Guide · Data & Privacy

Missing SAR data

Missing SAR data: test search methodology across email, Teams, calls, notes, archives, backups, personal devices, processors, deletions and exemptions.

A thin SAR response is not proved incomplete merely because you expected more. The strongest challenge identifies specific missing data, the systems or custodians likely to hold it, and why the search appears unreasonable or incomplete.

Under the current UK GDPR right-of-access framework, controllers must make a reasonable and proportionate search for requested personal information. The ICO’s updated guidance expressly discusses electronic archives, backups, deleted information, emails, different locations and personal devices. That makes a missing-data challenge an evidence exercise: reconstruct what should exist, compare it with what was disclosed, then ask targeted questions about the search.

Key points

  • A SAR gives access to your personal information, not automatically every document containing your name or every document connected with your dispute.
  • The controller must make a reasonable and proportionate search; it does not have to perform technically extreme reconstruction of genuinely deleted data.
  • Archived or backed-up data is not automatically outside scope merely because it is inconvenient to retrieve.
  • Emails, Teams/Slack/WhatsApp/SMS and personal devices can be in scope where they contain your personal information and are held by or on behalf of the controller.
  • Missing information may instead have been lawfully withheld, redacted, deleted under retention policy or outside the right of access. Make the controller explain which.
  • Since June 2026, organisations have a statutory data-protection complaints process with new complaint-handling duties, giving consumers a clearer route before ICO escalation.

First: what kind of gap have you found?

GapWhat it may indicate
You have an email the organisation did not discloseSearch terms, mailbox/custodian coverage or exemption/redaction issue.
A call is referenced in notes but no recording/transcript appearsRetention, recording system search or distinction between personal data and entire recording.
Complaint notes jump from one date to anotherMissing account-note source, archive, deletion or incomplete export.
Staff refer to Teams/Slack/WhatsApp messagesCollaboration-system or personal-device searches may need examining.
Audit trail shows an event but underlying record is absentSeparate access to personal data from access to system metadata/document itself.
The response says “no data found” despite known interactionsAsk what identifiers, systems, dates and custodians were searched.
Large sections are blacked outThis is primarily a redaction/exemption question, not necessarily a search failure.
Old data is absentCheck retention/deletion history and whether deletion occurred before or after the SAR.

The legal standard: reasonable and proportionate search

The ICO’s current guidance says organisations must make reasonable efforts to find and retrieve requested information but need not conduct searches that would be unreasonable or disproportionate to the importance of providing access. The controller should be able to justify why a search is unreasonable or disproportionate.

This is not permission to search only the easiest database. Equally, it is not a right to demand forensic reconstruction of every deleted byte. A good challenge identifies why a particular source is likely to contain material personal information and asks what effort was made to search it.

Start with a missing-data schedule

Create a table before writing the complaint. Each row should identify the missing item/category, evidence it exists or probably exists, likely system/custodian, date range and what you want the controller to do.

Missing materialEvidence it existsLikely sourceRequested action
Email discussing complaint decisionAnother disclosed email quotes itManager mailboxSearch named mailbox/date/subject and disclose personal data or explain withholding.
Call recordingAccount note says “call listened to”Telephony/QA platformConfirm retention and search recording ID/date/time.
Teams discussionSAR disclosure refers to “Teams chat with X”Microsoft 365/TeamsSearch identified custodians and date range.
Account-note historyDisclosure jumps from note 41 to 48CRM/archiveExplain missing sequence and search archive/audit store.

Emails: search the people and context, not only your email address

Email searches can miss personal information if staff discussed you internally without copying you. Useful identifiers can include your name, account/reference number, phone number, complaint reference, address and distinctive transaction terms. Named custodians and a sensible date range can make a supplementary search more targeted.

Remember that the right is to personal information within emails, not necessarily complete copies of every email. The controller may extract relevant personal data or redact information about others.

Teams, Slack and workplace messaging

Collaboration messages can contain exactly the internal discussion consumers expect from a SAR. If the organisation uses Teams, Slack or similar systems and there is evidence staff discussed your case there, ask whether those systems and relevant custodians were searched.

Do not assume every channel history is retained. Retention policies, account deletion and licensing can affect availability. The useful question is what was held when the request was received and what reasonable/proportionate searches were performed.

WhatsApp, SMS and personal devices

The ICO says personal information held by staff on personal devices can be within scope where it is held on behalf of the controller, particularly where the organisation permits staff to use private email, smartphones or instant-messaging applications for work. If you have good reason to think this happened, identify the staff member, communication and approximate date.

A blanket demand that every employee surrender every private phone is unlikely to be proportionate. A targeted request based on evidence is much stronger.

Call recordings and transcripts

A call recording can contain your personal information, but whether the entire audio must be supplied can depend on third-party information and how access is provided. First establish whether the call was recorded, the retention period, recording identifier and whether a transcript or QA record exists.

If a disclosed note says a manager listened to a recording after the date the organisation claims it was deleted, that contradiction is powerful evidence for a targeted follow-up.

Internal account and complaint notes

CRM notes often provide the chronology connecting emails, calls and decisions. Missing note ranges, unexplained numbering gaps or references to unseen notes can justify questions about archived systems, migrated records or filtered exports.

Do not assume every numeric gap proves deletion; systems may use global identifiers or hide non-personal/system events. Ask how the note sequence works and what repositories were searched.

Audit logs

Audit logs can themselves contain personal information, such as who accessed or changed your account, timestamps tied to your record, or status changes. But a SAR is not a general right to a complete security log merely because your account was involved.

Frame the request around the personal information you need, for example, the recorded changes to your account and associated user/time data, and explain why a known unexplained event makes the source relevant.

Archived systems and legacy platforms

Moving data out of the live CRM does not automatically place it outside subject access. The ICO says there is no technology exemption for electronically archived or backed-up personal information; organisations should have procedures to find and retrieve such information, subject to the reasonable/proportionate standard.

Ask whether the relevant date range sits in a legacy system, migration archive or off-line store and what search was performed there.

Backups: in scope does not mean every backup tape must be restored

Backups require nuance. The ICO expects organisations to have procedures for archived/backed-up information and to use reasonable effort, but proportionality matters. A routine disaster-recovery backup may be difficult to search granularly.

Your challenge is stronger where the organisation routinely restores or queries the backup for its own purposes, or where the missing information is particularly important and no live copy exists. Avoid demanding “all backups” without identifying why the source is likely to contain relevant personal data.

Deleted data

Genuinely deleted information does not have to be recreated using extreme forensic techniques simply because fragments could theoretically be recovered. The ICO distinguishes ordinary deletion from accessible archived/backup data.

The key chronology is when deletion occurred. If records were deleted under a routine retention schedule before the SAR, that may explain the absence. If information was deliberately deleted after receipt while the request was being handled, ask for the deletion event, policy basis and whether the information remained held at the time the SAR was received.

Third-party processors

Using an outsourced processor does not normally allow a controller to ignore personal information held on its behalf. Relevant data may sit with cloud platforms, call-recording vendors, outsourced complaints teams or service providers. Ask whether processor-held repositories forming part of the controller’s records were included.

Again, scope matters: the controller is responsible for responding to its SAR obligations, while the processor’s independent data about you may involve a separate controller relationship in some circumstances.

Exemptions and redactions: missing is not always missing

Some information can be lawfully withheld because an exemption applies or because disclosure would adversely affect the rights and freedoms of others. Legal professional privilege, management forecasting in relevant contexts and third-party information can all raise separate questions.

Ask the controller to identify the basis sufficiently for you to understand the decision, without demanding disclosure of the very information the exemption protects. A redacted document is evidence that a search found something; your challenge may therefore be about withholding rather than search methodology.

Search terms, custodians and date ranges

The law does not give every requester an automatic right to dictate exact e-disclosure methodology. But where material gaps appear, asking sensible questions about identifiers, systems, custodians and dates can test whether the search was reasonable.

A useful formulation is: “Please confirm whether the following repositories/custodians were searched and, if not, whether they were excluded as disproportionate, not held, outside scope or subject to another reason.” That invites a reasoned answer rather than demanding a privileged internal search script.

Evidence that a search actually happened

Look for consistency between the disclosure and the controller’s explanation. If it says every mailbox was searched but an internal email in your possession is absent, ask how that email escaped the search. If it says recordings are retained 12 months but a six-month-old call is missing, ask for the recording search result and deletion history.

The aim is not to prove bad faith. It is to demonstrate an objective gap that requires a supplementary search or explanation.

Data deleted after the SAR was made

Once an organisation has received a SAR, routine business processing does not necessarily freeze every record forever. However, deleting information that is held and within scope while handling the request can create serious questions about whether the controller has complied with the right of access and its accountability obligations.

If you suspect post-request deletion, identify the record, why you believe it existed at receipt, the deletion date and any retention/audit evidence. Avoid alleging deliberate destruction unless the evidence supports that conclusion.

Ask for a targeted supplementary search

A strong follow-up does not simply say “your SAR is incomplete”. It lists the gaps and asks for defined searches: named mailbox, CRM archive, call platform, Teams account, date range, reference number or processor repository. This makes proportionality easier for both sides and creates a clear record if the controller refuses.

Ask for newly found personal data plus an explanation for items not located or withheld.

A SAR gives access to personal data, not automatically every document

A common mistake is to argue that an organisation must disclose every document mentioning a dispute. Article 15 is a right to personal data and supplementary information. A document can contain your personal data without the entire document being your personal data; conversely, information about you can be personal data even if your name is not written on every line.

When identifying a gap, say what personal information you believe is missing and where it is likely to be held. “Send the entire case file” may be a useful practical request, but the legal analysis should still focus on personal data rather than ownership of documents.

Distinguish “not held”, “not found”, “deleted” and “withheld”

These explanations are not interchangeable. “Not held” means the controller says it does not possess the personal data. “Not found” may describe the outcome of a search. “Deleted” raises when and under what retention process deletion occurred. “Withheld” means data was found but an exemption, restriction or third-party balancing exercise affected disclosure.

Ask the organisation to be precise. If a record existed last month and the response now says only “nothing further located”, the next question is different from a case where the controller says the record was lawfully deleted two years before the SAR.

Attachments and linked files are easy to miss

Email searches can find the covering message while missing an attachment stored elsewhere, a linked SharePoint file, a CRM export or a document referenced by filename. Build your missing-data schedule around those breadcrumbs. If an email says “see attached call review” but no review appears in the disclosure, identify the exact email and attachment name.

The same applies to ticketing systems: a note may contain a link to a complaint record or quality-assurance form. The existence of the link is evidence that another repository may need to be searched.

Metadata can itself be personal data

Useful personal data is not limited to the visible prose of emails. Depending on context, sender/recipient information, timestamps, account identifiers, audit events, status changes, user IDs, location or device information can relate to an identifiable person and explain what happened.

If the substance of your complaint depends on who changed a record and when, a disclosure containing only the final field value may be incomplete even though the main account screen was provided. Ask whether audit or event history containing your personal data was searched.

Search by custodian as well as keyword

A keyword-only search can miss records where you are identified by account number, phone number, case reference, shortened name or context. If you know which employees handled the issue, ask whether the relevant custodians and systems were considered over the relevant date range.

That does not mean you have an automatic right to dictate the controller's exact e-discovery protocol. The legal obligation is a reasonable and proportionate search. Your evidence should show why an omitted custodian or repository is likely to contain relevant personal data and why the omission matters.

Reasonable and proportionate does not mean “search wherever the requester tells us”

The post-DUAA statutory standard is expressly reasonable and proportionate. An organisation does not have to carry out searches that are unreasonable or disproportionate to the importance of the information. That qualification matters in huge enterprise environments.

Challenge by showing why a further search is proportionate: name the repository, custodian, date range and evidence that relevant records exist there. A targeted request for a known complaint mailbox over three months is very different from demanding restoration of every historic backup across a multinational group without evidence that the missing data matters.

Backups: existence is not the same as reasonable retrievability

Backup systems are designed for disaster recovery, not necessarily routine record retrieval. Personal data on a backup is not magically outside data-protection law, but the effort, technical architecture, likelihood of relevant data and importance of the information all matter to whether restoration/search is reasonable and proportionate.

If the organisation says the only remaining copy is on backup, ask enough to understand the position: what was deleted from live systems, when, what backup class remains, and why retrieval would be disproportionate. Do not assume the law requires restoration of every tape merely because a copy could theoretically exist.

Personal devices and messaging apps: focus on business-controlled processing

If staff used WhatsApp, SMS or personal devices for business, relevant personal data does not automatically become invisible to the SAR merely because the hardware is privately owned. The practical question is whether the organisation is controller of the business processing and what reasonable steps it can take to locate that information.

Evidence matters. A disclosed email saying “I sent Jack the decision on WhatsApp” is a concrete reason to ask about that channel. A speculative demand that every employee surrender their entire personal phone is not proportionate and would also engage other people's privacy.

Processors and outsourced systems

An organisation cannot necessarily answer “our supplier holds that data” and stop. A controller may use processors for call recording, CRM, cloud storage, payroll or customer messaging. If the processor holds personal data on the controller's behalf, the controller may need to take reasonable steps through that relationship to satisfy the SAR.

Identify outsourced systems from privacy notices, correspondence, login domains or disclosed documents. Ask whether the controller searched data held by processors within scope, rather than trying to make a SAR directly to every software vendor that merely processes on the controller's instructions.

Call recordings: retention dates can decide the issue

Call recordings are often kept for much shorter periods than account records. If a call is important, request it promptly and note any published retention period. If the recording disappears after the SAR was made, ask when the deletion occurred and whether the organisation's SAR handling should have preserved or retrieved it before routine deletion.

If the audio no longer exists, associated metadata, transcripts, summaries, quality-monitoring records or agent notes may still exist. Treat those as separate repositories rather than assuming the disappearance of the audio means there is no personal data about the call.

Deletion after a SAR: chronology is critical

A SAR does not necessarily impose an indefinite litigation-style preservation hold over every record, but an organisation cannot fairly answer an access request by ignoring relevant data that was held and reasonably retrievable while the request was being processed. If deletion timing matters, build an exact chronology.

Record the SAR receipt date, any ID or clarification pause, the known existence date of the record, the retention/deletion event and the response date. Ask whether routine deletion continued after the organisation knew the data was responsive and what steps were taken to retrieve it.

You are not automatically entitled to the organisation's internal search log

Asking about search methodology is often useful, but Article 15 does not itself create a blanket right to receive every internal search term, staff instruction or compliance log. The aim is to test whether the statutory search was reasonable and proportionate, not to create a second SAR for the SAR team's entire working file.

Ask targeted questions where the disclosure gives reason for concern, which systems were within scope, whether named repositories or custodians were searched, whether a known date range was covered, and whether archived/processor data was considered. If the organisation gives enough evidence to explain a reasonable search, demanding every internal detail may add little.

When newly discovered material proves the first search was incomplete

Sometimes the strongest evidence arrives later: a complaint response quotes an email that was absent from the SAR, a litigation bundle contains internal notes never disclosed, or a second SAR produces records from the same period. Preserve the new material and compare it directly with the first response.

One missing record does not automatically prove deliberate concealment. It does, however, justify asking why the search failed and whether the same search weakness affected other records. Frame the challenge around methodology and remediation rather than accusing staff of destruction without evidence.

Evidence worth keeping

Original SAR and proof of receipt
Disclosure index/files
Your missing-data schedule
Known emails/messages absent from disclosure
Retention-policy extracts
Call dates/recording references
CRM note/audit gaps
Search-methodology correspondence
Data-protection complaint and response
ICO correspondence