When to refuse a subject access request?
The Problem: individuals are entitled to access personal information about themselves under the GDPR. However the right is not absolute and a number of exemptions apply. There are also additional requirements on organisations regarding certain supplementary information that are hard to comply with.
The Solution: develop a general understanding of what is and is not covered by the right of access. Understand when, how and and what exemptions apply.

Contents
-
Data Protection Law
-
What are People Entitled To?
-
Are there exemptions?
-
When can you refuse a subject access request?
Specific or Absolute Exemptions
-
Data about other people
-
Requests about other people
-
What does Unfounded, Unreasonable or Excessive look like?
-
If people object to our refusal
-
What if we hold a lot of data about people?
-
If people think we’ve misused their data?
Data Protection Law
Subject Access Requests (SARs) have been with us since the Data Protection Act 1998. It gave individuals – often referred to in this context as data subjects – the right to see data held about them, and to receive it within 40 days. For a small fee.
In 2018 a new Data Protection Act brought the GDPR into UK law. The GDPR introduced, among other things, a Right of Access, which replaces the old SAR. Because it is similar in many ways. People in the UK still refer to the Right of Access as a Subject Access Request or SAR. That is what we will do here too.
Ultimately the GDPR imagines a world where people will be able to see their data on the systems of the data controller. We already see this in some areas. For example:
-
many people can look at their medical records online
-
a lot of employers maintain an electronic staff record. This allows people can see their own information and update it directly.
Key Changes under the GDPR
-
you may no longer charge a fee or complying with SARs in most instances
-
the timescale for a response to a subject access request is one calendar month in most circumstances.
-
people can make their request verbally – it no longer has to be in writing. People should not be required to send you a letter or complete a form
-
what people are entitled to is broader than simply having a copy of their information
You can, however, seek evidence of an individual’s identity before processing their request
Organisations must engage with individuals when they make a SAR whether they comply with it or refuse it. You cannot ignore a SAR when a data subject makes one. Also the GDPR applies to every organisation that processes information about a data subject for its own purposes or on behalf of other companies.
Related Content: People’s Rights Under GDPR
What are people entitled to under a The Right of Access?
People are entitled to know not only what information you have about them. They also are allowed supporting information about your data processing including:
-
confirmation of whether any personal data are being processed
-
given a description of the personal data, the reasons they are being processed, and whether they have been or will be shared more widely
-
given a copy of the information comprising the data; and given details of the source of the data (where this is available).
People should also be told of any cross-border data flows.
Are there exemptions?
There are a exemptions to this right. A good example is that employment references, both given and received, are usually exempt from disclosure.
However, an exemption to disclosing the data does not mean that you cannot provide the supplementary information listed above. For example if you do have employment references for a person making a subject access request then you may not disclose them. However, you must still confirm you have them, and so on.
There are a few instances where you can both refuse to disclose information and conceal that you have the information at all. These usually apply in circumstances where there is a material risk of harm to the data subject or any other person.
In this way the Right of Access is more complex than what went before.
When can you refuse a subject access request?
At its simplest you can refuse a SAR when it is manifestly unfounded, unreasonable or excessive. You can also refuse requests because they are repetitive. You may also refuse to comply you are unable to reasonably verify the identify the person making the request.
Where you refuse to respond to a request, you must explain why to the individual. You must inform them that they can complain to the Information Commissioner if they are dissatisfied with your response
Alternatively, you can sometimes charge the administrative costs for complying with the request.
There are a number of other grounds for refusing a SAR and we will look at these next.
Specific or Absolute Exemptions
Schedule 2 of the Data Protection Act 2018 sets out a number of specific exemptions to giving an individual copies of their data. These, briefly, include:
-
self incrimination
-
certain functions relating to corporate finance
-
some instances related to management forecasts or management planning
-
personal data that would prejudice negotiations with the data subject
-
confidential references
-
exam scripts and marks
If you do decide not to disclose information to data subjects based on these exemptions it is good practice to keep a record of how they apply.
Data About Other People
One important area that we have seen frequently is that people are not entitled to the data of people than the data subject. This means you can refuse a request absolutely if a person makes a request about their spouse, their child, or their parents unless it is clear they have the relevant permission.
Another important thing to consider is you must not release information as part of a SAR if it contains identifiable information about other people unless:
-
you have their consent, or
-
it is reasonable to disclose the information anyway.
Reasonable means if the person would know the information anyway, such as an email to or from the requestor from another person, or the minutes of a meeting that the requestor attended.
You should be cautious about the scope of identifiable information. Sometimes the identity of a person can be inferred from the content or context of a document so it is not limited to explicit identifiers such as name or email address. That is why all narrative documents that fall within the scope of a request need to be carefully reviewed before disclosure.
When you do find identifiable personal data in a document you should try to redact it first. If it is not possible to do that because the context of the document means it cannot be properly redacted you can refuse to disclose it – but remember you will still need to include the existence of the document and other information as part of the wider response information noted above.
Sign Up Here:
In general people cannot make requests for data about other individuals. Husbands cannot ask for the data of their wives or vice versa, for example. You can refuse a request from someone for copies of the data of another individual unless they can provide evidence that individual has given them consent to do so on their behalf. A third party (whether an individual or an organisation like the police) cannot rely on individual’s GDPR rights to see their personal data and need to find another lawful basis. It is in fact a criminal offence to require someone to make a SAR for you. This also means a parent or guardian generally cannot make requests on behalf of their child. However, the situation with children is more complex. When dealing with children’s data sharing personal information will depend on an assessment of the child’s competence. Companies or other organisations that deal with children’s data should have a policy and detailed guidance on how to comply with children’s information rights. In general the options you have when a parent makes a request for personal information about their child are: Refuse the request because the child is competent to exercise their own data rights Consult the child about how their want they personal information shared with their parent or guardian Provide the child with a copy of their personal information and invite them to decide if they want to share it Refuse the request It depends. Generally you should respond to repeated requests if data are updated frequently or they contain special or sensitive classes of data. If it would not put you to too much inconvenience or cost then it would probably be good practice to give people their data whenever they request it. However, the volume of the data and the costs of compliance are legitimate factors to consider. As are the limits on the resources you can bring to bear to deal with requests. We strongly advise that you do not refuse requests because, for example, you are in a legal dispute with the requestor. Being in dispute does not make a request unreasonable or excessive. However, if you feel someone is making a request deliberately to cause you inconvenience then it is legitimate to refuse to comply. In essence, the identity of the requestor shouldn’t matter their behaviour should. However in our experience the Information Commissioner will place a very high threshold on denying people their data rights. We have seen instances where several people have made identically worded requests simultaneously and the receiving organisation felt it was the subject of a campaign to cause inconvenience and expense. However the Information Commissioner concluded, after the organisation had refused the requests, that the requests were legitimate. In the first instance if you refuse to comply with a SAR – or you do not fully comply e.g. by responding outside the relevant time limit – and the requestor complains to the Information Commissioner’s Office (ICO) then the ICO will not weigh up the arguments for and against disclosure, but will primarily focus on the process you followed and the explanation you gave the requestor, plus any history you may have of previous complaints. If your process and explanation is reasonable then it is unlikely you will be found in breach of GDPR. If you are, then under these circumstances you will simply be required to provide the requested information. Nearly half of all complaints to the ICO relate to SARs. Typically however they relate to delays in responses, or because the wrong information is disclosed. It is important that you take time to ensure you are not disclosing the information of another person or any other information you should keep confidential (perhaps information received from a third party on condition of confidentiality). This kind of breach is more likely to result in enforcement action, and a significant fine, than a reasoned, auditable decision not to disclose. The volume of information that you hold should not be a barrier to disclosure. If you are complying with the data privacy principles then you should only have the information you need to deliver your functions and no more. As such complying with individual rights should never present a terrible burden. Essentially if you find it difficult to find and collate data about a person the Information Commissioner may well ask: why? In reality we know that there is a lot of information about people held within a company’s systems and archives. In our experience this is often the case with member of staff. Particular risks include the volume of emails people retain, and a failure to delete older data in a timely manner. The best thing you can do is ensure data are deleted when no longer needed so that you don’t find yourself confronted with large volumes of data to review before you disclose it. We sometimes see that people make requests for their data because they think it may have been misused or they have been the victim of a data breach. There is nothing wrong with an individual asking for their information in these circumstances. However a SAR is not necessarily the best way of resolving these concerns. It may be helpful to engage with the requestor and investigate the problem they think has happened. If they still want their data then you should comply, but there may be a more suitable way forward for the requestor. Because the circumstances under which you can refuse a subject access request are limited we recommend you consider the following: Your organisation is expected to respond to SARs without undue delay and in any event within the one month time limit in most circumstances. You risk enforcement action if in the ICO’s view you have taken unreasonably long to respond to a subject access request even if you do within statutory limits. Make sure you have processes and guidance in place to recognise and act on requests. Don’t forget the supplementary information that that should also be disclosed. Keep track of requests, and if possible appoint one person to receive them, co-ordinate data collection, and send responses. This person will develop an eye for what is unreasonable, or excessive, and recognise repeat requests quickly. If you do get repeated requests, you should consider disclosing only information that has changed since the previous request. Be upfront about the threshold you apply when deciding not to respond to a subject access request or to charge a fee for doing so. It will help people avoid sending requests you will not reply to. There is no reason to suppose someone won’t accept your professional view of what is reasonable in the context you work in. If you put this guidance on your website you can make it public and available before data subjects contact your organisation. This will also help you demonstrate how you are meeting legal requirements, and comply with your duty of accountability. It will also be a useful exercise for companies that process large volumes of personal data, to which subject access requests can impose a considerable burden. If you do refuse a subject access request because it is unreasonable or excessive the burden is on you to demonstrate that is the case. Therefore, have a decision making and sign off mechanism that records your reasoning in each case. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.Requests About Other People
Subject Access Requests for a Child’s Data
What does unfounded, unreasonable or excessive look like?
What if people object to your refusal?
What if we hold a lot of information about people?
What do we do if people think we’ve misused their data?
Top tips
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: