r/gdpr 9h ago

UK šŸ‡¬šŸ‡§ ICO DSAR

What is your idea on witholding the information that the data subject already received?

It may be either to cc emails or documents that they have sent or received.

We’re planning to apply it as a DSAR policy and not providing these documents unless the data subject asks again, but wanted to ask your opinion.

We’ll only state this fact in our DSAR response letter.

2 Upvotes

12 comments sorted by

5

u/ProfessorRoryNebula 5h ago

We have a portal where certain documents can be directly accessed by the data subject, so routinely have not included them in SARs.

One data subject complained to the ICO that we hadn't included this information, because they, unbeknownst to us, were having difficulties accessing the portal, and the ICOs position was that we should be including the documents in SARs.

Given this was the first time anyone had complained they hadn't received the documents, I wouldn't think it particularly high risk to not include information we can reasonably assume is currently accessible to the data subject, but I wouldn't apply this to any information they were sent as a one-off like emails or posted documents because we don't know the status of that document, and there's no legal exemption to not include it. Even if you went down the route of justifying it as being excessive, this should be applied on a case-by-case basis and not as a blanket policy.

3

u/ewill2001 2h ago

Exactly this. And ICO guidance is clear that repeated requests or requests made regularly can be declined as manifestly unreasonable. Not just because it makes work for you.

2

u/Noscituur 8h ago

As part of a practical DSAR strategy, I advise that not disclosing materials which the data subject is already privy to is a reasonable measure on the basis that it is surely not within the intention of the law (ergo a ā€˜mischief’) to provide that which the data subject has already seen, especially given recent case law has emphasised that the purpose Article 15 is validate the lawful processing of personal data not to chase litigation ghosts.

To countenance the risk, I always advise that your disclosure pack includes a line to the effect of ā€œIn keeping with Article 15A (that we are only obligated to undertake a ā€˜reasonable and proportionate’ search) we have elected to not include within scope any materials which you have already been privy to. If there’s something you’re specifically seeking of this nature, please let us know and we’ll assist in locating it for you however we would not consider a blanket inclusion of materials you’ve been party to in keeping with our Article 15A obligations.ā€

2

u/pawsarecute 3h ago edited 2h ago

Sure, but the law says otherwise. This is a risk based approach.

0

u/ewill2001 2h ago

The law: provide copies of what personal data you have.

The business: but it's soooooo hard do we have to?

The law: yes unless an exemption applies.

The business: Can't we just make up stuff to make our lives easier that seems reasonable?

The law: No.

0

u/Comfortable-Fall1419 1h ago

You both seem confused. U/noscituur correctly quotes the UK 2025 DUAA and DPA amendments that introduced ā€œReasonable and Proportionateā€

https://www.legislation.gov.uk/ukpga/2025/18/section/78

1

u/ewill2001 56m ago

That relates to searching. Try arguing that searching the email system is not reasonable when you've searched it and decided to withhold a bunch.

The law is there to say you don't need to boot up archived backups to scour for records or do crazy things to ensure every last drop of information is found. You look in all the normal and usual places. You can't avoid that.

1

u/Comfortable-Fall1419 1h ago

It’s unclear what you mean by ā€œrecievedā€. Is it a portal type arrangement as u/Rory mentions or something else like personal or work emails. The trouble with email is it’s effectively transitory for anyone with retention rules or a clean inbox fetish. .

I’d be more questioning whether or not the entire document should be sent at all, and either redacting it or extracting snippets.

1

u/mooooooort 9h ago

It's less effort for you and it's not in an organisation's interest to share more than required

-3

u/ewill2001 8h ago

There is no exemption that would allow for this. Why do you think you can do this? What a ridiculous thought. If you have already provided it in response to a DSAR then you can say that asking for it again is unreasonable; otherwise, everything you have must be considered for release.

2

u/Noscituur 8h ago

I believe as DPOs we typically have to advise this to ensure that we can practically manage employee/complex DSAR pressures.

-2

u/ewill2001 2h ago

It's okay, DPOs can be wrong. Just learn and improve and be better. I know the pressure is to work for the business and not ensure full legal compliance, just what little the business can get away with doing. But on this forum the advice needs to follow the law.