Responding to Subject Access Requests

Solicitor, Jack Horwitz talks us through James Pavur's study and how to best review Subject Access Requests.

No items found.

Ever since the General Data Protection Regulation (“GDPR”) came into force on 25 May 2018, responding to Subject Access Requests (“SARs”) has become an almost day to day job for plenty of businesses.

This boom in the number of SARs can largely be put down to two main factors:

  • The first is the increased awareness amongst the general public of their own data protection rights, resulting from the publicity surrounding GDPR coming into force and a number of high profile data protection-related news stories, such as the Cambridge Analytica affair.
  • The second key reason is that there is no longer any fee payable (unless the request is “manifestly unfounded or excessive”, in which case a reasonable fee may be charged). Under previous legislation, a £10 fee could be charged by businesses to the individual making the request. It seems that the removal of this small barrier has opened the floodgates.

As well as opening the door for many legitimate (and some spurious) SARs, the removal of the £10 fee has also made the SAR into another potential tool for hackers to use when seeking to obtain personal data which can then be used for identity theft purposes.

A recent study carried out by James Pavur, a PhD student at Oxford University, demonstrated the vulnerabilities created by the sheer number of SARs most businesses face nowadays. The volume of requests, and the relatively short period in which to respond (only one month), creates significant pressure on the employees tasked with dealing with SARs. This, coupled with the potentially huge fines which can be levied under GDPR, creates an environment in which the prevailing attitude can end up being one of “get the response over and done with without asking too many questions”.

Mr Pavur’s theory is that this regulatory framework may lead to SARs being responded to without the business having confirmed the identity of the individual actually making the request. In order to test this theory, Mr Pavur sent out 150 SARs in the name of his fiancée. The aim of the experiment was to obtain as much personal information about his fiancée as he could, without the various businesses finding out that it was not actually his fiancée making the request (for those wondering, she was complicit in this experiment!).

The results are either interesting, or quite concerning, depending on your viewpoint. 24% of the companies responded on the basis of nothing more than an email address and phone number, and sent over all data they had on Mr Pavur’s fiancée. A further 16% requested some ID, which Mr Pavur described as ID that could be “easily forged”.

Other companies asked for log in details to prove identity. However, one of these companies sent over all the personal data it held after Mr Pavur simply told them he had forgotten the log in details.

The information received by Mr Pavur ticks all of the boxes for the type of personal data a hacker could use to carry out all kinds of identity theft online: social security number, date of birth, mother's maiden name, 10 digits of a credit card number, credit card expiration date, card type and postcode.

The advice for businesses off the back of this study is clear: you must be certain of the identity of the individual making the SAR or, where it is made on behalf of another person, that the individual making the request has the proper authority.

GDPR does provide companies with the power to request information necessary to confirm identity, where there are “reasonable doubts” about the identity of the person making the request. However in the time pressured environment of having to respond to SARs within a month, it is easy to see how asking for appropriate ID gets overlooked.

Don’t be afraid to use the powers granted by GDPR if you have any doubts at all about the identity of the individual making the request. Sending out personal data to a hacker in response to a fraudulent SAR is likely to be a data breach in its own right, thereby turning what is an attempt to comply with GDPR into a whole new set of data protection issues for an organisation.

If you have any questions regarding the above, please feel free to email Jack Horwitz at jhorwitz@leathesprior.co.uk. or visit the website for more information.

Note: The content of this article is for general information only and does not constitute legal advice. Specific legal advice should be taken in any specific circumstance.

Article by
Jack Horwitz
October 29, 2019
Article by
Leathes Prior Team
October 29, 2019
You might also like...

Charity of the Month: Sue Lambert Trust

Leathes Prior is delighted to be supporting the Sue Lambert Trust as our Charity of the Month for February 2026. Sue Lambert Trust is a leading charity in Norfolk offering free therapeutic counselling and support services to survivors of sexual violence and abuse.

Rhiannon Bond
23.02.2026

Supreme Court ruling set to impact NHS - Children injured by NHS can claim damages for lifetime lost earnings

In February 2026, the Supreme Court passed a ruling which is set to significantly increase the amount of damages the NHS may have to pay for claims brought in respect of children injured at birth, as a result of medical negligence.

Kimberley Nelson
20.02.2026

The Value of Planning Ahead: LPAs & Court of Protection

Putting LPAs in place allows you to choose trusted people to make decisions for you if you lose capacity in the future. This avoids the need for loved ones to make a costly and time-consuming deputyship application to the Court of Protection. With more people likely to experience conditions affecting capacity, more families may need to turn to the Court for support where no LPAs are in place.

Jordan Walker
19.02.2026

Clinical Wills: An overview for Healthcare Practitioners

Ejike Ndaji, Partner in our Wills, Trusts and Probate Team provides an overview of Clinical Wills and their importance to Healthcare Practitioners.

Ejike Ndaji
17.02.2026

More industry insights

Stay informed with our latest legal insights.

View All

Charity of the Month: Sue Lambert Trust

Leathes Prior is delighted to be supporting the Sue Lambert Trust as our Charity of the Month for February 2026. Sue Lambert Trust is a leading charity in Norfolk offering free therapeutic counselling and support services to survivors of sexual violence and abuse.

Rhiannon Bond
23.02.2026

Supreme Court ruling set to impact NHS - Children injured by NHS can claim damages for lifetime lost earnings

In February 2026, the Supreme Court passed a ruling which is set to significantly increase the amount of damages the NHS may have to pay for claims brought in respect of children injured at birth, as a result of medical negligence.

Kimberley Nelson
20.02.2026

The Value of Planning Ahead: LPAs & Court of Protection

Putting LPAs in place allows you to choose trusted people to make decisions for you if you lose capacity in the future. This avoids the need for loved ones to make a costly and time-consuming deputyship application to the Court of Protection. With more people likely to experience conditions affecting capacity, more families may need to turn to the Court for support where no LPAs are in place.

Jordan Walker
19.02.2026

Clinical Wills: An overview for Healthcare Practitioners

Ejike Ndaji, Partner in our Wills, Trusts and Probate Team provides an overview of Clinical Wills and their importance to Healthcare Practitioners.

Ejike Ndaji
17.02.2026

Leathes Prior assists Almalumi Group on the acquisition of Yarrowside Limited

Alex Saunders, Partner in the Leathes Prior’s Corporate Team assists Almalumi Group on the acquisition of Yarrowside Limited.

Alex Saunders
17.02.2026
Will

What do Executors and Trustees do, and who should I appoint?

Charlie Watkins, Trainee Solicitor in our Wills, Trusts & Probate Team discusses what Executors and Trustees do, and who you should appoint.

Charlie Watkins
03.02.2026

Charity of the Month: Big C

Leathes Prior is pleased to support Norfolk cancer charity, Big C as its Charity of the Month for January.

Rhiannon Bond
28.01.2026

Freddie Slater becomes the first development driver to be signed by new F1 Team Audi

Dan Chapman, Managing Partner and Head of Sports at Leathes Prior acted on behalf of Freddie Slater as he becomes the first development driver to be signed by Audi Revolut F1 Team.

Peter Lambert
26.01.2026

Business Lasting Powers of Attorney – Why Your Business Needs One

The benefits of having in place Lasting Powers of Attorney (LPA) documents for one’s personal affairs are now more widely known than was previously the case, Partner, Ejike Ndaji explains.

Ejike Ndaji
26.01.2026

Breaking Up Doesn’t Have to Be Hard: FAQs for Break Clauses in Commercial Leases

Georgia Sartin, Solicitor in our Property Disputes Team answers some frequently asked questions around break clauses in commercial property leases.

Georgia Sartin
23.01.2026

The case of the fake cases: another judgment on AI-hallucinations in litigation

The use of AI Large Language Models in litigation continues to generate headlines (and consternation from the judiciary). In 2025, it seemed that rarely a month went by without a new case on fake AI-generated case law. December was no exception, and the High Court has now issued a further warning regarding the use of AI by litigants.

Chris Goodwin
15.01.2026

LP Celebrates 150th Anniversary

To begin a year of celebrations, this week Leathes Prior are delighted to reveal our refreshed brand identity and website.

Peter Lambert
05.01.2026

The Future of EOTs: Less Tax Relief, Still Strong Potential

Hugo Persad, Trainee Solicitor in our Corporate Team, summarises the impact of reduced Capital Gains Tax (“CGT”) relief on sales to Employee Ownership Trusts (“EOTs”) following the Autumn Budget.

Hugo Persad
18.12.2025

Autumn Budget 2025: Agricultural Property Relief & Business Property Relief Changes

It was announced in the 2025 Budget that from 6 April 2026, changes will be made to agricultural property relief and business property relief. These changes bring APR and BPR in line with the nil-rate band rules, meaning unused allowances can be transferred to a surviving spouse or civil partner. This is a significant step towards making estate planning easier for families who own farms or businesses.

Claire Woolliscroft TEP
18.12.2025

The Employment Rights Act 2025 is expected to come into force tomorrow (18 December 2025)

After an extended period of back-and-forth amendments between Parliament and the House of Lords, on 16 December 2025, the ERB finally received approval from the House of Lords, with the formality of Royal Assent due to take place tomorrow (18 December 2025). Head of LP Employment, Dan Chapman, explains...

Dan Chapman
17.12.2025

Charity of the Month: The Matthew Project

Leathes Prior is delighted to be supporting The Matthew Project as our Charity of the Month for December 2025. The Matthew Project supports young people and adults across Norfolk, Suffolk, and Essex to overcome issues around drugs, alcohol, and mental health, empowering them to rebuild confidence and lead fulfilling lives.

Rhiannon Bond
10.12.2025

Leathes Prior’s Milan Pandit appointed President of the Norfolk & Norwich Law Society

Leathes Prior Solicitors is proud to announce that Milan Pandit, Solicitor in our Corporate & Commercial Team, has been appointed President of the Norfolk & Norwich Law Society (NNLS) for 2025/26.

Peter Lambert
04.12.2025

Leathes Prior advises Mapus-Smith & Lemmon LLP on the acquisition Kathryn Gigg Chartered Accountants

Leathes Prior’s Corporate Team has advised Mapus-Smith & Lemmon LLP on the acquisition of Kathryn Gigg Chartered Accountants, Business Advisors & Tax Consultants.

Peter Lambert
03.12.2025

The Autumn Budget 2025: A Summary

Lucy Matthews, Solicitor in our Commercial Team summarises the Autumn Budget 2025 presented by Chancellor of the Exchequer, Rachel Reeves.

Lucy Matthews
26.11.2025

Commercial Lease Renewals: A guide for Landlords & Tenants

Commercial lease renewals are a topic that every commercial landlord and business that rents commercial premises should have at the forefront of their minds. It is essential for good succession planning, though it is often neglected until the expiry of an existing lease term is looming or once the existing term has come to an end and the tenant is holding over. In this article, our newly qualified solicitor, Maggie Berry explores the process that landlords and tenants can expect when navigating this complex area of law.

Maggie Berry
24.11.2025

Our Guidance, Your Legacy: What is a Will, and why should I make one?

Not only is a Will one of the most important steps you can take to protect your loved ones and ensure your wishes are respected, but it also limits the likelihood of a claim/dispute following your death. To ensure your loved ones and the causes you care about benefit from your estate, a Will is essential to ensuring this happens. Find out more in this article.

Ejike Ndaji
24.11.2025

Lease extensions: The essentials to getting started

Extending your lease can seem complex, but taking the right steps early can make the process much smoother. Jake Mowatt, Associate and Harry Smith, Trainee Solicitor in our Residential Property Team outlines the key essentials every leaseholder should understand prior to extending their lease.

Jake Mowatt
14.11.2025

Leathes Prior acted for Hatfield Investments Limited on the sale of Crossways Residential Home

Leathes Prior's Corporate, Commercial Property & Employment Teams acted for Hatfield Investments Limited on the sale of Crossways Residential Home.

Peter Lambert
13.11.2025

Leathes Prior assists Greenhaul Limited with sale to Ascent Acquisitions Limited

Leathes Prior’s Corporate Team has advised the shareholders of Greenhaul Limited, a family-owned Norfolk transport business, on its sale to Ascent Acquisitions Limited.

Peter Lambert
13.11.2025

Upcoming changes to bringing employment law claims: What these mean for you

The highly anticipated Employment Rights Bill (ERB) is set to increase the time limits in which employees can bring an employment tribunal claim. Gareth Stevens & Rose Woolterton explain what this means for employers & employees.

Gareth Stevens
12.11.2025

Get in Touch

By clicking submit, you agree to our Privacy Policy

Submit
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.