What has happened
You sent a Subject Access Request to a company. They were supposed to provide a copy of your personal data. Instead, you have received a refusal, a heavily redacted response, or a letter explaining why they are not providing what you asked for.
Accessing personal data can be critical for legal disputes, employment grievances, or understanding what an organisation holds about you. Organisations can lawfully withhold some information in certain circumstances. Understanding which exemptions genuinely apply helps you decide what to do next.
Image and Photo Use Rights Checker (UK)
Someone has used your photo (or your child's) on a website, social media or marketing and you are not sure what your rights are. Answer a few questions and we will explain the position and what to do.
Try our Image and Photo Use Rights Checker (UK) free, here on this site →Why companies refuse or redact SAR responses
The UK GDPR and Data Protection Act 2018 give you the right to access your personal data. That right is not absolute. Several exemptions allow organisations to withhold or redact information.
Third party data: If your records contain personal data about other people, the organisation may redact or withhold that information. They must balance your right to access against the other person's privacy. They may release it with the third party's consent, or if reasonable to do so without consent. Often they redact it entirely.
Legal professional privilege: Communications between a company and its lawyers, created for the purpose of giving or receiving legal advice, are usually exempt. If you are in a dispute with the organisation, expect privileged material to be withheld.
Crime and taxation exemption: Organisations can refuse to provide data if doing so would prejudice the prevention or detection of crime, or the assessment or collection of taxes. The organisation must demonstrate a genuine risk of prejudice rather than a theoretical possibility. If the stated reason does not clearly fit your situation, challenge it.
Management forecasting: Data relating to management planning, including business forecasts and negotiations, may be exempt if disclosure would harm the organisation's business. Under the Data Protection Act 2018, this exemption applies only where prejudice to the business would actually result. It does not cover routine management information.
Manifestly unfounded or excessive requests: If your request is clearly without merit or makes unreasonable demands, the organisation can refuse it or charge a reasonable fee. To rely on this exemption, the organisation must provide evidence justifying their assessment. The ICO considers factors including the nature of the request, whether it appears intended to cause disruption, and the burden relative to the organisation's size and resources. A complex request requiring significant effort is not automatically excessive.
Your situation may be slightly different. ask a question below ↓ and our editorial team will reply with our advice.
Timelines and extensions
Organisations must respond to your SAR within one calendar month. If your request is complex or they receive multiple requests from you, they can extend this by a further two months. They must notify you of the extension within that first month and explain why it is necessary.
An extension requires a genuine reason relating to complexity. Administrative difficulty alone does not qualify. If the organisation misses deadlines without explanation or extends without proper justification, this constitutes a compliance failure you can raise with the ICO.
Check your original request date and all responses. Verify whether the organisation explained any extension within the first month and whether their reasoning addresses genuine complexity.
What you can do now
Send a formal written complaint to the organisation's Data Protection Officer or privacy team. Explain specifically why you believe the refusal or redactions are unjustified, citing the relevant exemption they relied upon. Request a formal review of the decision. Maintain a detailed log of all communications, including dates, recipients, and content.
If the internal complaint does not resolve the matter, complain to the Information Commissioner's Office. The ICO investigates whether the organisation has complied with data protection law. They may find a breach but cannot order the release of specific documents. Submit your complaint through the ICO website at ico.org.uk/make-a-complaint. If you receive no response from the ICO within eight weeks, follow up in writing.
Before pursuing court action, consider whether alternative dispute resolution might help. Some industry sectors have ombudsman schemes or mediation services that handle data protection disputes. Seek legal advice if the organisation continues to refuse compliance despite ICO involvement.
For cases involving genuine harm, you may claim compensation through the small claims court. This requires demonstrating actual damage: financial loss, or distress beyond ordinary frustration. Information on the small claims process is available at gov.uk/make-court-claim-for-money. You will need documented proof of the breach and the resulting harm.
- Retain all correspondence, including the original request and every response
- Record all dates to verify whether statutory deadlines were met
- Review ICO guidance on SAR exemptions at ico.org.uk/for-the-public
- Assess whether the exemption cited by the organisation genuinely applies to your data
- Use formal written communication throughout to create a clear evidence trail
Ask Your Privacy a question
Ask our editorial team a question and we will reply with our advice. Tell us as much about your situation as you can: the more detail you give, the more useful our answer can be.
You do not need to use your real name. Please do not include your full address, phone number, email address, or the names of other people. We may edit or remove identifying details for privacy and legal reasons.
Comments are moderated before publication.