What happened?
Mike Ashley, former owner of Newcastle United F.C. and founder of Frasers Group, submitted a data subject access request (DSAR) to HMRC for all information related to him amid an ongoing tax dispute. HMRC provided limited, heavily redacted data. They refused most of the request, citing exemptions from the Data Protection Act 2018.
Ashley argued that HMRC had:
- provided an inadequate response;
- misapplied the concept of personal data;
- conducted insufficient searches; and
- failed to provide data in a comprehensible manner.
In December 2024, the court ruled largely in Ashley’s favour. This required HMRC to reconsider its response to his DSAR (Ashley v HMRC).
Why is the judgement important?
The judgement is important because it’s one of the few times a court has ruled on how a controller is to respond to a DSAR (Harrison v Cameron & Anor is another). The key takeaways for controllers are:
-
Scope of a DSAR
Broad requests require comprehensive searches across all business divisions, not just specific departments. A controller shouldn’t assume that a search should be limited to a specific department – an approach taken by HMRC. It’s, therefore, important to know where in your business data is held.
-
Meaning of ‘Personal Data’
Whilst a controller should always consider what is personal data on a case by case basis, the key takeaway is that data should be provided where it is ‘linked’ to an individual by a ‘continuum of relevance’. In this case, although the data related to Mr Ashley’s properties (as opposed to him in an individual capacity), the data indirectly related to him, so HMRC should have disclosed it.
-
How to determine a ‘reasonable and proportionate’ search
The court commented that HMRC should have been fully aware of its obligations and have processes in place to deal with DSARs. This implies that delays or non-compliance related to not being prepared to deal with DSARs would be considered unacceptable, highlighting the importance of having a DSAR policy and training for staff.
Helpfully for controllers, however, the court made clear that in determining whether replying to a DSAR would be ‘disproportionate’, controllers can consider the time it would take to fully reply, including redacting data and applying any applicable exemptions. Many controllers often only consider the time it would take to just search for data.
-
Providing data in a transparent and intelligible manner:
The court considered it too narrow and insufficient to provide decontextualised pieces of data in response to a DSAR. When responding to a DSAR, the controller should provide the data subject with contextual information as well as their personal data, so that they can fully understand how their data is processed, and for what purpose. Controllers, therefore, will need to give further thought to any redaction process. This should ensure that contextual information is provided so far as it can be without disclosing, for example, third party personal data.
Future considerations
Handling DSARs can be complex and time-consuming. Implementing a robust DSAR policy and training can streamline the process and ensure compliance with data protection laws.
If your business already has a DSAR policy, consider whether in light of Ashley v HMRC, you need to update it to reduce the risk of failing to respond adequately.
If you need help with your DSAR policy and/or processes, or replying to a specific DSAR, please contact our Commercial team or call +44 (0)3333 231 580.