Subject access requests: what to do when the firm fights back
A subject access request is one of the most powerful tools consumers have, and one of the most frequently obstructed. Firms drag their feet, send partial files, redact heavily, and cite vague exemptions that don't exist. Most consumers accept this. They shouldn't. Each of those moves has a name in the law, and each of them is enforceable.
This article walks through the right of access, the limits firms are allowed to apply, and the four obstruction patterns most firms use, with the response that fixes each one.
The right, in one paragraph
The right of access comes from Article 15 of the UK GDPR and section 45 of the Data Protection Act 2018. Anyone whose personal data a firm holds can request a copy of it, free, with limited exceptions. The firm must respond within one calendar month. They can extend by two further months if the request is complex (and they must tell you, in writing, that they are extending and why). Redactions are permitted only where a specific statutory exemption applies, and the firm must tell you the legal basis for each redaction.
This is not optional. Failures are reportable to the Information Commissioner's Office and, in some cases, actionable in court for compensation.
Can a company redact my subject access request without telling me why?
No. Redactions must have a statutory basis. The most common bases are:
- The redacted information identifies a third party (Schedule 2, Part 3, Data Protection Act 2018).
- The information is subject to legal professional privilege (Schedule 2, Part 4).
- Disclosure would prejudice an ongoing criminal investigation (Schedule 2, Part 1).
- The information is exempt because it relates to negotiations with the data subject (limited and narrowly construed).
What firms cannot do:
- Redact without telling you the legal basis.
- Apply a blanket "commercial confidentiality" exemption (it does not exist in the data protection regime for SARs).
- Refuse the entire request because it is "broad" (they must instead ask you to clarify, or comply in part).
- Charge a fee (with very limited exceptions for manifestly unfounded or excessive requests).
Each of these is a separate ICO complaint point.
The four obstruction patterns
1. Silence past the deadline
You sent the SAR and heard nothing for more than one calendar month, with no extension letter.
Response: A short follow-up email putting the firm on formal notice:
"My subject access request of [date] has not been responded to within the statutory time limit of one calendar month under Article 12 of the UK GDPR. No extension under Article 12(3) has been notified. I require a full response by [date 14 days out] failing which I will refer the matter to the Information Commissioner's Office."
Most silence is broken by a follow-up of this length. If it isn't, the ICO complaint is straightforward.
2. Partial response
The firm has sent some documents but not the categories you asked about, or the response is obviously thin compared to the data they must hold.
Response: Identify the categories missing and ask explicitly:
"The response of [date] does not include the following categories of personal data, which I have reason to believe you hold: [list]. Please confirm whether these have been withheld and, if so, on what specific statutory basis."
This forces the firm into either supplying the data or naming an exemption it can be held to.
3. Heavy redactions without explanation
You receive documents but large portions are blacked out, with no marginal note or accompanying letter explaining the legal basis.
Response: A challenge letter:
"The response includes redactions on pages [list]. Under Article 15 of the UK GDPR and the principles of transparency in Article 12, I am entitled to know the legal basis for each redaction. Please identify, by document and page, the specific statutory exemption relied on for each redaction. A blanket reference to 'third-party data' or 'commercial confidentiality' is not sufficient."
If they don't answer, you have a clean ICO complaint: redactions without identified statutory basis are a procedural breach.
4. Outright refusal
The firm tells you the request is manifestly unfounded, manifestly excessive, or otherwise refused.
Response: Article 12(5) requires the firm to give you specific reasons for refusal and to inform you of your right to complain to the ICO. If they haven't done both, that's the first ICO complaint point. Even where a refusal is reasoned, the threshold for "manifestly unfounded" is high, and the ICO regularly finds firms have applied it incorrectly.
How to make the ICO complaint
The ICO online form is straightforward. Three sections:
- The firm and the request (date sent, what you asked for).
- The breach (one of the four patterns above), with documentary evidence.
- The outcome you want (full response, removal of unjustified redactions, formal action).
Attach the SAR, the firm's response, and your follow-up correspondence.
What usually happens next
The ICO doesn't usually order specific compensation. It investigates, issues a reprimand or enforcement notice in serious cases, and (importantly) records the firm's compliance pattern. Multiple complaints against the same firm aggregate. For the consumer, the ICO complaint creates two practical effects:
- The firm often produces the missing data or revises the redactions once the ICO is involved, to avoid escalation.
- The ICO's eventual letter (even a "no further action" one) usually contains language the consumer can quote in a parallel FOS complaint or court claim, framing the firm's data handling as a breach.
A separate civil route exists under section 168 of the Data Protection Act 2018 to claim compensation for distress and material damage caused by a breach. This is rarely used by self-represented consumers and usually requires legal advice.
The bottom line
A SAR that is met with silence, partial files, unexplained redactions, or refusal is not the end of the request. It is the start of a separate procedural complaint. Each pattern has a named legal basis the firm must produce, and each can be tested at the ICO. The consumers who get the data are the ones who treat the response as a draft, not a final answer.
Docketory publishes general information based on real disputes. Identifying details are changed and patterns from multiple cases may be combined. This is not legal advice. For advice on your specific situation, contact a solicitor or Citizens Advice.
Related on Docketory:
Need help with this?
Tell us about your situation. We will confirm whether we can help, which service applies, and the cost: no obligation to proceed.
Related articles
The Consumer Duty, line by line: what it means for your complaint
The FCA Consumer Duty is the most useful tool consumers have. It does not replace your contract. It adds an obligation the firm has to meet alongside it.
Your insurer authorised repairs without your permission. Now what?
Your insurer can authorise repairs through an agent you never instructed: but not always lawfully. Here's the Consumer Duty argument and how to use it.
The FOS rejected your complaint. Here's what comes next.
An investigator's view is not the final word. A final ombudsman decision is not the end of every route. Here's what to do when the FOS says no.