Who's allowed to ask for someone else's data and what if it's already gone?

Following on from our last post on refusing and charging for data access requests (DSARs), here are two more case studies from the DPC's 2025 case studies booklet, this time on requests made on someone else's behalf, and what happens when the data being asked for simply doesn't exist anymore.

Being a family member doesn't automatically give you access rights

A family member and primary carer of an individual with additional needs, living in residential care, asked for a copy of that person's personal data. The facility refused, because the family member didn't hold the legal authority needed to act on the individual's behalf. Rather than shutting the conversation down completely, the facility offered a meeting to talk through the records so the carer could stay informed. The DPC found this struck the right balance between the data subject's rights and the carer's role.

Takeaway: A close family or caring relationship, on its own, doesn't give someone the right to exercise another adult's data protection rights. Verify legal authority before releasing records, but look for other ways to keep carers and family members engaged without handing over the data itself.

You can't hand over data that no longer exists, but you do need to say so upfront

A hospital was asked for video and audio recordings made during someone's participation in a medical study. The video had been automatically overwritten after two weeks, and the audio, though it may have still existed, couldn't be accessed because the hospital no longer had the specialist software to open it. The complainant also pointed out they'd never been told the footage would be deleted so quickly. The DPC accepted the hospital had responded in full, since the data no longer existed, but found it fell short on transparency, because participants hadn't been told about the retention period in advance.

Takeaway: You're not expected to produce data you no longer hold. But you are expected to tell people, upfront, how long you keep their data. Clear, communicated retention periods head off a lot of DSAR problems before they start.

Need a data access request process that would hold up under the DPC's spotlight? Privacy Path helps Irish and UK businesses build practical, plain-English GDPR procedures. Get in touch at privacypath.ie.

Next
Next

Can You Just Say No to a Data Access Request?