Challenge a weak SAR response like an audit: identify each failure, attach the evidence, ask for the specific correction, and keep separate issues separate.
A response can be defective for many reasons: missing data, unreasonable search limits, unexplained redactions, incorrect exemptions, failure to provide supplementary Article 15 information, format/accessibility problems, deadline errors or inadequate complaint handling. The strongest challenge does not accuse the controller of “hiding everything”; it shows exactly which obligation or evidential gap remains unresolved.
Key points
- Start with a response audit: what was requested, what was supplied, what was withheld and what explanation was given.
- Use the Missing SAR Data guide for the forensic search analysis; this page focuses on turning those findings into a formal challenge.
- A controller must make a reasonable and proportionate search, but it should be able to justify exclusions said to be unreasonable or disproportionate.
- Redactions, exemptions and third-party data require their own analysis; they are not automatically proof that the search failed.
- Since June 2026 organisations must operate a data-protection complaints process, acknowledge complaints within 30 days, investigate and communicate the outcome.
- If the controller does not resolve the complaint, the ICO can consider compliance with data-protection law; it is not a substitute forum for deciding every underlying employment, debt or contractual dispute.
First: audit the response into separate issues
| Issue | What to record |
|---|---|
| Missing records | Specific item/category, evidence it exists, likely source. |
| Search limitation | Which system/date/custodian was apparently omitted and why it matters. |
| Redaction | Document/page, what was obscured and any exemption/third-party explanation. |
| Exemption | Exemption named, information category affected and reasoning given. |
| Supplementary information missing | Purposes, categories, recipients, retention, source and other Article 15 information where applicable. |
| Format/accessibility | Unreadable export, broken files, inaccessible portal, unexplained codes. |
| Deadline/extension | Request date, ID/clarification pauses, extension notice and final response date. |
| Complaint handling | Acknowledgement date, investigation, response and outstanding questions. |
Do not combine every disagreement into “the SAR is incomplete”
Suppose a bundle omits an email, redacts a colleague’s name, refuses privileged legal advice and contains an inaccurate account note. Those are four different issues: search gap, third-party/redaction decision, exemption and data accuracy. A single allegation of “incomplete disclosure” makes it easier for the controller to answer only one part.
Number the grounds and ask for a remedy under each. This also makes later ICO escalation much clearer.
Ground 1: unreasonable or incomplete search
Where the evidence points to missing sources, identify them and explain why a reasonable and proportionate search should have covered them. Refer to known custodians, systems, date ranges and identifiers. Ask whether the source was searched; if not, whether the controller says the search would be unreasonable/disproportionate, the data is not held, or another reason applies.
Do not demand a perfect search. Demand a defensible one.
Ground 2: unexplained gaps and contradictions
Contradictions are often more persuasive than volume. A disclosed note that says “reviewed call recording” conflicts with a response saying no recordings were held. An email quoting an earlier message conflicts with a claim that no internal correspondence exists. A retention schedule saying 12 months conflicts with deletion after three.
Put each contradiction in a table with the two pieces of evidence and the question it creates. Ask the controller to reconcile them.
Ground 3: redactions and third-party information
The right of access is to your personal information. A controller may need to protect another person’s personal data and can sometimes disclose an extract or redact identifiers rather than withhold an entire record. The assessment is contextual.
Challenge over-redaction by explaining why the obscured information appears to be your personal data or why less restrictive redaction could protect third parties. Avoid demanding disclosure of someone else’s private information simply because it appears in your complaint file.
Ground 4: exemptions
A controller relying on an exemption should identify the relevant basis sufficiently for the requester to understand why information has been withheld, subject to limits where explaining more would defeat the protection. Common disputes involve legal professional privilege, management information, negotiations or other statutory restrictions.
Ask which exemption applies to which category and whether it was applied to the whole document or only the protected information. Do not argue that “GDPR overrides privilege”; it does not.
Ground 5: supplementary Article 15 information
A SAR response is not only a dump of documents. The right of access also includes supplementary information about processing, broadly covering matters such as purposes, categories of personal data, recipients/categories, retention, rights, complaint routes, source of data where not obtained from you, and relevant automated-decision information where applicable.
Some of this may be supplied through a privacy notice or covering letter. If it is missing or generic, identify the specific supplementary information that has not been answered.
Ground 6: format, intelligibility and accessibility
Information must be provided in a clear and accessible form. A folder of corrupt files, screenshots too small to read, exports full of unexplained codes, or a portal that you cannot access can undermine meaningful access even if data was technically “sent”.
Ask for replacement files, code legends or an accessible commonly used electronic format as appropriate. Keep screenshots of download errors and corrupted archives.
Ground 7: scope and clarification
The controller can ask for clarification in appropriate circumstances and current law permits the response clock to pause in defined cases, but it cannot force you to abandon a broad request merely because it would prefer a narrower one. If you refuse to narrow, it still needs to carry out a reasonable and proportionate search.
If clarification was requested late or used repeatedly, set out the dates and explain why the controller already had enough identifiers/context to search obvious systems.
Ground 8: deadline and extension handling
The ordinary SAR deadline is one month, with a possible extension of up to two further months where necessary because of complexity or number of requests. ID and reasonable clarification can affect when the clock runs under the current framework. Build the date calculation rather than saying only “they were late”.
Record request receipt, any ID request, ID response, clarification request/response, extension notice and disclosure date. Then identify which event you dispute and why.
Separate access from accuracy, erasure and restriction
A SAR gives you a copy of personal data; it does not automatically correct it. If the disclosure contains an inaccurate date, address, account note or credit marker, make a rectification request as a separate right. If you want processing restricted while accuracy is checked, consider the restriction route.
This separation matters because the controller may have complied perfectly with access by disclosing an inaccurate record. The next issue is what it does with that inaccurate data.
Separate data protection from the underlying dispute
Internal notes may reveal that a bank, employer, telecom provider or council made a decision you think is wrong. The ICO can consider data-protection compliance, but it does not usually decide the underlying contractual debt, employment grievance or merits of an ombudsman dispute.
Use the SAR evidence in the correct substantive forum while keeping the data-protection complaint focused on access, accuracy, lawful processing and related rights.
The new statutory data-protection complaints process
From June 2026, organisations handling personal data have legal duties around data-protection complaints. ICO guidance says organisations must provide a clear way to complain, acknowledge a complaint within 30 days, investigate appropriately and communicate the outcome.
That creates a useful formal stage after an inadequate SAR response. Label the correspondence as a data-protection complaint, identify the SAR reference and list the unresolved grounds. Ask for a substantive response to each rather than another generic “we consider the SAR complete” statement.
Build a failure-to-answer schedule
If the controller responds selectively, create a schedule showing each numbered question, its answer, and whether the answer actually resolves it. This is especially useful where you asked “Was Teams searched?” and received only “we conducted appropriate searches”.
| Question | Response | Assessment | Next action |
|---|---|---|---|
| Was the named Teams custodian searched? | “We searched relevant systems.” | Does not identify whether Teams/custodian was included. | Repeat targeted question in complaint/ICO evidence. |
| Why is email X absent? | No response | Unanswered | Attach your copy and request supplementary search. |
| Which exemption supports redaction on page 14? | “Third-party data.” | Partial answer | Ask whether balancing/consent/partial disclosure was considered as applicable. |
Ask for remedies, not just admissions
- A targeted supplementary search of specified systems/custodians.
- Disclosure of newly located personal data.
- A revised/redacted copy where an exemption was applied too broadly.
- Identification of the exemption or reason for withholding a category.
- Missing supplementary Article 15 information.
- Replacement readable/accessibly formatted files.
- Correction of a procedural record, such as inaccurate request dates.
- A reasoned data-protection complaint outcome addressing each numbered ground.
Useful wording for a structured challenge
Opening: “I am not asking you to repeat that the SAR is complete. I have identified the following specific access issues and ask you to address each one separately.”
Search gap: “The disclosure contains [evidence] indicating that [system/record] existed. Please confirm whether [repository/custodian/date range] was searched and, if not, the basis on which that search was excluded.”
Complaint: “Please treat this as a data-protection complaint concerning the handling of my Article 15 request. I ask for a reasoned response to Grounds 1–6 and the remedial action under each.”
The 2026 complaints duty changes the procedural route
Since 19 June 2026, organisations handling personal data must have a process for data-protection complaints. ICO guidance says they must provide a way to complain, acknowledge a data-protection complaint within 30 days, take appropriate steps to investigate, keep the complainant informed and provide an outcome without unnecessary or unjustifiable delay.
That complaint is separate from the original SAR deadline. A controller does not gain another month to answer the SAR simply because you complained about it. Keep two timelines: the Article 15 request and its statutory response period, then the later complaint and its acknowledgement/investigation obligations.
Build grounds that can be answered yes or no
Vague complaints produce vague outcomes. Instead of “the disclosure is incomplete”, create numbered grounds tied to evidence and remedy. Each ground should identify what happened, why it appears inconsistent with the right of access, the evidence supporting it and what correction you want.
| Ground | Evidence | Requested action |
|---|---|---|
| Known email omitted | Later document quotes email dated 4 March | Search named mailbox/date range and disclose responsive personal data. |
| Exemption unexplained | Pages removed with generic “third party” label | Identify the exemption/restriction relied upon and reconsider partial disclosure. |
| Call recording absent | Complaint log confirms call was recorded | Confirm retention/deletion date and search recording/transcript systems. |
| Article 15 information missing | Response contains data only | Provide the required supplementary information that was omitted. |
Challenge the evidence, not the word “complete”
An organisation saying “we confirm the SAR was complete” is a conclusion, not an explanation. Your response should identify the factual contradiction: an email chain jumps from message 2 to message 5; an account note refers to a recording; a disclosed manager email quotes an omitted Teams message.
Ask how the conclusion accounts for that evidence. This keeps the exchange testable and makes any later ICO complaint much easier to follow.
Article 15 includes supplementary information as well as copies
A compliant response is not only a document dump. The right of access also includes information about matters such as purposes of processing, categories of personal data, recipients or categories of recipient, retention information, rights and certain information about source and automated decision-making where applicable.
If those elements are absent, identify which supplementary information is missing. Do not ask the controller to repeat information already clearly supplied in a privacy notice or response merely to make the complaint longer; target genuine omissions or ambiguity.
Redactions: ask what legal issue they protect
Redaction can be lawful where disclosure would adversely affect another person's rights or an exemption applies. But a black box with no intelligible explanation can make it impossible to understand the response. Ask whether material was removed because it was not your personal data, because third-party rights were balanced, or because a specific exemption/restriction was applied.
The controller may not be able to reveal exempt information merely to prove why it is exempt. The practical aim is a reasoned explanation and, where possible, disclosure of the remainder rather than demanding that every redaction be removed regardless of third-party rights.
Clarification disputes, was narrowing genuinely required?
The current right-of-access framework allows the controller to seek clarification where reasonably required, with the statutory clock pausing under the applicable rules. It cannot force you to narrow a request simply because it would prefer a smaller search.
If clarification caused delay, preserve the exact question and your answer. Ask why clarification was reasonably required and whether searches that did not depend on the clarification continued. If you repeated the original scope, the organisation still needs to make a reasonable and proportionate search rather than treating non-narrowing as withdrawal.
Separate a missed deadline from an incomplete search
A response can be late but substantively complete, or timely but incomplete. Plead those as separate grounds. This matters because the evidence and remedy differ: a timing breach is shown by receipt, pause/extension events and response date; an incomplete-search challenge is shown by omitted data and search evidence.
If the organisation extended the deadline, ask what complexity or number of requests made the extension necessary and whether it notified you within the original period. Do not assume every large SAR automatically permits an extension.
When the underlying dispute is not for the ICO to decide
A SAR may reveal evidence about a billing dispute, employment grievance, credit default or consumer complaint. The ICO can consider data-protection compliance; it will not normally decide the merits of the separate contract, employment or ombudsman dispute for you.
Use the SAR evidence in the correct forum. For example, challenge inaccurate personal data through rectification/data-protection routes, but challenge whether a telecom charge was contractually due through the provider and sector ADR. Keeping jurisdiction clear makes both complaints stronger.
What outcome should you ask the organisation for?
Ask for concrete remedial steps: supplementary searches of named systems, disclosure of newly located personal data, reconsideration of specified redactions, a reasoned exemption explanation, missing Article 15 information, correction of the response format, or confirmation that particular data is no longer held and why.
An apology can be appropriate where handling was poor, but “please apologise” is not enough if the access problem remains. The primary aim is to obtain a legally adequate response and an auditable explanation of what was corrected.
What makes an ICO escalation easy to assess
Give the ICO a short chronology, numbered grounds and a document map. For each ground, identify the original request, what the controller supplied, the evidence showing the problem, the complaint you raised and the final response. This is much more useful than attaching a 500-page disclosure and asking the ICO to discover the omissions itself.
Explain the unresolved compliance issue rather than asking the ICO to re-run the underlying consumer or employment dispute. If new evidence emerges after the complaint, add it as a short supplement and explain exactly which ground it changes.
Do not overclaim deliberate concealment
Missing data can result from poor indexing, narrow search terms, retention, human error, system migration or a lawful exemption. Evidence of intentional deletion or concealment is a serious allegation and should not be inferred merely because something is absent.
Where chronology genuinely suggests post-request deletion, state the dates and ask for an explanation. A measured challenge built on verifiable facts is usually stronger than attributing motive before the search history is known.
Supplementary disclosure does not erase the handling issue
An organisation may respond to your challenge by sending another batch of data. That can be the correct remedy and should be welcomed, but it does not necessarily answer why the first response was incomplete or whether the search problem affected other material. Index the supplementary disclosure separately and identify which grounds it resolves.
If the new batch contains records that should plainly have been found first time, ask whether the controller has repeated or widened the search and whether the same flaw could have excluded other records. Avoid continuing grounds that have genuinely been fixed; narrow the complaint to what remains unresolved.
Do not make a fresh SAR every time the controller misses something
A targeted supplementary search or complaint about the existing response is often more efficient than repeatedly submitting new broad SARs. A new SAR can create a new scope and deadline while leaving the defect in the first response unexplained.
Use a fresh request where you genuinely want a new time period or new category of personal data. Use the complaint/challenge route where the issue is that the controller failed to comply properly with the request it already received.
Keep a resolution schedule
As the organisation replies, mark each numbered ground as resolved, partly resolved or outstanding. Record the response date, what new data or explanation was supplied, and the remaining issue. This prevents a long correspondence chain from obscuring the fact that three questions have been answered and two have not.
The same schedule can become the index for an ICO complaint. It demonstrates that you gave the controller a fair opportunity to put matters right and shows the regulator exactly what still needs attention.
What to do
A practical SAR-challenge sequence
- Index the request, response and disclosure so every point can be cited precisely.
- Split the challenge into search, redaction/exemption, supplementary-information, format and timing grounds.
- Use a missing-data schedule for concrete search gaps and attach only the evidence needed to prove them.
- Ask targeted questions and a defined remedial action under each ground.
- Where the issue is accuracy, erasure, restriction or another right, raise it separately instead of hiding it inside the SAR complaint.
- If the first challenge fails, invoke the organisation’s statutory data-protection complaints process.
- Track unanswered questions in a failure-to-answer schedule.
- Escalate to the ICO with the original SAR, response, schedules and complaint outcome, explaining the unresolved legal/compliance issues concisely.
What to send the ICO
Give the ICO a usable record: original SAR, proof of receipt, controller response, the relevant extracts of disclosure, your missing-data/failure-to-answer schedules, your data-protection complaint and the organisation’s outcome. Explain what you want the ICO to examine.
Avoid uploading hundreds of pages without a map. A short chronology and numbered grounds let the regulator see the compliance question quickly.
Evidence worth keeping
Official sources
Check the rules behind this guide
- ICO: A guide to subject access
- ICO: Detailed right-of-access guidance
- ICO: Make a data-protection complaint to an organisation
- ICO: How organisations must deal with data-protection complaints
These are official or primary sources for this topic. Rules, scheme terms and deadlines can change, so check the live source before relying on a formal time limit or procedure.