Back to Blog

ICO Opens SAR Investigation: What Private Clinics Should Fix Before They Get a Similar Letter

Sep 16, 2026
ICO Opens SAR Investigation: What Private Clinics Should Fix Before They Get a Similar Letter

The Information Commissioner's Office announced on September 11, 2026 that it had opened a formal investigation into a public body's handling of Subject Access Requests. The ICO hasn't published the full details yet, but the pattern is familiar: an organisation takes too long, redacts too much, or loses track of requests entirely, and eventually someone complains.

Public body or private clinic, the underlying GDPR obligation is identical. Article 15 of UK GDPR gives any individual the right to request a copy of the personal data you hold about them. You have one calendar month to respond. No exceptions for being busy, understaffed, or mid-holiday-season.

Most clinic owners I've spoken to treat SARs as a rare event and deal with them ad hoc when they arrive. That's fine until it isn't.

What the ICO Investigation Actually Signals

The ICO doesn't open formal investigations for fun. They're resource-constrained and tend to act when there's a pattern of complaints or a high-profile failure. When they publish findings from this one, those findings will set the practical bar for what "adequate" SAR handling looks like across all sectors, not just public bodies.

Private clinics are not outside their reach. The ICO has issued fines to small organisations before, including a 2022 monetary penalty against a private dental practice for failing to respond to a SAR within the statutory timeframe. The fine was £1,500, which sounds small, but the accompanying reputational damage and the time spent dealing with it was considerably more costly.

The ICO's own guidance (updated in January 2024) makes clear that organisations must have a documented process for receiving, logging, and responding to SARs. "We had a look and couldn't find anything relevant" is not a process.

The Three Places Clinics Actually Go Wrong Failing to recognise a SAR when it arrives

A SAR doesn't have to say "Subject Access Request" on the tin. An email from a patient saying "can you send me everything you have about me" is a valid SAR. So is a letter saying "I want to see my records." Receptionists sometimes log these as general enquiries and forget them. By the time anyone realises, three weeks have gone.

Train whoever handles incoming correspondence, whether that's a receptionist, practice manager, or an email alias, to flag anything that looks like a data access request the same day it arrives. The clock starts ticking on receipt, not on the day you get round to reading it.

Not knowing what data you actually hold

This is the one that catches clinics out. You might hold patient data in your practice management system, a separate email account, WhatsApp messages to patients, a paper file in the back office, and a spreadsheet someone built two years ago that nobody uses any more. A SAR requires you to search all of it.

Go through the exercise now, before you get a request. Write down every place patient data could live. That list is your search scope when a SAR lands.

Overclaiming exemptions

UK GDPR does include exemptions that let you withhold some information, for example, data that would reveal the identity of a third party who hasn't consented to disclosure, or information that might cause serious harm to the patient's physical or mental health (Schedule 2, Part 5 of the Data Protection Act 2018, the "health data exemption"). Clinics sometimes apply these too broadly, refusing to release anything because a clinician mentioned a colleague by name in a note.

The exemptions are narrow and specific. If you're withholding anything, you need to be able to point to the exact legal basis and tell the requester you've withheld something (even if you can't say what). Blanket silence is not an option.

A Process You Can Actually Run

This doesn't need to be complicated. It does need to exist and be written down.

A workable SAR process for a small clinic looks roughly like this:

  • A named person is responsible for SAR responses. Not "the practice manager, or whoever is available." One person, with a deputy.
  • Incoming requests are logged in a central place with the date received and the response deadline (one calendar month from receipt, or three months if you extend under the "complexity" provision, which requires written notice to the requester within the first month).
  • A search checklist covers every data location you identified above.
  • The response is reviewed by the responsible person before it goes out.
  • Completed requests are filed, not deleted.

If you use HealSuite, you can build the logging and deadline-tracking into your existing admin workflow rather than running a separate spreadsheet alongside it. But even a shared Google Doc works if everyone uses it.

The Third-Party Complication

A common scenario in aesthetics and private GP clinics: a patient requests their records, but the records contain notes about a family member who also came in, or a referral letter that names another clinician's opinion. You can't simply redact everything that mentions another name. You have to weigh the third party's privacy against the requester's right of access, considering whether the third party has given consent and whether it's reasonable to provide the information without that consent.

The ICO's guidance on this (published at ico.org.uk under "Right of access") runs to several pages and is worth reading in full if you haven't. I'm not a solicitor and I'm not going to summarise it here and have you act on a paraphrase. Read the source.

What to Actually Do This Week

If your clinic doesn't have a documented SAR process, write one before Friday. It doesn't need to be long. A single page covering: who receives requests, who logs them, what the deadline is, where you search, who reviews the response, and where completed responses are filed.

Then test it. Send yourself a pretend SAR and follow the process. See how long it takes and where it breaks down.

If you last reviewed your data mapping more than twelve months ago, add a data audit to your Q4 calendar now. Patient data has a habit of accumulating in places nobody intended, and the ICO's expectations around data minimisation under Article 5(1)(e) mean you should be deleting data you no longer need, not just cataloguing it.

The ICO investigation will publish findings eventually. By the time it does, your process should already be in place.

Ready to modernise your practice?

Join thousands of UK healthcare professionals using HealSuite to manage their clinics.

Enquire now