The Corporate Grenade: Weaponised Data Subject Access Requests

GDPR Compliance
Share this Article:

Following the introduction of the EU General Data Protection Regulation (GDPR) on 25th May 2018, the rules surrounding Data Subject Access Requests (DSARs) underwent significant changes to bring them forward into the modern world. GDPR became synonymous with Data Protection in the corporate world, and DSARs opened a new front for organisations to contend with. The promotion of the GDPR by entities such as the ICO, HMG and private sector advisors raised public attention to DSARs and resulted in many organisations experiencing an increase in the number received. The removal of the standard fee also made DSARs more accessible to the Data Subject (DS).

With this monetary barrier now removed, requestors were able to make as many requests as they wished, for as much information as they wanted without a financial implication. With this newfound freedom, some requestors began to use DSARs as a weapon, wielding the threat in order to tie up resources or cause other interference, rather than for genuine requests for data. Luckily, this was pre-empted by the legislators, who included mechanisms to allow a controller to fully or partially reject a request if it is:

  • Excessive (or repetitive) – if the request overlaps other requests, or the same, or very similar, request is made on multiple occasions

OR

  • Manifestly unfounded – if the request is made with no clear intention of exercising the right to access or used to harass an organisation and/or cause disruption

Excessive or repetitive requests are usually easy to identify, as the Data Protection team handling the request are able to spot frequent requestors or similar requests. The DS may attempt to use multiple email addresses or may even try different methods of contact (emails, letters, telephone etc.) in order to disguise their origin. Instances such as these highlight the importance of a central Data Subject Rights or specific DSAR log, as it will make it easier to notice the same name or nature of request if they are all recorded in one location. Rejecting a request on this basis is straightforward as the previous requests, once verified, can be cited in the reply. If multiple requests can be demonstrated, then this will assist with any potential ICO investigation, should the requestor lodge a complaint.

Unfortunately, in practice, it is often difficult to prove the latter of these criteria. The legislation does not require a requestor to provide a reason for their request, and many will not offer this information freely. It is becoming increasingly common for individuals to make DSARs with the express intention of causing additional work for the controller, especially if the request contains a large volume of information or covers a large period of time. Common indicators of a manifestly unfounded DSARs include ongoing complaints or other disputes between the requestor and the controller. It is especially obvious if the requestor offers to withdraw the request in exchange for a financial settlement or resolution of another issue. Requests of this type are often seen in employment disputes or related disciplinary or grievance proceedings. The requestors are aware of the statutory 1-month time period in which the DSAR must be responded to and will use this in order to prolong the process and delay any meetings or final decisions. A rejection on this basis must only be carried out if the controller can prove definitively that the DSAR is being used in this way.

The case of weaponised or abusive DSARs is not confined to the UK. The Court of Justice for the European Union (CJEU) recently made a ruling in a case known as the Brillen Rottler judgement. This surrounds an Austrian DS who signed up for a newsletter from a German optician, made a DSAR and later a complaint claiming compensation for an alleged failure to respond. The CJEU held that the DSAR itself was manifestly unfounded as they believed that it was made with no intention of exercising the right of access and instead was done so solely to manufacturer a damaged claim. The individual in question had a history of making similar DSARs and claims. A central part of the judgment was deciding on whether a first DSAR can be considered in this way, and it was decided that any request, be it the initial one or any subsequent requests, can be refused and that “a repeated course of conduct is not a necessary element”. It did, however, still emphasise that burden of proof remains high and the onus is on the controller to prove this. Since Brexit in 2020, CJEU rulings are no longer binding in UK law, however they remain highly influential and the courts and ICO have recognised similar outcomes in the past.

In summary, DSARs remain an integral part of current data protection legislation and on the whole, are used appropriately. It is important for controllers to review each request received and make a judgement based on the individual circumstances. Our consultants are highly experienced and can assist your organisation in identifying those DSARs which are genuine and those which have been made in bad faith.

If you find yourself in a situation where you are unsure of the legitimacy of a DSAR you have received, please fill out our enquiry form which can be found at www.privacyhelper.co.uk/contact and we will be more than happy to provide any assistance we can.

About the Author: