Subject access requests · Transparency · Accountability
A subject access request should not become a controlled narrative exercise. The right of access is meant to help a person understand how their personal information is used. Where a response is narrow, heavily redacted, processor-led or difficult to challenge, the accountability question is whether the controller can show a lawful route from request, to search, to review, to reason, to response.
Publication snapshot
This article examines how subject access requests can lose practical force when responses are framed around the controller's preferred account rather than the data subject's right of access. It focuses on search scope, personal information, redactions, exemptions, processor involvement, clarification, complaint routes and the evidence a requester should preserve when challenging an opaque SAR response.
Reader note: this article is public-interest commentary and practical legal education. References to SAR handling, controller conduct, redactions, processor involvement, complaint routes and regulatory oversight are criticism and analysis. They should not be read as findings of misconduct, dishonesty, unlawful concealment, data misuse, regulatory failure or professional wrongdoing by any named person, organisation, controller, processor, regulator or public body unless established by a competent court, tribunal, regulator, ombudsman, inquiry, audit report or official decision.
The right of access
The right of access allows a person to obtain a copy of their personal information and supplementary information about how that information is being used. It is a practical transparency right. It helps the person understand what is held, why it is held, who receives it, how long it is retained, and whether the organisation's use of that information can be checked.
That purpose matters because many SARs are made when trust has already broken down. The request may arise during an employment dispute, a complaint, a legal services dispute, a professional regulation issue, a landlord dispute, a safeguarding matter, a data breach concern or a conflict with an organisation that controls the relevant records.
The right is not unlimited. A SAR is not the same as litigation disclosure, freedom of information or a general demand for every document. The requester is entitled to personal information, not every record that exists. But where the response is incomplete, heavily redacted or difficult to understand, the controller should be able to explain the route it took.
Narrative control
A recurring concern in SAR disputes is narrative control. The requester asks for their data, but the response appears to preserve the organisation's version of events. Material that supports the controller's account is disclosed clearly. Material that may test that account is absent, redacted, described generally or said to fall outside scope.
That does not prove bad faith. A controller may lawfully withhold information because it is not personal data, relates to other people, is privileged, falls within an exemption, cannot be found after a reasonable and proportionate search, or requires clarification before it can be identified. But those concepts should not be used as labels without an audit trail.
The stronger question is not whether the requester suspects manipulation. It is whether the controller can show the route from request, to search, to review, to redaction, to exemption, to response.
Request
What was asked for, when was it received, and was identity or authority genuinely in issue?
Search
Which systems, people, periods, files and categories of personal information were considered?
Reason
What explains each omission, redaction, exemption, refusal or search limitation?
Scope and search
Scope is often where the dispute begins. A controller may say a document is not personal data, that the request is too broad, that searches would be disproportionate, or that further clarification is needed. Some of those points may be legitimate. The issue is whether they are being applied carefully.
Current guidance reflects the need for reasonable and proportionate searches. That does not permit a controller to avoid obvious sources. It means the controller should be able to show why the search was reasonable in the circumstances: the systems searched, the custodians considered, the date range used, the terms applied, the archived material checked and the reason any wider search was not proportionate.
Clarification is also a controlled tool. A controller may ask for further information where reasonably required to identify the personal information or processing activity to which the SAR relates. But clarification should not be requested on a blanket basis or used as a delay mechanism. The controller should explain why clarification is needed, keep a record of the request, and calculate any pause to the time limit properly.
Redaction and exemptions
Redaction can be necessary. A SAR may include information about other people, legally privileged material, confidential references, management information, regulatory material, health information, social work information, negotiations or material covered by a specific exemption. The problem is not the existence of exemptions. The problem is blanket use.
Exemptions should be considered case by case. They should not be relied on routinely or applied in a blanket fashion. If a controller relies on an exemption, it should document the reasons and be able to justify the position. Where a refusal is made, the requester should usually be told why, told about the right to complain to the controller and the ICO, and told about the ability to enforce rights through the courts.
Some reasons may need to be general where fuller explanation would defeat the exemption. But even then, the internal record should show what was withheld, why it was withheld, who considered it and how the decision was checked.
Identify the basis
Is the material withheld because it is not personal information, concerns another person, is privileged or falls within an exemption?
Apply it narrowly
Has the controller considered the actual information, rather than applying a broad category label?
Record the reason
Can the controller later justify each refusal, omission, redaction or exemption decision?
Processors and law firms
Controllers may use processors to help with SARs. That may be sensible where the request is large, technical, litigation-sensitive or requires secure review. A processor may help retrieve records, apply search terms, prepare review batches, propose redactions or assemble a response pack.
But processor involvement does not transfer responsibility. The controller remains responsible for complying with SARs and deciding how to deal with the request. The processor must be contractually required to help the controller meet its SAR obligations, including by allowing the controller to obtain the information needed for the response.
Law firms require particular care because roles can overlap. A law firm may advise the controller, act in the underlying dispute, review privilege, assist with SAR processing, draft the response or correspond with the requester. Those roles can be legitimate. They should also be clear. Where the adviser is close to the disputed facts, the controller should consider whether independent review, role separation or tighter supervision is needed.
The complaint route
Many requesters experience the complaint route as uneven because the controller holds the systems, search logs, internal reasoning and review records. The requester usually sees only the response. That imbalance can make a complaint feel frustrating, especially where the requester believes material has been withheld or selectively explained.
The practical answer is evidence discipline. A complaint is stronger when it identifies the SAR, the deadline, the likely data sources, the missing records, the redactions in issue, the exemption relied on, the reason it appears inadequate, and any inconsistency between the controller's account and documents already known to exist.
General allegations that a controller manipulated the narrative may express the frustration, but they rarely provide the route. The stronger formulation is narrower: this information appears to be personal information; this system or person likely held it; this record is missing or redacted; this exemption has not been explained; this is why the response does not show a reasonable and proportionate search or a case-by-case exemption decision.
The SAR evidence map
The practical tool is a SAR evidence map. It prevents a complex SAR dispute from becoming a general complaint that everything has been hidden. It also prevents the controller from treating uncertainty as if it were proof that no further data exists.
The map starts with the request. What was asked for, when was it sent, how was it delivered, and how did the controller respond? It then identifies the expected data sources: email accounts, case files, HR systems, complaint files, case-management systems, invoices, calendars, meeting notes, call recordings, audit logs, portal records and third-party correspondence.
The next step is comparison. What was disclosed? What was missing? What was redacted? What exemption was relied on? What supplementary information was supplied? What complaint route was given? What evidence shows that the missing material likely exists or that the redaction may be too broad?
Request. Record the date, wording, delivery method, acknowledgement and deadline calculation.
Sources. Identify people, systems, files and time periods likely to hold personal information.
Response. List what was disclosed, withheld, redacted, refused, explained or not addressed.
Gap. State the precise missing-data, redaction, exemption, processor or search concern.
Reform and practice
Realising the right of access requires more than formal compliance. Controllers should treat SAR handling as a governance issue: trained staff, clear ownership, documented searches, redaction logs, exemption reasons, processor controls, prompt clarification and intelligible responses.
Regulatory oversight also depends on usable records. If a requester complains, the controller should be able to reconstruct the response. If it cannot, the issue is no longer only whether a document was missing. It is whether the controller kept a record sufficient to demonstrate accountability.
The same applies to requesters. The stronger challenge is not broad accusation. It is a structured record showing what was requested, what should have existed, what was supplied, what was withheld, and why the explanation is inadequate.
Source anchors
These sources support the legal and regulatory framework used in this article. They do not prove any disputed complaint, breach, redaction issue, SAR failure, regulatory failure or organisation-specific misconduct.
ICO right of access guidance
SAR entitlement, supplementary information and controller responsibility where processors assist.ICO SAR response guidance
Time limits, clarification, processor reliance, fees, ID checks and reasonable handling.ICO search guidance
Finding and retrieving information, search effort and reasonable and proportionate searches.ICO SAR exemptions guidance
Case-by-case exemptions, refusal reasons, accountability and transparency where possible.GOV.UK DUAA factsheet
2025 clarification of subject rights, stop-the-clock provisions and reasonable searches.ICO complaint route
Public route for raising data protection complaints after engaging the organisation.The Legal Lens point
A SAR response should not leave the data subject guessing whether the controller searched properly, redacted lawfully, relied on exemptions selectively, used a processor appropriately or controlled the narrative of a dispute.
The strongest response to an opaque SAR is not louder accusation. It is better structure. Identify the request, the likely data sources, the disclosed material, the missing records, the redactions, the exemptions, the processor role and the specific accountability gap.
The right of access is weakened when it becomes a one-sided explanation managed by the controller. It is strengthened when both sides can see the route from request, to search, to review, to reason, to response.
SAR evidence and accountability map
Get a free written assessment of the route
If a SAR response appears incomplete, over-redacted or shaped by a disputed narrative, Legal Lens can help structure the request, response, evidence gaps and complaint route before escalation or specialist review.
Clarify whether the concern is missing data, narrow search, redaction, exemption, delay or processor role.
Connect expected records, disclosed material, redactions and correspondence to the precise accountability gap.
Separate controller complaint, ICO complaint, legal advice, processor concern and any public commentary issue.
Search, redaction, exemption, processor role, missing records and complaint route.
Requests, responses, known sources, missing records, chronology and next questions.
Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors' firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

