r/gdpr • u/Adventurous-Text-449 • 9h ago
UK š¬š§ ICO DSAR
What is your idea on witholding the information that the data subject already received?
It may be either to cc emails or documents that they have sent or received.
Weāre planning to apply it as a DSAR policy and not providing these documents unless the data subject asks again, but wanted to ask your opinion.
Weāll only state this fact in our DSAR response letter.
2
u/Noscituur 8h ago
As part of a practical DSAR strategy, I advise that not disclosing materials which the data subject is already privy to is a reasonable measure on the basis that it is surely not within the intention of the law (ergo a āmischiefā) to provide that which the data subject has already seen, especially given recent case law has emphasised that the purpose Article 15 is validate the lawful processing of personal data not to chase litigation ghosts.
To countenance the risk, I always advise that your disclosure pack includes a line to the effect of āIn keeping with Article 15A (that we are only obligated to undertake a āreasonable and proportionateā search) we have elected to not include within scope any materials which you have already been privy to. If thereās something youāre specifically seeking of this nature, please let us know and weāll assist in locating it for you however we would not consider a blanket inclusion of materials youāve been party to in keeping with our Article 15A obligations.ā
2
u/pawsarecute 3h ago edited 2h ago
Sure, but the law says otherwise. This is a risk based approach.
0
u/ewill2001 2h ago
The law: provide copies of what personal data you have.
The business: but it's soooooo hard do we have to?
The law: yes unless an exemption applies.
The business: Can't we just make up stuff to make our lives easier that seems reasonable?
The law: No.
0
u/Comfortable-Fall1419 1h ago
You both seem confused. U/noscituur correctly quotes the UK 2025 DUAA and DPA amendments that introduced āReasonable and Proportionateā
1
u/ewill2001 56m ago
That relates to searching. Try arguing that searching the email system is not reasonable when you've searched it and decided to withhold a bunch.
The law is there to say you don't need to boot up archived backups to scour for records or do crazy things to ensure every last drop of information is found. You look in all the normal and usual places. You can't avoid that.
1
u/Comfortable-Fall1419 1h ago
Itās unclear what you mean by ārecievedā. Is it a portal type arrangement as u/Rory mentions or something else like personal or work emails. The trouble with email is itās effectively transitory for anyone with retention rules or a clean inbox fetish. .
Iād be more questioning whether or not the entire document should be sent at all, and either redacting it or extracting snippets.
1
u/mooooooort 9h ago
It's less effort for you and it's not in an organisation's interest to share more than required
-3
u/ewill2001 8h ago
There is no exemption that would allow for this. Why do you think you can do this? What a ridiculous thought. If you have already provided it in response to a DSAR then you can say that asking for it again is unreasonable; otherwise, everything you have must be considered for release.
2
u/Noscituur 8h ago
I believe as DPOs we typically have to advise this to ensure that we can practically manage employee/complex DSAR pressures.
-2
u/ewill2001 2h ago
It's okay, DPOs can be wrong. Just learn and improve and be better. I know the pressure is to work for the business and not ensure full legal compliance, just what little the business can get away with doing. But on this forum the advice needs to follow the law.
5
u/ProfessorRoryNebula 5h ago
We have a portal where certain documents can be directly accessed by the data subject, so routinely have not included them in SARs.
One data subject complained to the ICO that we hadn't included this information, because they, unbeknownst to us, were having difficulties accessing the portal, and the ICOs position was that we should be including the documents in SARs.
Given this was the first time anyone had complained they hadn't received the documents, I wouldn't think it particularly high risk to not include information we can reasonably assume is currently accessible to the data subject, but I wouldn't apply this to any information they were sent as a one-off like emails or posted documents because we don't know the status of that document, and there's no legal exemption to not include it. Even if you went down the route of justifying it as being excessive, this should be applied on a case-by-case basis and not as a blanket policy.