Back in March 2020 we reported here on some new guidance from the Information Commissioner’s Office concerning DSARs. In particular, we looked at what it said about the employer’s rights not to comply with a DSAR to the extent that it was manifestly unfounded or manifestly excessive, and concluded that despite the superficially encouraging words of the guidance, The Law would take an altogether more restrictive view of those two exemptions, leaving them both basically neutered.
Three years, a pandemic and Brexit later, the ICO has published some more guidance last week which takes another look at those two possible get-outs for employers in receipt of DSARs. Does this new version give them any greater joy? How much EU-sourced red-tape has been consigned to the flames this time?
The “manifestly unfounded” section begins unpromisingly. A request may fall into that exemption if “the worker clearly has no intention to exercise their right of access; or the request is malicious in intent . . . for example if the person explicitly states in the request itself or other communications that they intend to cause disruption“. This is unchanged from the last version and since you would need to be a weapons-grade halfwit to say either of those things in your DSAR, we must look elsewhere for help. For example, what about the request might suggest that it is made with “malicious intent“? Where the requester is “making unsubstantiated accusations against you or specific employees which...
Read Full Story:
https://news.google.com/rss/articles/CBMiWWh0dHBzOi8vd3d3LmVtcGxveW1lbnRsYXd3...