22 reader checks this week

DPC Report Highlights Dispute-Driven Data Access Requests

| By Legal News Team | Updated
DPC Report Highlights Dispute-Driven Data Access Requests

The Irish Data Protection Commission has once again highlighted a persistent trend in its latest annual report and accompanying case studies booklet for the year 2025. Published at the end of June 2026, the comprehensive review underscores that Data Subject Access Requests remain the primary source of friction between individuals and organisations across the Republic of Ireland. Accounting for a staggering forty-two per cent of all complaints lodged with the regulatory body, these requests allow individuals to obtain a copy of their personal data. However, the sheer volume of these inquiries indicates a landscape where data rights are increasingly intertwined with broader personal and professional conflicts.

As noted by the Data Protection Commission, a significant proportion of these access requests are not driven by pure data protection concerns. Instead, they frequently serve as a precursor to, or a weapon within, deeper underlying disputes. It is common practice for individuals to submit an access request while simultaneously preparing a case for the Workplace Relations Commission or contemplating a personal injury claim through the Injuries Resolution Board. Furthermore, as cases progress towards the Court Service, the distinction between a legitimate data privacy request and a back-door attempt at early legal discovery becomes increasingly blurred. Disgruntled employees and dissatisfied customers often utilise the statutory mechanism to force organisations to disclose internal communications, thereby applying pressure during ongoing disputes. Consequently, Irish businesses and public bodies must navigate these requests with extreme care, recognising that a mishandled response could exacerbate an already volatile legal or regulatory situation.

No Exemptions for Small Enterprises

The regulatory framework of the General Data Protection Regulation does not offer a free pass to organisations simply because they operate on a smaller scale. This principle was starkly illustrated in a case study involving an independent publisher that attempted to refuse an access request outright. The company argued that its limited resources made the extensive review of records manifestly unfounded and excessive. The Data Protection Commission firmly rejected this defensive posture. The burden of proof remains firmly on the data controller to justify any refusal or delay. The regulator noted that all entities processing personal data are legally obligated to implement appropriate organisational and technical measures. These measures must ensure that the organisation is fully capable of responding to rights requests within the strict statutory timeframes, regardless of its administrative headcount or financial limitations.

Administrative Fees and Repeat Requests

While the fundamental premise of the General Data Protection Regulation dictates that individuals should be able to access their personal data free of charge, there are specific exceptions designed to protect data controllers from unreasonable administrative burdens. A notable case involved a general practitioner who sought to charge a fee for providing a copy of medical records. Crucially, the patient had submitted a repeat request for the exact same information, introducing no new elements or additional data queries. The regulatory body confirmed that the medical practitioner was entirely within their rights to levy a reasonable administrative fee in this specific scenario. This ruling provides a degree of reassurance to Irish healthcare providers and other heavily burdened sectors, confirming that they are not expected to absorb the costs associated with duplicate and vexatious demands.

Navigating Third-Party Requests and Vulnerability

Handling access requests becomes particularly complex when third parties attempt to access data on behalf of vulnerable individuals. In one sensitive case reviewed by the Commission, a family member who acted as the primary carer for a resident with additional needs submitted a request for the resident's personal data. The residential care facility refused to release the formal records, correctly identifying that the family member lacked the explicit legal authority, such as an enduring power of attorney or wardship, required to act formally on the individual's behalf. However, rather than simply shutting down communication, the facility arranged a face-to-face meeting with the carer to discuss the records contextually. The Data Protection Commission praised this nuanced approach, finding that the facility successfully balanced the strict privacy rights of the data subject with the practical need to support the family member in their essential caring capacity.

Data Retention and the Importance of Transparency

A fundamental reality of data protection law is that an organisation cannot provide data that it no longer possesses, but it must be transparent about how and when data is destroyed. This was highlighted when an individual complained about a hospital's refusal to provide video footage and audio files generated during a medical study. The hospital demonstrated that the video footage had been automatically overwritten after a standard two-week retention period, while the audio file was inaccessible due to a lack of specialist software. The regulator concluded that the hospital had technically fulfilled the access request, as the requested data effectively no longer existed in a retrievable format. However, the Commission strongly criticised the hospital for failing to clearly inform the participant about these retention periods and technical limitations at the outset of the study, underscoring a significant breach of transparency obligations.

Ultimately, the latest publication from the Data Protection Commission serves as a critical reminder for all entities operating within the Irish jurisdiction. The consistent themes emerging from these case studies point toward the absolute necessity of proactive engagement with individuals, meticulous documentation of all decision-making processes, and unwavering transparency regarding data handling practices. As data access requests continue to dominate the regulatory landscape, organisations must treat their compliance procedures not merely as an administrative afterthought, but as a core component of their operational risk management strategy.

Free Claim Assessment

Find out if you have a valid claim — free, no obligation.

Start Free Assessment