Case Studies Access Request Complaints

 

Refusal of Access Request of a non-customer

The DPC received a complaint from an individual in relation to an access request made to an internet service provider. According to the individual, they rang the company regarding the possibility of switching broadband services and considered that the level of service received from the customer service agent was unsatisfactory. As a result, they made an access request for a copy of their personal data processed by the company.  

 
In response to the individual’s access request, the company sought further information from the individual including an account number.  The individual informed the company they could not supply an account number, as they were not a customer, merely a potential customer enquiring about switching their broadband service. In their response, the company advised the individual that without an account number they could not process the access request. On foot of this response, the individual proceeded to make a complaint to the DPC. Following receipt of this complaint, the DPC corresponded with the internet service provider to ascertain why the access request could not be processed without an account number, and to comply with the individual’s access request. 

The company promptly responded to the DPC accepting that the agent who responded to the individual should not have informed them that they could not process the access request. They also outlined that the agent involved did not follow the correct process for dealing with access requests from non-customers, and advised that additional data protection training would be provided to the agent. The company also provided the individual with a copy of their personal data. The individual confirmed that while they did receive a copy of their personal data, the matter was only resolved following the DPC’s intervention.

Key Takeaway

  • Under Article 15(3) of the GDPR, there is an obligation for an organisation to provide a copy of the personal data, whether the individual is a customer of the organisation or not. This particular case highlights the importance of data protection training including refresher training for all employees in customer facing roles to ensure that an individual’s right to access to their personal data is upheld in all instances and that appropriate and accurate information is provided to the public by organisations.

Case Studies Access Request Complaints

 

Seeking access to deceased siblings medical records

An individual contacted the DPC inquiring about how to access the medical records of their late sibling, who had tragically passed away as an infant many
years previously. Since both parents had also passed away several years ago, the individual was unable to obtain information about the circumstances surrounding the death of their sibling.

The DPC recognises the sensitive nature of such queries and always responds with empathy and respect. In this instance, the individual was informed that, as per Article 4(1) of the GDPR, personal data is defined as “any information relating to an identified or identifiable natural person (data subject).” However, as also outlined in Recital 27 of the GDPR, the law does not apply to the personal data of deceased persons. Notwithstanding the sensitive nature of the query raised, the DPC advised that while the organisation may choose to release the data they were seeking, unfortunately as outlined above, the DPC could not compel them to do so as there was no obligation on the organisation to do so under the GDPR. As a result, the DPC advised that data protection law could not be engaged in relation the issue in question, meaning the concerns raised were beyond the DPC’s remit. Unfortunately, this meant the Office could not assist the individual further in this matter.

Key Takeaway

  • Notwithstanding the sensitivity of cases such as this one, it is the obligation of the DPC to inform those raising a query with it that data protection legislation only covers a “natural person” and that data protection law does not grant access to personal data relating to deceased individuals. The DPC is conscious of the upset surrounding matters relating to deceased relatives and will always strive to communicate the facts as they relate to data protection in as empathetic a manner as possible when responding to queries of this nature.

Case Studies Access Request Complaints

 

Failure to respond to an Access Request

The DPC received a complaint with regard to an individual who made an access request under Article 15 of the GDPR to a public/state hospital for a copy of all personal information held concerning them. The response from the hospital remained outstanding after more than a month, whereas information provided to the DPC indicated that due the health of the individual this matter required urgent attention.  


The DPC contacted the Data Protection Officer for the Hospital Group by phone and email to inform them of the urgency of the complaint, and requested they respond to the individual’s representatives promptly, providing them with a copy of the individual’s personal information as part of the engagement. The hospital followed the instructions from the DPC.

Whilst the hospital acknowledged receipt of the request within one month of its receipt, the personal data the individual was entitled to was only provided to the individual following the intervention of the DPC.   

Key Takeaway

  • Organisations are required to implement appropriate organisational measures in place to ensure that they are in a position to respond to any rights requests within the stipulated timeframes under the GDPR. Organisations should not await the intervention of the Regulator to respond promptly to subject access requests. 

DPC Public Attitudes Survey 2025

19th June 2025

 To coincide with the publication of the 2024 Annual Report, the Data Protection Commission has also released the results of an independent Public Attitudes Survey. The survey, which was undertaken as part of a mid-point review of the DPC’s Regulatory Strategy 2022-2027, was conducted in May 2025. ...

DPC announces conclusion of investigation into use of facial matching technology in connection with the Public Services Card by the Department of Social Protection

12th June 2025

The Data Protection Commission (DPC) has today announced its final decision following the conclusion of an inquiry into the Department of Social Protection (DSP). This inquiry, which commenced in July 2021, examined the DSP’s processing of biometric facial templates, and usage of associated facial matching technologies, as part of the registration process for the Public Services Card. ...

Case Studies Transparency

 

Use of employee’s swipe-card data for disciplinary purposes

The complainant in this case was an employee who was the subject of disciplinary proceedings by their employer. An aspect of those proceedings concerned the complainant’s time keeping, and the employer sought to rely on swipe-card data derived from the complainant’s entry into and exit from the workplace during the relevant period. As a result of an internal appeal process, the employer subsequently agreed not to use the data for this purpose and removed it from the complainant’s disciplinary record. However, the complainant asked the DPC to continue its investigation of the complaint.

The DPC’s investigation focused on the data protection principle that data must be obtained and processed fairly . This includes an obligation to give data subjects’ information including the purpose or purposes for which the data are intended to be processed .

In this case, the employer had not informed the complainant of the use of swipe-card data for the purpose of disciplinary proceedings . (During the investigation, the employer informed the DPC that the complainant’s case was the only one in which it had used swipe-card data for disciplinary purposes .) Similarly, the employer had not informed the complainant or other employees that swipe-card data collected in the workplace was intended to be used for time-keeping purposes .

The employer had failed to inform the complainant about the use of swipe-card data for time-keeping and disci- plinary purposes . The DPC therefore concluded that the employer had not obtained and processed that data fairly .

This case demonstrates the importance of fairness and transparency in protecting data protection rights . Controllers such as employers may have valid legal bases for processing personal data, whether on grounds of performance of contract, legitimate interest or otherwise . However, the principles of data protection set out in Article 5 of the GDPR must be observed regardless of the legal basis that is relied on .

Case Studies Transparency

 

Processing of health data

The complainant was a member of an income protection insurance scheme and had taken a leave of absence from work due to illness. The income protection scheme was organised by the complainant’s employer. In order to claim under the scheme, the complainant was required to attend medical appointments organised by an insurance company. Information relating to the complainant’s illness was shared by the complainant with the insurance company only. However, a third-party company (whose involvement in the claim was not known to the complainant) forwarded information to the complainant’s employer regarding medical appointments that the complainant was required to attend. The information included the area of specialism of the doctors in question.

It was established that the insurance company was the data controller as it controlled the contents and use of the complainant’s personal data for the purposes of managing and administering the complainant’s claim under the insurance scheme . The data in question included details of the complainant’s illness, scheduled medical appointments and proposed treatment and was deemed to be personal data because the complainant could be identified from it and it related to the complainant as an individual .

During the course of the investigation, the data controller argued that the complainant had signed a form, which contained a statement confirming that the complainant gave consent to the data controller seeking information regarding the complainant’s illness . When asked by the DPC to clarify why it had shared the information regarding the complainant’s medical appointments with the third-party company (who was the broker of the insurance scheme), the data controller advised it had done so to update the broker and to ensure that matters would progress swiftly .

The data controller stated it had a legislative obligation to provide the complainant with certain information . In particular, that the data controller was obliged to inform the complainant as to the recipients or categories of recipients of the complainant’s personal data . The DPC pointed out that, while the data controller had notified the complainant that it might seek personal data relating to them, it had failed to provide sufficient information to the complainant as regards the recipients of the complainant’s personal data .

Data protection legislation also requires that data, which are kept by a data controller, be adequate, relevant and limited to what is necessary in relation to the purposes for which the data were collected . The DPC examined the reason given by the data controller for disclosing information about the nature of the complainant’s medical appointments (i .e . to update the broker and to ensure matters progressed smoothly) . The DPC was of the view that it was excessive for the data controller to disclose information regarding the specific nature of the medical appointments, including the specialisms of the doctors in question, to the third party company .

The DPC pointed out that, under data protection legislation, data concerning health is afforded additional protection . The DPC was of the view that, because the information disclosed by the data controller included details of the specialisms of the doctors involved, it indicated the possible nature of the complainant’s illness and thus benefitted from that additional protection.

The DPC confirmed that, because of the additional protection, there was a prohibition on processing the data in question, unless one of a number of specified conditions applied . For example (and of relevance here), the personal data concerning health could be legally processed if the complainant’s explicit consent to the processing was provided to the data controller . The DPC then considered whether the complainant signing the claim form (containing the paragraph about consent to the data controller seeking information, as described above) could be said to constitute explicit consent to the processing (disclosure) of the information relating to the complainant’s medical appointments . The DPC noted that it could be said that the complainant’s explicit consent had been given to the seeking of such information by the data controller . However, the complainant had not given their explicit consent to the giving of such information by the data controller to third parties . On this basis, the DPC held that a further contravention of the legislation had been committed by the data controller in this regard .

Under Article 13 of the GDPR, where personal data are collected from a data subjects, the data controller is required to provide the data subject with certain information at the time the personal data are obtained, such as the identity and contact details of the data controller and, where applicable, its Data Protection Officer, the purpose and legal basis for the processing and the recipients of the data, if any, as well as information regarding the data subject’s rights . This information is intended to ensure that personal data are processed fairly and transparently . Where the personal data have been obtained otherwise than from the data subject themselves, additional information is required to be provided to the data subject under Article 14 of the GDPR . This information must be given in a concise, transparent, intelligible and easily accessible form .

Additionally, the data minimisation principle under Article 5(1)(c) requires that personal data be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed . This means that the period for which personal data are stored should be limited to a strict minimum and that personal data should be processed only if the purpose of the processing could not reasonably be fulfilled by other means.

Finally, data controllers should note that personal data concerning health is considered a “special category of personal data” under Article 9 of the GDPR and is subject to specific rules, in recognition of its particularly sensitive nature and the particular risk to the fundamental rights and freedoms of data subjects which could be created by the processing of such data . The processing of medical data is only permitted in certain cases as provided for in Article 9(2) of the GDPR and sections 45 to 54 of the Data Protection Act 2018, such as where the data subject has given explicit consent to the processing for one or more specified purposes.