How often do you think about the data that you hold about your clients, where it is held, and the rights they have to see what is in your files? What do you think you need to provide to a client who requests sight of the data you hold about them?

The Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR) give individuals the right to access the personal data that a firm holds about them.

These notes provide guidance for firms in the event that a client or their representative submits a request for the data that your firm holds.

The right of access

The right of access, or subject access, gives individuals the right to obtain a copy of their personal information held by your firm, as well as other supplementary information. Some firms call these a Data Subject Access Request (DSAR) to differentiate them from a Suspicious Activity Report (SAR).

It is a fundamental right for individuals to see all data that you hold, whether electronically or on paper. Electronic data includes the files you hold in your back-office systems, email exchanges (internal and external), WhatsApp messages and, for firms that use Slack, those internal exchanges.

Any request must be in writing. If your firm receives a DSAR you have 30 calendar days to respond and must provide the information free of charge.

Be aware that this is not restricted to factfinds, meeting notes and correspondence with product providers

If the wording of the request does not clearly identify the information that the individual is seeking, you may write to the individual within three working days asking for further clarification to assist in locating the information or data required. The reasons for holding client information will be set out in your firm’s Terms of Business and in your Privacy Notice. You may refer to these when responding to a DSAR.

What is a person entitled to?

Individuals have the right to obtain the following from an organisation:

  • Confirmation that you are controlling and/or processing their personal information
  • A copy of their personal information
  • Other supplementary information

In most cases, you can confirm whether you are processing a person’s personal information in general terms. However, this will depend on the nature of the request. If the request is for a specific piece of information, you must confirm or deny whether you are processing this information unless an exemption applies.

What can be redacted?

Firms can redact third-party personal data, legally privileged material and confidential references from a DSAR response. Under UK GDPR, individuals have a right to see their own personal data, but not information that compromises others or falls under specific legal exemptions. For example:

  • Other people’s personal data: Names, email addresses, contact details or opinions belonging to other identifiable individuals mentioned in the records. The rule of thumb is to redact information that identifies another person unless they give their permission.
  • Legally privileged material: Communications and advice shared between an organisation and its internal or external legal counsel.
  • Confidential references: References given or received by the organisation for employment, training or education purposes where confidentiality is expected.
  • Management intentions or negotiations: Records detailing corporate strategy or negotiations where disclosing personal data prematurely would prejudice those discussions—for example, those referring to a merger or acquisition.
  • Health and safety: Information that could harm someone’s physical or mental health if released.
  • Crime and taxation exemption: Data that, if revealed, would seriously hinder the prevention or detection of crime or the apprehension of offenders.

When redaction is not required

Organisations should balance privacy rights carefully. You do not automatically redact third-party data if:

  • The other person has given explicit consent to share their information.
  • It is entirely reasonable in the circumstances to disclose the information without consent. Consider your client’s rights to see the data you hold against the third party’s privacy.

What is the supplementary information?

At the beginning of this guidance, I listed that you need to provide your client with other supplementary information. Most of this information is within your firm’s privacy notice.

  • Purpose: Why you process clients’ personal data.
  • Categories: The specific types of personal data you hold.
  • Recipients: Who you share the data with, including outside organisations or specific categories of recipients.
  • Retention periods: How long you will store the data, or the specific criteria used to determine that timeframe. You may refer to the FCA’s document retention rules to provide the relevant detail.
  • Source of data: Where you obtained their information if you did not collect it directly from them.
  • Individual rights: Information on the client’s rights to request rectification if data is incorrect or out of date; request erasure, subject to the FCA’s retention rules; restrict processing; object to automated decision-making; and complain to the Information Commissioner’s Office.
  • Automated decisions: Details about any automated decision-making or profiling used, including the logic involved and the significance or likely consequences for your client. This may include underwriting processes.

Permitted exceptions for charging a fee

Your firm may charge a “reasonable fee” to cover administrative costs in these specific situations:

  • Manifestly unfounded or excessive requests: Where the request is repetitive or clearly designed to cause disruption or harassment for your firm.
  • Extra copies: Where the data subject asks for additional copies of information after the initial report has already been supplied.

Rules for charging

  • Administrative costs only: The fee must be based strictly on the actual administrative costs of providing the extra copies or dealing with the exceptional request—for example, staff time, photocopying and delivery costs.
  • Burden of proof: Your firm must be able to justify why a request is excessive or unfounded if challenged. The threshold for this is high.
  • Prompt notification: Your firm must inform the client about the fee without undue delay. You are not obliged to supply the duplicate or additional report until the fee is paid.

Care when recording information

As you can see, a client is entitled to see everything your firm holds about them. This includes internal emails and internal messages sent over communication platforms such as Slack, Teams and WhatsApp. Clients may submit a DSAR as part of a complaint when they have already expressed dissatisfaction with your firm. Be careful not to commit to a disclosable medium anything you would not want the client to see, or their barrister to read out in court should the client take it that far.

In summary

Clients have the right to see the data you hold about them. Be aware that this is not restricted to factfinds, meeting notes and correspondence with product providers. It will also include internal emails and other exchanges with colleagues. In these days of remote working, be aware that when you correspond with a colleague your words may be seen by the client.