“under s.165 of the [DPA 2018] which requires us to take steps to respond to complaints including investigations to the extent that we feel is appropriate. It also requires us to inform the complainant of the outcome of their complaint.”
“cannot involve ourselves in disputes between data controllers and data subjects when there is a disagreement regarding what personal information is held and/or provided by an organisation. Ultimately as a regulator, we have to take what a controller says in good faith, our investigations under s.165 of the [DPA 2018] are not to prove matters beyond reasonable doubt, instead to provide an outcome based on the balance of probabilities. As such a SAR may not be the most appropriate route for obtaining the information or documents you seek. In light of this, you may wish to consider independent legal advice with a view to obtaining a Court Order to access the documents you require… …A case review is the final stage of the ICO’s case handling process which means that we won’t consider this complaint further. However, I recognise that you may continue to disagree with our view. It may be helpful to explain that you are entitled to take your own cases to court under data protection legislation, irrespective of our decision.”
“When you submit a complaint to The Information Commissioner’s Office (ICO) you are asked to provide supporting documents to evidence your data protection complaint. The ICO has very limited resources and we can only use those resources effectively if concerns are presented in a manner which is clear and concise, and where we are provided only with the appropriate evidence which is actually relevant to the appropriate elements of the legislation concerned. Unfortunately, you provided the ICO with a large volume of documents/correspondence which meant we were unable to determine the evidence we require to support your complaint. We did note that the FCA responded to your SAR and provided the following information in relation to any redactions applied: ‘You will notice that some redactions have been applied. There are two reasons for this. Firstly, we have removed the personal data of third parties which have no connection with your personal data. Secondly, we have removed information that is not ‘personal’ data at all and therefore falls outside the UK GDPR.’” … “At no point, through the assessment process, have you clarified the main data protection concerns beyond you being unhappy with the way in your SAR was handled by the FCA. Using the information available to us on this case, we were able to determine that the FCA responded to your SAR and provided information in regard to any redactions made. This is inline with our guidance and in accordance with UK GDPR legislation. We therefore cannot determine any infringement has occurred by the FCA on this occasion. This is what we implied when we advised you ‘At this stage we do not appear to hold clear evidence of an infringement of the legislation that we oversee in your case.’ If you believe the FCA has deliberately withheld your personal data, you will need to provide clear evidence to support this claim. This might include specific instances where you believe data was omitted or inconsistencies in the information provided. I hope this provides you with some clarification on how we have assessed your complaint and arrived at our decision outcome letter.”
“I submitted a request on26 October 2023 to the [ICO] to investigate a breach of the legislation by the [FCA]…. The ICO rejected my request by their e-mail dated26 January 2024 … Their decision not to investigate my complaint was based upon the following statement in the above referenced e-mail: At this stage we do not appear to hold clear evidence of an infringement of the legislation that we oversee in your case. The rejection was ostensibly confirmed by the ICO Team Manager in her e-mail of10 April 2024 … I say ostensibly because, rather surprisingly, her e-mail is totally devoted to pointing out that I was wrong to make my request under [FOIA] and that the ICO was correct in declaring it, and treating it as, a complaint under the [DPA 2018]. She did not confirm her caseworker's findings that there was no evidence of an infringement of the legislation but, since she declared the correspondence closed, we must assume that she was confirming the caseworker's findings. On the matter of which Act my complaint should have been considered under, I refer the Tribunal to the following extract from the ICO's website, drawn to my attention by the Parliamentary and Health Service Ombudsman (PHSO): A request does not have to include the phrases “subject access request,” “right of access,” or “section 45(1) of the DPA 2018”
“…in general, in section 166 cases, given their limited scope, all that will be necessary for the fair disposal of the application is for the Commissioner to put before the Tribunal the documentary trail demonstrating the steps taken in dealing with any complaint (as the Commissioner did in this case by disclosing the7 February 2023 email among others) or, if that does not tell the story, a short witness statement from the officer who dealt with the complaint may be appropriate. Since the Tribunal is not concerned with the merits of the complaint, what is required by way of disclosure or witness statement will in most cases be neither extensive or elaborate, and there is certainly no requirement for the Commissioner to put in evidence justifying or explaining the merits of the decision he took on the complaint.”