Can You Just Say No to a Data Access Request?

Data access requests (DSARs or SARs) are the number one thing people complain to Ireland's Data Protection Commission (DPC) about, in fact it accounted for 42% of all complaints in 2025. Consistent with our experience of DSARs, usually the real issue isn't data protection at all, it's a falling-out at work or bad customer service. However, a DSAR lands on your desk, the DPC expects you to handle it properly. Two case studies from its newly published report for 2025 show what “properly” looks like and what doesn't.

“We're too small to deal with this” isn't a valid reason to refuse

An independent publisher turned down a data access request, arguing it was too small a company to carry out the review involved and that the request was, in its view, excessive. The DPC didn't accept that. Every organisation, no matter its size, is expected to have measures in place that let it respond to rights requests within the legal timeframe.

Takeaway: If a request is broad, don't refuse it outright. Releasing data in phases, and talking to the person about narrowing the scope, is a far safer approach than saying no, and it's more likely to resolve things before they turn into a formal complaint.

When is it actually OK to charge a fee?

A GP was asked, again, for a copy of a patient's medical records, a repeat of a request already answered in full, with nothing new added. The GP wanted to charge an administrative fee to cover the cost of handling it. The DPC said that was fine. DSARs are normally free of charge, but where a request is genuinely repetitive, an organisation can either charge a reasonable fee or decline to act on it.

Takeaway: Charging a fee is only permitted in narrow circumstances, like a genuinely duplicate request — and the burden is on you to show that's what it is. Keep clear, documented reasoning for any fee you charge, in case it's challenged.

Need a data access request process that would hold up under the DPC's spotlight? Privacy Path helps Irish and UK businesses build practical, plain-English GDPR procedures. Get in touch at privacypath.ie.

Next
Next

What Should You Look for When Choosing a GDPR Consultancy Service?