UK High Court Clarifies DSAR Rules: You Owe the Data, Not Every Document

Table of Contents

A U.K. High Court decision is giving privacy teams useful guidance on one of the most persistent problems in handling data subject access requests: exactly how much information does an organization have to hand over?

The answer is more nuanced than either extreme.

A data subject access request, or DSAR, does not automatically entitle someone to every document containing their name or personal information.

But a controller also cannot strip personal data from its surrounding context so aggressively that the response becomes meaningless.

And perhaps most importantly for large organizations, a company cannot use its own departmental structure to artificially narrow the scope of a request.

Those principles come from Ashley v. The Commissioners for His Majesty’s Revenue and Customs, a January 2025 High Court decision that has received renewed attention following a September 2026 analysis by the International Association of Privacy Professionals.

The case provides a useful roadmap for companies trying to balance a data subject’s access rights against the practical reality of searching thousands of emails, documents, systems and databases.

The Case Started With a Tax Investigation

Michael Ashley submitted a subject access request to HM Revenue & Customs in September 2022.

The request sought information HMRC held about him in connection with an inquiry into his 2011-2012 tax return.

The tax investigation was primarily being handled by HMRC’s Wealthy and Mid-Size Business Compliance department, but another part of HMRC, the Valuation Office Agency, was also involved.

HMRC did not provide Ashley’s personal data within the required period.

After litigation began, the agency eventually produced a series of schedules containing personal information extracted from hundreds of documents.

According to the High Court judgment, HMRC provided one schedule based on 118 documents, another involving 180 documents, additional material from 19 documents and then another schedule covering 15 documents.

It ultimately also provided personal data extracted from 311 documents held by the Valuation Office Agency.

HMRC acknowledged that its original handling of the request violated Article 15 of the U.K. GDPR because information that should have been provided in December 2022 was not disclosed until much later.

But the litigation continued because Ashley and HMRC disagreed over something more fundamental: what exactly did the right of access require HMRC to produce?

A DSAR Cannot Be Narrowed Because of an Internal Org Chart

One of the most useful parts of the decision concerns how an organization defines the scope of a request.

HMRC argued that the request should effectively be treated as relating to the Wealthy and Mid-Size Business Compliance department that was conducting the tax inquiry.

The Valuation Office Agency operated separately and had its own internal processes for dealing with access requests.

The court did not accept that internal distinction as a basis for limiting the request.

The request sought information held in connection with the tax inquiry. The Valuation Office Agency was part of HMRC and had participated in that same inquiry.

An organization’s internal administrative structure does not rewrite the request made by the individual.

The IAPP summarized the principle succinctly: controllers should interpret the scope of a DSAR objectively rather than narrowing it for administrative convenience.

That has practical consequences well beyond government agencies.

Consider an employee who asks a multinational company for personal data connected to an internal investigation.

The relevant information might exist within:

  • Human Resources;
  • Legal;
  • IT security;
  • the employee’s business unit;
  • corporate email;
  • Slack or Microsoft Teams;
  • an outside investigation firm; and
  • a regional subsidiary.

A company cannot necessarily decide that the DSAR concerns only HR because that happens to be where the request arrived.

The scope comes from the substance of the request and the data processing involved, not the company’s preferred internal workflow.

That Does Not Mean Organizations Must Search Everywhere

The Ashley decision should not be read as requiring unlimited searches across every system whenever somebody submits a broad DSAR.

The relevant standard is a reasonable and proportionate search.

That principle, already reflected in earlier U.K. case law, has since been expressly written into the U.K. GDPR through the Data (Use and Access) Act 2025.

Section 78 of the Act amended the access provisions to clarify that a controller is required to provide information it can locate following a reasonable and proportionate search. The amendment applies retrospectively from January 1, 2024.

That is an important limitation.

The right of access is substantial, but it is not an obligation to perform an unlimited forensic investigation regardless of cost, complexity or likelihood of locating relevant data.

The harder operational question is determining what is reasonable.

A company should be able to explain why particular repositories, custodians, date ranges or systems were searched and why others were excluded.

That makes DSAR documentation increasingly important.

If a dispute reaches a regulator or court, the organization may need to show not simply that someone ran a search, but why the search methodology was reasonable given the request.

A DSAR Gives Access to Personal Data, Not Automatically to Documents

The second major issue in Ashley involved a question privacy teams encounter constantly.

If someone’s personal data appears inside a document, does the organization have to provide the entire document?

Generally, no.

The High Court reaffirmed the established distinction between a right to personal data and a general right to documents.

Article 15 requires the controller to provide a copy of the personal data undergoing processing.

It does not convert the U.K. GDPR into a general-purpose litigation discovery mechanism.

A requester therefore cannot necessarily demand every email, report, spreadsheet, investigation memo or internal document in which their personal data appears simply because the document exists.

The IAPP’s analysis describes this as the fundamental principle that access is a right to personal data rather than a general right to documents.

This distinction is particularly important when a DSAR is made during an employment dispute, commercial lawsuit or regulatory disagreement.

The individual may want the documents.

The data protection law gives them access to their personal data.

Those are not always the same thing.

But Extracting a Name From a Document May Not Be Enough

The ruling becomes more interesting when it addresses context.

HMRC had responded to the request largely by extracting Ashley’s personal data from documents and placing the information into schedules.

That can be a perfectly legitimate way to respond to a DSAR.

But some of the resulting entries were effectively isolated snippets, including instances containing little more than Ashley’s name or initials.

The question was whether those fragments were actually meaningful to the person receiving them.

The High Court concluded that Article 15 must be read together with Article 12, which requires information to be provided in a concise, transparent, intelligible and easily accessible form.

Where removing personal data from the original document makes it unintelligible, the organization may have to provide additional context.

That could mean a larger passage of an email.

It could mean several paragraphs from a report.

In some circumstances, it could mean providing an entire document or an extract from a database.

The court stressed that this additional context is required where it is necessary to make the personal data intelligible and allow the individual to effectively exercise their data protection rights.

Context Does Not Mean Automatically Providing the Entire File

There is an important limit here too.

The court did not say that whenever context would be useful, a controller has to disclose the complete underlying document.

The requirement is narrower.

Additional information becomes necessary when the personal data cannot otherwise be understood well enough for the individual to exercise their rights.

The judgment repeatedly treated this as a case-specific test.

The High Court said the need to provide additional contextual material does not undermine the underlying rule that access is to the data rather than to the document itself.

This distinction gives privacy teams some flexibility.

Suppose an email says:

“John Smith has repeatedly arrived late to work. We should discuss whether this requires a formal warning.”

Providing only:

“John Smith”

would technically reproduce personal data but would tell John almost nothing about how his information was being processed.

The relevant surrounding sentence may therefore need to be disclosed.

That does not necessarily mean the company must provide the entire 20-message email chain containing unrelated information about other employees.

The objective is intelligibility, not wholesale document production.

This Matters for Automated DSAR Tools

The decision also exposes an important limitation of poorly configured DSAR automation.

Modern privacy platforms can search repositories, locate names and identifiers, identify duplicate records and help redact information relating to third parties.

Those tools can substantially reduce the amount of manual work required to fulfill access requests.

But simply extracting every occurrence of someone’s name may produce a technically complete but practically useless response.

An automated system needs enough contextual awareness to distinguish between information that makes sense independently and information that becomes meaningless when extracted from its source.

Human review remains important in that process.

A privacy professional may need to determine whether the relevant response should contain one sentence, a paragraph, an entire email or a document.

The technology can find the data.

Judgment is still required to decide how much context must accompany it.

The Decision Also Shows Why Data Mapping Matters

The HMRC dispute illustrates another problem familiar to privacy teams: personal data does not respect organizational boundaries.

A company might think a customer relationship belongs to Sales while copies of the same customer’s information exist in:

  • Salesforce;
  • customer support software;
  • billing systems;
  • marketing platforms;
  • email;
  • fraud prevention systems;
  • analytics platforms; and
  • data warehouses.

If a DSAR is scoped incorrectly at the start, an organization can spend substantial time conducting technically competent searches and still produce an incomplete response.

That is essentially one of the lessons identified by the IAPP: extensive effort later in the process does not necessarily cure an incorrect interpretation of the request at the beginning.

This is where maintaining accurate records of processing activities and data maps becomes operationally useful rather than simply a documentation exercise.

When someone submits a DSAR, the organization should already have a reasonable understanding of which systems and business functions are likely to contain the relevant personal information.

Privacy Teams Should Document Why They Searched What They Searched

The reasonable-and-proportionate standard also changes what good DSAR evidence looks like.

A mature process should preserve information about the search itself.

That might include:

  • how the request was interpreted;
  • which business functions were considered relevant;
  • which systems were searched;
  • which identifiers and search terms were used;
  • which date ranges were applied;
  • why certain repositories were considered outside scope;
  • how duplicate information was handled; and
  • which exemptions or third-party rights affected disclosure.

That documentation can become important when someone challenges the completeness of the response.

An organization that can show a structured process is in a very different position from one whose explanation is simply that an employee searched Outlook and exported what appeared.

DSARs Are Not Litigation Discovery, but They Cannot Be Treated as a Checkbox

Ashley v. HMRC ultimately draws a useful middle line.

Individuals do not receive a general legal right to every document mentioning them simply because they submit a subject access request.

Controllers can provide extracted personal data rather than automatically turning over original files.

But the response has to be meaningful.

An organization cannot provide disconnected names, initials or fragments when the surrounding information is necessary to understand how the personal data is being processed.

Nor can a controller decide that relevant information is out of scope merely because another department, subsidiary or internal team happens to hold it.

And following the Data (Use and Access) Act 2025, the U.K. GDPR now expressly recognizes that the search itself must be reasonable and proportionate.

For privacy teams, that produces a fairly practical rule.

Start by interpreting the request correctly.

Understand where the relevant data is likely to exist.

Conduct and document a reasonable search.

Provide the personal data rather than automatically disclosing entire documents.

But when a data extract loses its meaning outside the source document, give the individual enough context to understand it.

That is a more demanding standard than simply running a search and exporting results.

It is also considerably more manageable than treating every DSAR as full-scale document discovery.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.