records likely exist.
For firms
Keep search logs, conflict checks, privilege review notes, exemption reasons, redaction basis and approval records.
For escalation
Separate SAR complaint, ICO route, SRA conduct issue, negligence concern, confidentiality issue and litigation step.
Source anchors
These sources support the legal and regulatory framework used in this article. They do not prove any disputed complaint, breach, conflict, SAR failure, professional misconduct or organisation-specific issue.
ICO right of access guidance
SAR entitlement, supplementary information and controller responsibility where processors assist.ICO SAR response guidance
Time limits, complexity, clarification, identity checks and processor reliance.ICO SAR exemptions guidance
Case-by-case exemptions, legal professional privilege, refusal reasons and accountability.ICO controllers and processors guidance
Controller, processor and joint-controller role analysis and governance.SRA Principles
Rule of law, public trust, independence, honesty, integrity and client interests.SRA Code of Conduct
Conflicts, confidentiality, former-client information and professional obligations.The Legal Lens point
A legal-sector SAR is not just a data request. It can be a test of professional culture. The requester is asking for access to personal information. The firm is also being tested on confidentiality, conflict control, independence, privilege handling, supervision and record-keeping.
The strongest question is not whether a firm says it complied. It is whether the firm can show the route: who handled the request, what role they were performing, what was searched, what was withheld, why it was withheld, how former-client confidentiality was protected and who took responsibility for the final response.
Where that route is missing, public confidence is weakened. Where it is documented, the firm can protect both the requester’s data rights and the professional duties that make legal advice possible.
Legal-sector SAR route map
Get a free written assessment of the route
If a SAR involves a law firm, former-client information, conflict concerns, privilege or missing records, Legal Lens can help structure the documents, issues and route before complaint, correspondence or specialist review.
Clarify whether the concern is search scope, missing data, redaction, privilege, conflict, delay or processor role.
Organise the SAR, response, redactions, known records, complaint trail, retainers and relevant correspondence.
Separate ICO complaint, SRA conduct issue, Legal Ombudsman issue, negligence question and litigation step.
SAR, conflict, confidentiality, privilege, missing records and complaint route.
Requests, responses, retainers, redactions, chronology, gaps and next questions.
Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors' firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

