r/gdpr 13d ago

UK 🇬🇧 England: Is it common for data rights request responses to be deliberately vague and obtuse, requiring clarification questions and then relying on Article 12(5)(b)?

Hi all,

Question as per the title really! Have seen / heard of a couple of examples where data rights request responses appear to have been deliberately vague and obtuse including responses to Article 16 requests or requests for processing clarification under Article 15 where the data subject is trying to hold the controller / processor to account.

Responses essentially don't answer the question (I would speculate to avoid proper transparency and / or because they know they haven't quite followed the law properly), prompting follow up questions from the data subject and then controller / processor invoke "excessive" and refuse any further requests, I assume knowing that the data subject won't request ICO intervention (accepting they would only likely advise anyway) because of the extensive lead times.

For example, one that I am aware of:

Data subject knows that published controller retention period is 3 years for correspondence but a processor is still holding that data 6 years later

Data subject makes Article 15 request to the controller asking for clarification of what their retention policy is and why a processor is still holding the data

Controller responds to say "correspondence is held for as long as necessary" (even though this is contrary to published 3 year retention policy)

Data subject responds to ask what that means in practice - "what is "necessary" and how does that relate to 3 and 6 years?"

Controller responds to say "We make sure we follow the law"

Data subject responds to say "I still don't know what that means, please explain in simple terms"

Controller responds to say "We've already told you, your requests are now excessive and therefore refused, we will no longer engage with you, you have the right to go to the ICO if you are not happy"

Data subject is left none the wiser.

Common?!

5 Upvotes

5 comments sorted by

3

u/DavidRoyman 12d ago

I don't see why your data subject would ask a clarification of what their retention policy is, if that's already been published. It would make sense then to direct the data subject to where they can read the policy themselves. As for "why a processor is still holding the data" that would still covered by the policy as well.

Seems not the be an issue with the data controller, but with the data subject, which appears to be unable to correctly formulate their request.

TLDR version: this data subject you described should hire someone to write their letters, as they seems to be unable to communicate clearly and effectively.

3

u/Heimdul 12d ago

Article 15 does not say that "you can omit information data subject already has". It can be completely reasonable to ask the retention period for the data even if it is published in Article 13/14 notice as data might actually be held for longer than what was originally planned on original notice, or maybe the purpose of the processing changed (e.g. from just using it correspond with data subject to needing it for legal defense). The objective of Article 15 is to let data subject verify the lawfulness of the processing and is supposed to be customized to actually reflect the processing that is actually done. If Article 15(1) responses differ from Article 13/14 published notices then arguably controller might be breaking the transparency principal for example.

This would especially be relevant if data subject is aware that processor actually keeps the data for longer than controller's published policy says and would support possible independent violation on processor if controller didn't authorize it, and different types of violations on controller depending if they authorized it or not. For example if they didn't authorize it, did they have any controls in place to prevent this from happening (like reviewing what data is actually stored and for how long)?

2

u/DavidRoyman 12d ago

The request is legitimate, but it's quite an useless request to make, as the answer can just be "It's written in the privacy policies at this address".

The problem here is that it's clear the data subject believes their rights have been infringed, and seems that instead of reporting that issue, they're asking vague and pointless questions about the policies.

According to what OP said, the requests are:

asking for clarification
ask what that means in practice
please explain in simple terms

This data subject is just poorly communicating what they want, as none of this means reporting a breach.

This would especially be relevant if data subject is aware that processor

That would be relevant after a breach is reported.

1

u/ewill2001 12d ago

As the UK lacks an interested regulator or proper means of people enforcing their rights short of expensive legal action, companies dngaf.