Why Organisations Refuse SARs
Understanding exemptions and your rights
Due to the Data (Use and Access) Act coming into law on 19 June 2025, this guidance is under review and may be subject to change. The ICO's guidance will be updated accordingly.
Organisations don't always have to give you all or any of the information you request. An organisation may withhold some, or all, of your personal information because of an exemption. Exemptions are in the law to protect particular types of information or how certain organisations work.
When Organisations Use an Exemption
When organisations use an exemption, they normally need to:
Tell you why
Explain why they are not completing your request for information
Explain their decision
Provide reasoning for why the exemption applies
Tell you how to challenge
Explain how you can challenge their decision (eg by submitting a complaint)
Sometimes it's acceptable for an organisation to refuse some or all of your request without telling you why. Organisations don't always need to tell you if they do or don't hold the requested information.
Common Exemptions Explained
What it means: The organisation believes you're not making a SAR because you truly want to exercise your legal right of access.
Examples include:
- Having no clear intention of exercising your right of access (eg if you make a request but then offer to withdraw it in return for some form of benefit from the organisation)
- Using your request to harass an organisation or cause disruption
To come to this decision, the organisation must consider each request on a case-by-case basis. They must also explain their reasoning to you and the ICO if necessary.
What it means: There is no set meaning of what makes a subject access request 'excessive'. However, organisations should consider whether the request is clearly unreasonable.
Examples include:
- It overlaps with other, previous requests for similar information (particularly if the organisation hasn't had the chance to respond to your first request)
- Your request asks for the same information as previous requests, but not enough time has passed (eg you're aware your information hasn't changed)
To come to this decision, the organisation must consider each request on a case-by-case basis. They must also explain their reasoning to you.
Responding to a SAR may involve giving out information about other people. Organisations must respect your right to get copies of your information, but they must also protect other people's rights over their information.
This means that if another person's information is included in the requested documents (eg that of a family member or colleague), the organisation might redact it or not provide it at all.
However, you may receive information which identifies another person if:
- That person gives their permission; or
- It is reasonable for the organisation to comply with your request without the other person's permission
The organisation must balance your right of access against the other person's rights under data protection law.
If your personal information is discussed or included in confidential communications between the organisation and their legal advisors (including in-house legal teams), they don't have to give it to you as part of your request.
This information is considered 'privileged', which means it should remain confidential between the organisation and the legal team.
Examples:
- If your insurance company asks for legal advice about a claim dispute involving you
- An employer asks for legal advice about a disciplinary matter involving you
In these examples, a response to a SAR would not include that information, even though it is about you.
Information can be withheld if disclosing it would prejudice the prevention or detection of crime, the apprehension or prosecution of offenders, or the collection of tax.
This is a qualified exemption, meaning the organisation must consider whether the public interest in disclosing the information outweighs the public interest in maintaining the exemption.
What to Do If Your SAR Is Refused
Check Their Reasoning
Have they explained which exemption applies and why? Is their reasoning sound?
Raise a Complaint
Ask the organisation to reconsider. While there's no formal "internal review" for SARs, they should respond to complaints promptly.
Complain to the ICO
If you're unhappy with their response, complain to the ICO. They have powers to order compliance.
Quick Reference: Exemptions at a Glance
| Exemption | What It Means | Must They Explain? |
|---|---|---|
| Manifestly Unfounded | No genuine intention to exercise rights; harassment | ✅ Yes |
| Excessive | Overlaps with previous requests; clearly unreasonable | ✅ Yes |
| Third-Party Data | Information identifies other individuals | ✅ Yes (with reasoning) |
| Legal Professional Privilege | Confidential legal advice communications | ✅ Yes |
| Crime & Taxation | Would prejudice crime prevention or tax collection | ✅ Yes |
- ICO – Exemptions: when can we refuse a SAR?
- UK GDPR Article 15 – Right of access
- Data Protection Act 2018 – Schedule 2 (Exemptions)
- Data (Use and Access) Act 2025 (forthcoming changes)
Last reviewed: March 2026. This guidance is based on current ICO guidance and may be subject to change following the Data (Use and Access) Act 2025.