Independent, non-profit website. This site is not affiliated with, endorsed by, or connected to Fox & Sons, Sequence (UK) Limited or Connells Group. It carries no advertising, sells nothing, and makes no profit — it exists solely as a free public-interest consumer resource. Nothing here is legal advice.
New to Subject Access Requests? Start with The DSAR: Your Most Powerful Tool, then come back here when the response lands.
You sent your DSAR. Now the organisation is asking for more time, demanding ID it already has, redacting whole pages, or refusing outright. Some reasons are legitimate. Many are vague excuses that deserve to be challenged — and the difference decides whether you get the internal records that matter or a folder of emails you already had.
The golden rule: the organisation must assess your request individually. It cannot extend deadlines or apply exemptions automatically just because responding is inconvenient. Every excuse below comes with the exact wording to fire back.
“Your request is complex”
They say: “Due to the complexity and volume of your request, we require an additional two months to respond.”
The one-month deadline can be extended by up to two further months — but only where the request is genuinely complex or the individual has made multiple rights requests. Genuine complexity means things like archived systems that are technically difficult to search, large amounts of particularly sensitive data needing careful review, or real legal and confidentiality questions requiring specialist advice.
A request is not automatically complex because it involves a lot of information. And they must notify you of the extension, with reasons, within the original month — an extension announced after the deadline has already passed is a warning sign in itself.
You reply: “Please explain which specific aspects of my request you consider complex, what work remains outstanding, and why that work could not reasonably be completed within the original statutory period.”
“We hold a large amount of information about you”
They say: “We hold a significant volume of information and require you to narrow the scope of your request.”
They can ask you to clarify what you want. You do not have to reduce your request — you remain entitled to everything they hold about you. But do reply promptly, because the response clock can pause while they wait for your answer. Note: the clock only pauses for clarification about the information requested, not side questions like your preferred delivery format — and they should ask promptly, not on the eve of the deadline.
You reply: “I confirm that I require the full scope of personal data described in my original request. To assist your searches, the principal date range is [date] to [date], and the matter concerns [account, property or complaint]. This clarification does not reduce or withdraw any part of my original request.”
“We need proof of your identity”
They say: “We cannot begin processing your request until you provide photographic identification and proof of address.”
ID checks are legitimate where there’s reasonable doubt about who’s asking — but they must be proportionate. A company that already knows you through an established account, a verified email address, or months of ongoing correspondence should not suddenly demand a passport. The clock generally starts once they receive what they reasonably require — so late, excessive ID demands are a classic stalling tactic.
You reply: “Please explain why the identification already held on my account, together with my correspondence from the registered email address, is insufficient and why each additional document requested is necessary.”
Tip: if you do send ID, redact anything they don’t reasonably need, as long as what remains is enough to verify you.
“The information contains other people’s personal data”
They say: “This correspondence cannot be disclosed because it contains third-party personal data.”
Third-party rights are real — but they rarely justify withholding an entire document. In most cases the company can redact the other person’s identifying details and still disclose the parts about you. The objective should be disclosure of your data with targeted redactions, not blanket suppression.
You reply: “I accept that genuinely identifying information relating exclusively to third parties may require redaction. However, please disclose my personal data and the substance of all correspondence about me, using targeted redactions where necessary rather than withholding entire documents.”
“The material is legally privileged”
They say: “Certain documents have been withheld because they are subject to legal professional privilege.”
Sometimes true — privilege covers confidential communications with a legal adviser for the purpose of legal advice, and certain documents created for litigation. But privilege does not automatically cover everything the legal department touched: not every email copied to a solicitor, not ordinary business correspondence involving a lawyer, not documents merely labelled “confidential,” and not pre-existing documents just because they were later sent to a lawyer.
You reply: “Please confirm the general category of each item withheld, the date of the item, and whether you rely upon legal advice privilege or litigation privilege. I am not requesting disclosure of the privileged legal advice itself, but I ask that all reasonably separable non-privileged personal data be provided.”
“The information is not your personal data”
They say: “The documents identified by our searches do not constitute your personal data.”
Your name appearing in a document doesn’t automatically make the whole document your personal data — a mass email with you in the recipient list says nothing about you. But an internal email discussing your conduct, complaint, account, credibility, property or treatment almost certainly contains your personal data — even though it was never sent to you. Those internal emails are usually exactly what you’re after.
You reply: “Please confirm whether the material was reviewed to determine whether it discusses, evaluates, identifies or records information about me, rather than considering only whether my name appears within it.”
“You’re entitled to your data, not complete documents”
Broadly correct — a DSAR gives you a right to your personal data, not to every original document. Extracts, redacted copies, transcripts and structured summaries can be acceptable, provided the personal data itself is included and remains understandable. Stripping out so much context that the data becomes meaningless is not an adequate response.
“Disclosure would prejudice negotiations”
They say: “The information records our position in negotiations with you and has therefore been withheld.”
There is a narrow exemption for records of an organisation’s intentions in negotiations with you — for example, an insurer’s internal note of its maximum settlement figure. It does not permit withholding every record connected to a dispute.
You reply: “Please identify which information records your intentions in negotiations and explain, in general terms, how disclosure would be likely to prejudice those negotiations. Please disclose all other personal data that can reasonably be separated from that information.”
“The information concerns management planning”
Another narrow exemption: genuine forward-looking management forecasting or planning (confidential redundancy plans, for instance) where disclosure would be likely to prejudice the business. It is far less likely to apply just because managers discussed a particular customer or complaint. They should show real planning activity and identifiable prejudice.
“Disclosure could prejudice an investigation”
Legitimate in the right circumstances — revealing investigative methods or witness information in an active fraud investigation, say. But the mere existence of a complaint, allegation or investigation does not exempt every record connected with it. Separable information should still be disclosed.
“The request is manifestly unfounded or excessive”
They say: “We consider your request to be manifestly unfounded or excessive and will not be responding.”
This is a serious position and the threshold is high — for example, a requester who offers to withdraw for money, or a request that’s clearly malicious. A request is not unfounded or excessive merely because it’s connected to a complaint, might assist litigation, follows an earlier DSAR, is inconvenient and time-consuming, or because the requester used angry language or is considered “difficult.” They must assess individually, keep evidence of the decision, and be able to justify it to the ICO.
You reply: “Please provide the evidence and specific factors relied upon in concluding that my request is manifestly unfounded or excessive. Please also confirm whether you have considered responding partially, narrowing any allegedly excessive element, or charging a reasonable administrative fee rather than refusing the request entirely.”
“The information has been deleted”
They say: “We no longer hold the information because it was deleted in accordance with our retention policy.”
Organisations aren’t expected to keep data forever, and they can’t be made to recreate what’s genuinely gone. But ask: what type of information was deleted, when, under which retention period, and — crucially — before or after your DSAR was made. Which live, archived and backup systems were searched? Do copies survive in individual mailboxes?
Know this one cold: deliberately altering, erasing, destroying, blocking or concealing information to prevent its disclosure after a DSAR has been made can be a criminal offence under section 173 of the Data Protection Act 2018. Routine deletion that would have happened anyway is different — which is exactly why the timing questions matter.
“We only searched the central complaint system”
They say: “We have provided all information identified on our central system.”
Not good enough if your request covered more. Individual employee mailboxes, branch inboxes, area and regional management, compliance departments, telephone systems, archived accounts, messaging platforms, paper files, external complaint-handlers — reasonable searches should cover the places your data actually lives. In our own case study, it was the absence of any call records in the DSAR response that dismantled an account which relied on a phone call.
You reply: “Please confirm which systems, departments, employee accounts, shared mailboxes, search terms and date ranges were searched. Please also confirm whether archived records, call-recording systems, paper files and records held by processors acting on your behalf were considered.”
Warning signs in a DSAR response
Push back with further questions where the company:
- Uses the word “complex” without identifying any complexity
- Extends the deadline after the original month has already expired
- Asks for clarification, or demands ID it already possesses, at the last moment
- Redacts entire pages rather than individual names or passages
- Labels everything touched by its legal department as privileged
- Claims internal emails aren’t your personal data because they weren’t sent to you
- Provides only correspondence you already received
- Searches only the branch involved while ignoring head office and regional management
- Gives no explanation of which systems and mailboxes were searched
- Says records were deleted without saying when, or under which retention policy
- Refuses the whole request where only a small part could be exempt
- Fails to tell you how to challenge the decision (internally, to the ICO, or in court)
Exemptions should be applied to particular information — never as a blanket reason to conceal a whole record or dodge the request entirely. A refusal must normally be explained, with your challenge routes set out.
Copy-and-paste challenge to an incomplete DSAR response
Dear Data Protection Officer,
Thank you for your response to my Subject Access Request.
The disclosure appears to be incomplete and/or contains information that has been withheld without sufficient explanation.
Please confirm:
1. The systems, databases, individual email accounts, shared mailboxes and departments searched.
2. The search terms and date ranges used.
3. Whether branch, area, regional, compliance, legal and head-office records were searched.
4. Whether call recordings, call logs, archived records, paper files and records held by processors were considered.
5. The legal basis for each category of withheld or redacted information.
6. Whether targeted redaction was considered instead of withholding complete documents.
7. The date and applicable retention policy for any information said to have been deleted.
8. Whether any information was withheld on the basis of legal professional privilege, third-party data, negotiations, management planning or another statutory exemption.Where an exemption is relied upon, please explain how it applies to the particular information withheld and provide all reasonably separable personal data that is not covered by that exemption.
Please also treat this correspondence as a request for an internal review of the completeness and lawfulness of your response.
Yours faithfully,
[Name]
If they still won’t budge
Send the challenge letter, give them a reasonable window (14 days is fair for a review of their own response), and if the answer is still silence or stonewalling, escalate — that’s what the regulator is for. Our guide to complaining to the ICO covers exactly when and how, and the Templates Library has the rest of your paper trail ready to copy.
Leave a Reply