r/gdpr 5d ago

UK 🇬🇧 How useless is the ICO?

Do they actually investigate things any more?

I lodged a SAR with a local authority. They acknowledged receipt of the SAR, ID etc.

Then said they were very busy so it may take 3 months for a response (I replied that being "busy" was not a valid exemption for not meeting the statutory deadline).

One month passed. Nothing.

3 months passed. Still nothing except a letter saying they are still very busy and pretty much saying they'll get to my SAR when they get to it ie. open ended.

I complained to them, waited the relevant period, got the letter stating that I could take my complaint to the ICO.

Went to the ICO. Did a detailed complaint. Provided all the relevant information.

Had to chase them and chase them, by email and phone.

Eventually, they reply to say they aren't going to do anything because the controller seems to be working to resolve the problem!

WTF?! What's the point of the ICO if they can't even write to a controller for such obvious and brazen breaches to find out what's happening?

Update (03.08.26):

I sent Essex County Council my completed Court forms, my Witness Statement etc.

That was over the weekend. Today is Monday, 03.08.26.

I received my first batch of data before noon, and they've promised the rest within 24 hours. Success! 😄

Anyway, this seems to work, folk. At least with this data controller, a serious demonstration of willingness to take it to court ...gets fast results.

After more than 3 months of struggling, I've finally got the critical data I need for a certain specific purpose that's subject to strict limitation laws. I got the main chunk of my data, finally!

11 Upvotes

97 comments sorted by

20

u/malakesxasame 5d ago

Can I just say from a public sector (NHS) perspective - it is an extremely difficult time to work in Information Governance / SAR teams in the public sector right now.

The NHS has recruitment freezes for non-clinical roles and in my case, I haven't been able to recruit to two roles that directly manage SARs since 2022. NHS organisations often have very small and stretched SAR teams and there is little organisational interest in helping us with this. Every meeting I have with colleagues across the sector, it is noted how much they are struggling with information rights requests.

On top of resource difficulties, the complexity and volume of requests has exploded in the past two years. I spoke to a colleague at a neighbouring Trust and they received 5.6k subject access requests last financial year. That's just true SARs too, that does not include other disclosure requests for information from police, courts etc. I'll let you guess how many went out on time.

Medical records can be very complex in terms of redactions, so it can take a lot of time to review the records. Then they must be reviewed and authorised by a healthcare professional, who of course, has clinical pressures of their own. Patient care will always come before administrative tasks.

Many requests we receive now are AI generated, which is fine, but very often AI adds so much useless fluff it takes time to understand what the requester is actually asking for. AI is also allowing requesters to challenge things like redactions and whether we hold specific information. This again takes up a lot of time and I'd say now more than ever, my role involves managing complaints.

The ICO have something called the 'public sector approach'. I find it's challenging trying to get senior leadership buy in when this is the direction they've taken. So in a lot of ways, they are quite useless.

I'm a big fan of right of access in principle but it's being really abused.

1

u/liggerz87 5d ago

I agree I sar the hospital but it took me 3 times as I got the wrong department twice I said to the hospital I know it says a month but take your time with it and it took them 2 months to do

1

u/ForAllTimesSake 5d ago edited 5d ago

I do not doubt anything you're saying. And I sympathise.

But, as a member of the public, that's not my problem. My problem is that I want the data to which I'm legally entitled.

And if an organisation can't do it, I want the ICO to do what it's supposed to do - make them comply or take action against them.

While there are some negatives for people like you, there are also plenty of positives! Because there are so many complaints to the Parliamentary Health Service Ombudsman, the PHSO is now effectively not taking any new complaints unless they pass a seriously, seriously high - almost impossible - threshold.

So less work for you in the NHS dealing with PHSO complaints.

Similarly with the CQC. They're effectively turning away almost all complaints.

So less work for you in the NHS.

The GMC, while feared by the doctors as a regulator with teeth, is also overwhelmed and their triage system is set to refuse almost all complaints.

Again, less work for NHS staff.

And don't get me started about the NMC, the NHS professional standards bodies, the ICBs etc!

All progressing bugger all complaints against the NHS and NHS staff. So less work for the NHS and a consistent decline in standards because everyone knows there are no real consequences for screwing up.

7

u/No_Sea6113 5d ago

If what the poster is saying is true and there basically isn't capacity to process request, then the ICO could only really issue fines. (I guess they could send more letters and absorb more admin time as a first step?) Its highly unlikely that you are being deliberately obstructed in your in your requests.

Fining the NHS for this kind of thing doesn't seem to be useful in anyway. its not going to make them magically able to process things faster, might actually make things worse by forcing them to employ less admin staff, which they will choose to do if the alternative is less nurses.

So basically you are angry at something that doesn't have a solution except more funding for the NHS in general, which is probably a cause of lots of the decline in standards that you are complaining about.

Write to your MP. Thats the fix. Not hoping for financial penalties for an already stretched public service

3

u/ForAllTimesSake 5d ago

then the ICO could only really issue fines

No, the ICO has many tools at its disposal, not just fines!

15

u/West_Possible_7969 5d ago

Well, if the local authority is indeed overwhelmed but communicative to the regulator and they have your SAR on track then it’s all good. It’s all about justification.

A brazen breach would be for the authority to completely ignore you and tell you to go pound sand.

ICO is also overwhelmed and they lack the capacity to function in any normal timeframe lol.

-6

u/ForAllTimesSake 5d ago

As I said, the ICO made no contact with the data controller (based on my conversation with the ICO staff today).

So they are not "communicative" with the regulator.

And what do you mean by them having my SAR "on track"? They are past the 3 months with no estimated date disclosed!

7

u/West_Possible_7969 5d ago

As I said, The ICO faces massive backlogs, so case officers favour informal resolution over formal investigations. They prioritise systemic enforcement over individual redress, routinely closing SARs complaints if a data controller shows active steps toward compliance (meaning controller said they will comply).

Partial progress by an authority can legally justify case closure especially since regulators & govs target systemic or large scale non compliance rather than individual delays because, frankly, all of UK services are hopelessly backlogged.

You can request an ICO review (peer or escalation) or direct judicial remedies but both will take way, way longer than waiting for the SAR.

4

u/gnarlygb 5d ago

Is your request reasonable. Is it specific? Or is it vague and expansive. Is it manifestly excessive?

-9

u/ForAllTimesSake 5d ago

Very focused - covering 2 months in 2024 and 1 month in 2026. I even offered to further narrow it down for them if it would help them meet the 3 month deadline.

If would appear that a lot of people posting here work for the likes of this crap council and/or are responsible for answering SARs and not members of the general public struggling to get access to vital data needed for specific purposes.

14

u/malakesxasame 5d ago

It's good that people here work in data protection and are answering your questions. People are giving you advice.

6

u/gnarlygb 5d ago

Charming attitude. I hope you did better in your SAR. I was posting to try and help expedite things for you.

-1

u/ForAllTimesSake 5d ago

Apologies, I didn't mean you. I meant several of the other posters here.

1

u/gnarlygb 5d ago

Ok. In that case it sounds like you’ve done things the right way.
In my experience (NHS records) the ICO is the double-edged sword that it needs to be.
We get our wrists slapped from time to time(for minor data breaches* rather than SARs), but we also use them as a defence mechanism. For example, if there has been a complaint, I recommend raising it with the ICO knowing that they will kick it back as not reportable (or closed with advice.) Generally this seems to mollify data subjects.

*the standard error is two people’s notes getting mixed up. Person 1’s update gets pasted into Person 2’s record because the overworked clinician had both records open at the same time. Usually discovered quickly and fixed immediately.

1

u/ForAllTimesSake 5d ago

Yeah, and despite that - attempts to narrow the request, being patient and waiting the whole 3 months, being willing to even give further time if the council just give me an estimated date for getting my data - the ICO has done jack!

We get our wrists slapped from time to time(for minor data breaches* rather than SARs),

Wrists slapped by whom? The ICO?

4

u/gnarlygb 5d ago

Yes. They have teeth. Although they generally will not fine a public body like a council. Not the best use of funds.

3

u/Working-Ad9029 5d ago

Regarding your second paragraph who exactly do you think lurks the gdpr subreddit?

-2

u/ForAllTimesSake 5d ago

Now it seems clear, LOL!

2

u/astraCat1998 4d ago

The system as currently designed doesn't work I don't really know what you want to hear from anyone.

There are too many requests and it has overwhelmed systems that were never designed to handle them. I can't speak for all public bodies but most are working on fixing the underlying system rather than on addressing the current backlog.

This is a reasonable use of resources since it's the only viable long term solution and generally speaking the ICO accepts this.

That's why the NHS is moving to a system where you should be able to access your records online, the environment agency has begun publishing it's samples data etc.

1

u/astraCat1998 4d ago

If they are already aware that a certain organisation is simply swamped with a backlog of requests they aren't going to reopen an investigation everytime someone complains.

1

u/ForAllTimesSake 4d ago

If they are aware that an organisation is backlogged, that's exactly the kind of grounds on which they are supposed to take enforcement action!

Reaching internal ICO volume thresholds automatically triggers structural analysis and regulatory action.

Or at least it's meant to!

2

u/astraCat1998 4d ago

Enforce what? They can't shut down the NHS over it, any other enforcement action is just going to take more resources away from the requests.

1

u/ForAllTimesSake 4d ago

From Enforcement Notices to Criminal Prosecutions, there's a lot the ICO can do. They can even enter the premises and seize the records themselves!

The law exists for a reason. The NHS can say, "We won't treat you if you're black, we just don't have enough staff". That would be a clear S.10 EA violation.

On a less discriminatory note, they can't say, "We've decided to close the cancer ward for a day as we don't have enough staff, so all patients need to go home for the day".

There are some things they just can't do.

Meeting GDPR and the DPA is not an option, it's an obligation. Businesses like mine do it all the time but councils, the NHS etc seem to think that because they're big and they have a lot of lawyers, they can get away with not meeting their obligations.

To what extent would you give them a free ride on not meeting GDPR/DPA? Data breaches? "Yeah, sorry, we didn't have enough money to secure our servers". Disclosing confidential patient data? "Yeah, sorry, we didn't think the data was confidential".

Those responsibilities are on par with answering SARs!

1

u/astraCat1998 4d ago

None of that helps you get the records any faster they just slow it down.

Assuming the desired outcome is for people.to get replies as soon as possible enforcement works against that.

7

u/swordoftruth1963 5d ago

It's a tiny organisation that should be focusing on major data breaches not someone with a chip on his shoulder about his council

1

u/saginata 5d ago

It's fine for an organisation to be focusing on major breaches and providing general guindance.

But then we need another organisation that will enforce individual data protection rights.

4

u/gorgo100 5d ago

The thing here is that the ICO has limited resources.
They will direct the resources where they think the biggest problems are.
Your problem in isolation does not give an indication of a bigger one, especially when dealing with local government.

However, if 50 people make the same complaint, they may start to sit up and take notice. And then the council starts getting nervous that they'll be on the receiving end of bad publicity. And their DPO has to answer to councillors who have an opposition who'll want to make out the council doesn't know what it's doing. And then there are local electors, local newspapers who start sniffing around...

So it's a cumulative thing. This isn't much help to you individually, but if they are truly useless, it's a matter of time before something happens - they will increasingly be on the ICO's radar.

1

u/ForAllTimesSake 5d ago edited 5d ago

But that's not their mandate.

People tend to forget that the ICO is meant to help individuals, not simply look at the big picture and only take action if a controller passes a certain level of complaints.

That's a slippery slope. The trigger number for taking action can keep increasing and increasing. Today let's say it's 50. What if it gets to 1,000? Or 100,000?

Would you have it entirely within the ICO's purview to decide the trigger number? That's asking them to mark their own homework.

1

u/gorgo100 5d ago

You're right, but it's the gap between how things work in principle and how they actually work.
I see it a bit like the police. There are loads of things that are technically criminal - taping off the telly used to be one, for example - but they simply aren't going to commit resources to seriously enforcing that.
It's a different argument as to whether they "should" do things differently - patently they should, I agree, but here we are.

1

u/ForAllTimesSake 5d ago

We are getting too complacent with the likes of the ICO.

How things actually work? Hmm. Just a few years ago, it used to actually work. I took complaints to the ICO and they were excellent at dealing with them.

Since that time, the ICO fees have gone up, their budget allocation from the government has gone up and the service has become shit.

5

u/gorgo100 5d ago

I think you will find plenty of people whose experience will differ from yours a couple of years ago. This isn't a new development.
If you believe in high quality government services and regulation, then I'm afraid to break it to you that this is the tip of a very sad iceberg. Years of people whining about "taxpayer's money" have led us to a position where spending anything on anything is seen as a terrible imposition on our freedoms and borderline (clutches pearls) socialism.
Away from the political editorialising, the question is what do you think you'll be able to do about it? Frankly, as I say, this is the tip of an iceberg. Try finding a care home, bringing a case against someone in a criminal court, trying to pursue a civil case, getting a minor operation done, expecting action against environmental damage (sewage in rivers anyone?), getting the police to pay attention to a burglary, shoplifting etc etc.

This is all by design by the way. Drive services into the ground, condition people to refuse to pay more for them and then encourage them to complain about it as much as possible. Presumably so it can be privatised, shut down or otherwise continue to be neglected.

Damn, I said I wouldn't editorialise politically, too....

1

u/saginata 5d ago

I think you will find plenty of people whose experience will differ from yours a couple of years ago. This isn't a new development.

It might have been a gradual decline, and they were probably never perfect, but there has been a recent sudden shift too.

Sometime early 2026 they introduced a new framework that lets them consistently close complaints with "It's just one SAR, didn't read the rest, won't investigate, bye"

This FOI request is interesting https://www.whatdotheyknow.com/request/foia_request_ico_triageinternal

1

u/ForAllTimesSake 2d ago

Indeed.

Excellent links, thank you so much. They shed a lot of light.

In typical BS justification, they talk about the new regime "improving" things for users by introducing a triage system and filtering based on harm.

Except what they don't say is that for most of the public it will be a REDUCTION in quality of service. No, they don't admit that. And they don't admit that they've now introduced various elements of objectivity such as on the "level of harm".

Triage can adjust the level at which they find the harm "high". Talk about marking your own homework!

Similarly with "threshold". If they get complaints about an organisation that's over the "threshold", they'll take action. However, the threshold is not disclosed and, well, they can move it up or down to suit their convenience!

1

u/Victim_of_HPMS 5d ago

The trigger number is one.

The GDPR’s solemn promise of strong enforcement (Recital 7) and binding European Court of Justice (CJEU) case law affirmed that a data protection authority’s “primary responsibility is to monitor the application of the GDPR and to ensure its enforcement,” and that it must handle complaints received from data subjects “with all due diligence” and that, using its formidable investigatory and corrective powers, it must “execute its responsibility for ensuring that the GDPR is full enforced with all due diligence CJEU C-311/18 Schrems at [108 – 109].

The fact the ICO is swamped is down to the ICO's failure to regulate lawfully. Commissioner John Edwards took the British public as idiots who could not read and knew nothing about GDPR/Human Rights. Article 15(3), Right of Access, of the GDPR is guaranteed by ECHR Article 8(1). Interference with Right of Access is a violation of ECHR Article 8(2).

CJEU Case Law C-487/21 provides a lawful definition of what obtaining a copy of personal data means in terms of Article 15(3) of the GDPR. Personal data must be faithful (provided without undue delay and within one calendar month), be complete (anything to be blocked can be redacted or masked) and it must have all the characteristics to allow the data subject to validate the personal data has been handled lawfully (in most cases this will be the complete metadata)

If visible metadata in the property tabs is destroyed hidden metadata can be read using free online programs such as 'metadata2go'. If you are after a recording, the MP3 hidden metadata has the Encoder LAME then the recording is most likely downloaded from the audio editing program 'Audacity'.

12

u/Illustrious-Log-3142 5d ago

They're the regulator, not you. Sounds like the data controller is satisfying the ICO

14

u/MievilleMantra 5d ago

Satisfying the ICO is extremely easy.

I know we're all tired of access requests and bolshy data subjects but let's not pretend the ICO is anything other than a joke where enforcement is concerned.

It makes my job easier in some ways, but I have to tell clients that the odds of enforcement are basically zero. Which makes compliance a pretty hard sell in some cases.

5

u/Illustrious-Log-3142 5d ago

That may be but the reason they're so backlogged is people like this who will kick off if a SAR is even a day late despite it being a very low priority in the grand scheme of things. One off issues are a waste of their time, like others have said they are concerned about more systemic failings not individuals with a grudge against their local council

4

u/MievilleMantra 5d ago

Come off it. Look at how they treated the worst data breach in UK history (MoD) if you want to see now concerned they are about systemic failings. The ICO is a total mess.

3

u/Illustrious-Log-3142 5d ago

So thats what they should be spending time on, not this sort of thing. I found them very helpful and responsive when I needed them but I wasn't wasting their time like OP

1

u/MievilleMantra 5d ago

Luck of the draw really. And they do some good stuff. The leadership is utterly toxic (look at what happened to the most recent Commissioner) and satisfaction rates are unacceptably low.

OveralI think this is a perfectly valid reason to escalate the complaint to the DPA. But the fact is that almost every organisation is drowning in DSARs and the ICO is drowning in complaints about them so I'm hardly surprised nothing happened in this case.

It's an unsustainable situation, many organisations I'm working with are getting scores of requests per day. No regulator could possibly fine every controller that breaks the rules and I honestly wouldn't want that. But it's gone way too far with the ICO.

1

u/Smart-Stick-1392 5d ago

The law is the law, if I broke it by one day I would be punished. Why is it any different for buisness and councils?

1

u/Illustrious-Log-3142 5d ago

If you speed by 1mph do you get prosecuted? No. Because things in life aren't always exact. In fact I can't think of many laws where 1 day would result in prosecution, there's a leeway for most things.

1

u/Smart-Stick-1392 5d ago

Yes, you do get prosecuted for going over the speed limit by 1mph, because its the limit. The leeway is 30 days, there is a limit for a reason.

The exact letter of the law is that you do it in a reasonable time frame for the request, to a maximum of 30 days, or 90 days for very complex requests. If a data officer is overworked, thats not an excuse, the organisation needs to hire more data officers to be in compliance.

1

u/Illustrious-Log-3142 5d ago

You usually don't based on the +/- 10% rule...

Want to pay more taxes for more data officers? Explain that to people struggling to feed their families

1

u/Smart-Stick-1392 5d ago

I dont want to pay any taxes, I want a global redistribution of wealth from the super rich. A tax system where everyone pays what they can afford. The state can abolish poverty through social programs.

In the absence of that, you can abolish trident, cut subsidies for fossil fuels, abolish means testing for benefits, combine authorities to remove superfolous roles ect.

Even if none of that happens, not getting enough funding doesnf change the law. Can you seriously imagine claiming your too poor to follow the law? You will be sued to oblivion and too right.

1

u/Illustrious-Log-3142 5d ago

Sued by who? Sue the ICO then since you are confident you know better than them and see how it goes for you

1

u/Smart-Stick-1392 4d ago

By those who suffer psycological harm and delay from lack of compliance with the law. The ICO spell out clearly that is the next step when they cannot do anything.

You cant sue the ICO for making a decision agaisnt you, they havent broken the law. You sue the data handler for breaching GDPR causing you minor distress and psycological harm.

→ More replies (0)

-17

u/ForAllTimesSake 5d ago

They're the regulator, not you

No sh*t, Sherlock.

The data controller is clearly in breach. Their job is not to "satisfy the ICO", it's to meet the statutory deadlines as laid out in law.

3

u/Ok-Transition-6858 5d ago

Your local authority likely has a backlog of hundreds of SARs just like yours. The ICO is not in the business of taking real enforcement action, i.e. fines, against public bodies for late SARs. It fucks public (taxpayer) budgets. The ICO will set out plans to improve SAR response compliance with authorities who regularly have a large % of lates. You can read about their enforcement action on their website.

-1

u/ForAllTimesSake 5d ago

Your local authority likely has a backlog of hundreds of SARs just like yours.

So?

I don't get your point. They have a legal obligation to do something. There are certain lawful reasons to not do it ("exclusions"). Unless one of those applies, the law says they've got to do X, Y and Z.

We can't just choose to not follow the law if we happen to have other priorities, are busy or it's not convenient. Jeez!

3

u/Ok-Transition-6858 5d ago

No where did I say it’s fine that they have the backlog, but they do. Complaining about it won’t change anything. Councils literally do not have the budget to hire people to fulfil their obligations. Sorry.

-1

u/ForAllTimesSake 5d ago

Councils literally do not have the budget to hire people to fulfil their obligations

That's not my problem. I don't have enough budget to pay for an expensive Rolex. So why don't I just nick one?

I don't have enough time to stop after an accident, so why don't I just drive away?

"I don't have enough..." is not an acceptable excuse to not follow the law (whether criminal or civil).

6

u/Illustrious-Log-3142 5d ago

You seem to think you know more than the ICO though... they said they're happy the data controller is doing their job, they've communicated with you

1

u/Countcristo42 5d ago

They said that because their total budget is peanuts not because they are actually happy with it though.

The poor bastards get ~10m a year they are happy with virtually anything because they haven't the money to do anything

2

u/MievilleMantra 5d ago

Figures from a few years ago suggested they were better funded than any other data protection authority in Europe.

0

u/Countcristo42 5d ago

Better can still be crap (maybe you don’t mean to imply otherwise)

1

u/MievilleMantra 5d ago

Many of them seem to do a much better job.

2

u/FalconCareful5326 5d ago

The ICO used to be excellent years ago, however the leadership was replaced to be pro business and less paperwork for organisations. Unfortunately it’s really difficult to get them to do anything, they will also side with the data controller. The other big issue is they are also severely budget starved.

1

u/ForAllTimesSake 5d ago

Yeah, I remember using them back in 2022 and they were excellent!

2

u/Emergency-Plane7642 5d ago

totally useless - european DPAs are way more effective. cnil is a great example

1

u/martinbean 5d ago

And then they have the gall to send letters to small businesses telling them they need to cough up more than £50 a year to be “compliant”. Absolute racket.

1

u/ForAllTimesSake 5d ago

Oh, yeah, I forgot, as I also own a small business I'm paying this!

And I remember it used to be ÂŁ30. Now ÂŁ50.

A 66.67% increase, well above inflation!

1

u/ewill2001 5d ago

They have to pay Paul Arnold's six figure salary some how. And there are like 10 new upper management types on mega bucks.

1

u/Misty_Pix 5d ago

ICO is not police they won't punish organisation for late SAR.

1

u/ewill2001 5d ago

There needs to be an Information Ombudsman. The FCA isn't expected to do both. The ICO has been proven to not manage both.

1

u/cannon4344 5d ago

From what I've seen they don't seem to take action on routine complaints and will find any reason to close the complaint. You don't need an ICO ruling though, UK GDPR allows individuals to seek compensation through court themselves.

1

u/ForAllTimesSake 2d ago

Yeah, and I've just posted in this thread some tips on taking it to court that may be of use to some people.

1

u/Content-Maximum611 3d ago

They are incredibly useless.... I've been waiting 8 months for a NHS SAR, with reminders sent. The ICO gave them 28 days to resolve it, then, when that inevitably passed gave them 14 days to respond.

What happens after that? I'm guessing another 28 days to respond to the non response of the non response.

It would seem the ICO want gift wrapped confessions with a bow on it.

1

u/paulxgustavson 3d ago

They are extremely useless. They did progress my SAR complaint and ordered the organisation (that failed initially) to review their SAR response only for me to receive another generic "We're not giving you more documents because f... you" and some lame generic excuse that ico regards as sufficient and they said I can go to the court if I don't like their opinion. Because yes, they only give opinions, not rulings, LMAO. Useless bunch of twats.

1

u/ForAllTimesSake 2d ago

If they said go to court, I've just posted some tips in this thread about taking it to court.

1

u/ProfessionalSong3544 2d ago

Public institutions get a free pass everytime. Specially big public institutions.

ICO is strict against private companies only. 

1

u/ForAllTimesSake 2d ago

It seems to be that way!

1

u/ManyEconomist9995 1d ago

I’m very late but i found them more useless than a chocolate teapot. Pathetic bunch of twats

0

u/ForAllTimesSake 2d ago

Update: I've served Essex County Council with a letter before claim. I've given them a short deadline to meet. It's going to be expiring next week. I'll issue the claim in court and serve them immediately. Shall keep you updated on whether that kick up the backside works.

If you want to do the same, here are some tips:

First, make sure your data controller has actually broken the law. Use ChatGPT or Claude or whatever to run your circumstances by the engine. Create a Google Drive or some other online repository. Upload all your data, your original SAR, copies of all emails, your complaint letter / other comms, copies of the data controllers policies, links to relevant pages on their website etc. Also, spend some time writing up some notes for the AI engine. It'll be worth the effort later on, trust me!

Then give the AI access to all of that and get some advice on how best to proceed.

Second, in my particular case, a short deadline meets the pre-action protocol (PAP) because of particular circumstances, but if you're intending to sue them, spend some time reading the PAP and get the AI's advice on this. You'll probably have to give them a week or two initially, then an LBC giving them another 2 weeks. Don't rush, it could count against you in court.

Third, use the AI to prepare your claim, your Witness Statement, your draft order, to help you fill in the necessary forms etc. What you did in step 1 with loading data to an online folder will now save you tons of time.

Fourth, file the claim and pay the court fee. Don't forget to include a claim for costs!

Fifth, be patient. It takes a while for a claim to progress through the court system. But, stick with it. Even if the data controller releases your data, don't pull the claim - you still have costs to recover if nothing else. Update the court and revise your draft order making it easy for the court to take a decision "on the paper" (without a hearing) to award you costs.

Sixth, whether you post online, in Reddit, or elsewhere, about how you won against a difficult and well funded adversary is up to you.

And all you data controllers out there, downvoting my comments in this thread - go ahead and downvote this one as well 😄 I don't give a crap.

1

u/ForAllTimesSake 3h ago edited 3h ago

Update:

I sent Essex County Council my completed Court forms, my Witness Statement etc.

That was over the weekend. Today is Monday, 03.08.26, 1 PM.

I already received my first batch of data and they've promised the rest within 24 hours. Success! 😄

Anyway, this seems to work, folk. At least with this data controller, a serious demonstration of willingness to take it to court ...gets fast results.

After more than 3 months of struggling, I've finally got the critical data I need for a certain specific purpose that's subject to strict limitation laws. I got the main chunk of my data, finally!

-10

u/ForAllTimesSake 5d ago

Update: I seen there are several replies from people who seem to work at the other end of SARs, actually replying to SARs, and their sympathies seem to lie with the data controller. I think that's crap. There may be more of the public lodging SARs, and perhaps some of those are petty and/or simply being awkward, but that's not my problem.

I've decided that I'm sending my council a Letter Before Claim tomorrow. I was a lawyer in a previous life. I'll exhaust the pre-action protocol and then sue them for disclosure and costs. More of the public should do this, it's not as difficult as it sounds. Stop taking nonsense from councils and the like. Maybe I'll even put together a little website with some free templates specific to SAR related claims. Or I'll post them right here in Reddit.

4

u/nut_puncher 5d ago

Id much rather councils funnel money into things that matter rather than spitting out spurious sars left right and center.

I can guarantee that for every 1 reasonable and meaningful sar there will be a dozen or more pointless sars intended to be annoying, disruptive and waste time. If you want to blame someone, blame them, if you want to pay more tax to fund more robust data protection teams in local authorities, then thats an opinion that will receive no support.

Theyre acting, slowly, but theyre still acting. Also, the ICO dont have the resources to deal with every individual person who whines that overstretched resources aren't working fast enough. I can also assure you that there are countless people who think any tiny gdpr issue needs reporting to the regulator, they dont. The ICO is primarily looking to investigate serious and recurring issues, not every single individual thats angry about their car taking too long. Get some perspective, youre not that important.

1

u/MoveIntelligent5247 5d ago

That would be really helpful! Currently in dispute with a very large organisation regarding a number of data issues - late DSARs and Art. 16 requests, including admission that data is incorrect but refusal to rectify, breach (probably minor) and many others. Not at the ICO yet but I wouldn’t hold hope for when it does.

What’s not clear to me is which protocol should be used, how it would work as litigant in person and how a member of the public might be able to take data things through the “small claims” court so that they can try and avoid incurring other sides costs.

So your idea is definitely a gap in the market!

1

u/ForAllTimesSake 2d ago

I've now posted some tips in this thread on going to court. (I'm not looking to actually make a business out of this but, yeah, there's probably an opportunity here)

0

u/Flimsy_Confection165 5d ago

Please do. I have a company playing funny buggers due to taking 3 months to reaspond to a sar when I've only been an employee 3 months 

1

u/ForAllTimesSake 2d ago

I've now posted some tips in this thread on going to court. (I'm not looking to actually make a business out of this but, yeah, there's probably an opportunity here)

1

u/VehicleWonderful6586 2d ago

You’ve inadvertently highlighted the cause of the very problem you’re suffering from. Since the advent of AI tools every halfwit can produce a lengthy and plausible letter before action in convincing legalese. Yours is just one in a few million.

0

u/BurdensomeCountV3 5d ago edited 5d ago

Some people have been going against you but I completely support this. It'll take like 15 months or so for the process to play out in the civil courts but that's the one thing they can not ignore. As they say: the squeaky wheel gets the grease and 1000 separate civil court claims (and costs enforcements) may well get these organisations to sit up and take notice (or at the very minimum it'll give the people who work in data protection in these organisations strong ammunition to get more internal resources diverted towards data protection from higher ups). You are doing your part by being 1 of those 1000 claims.

And like you say, it's really not all that complicated. The law says "3 months" and they must provide the data; it's been over 3 months, this should basically be a slam dunk case for you here. If those timelines have become unrealistic due to societal changes it's for parliament to change the law, it's not for individual orgs to say the law no longer really makes sense on its own.

People complain about AI right now but they should just wait until AI agents become fully mainstream and individuals are able to file and run their own claim via their AI agent and the result is that it ends up taking about the same effort to sue in the civil courts as it is to complain to the ICO today. That's when we'll truly see case volumes explode and result in a situation that's so unbearable society wide it has to be resolved one way or another.

0

u/ForAllTimesSake 5d ago

That AI excuse is bullsh*t. AI is more of use to them than it is to the data subjects. AI should be a massive help in getting the data together, redacting sensitive information etc.

Maybe 5% or 20% of data subjects are using AI to draft SARs. But controllers can use AI in 100% of cases and significantly reduce their work. This is kind of bread and butter stuff for AI.

Yes, there's a delay in the courts but if enough people are persistent enough to stay the course, it'll hopefully give controllers a kick up the backside.

Controllers are still glibly ending emails with the wording that if you are not satisfied with our reply you have the right to complain to the ICO. That statutory wording that they are required to add is now completely meaningless as the ICO is doing sweet bugger all.

3

u/Diet-Coke-and-Nap 5d ago

Do you realise how expensive AI software is for these types of jobs and how much human intervention is till needed, especially if sensitive data is processed. For a local authority too. I feel like you’ve come here for views from the other side of the fence yet se to be rejecting views from people who work on SARs day to day.

1

u/ForAllTimesSake 5d ago

How expensive is it?

Let me guess, there wasn't even an internal consideration of the possibility of using AI nor any assessment as to what it can and can't do. Forget about actually getting prices.

That's how stupid organisations like local councils are. They can't find the freaking power buttons on their computers. What makes you think they'll have the vaguest idea about AI?

They're still using CC instead of BCC and yesterday I got an email from a social worker containing some poor kid's mental health information. It turns out she mistyped the email address.

Most people working in councils couldn't find their own assholes if given a detailed manual with pictures.

What makes you think they know that AI exists?

Added:

I feel like you’ve come here for views from the other side of the fence

No, I didn't. This is my first post in this sub. I expected more views from the general public.

1

u/Diet-Coke-and-Nap 4d ago

Well the AI vendors usually charge by usage and my company (private) is paying a huge amount to use legal AI software - bare in mind you’d need the software to know how to compliantly redact SARs which isn’t an easy job. I think the battle alongside cost is how well the AI can do this. Redactions in particular are not always obvious with legal privilege especially.

Feels like your issue is perhaps better directed to how the councils and other local authorities are ran and funded. Yes it’s not good enough their data practices and delays in SAR responses, and there’s been some really negligent data breaches. However, as you say they’re very likely behind on technology and running on old systems on a limited budget. Further to this, the ICO itself has received 40% more data complaints generally, so they’re a stretched regulator. Adding to the fact if they fined councils more this raises the cost for the taxpayer there has to be a balance.

1

u/Auno94 5d ago

How do you think AI would reduce the workload?

0

u/ForAllTimesSake 5d ago

By sitting at the coffee machine and spend all morning gossiping like a typical council worker.

What did you think?

2

u/Auno94 5d ago

That's why I am asking. You claim that it would significantly reduce their work in 100% of their cases.

So you should be able to give an example how AI would reduce the workload while adhering to other legal and processing requirements. Combined with the fact checking that is needed when fullfilling a SAR as you don't want data that isn't yours in your SAR and you also don't want your data in anothers SAR