Data protection, client information, and subject access requests

Jonathan Swift QC considers the lines of defence available to firms faced with a subject access request, and whether they should be treated as data controllers at all
All law firms are data controllers under the Data Protection Act 1998 (DPA). Two recent decisions of the Court of Appeal highlight the risk that client information held by firms can be vulnerable to disclosure through subject access requests under the DPA. The cases are Dawson-Damer v Taylor Wessing LLP [2017] EWCA Civ 74 and Deer v University of Oxford [2017] EWCA Civ 121. But how great is this risk?
The risk arises when a DPA subject access request is directed to a law firm by someone who is not that firm’s client. The requestor only asks to see their personal data, but that information may well be held in the firm’s client files – particularly if the requestor is in dispute with the client. The judgments in Dawson-Damer and Deer make important points about the lines of defence that are available to a firm facing this type of request, but there is also one important issue not raised in either case, which goes to whether firms should be treated as data controllers at all when it comes to client information.
Legal professional privilege
The most visible defence is the section 10, schedule 7 DPA exemption, covering information that is subject to legal professional privilege (the LPP exemption). In Dawson-Damer, the court confirmed this exemption could be relied on by a solicitor to the extent that any person could assert LPP against the requestor in respect of information held by the solicitor.
The LPP exemption may be a solution in many cases, but not in all, as Dawson-Damer demonstrates. There, the solicitor’s clients were trustees, and the requestor was a beneficiary of the trust. The court accepted the LPP exemption would cover information that was subject to litigation privilege, but concluded that the exemption would not prevent disclosure if only legal advice privilege could be asserted because, on the facts of that case, that privilege was held jointly by the trustees and the beneficiary.
Another, more run-of-the-mill issue is that the LLP exemption will often not provide a complete answer because the contents of solicitors’ files are rarely limited to LPP material – in particular when the file is not a litigation file. Here, a second line of defence can come in. In Dawson-Damer and in Deer, the court readily accepted that a data controller need undertake only a proportionate (not an exhaustive) search for disclosable personal data. So, depending on the circumstances, it may be too difficult, time consuming, or expensive to separate exempt information (or third-party personal data) from disclosable information.
But, as the judgment in Dawson-Damer made clear, this defence must be supported by evidence; the solicitor must be able to demonstrate why it would be disproportionate to respond to the request. In many instances it will be impossible to justify a blanket refusal. The information will most likely be electronically stored, and when it comes to searches and search techniques there is obvious scope here to read across from the e-disclosure provisions in the Civil Procedure Rules practice direction 31B.













