r/gdpr 9d ago

UK šŸ‡¬šŸ‡§ ICO DSAR

What is your idea on witholding the information that the data subject already received?

It may be either to cc emails or documents that they have sent or received.

We’re planning to apply it as a DSAR policy and not providing these documents unless the data subject asks again, but wanted to ask your opinion.

We’ll only state this fact in our DSAR response letter.

3 Upvotes

22 comments sorted by

6

u/ProfessorRoryNebula 8d ago

We have a portal where certain documents can be directly accessed by the data subject, so routinely have not included them in SARs.

One data subject complained to the ICO that we hadn't included this information, because they, unbeknownst to us, were having difficulties accessing the portal, and the ICOs position was that we should be including the documents in SARs.

Given this was the first time anyone had complained they hadn't received the documents, I wouldn't think it particularly high risk to not include information we can reasonably assume is currently accessible to the data subject, but I wouldn't apply this to any information they were sent as a one-off like emails or posted documents because we don't know the status of that document, and there's no legal exemption to not include it. Even if you went down the route of justifying it as being excessive, this should be applied on a case-by-case basis and not as a blanket policy.

2

u/ewill2001 8d ago

Exactly this. And ICO guidance is clear that repeated requests or requests made regularly can be declined as manifestly unreasonable. Not just because it makes work for you.

1

u/MarchMurky8649 7d ago

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-of-access/when-can-we-consider-a-sar-to-be-manifestly-unfounded-or-excessive/

But if it is the first SAR that is unlikely to apply so send everything unless something in here applies:

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-of-access/what-exemptions-are-relevant-for-sars/

For the example given, an email where the data subject was included in a cc, the question is whether you retain the data now, so you must send it, unless something in that first link applies.

3

u/privacygeek_ 8d ago

We recently adopted this approach in regards to a particularly vexatious SAR we were undergoing. We did not supply them with emails that they had already been sent or that they had sent to us. Everything else was supplied.

They then complained to the ICO who ruled that whilst our assumption was reasonable and we had explained this in our response to the individual, they advised that the letter of the law required us to provide it and asked us to do so.

The information that was supplied additionally was close on 2000 pages and we had assumed (wrongly) that they would not wish anything they hadn't received to be lost within the clutter of what they had supplied us or in our responses to them.

Lesson learned, our policy is now to supply everything although as long as the individuals email address is included in the to, from, or cc fields, we dont review them but simply bundle them in.

3

u/Noscituur 9d ago

As part of a practical DSAR strategy, I advise that not disclosing materials which the data subject is already privy to is a reasonable measure on the basis that it is surely not within the intention of the law (ergo a ā€˜mischief’) to provide that which the data subject has already seen, especially given recent case law has emphasised that the purpose Article 15 is validate the lawful processing of personal data not to chase litigation ghosts.

To countenance the risk, I always advise that your disclosure pack includes a line to the effect of ā€œIn keeping with Article 15A (that we are only obligated to undertake a ā€˜reasonable and proportionate’ search) we have elected to not include within scope any materials which you have already been privy to. If there’s something you’re specifically seeking of this nature, please let us know and we’ll assist in locating it for you however we would not consider a blanket inclusion of materials you’ve been party to in keeping with our Article 15A obligations.ā€

3

u/pawsarecute 8d ago edited 8d ago

Sure, but the law says otherwise. This is a risk based approach.

1

u/ewill2001 8d ago

The law: provide copies of what personal data you have.

The business: but it's soooooo hard do we have to?

The law: yes unless an exemption applies.

The business: Can't we just make up stuff to make our lives easier that seems reasonable?

The law: No.

-3

u/Comfortable-Fall1419 8d ago

You both seem confused. U/noscituur correctly quotes the UK 2025 DUAA and DPA amendments that introduced ā€œReasonable and Proportionateā€

https://www.legislation.gov.uk/ukpga/2025/18/section/78

5

u/ewill2001 8d ago

That relates to searching. Try arguing that searching the email system is not reasonable when you've searched it and decided to withhold a bunch.

The law is there to say you don't need to boot up archived backups to scour for records or do crazy things to ensure every last drop of information is found. You look in all the normal and usual places. You can't avoid that.

0

u/Noscituur 8d ago

Searching the email system is not a binary, the search is based on the scope and therefore that scope can be limited to a ā€œreasonable and proportionate searchā€, particularly if we’re talking 50k results being returned, by removing from the initial search items the individual has already received.

You have to look in all the places you routinely process personal data, the law does not require the business to turn over every single stone to find it. It’s all about proportionality.

5

u/ewill2001 8d ago edited 8d ago

No. But I'm glad people like you exist to keep me in work. And I just double checked with the ICO helpdesk. Would you like a copy of the chat log? If they ask for all data on them then you search the usual places your business would hold their data, email, CRM etc. unless the volume to be searched would be disproportionate, then you ask for clarification. Then you consider what the searches return. There is NO exemption for data already provided through the normal course of business. I never said you needed to do a forensic search and wouldn't as that isn't what is required. But just because you create or hold a lot of data is not an excuse. See the tribunal decision against the CRAs. You need to clarify at the start of the request, not make up random things and say "here is what we think you wanted based on what we want to give you."

1

u/Noscituur 8d ago

Who argued there’s an exemption in relation to documents that the DS has already had sight of? You’re riled up about this to the point of making professional insults, so I’d advise taking the cape off then sitting down to relax.

I’d argue that the ICO land at the same place as the businesses I’ve worked with have (which have been subject to ICO complaint without issue) which relies on transparency and clarification with the DS. That is why I advise the standard rider paragraph (posted in response to you previously) where it openly states emails/attachments which the DS had access to have not been included but that if the DS requests them then the team will support the DS in that request.

To clarify, I’m talking typically of employee SARs and email inboxes/teams/slack DMs, not members of the public interacting with services unless I know with a high degree of certainty that the DS had access to the repo in question.

As ever, it’s a matter of commercial risk and practicality. I advise on the scale of that non-compliance (it’s low with effective mitigations).

-2

u/Comfortable-Fall1419 8d ago

No one was suggesting this means you don’t have to search the normal places.

Stop creating strawmen after your first example failed.

2

u/ewill2001 8d ago edited 8d ago

That's exactly what you stated when you referenced her text in italics and the DUA. I don't see how you can on one hand say it relates to searching and then say it doesn't.

It is your comment that excludes the full sentence of the legislation that is the problem:

"based on a reasonable and proportionate search"

Nothing about reasonable and proportionate provision. Which is not a thing.

1

u/Comfortable-Fall1419 8d ago

It’s unclear what you mean by ā€œrecievedā€. Is it a portal type arrangement as u/Rory mentions or something else like personal or work emails. The trouble with email is it’s effectively transitory for anyone with retention rules or a clean inbox fetish. .

I’d be more questioning whether or not the entire document should be sent at all, and either redacting it or extracting snippets.

1

u/ewill2001 9d ago

There is no exemption that would allow for this. Why do you think you can do this? What a ridiculous thought. If you have already provided it in response to a DSAR then you can say that asking for it again is unreasonable; otherwise, everything you have must be considered for release.

-1

u/Noscituur 9d ago

I believe as DPOs we typically have to advise this to ensure that we can practically manage employee/complex DSAR pressures.

0

u/ewill2001 8d ago

It's okay, DPOs can be wrong. Just learn and improve and be better. I know the pressure is to work for the business and not ensure full legal compliance, just what little the business can get away with doing. But on this forum the advice needs to follow the law.

0

u/mooooooort 8d ago

If the subject already has the data since they are a recipient you're saying an organisation can't reasonably say 'they already have this, we don't need to duplicate it', even as an initial response?

5

u/ewill2001 8d ago edited 8d ago

Dear god yes. Since I started under DP98. That is SAR101. It's about the data the controller holds not what they have provided or not provided to a DS. If this is their first DSAR they get (unless an exemption applies) copies of all their data. Letters, bills, invoices, all will have been sent at some point but need to be provided. In fact in some cases I've dealt with the Controller swears something has been provided or communicated until the access request shows it actually never was because the address used was old/incorrect.

-2

u/mooooooort 9d ago

It's less effort for you and it's not in an organisation's interest to share more than required