What happened?

On 24 September 2025, the Information Commissioner’s Office (ICO) issued an enforcement notice to Bristol City Council. The reason? The council had struggled to respond to Subject Access Requests (SARs) within the legally required timeframes, with some requests dating back to 2022. The ICO’s notice requires the council to clear its backlog, communicate with affected individuals, publish an action plan within 90 days, and strengthen its processes to prevent future delays.

Read the full ICO Press Release.

Why should we be sympathetic?

It’s important to recognize that Bristol City Council is not alone. Managing SARs is a complex and resource-intensive task, especially for large public bodies facing increasing demand and limited resources. The council’s experience highlights how easy it is for even well-intentioned organizations to fall behind, especially when compliance teams are stretched and processes are not fully optimized.

Why does this matter to everyone?

Subject Access Requests are a fundamental right under data protection laws worldwide—whether it’s UK GDPR, EU GDPR, CCPA, or others. When organizations struggle to meet these obligations, it’s often due to systemic pressures rather than neglect. This case sets a precedent: regulators are watching, and any organization—public or private—could be next if they don’t keep pace with compliance.

Similar stories around the world

  • In 2023, the Dutch Data Protection Authority reprimanded a regional municipality for similar SAR delays. Read More.
  • In Canada, the Office of the Privacy Commissioner flagged public healthcare bodies for slow SAR responses. Read More.

These examples show that SAR management challenges are widespread and not unique to Bristol City Council. 

What went wrong, and why it could happen to you

The main issue was a systemic inability to meet SAR response deadlines. This often stems from under-resourced teams, lack of prioritization, and poor records management. Bristol City Council’s experience is a reminder that any organization can find itself in this position if it doesn’t invest in robust processes and adequate training.

How could this have been prevented?

  • Centralized SAR management
  • Regular staff training on compliance deadlines 
  • Sufficient resources and staffing 
  • Automated acknowledgements, triage, and reminders 
  • Routine audits and governance reporting 

These steps can help organizations spot risks early and avoid enforcement action. 

How we can help you avoid the same pitfalls

We at Leadership Through Data specialise in training for all of these issues that have presented themselves in this case. The key ones of note to upskill yourself and your teams are:

If you haven't got your records management quite right yet, then your findability and retrieval of information will likely be poor. We can help upskill you and your team in this area too with our:

In addition to these training courses, we can also offer Information Governance Consultancy Services which will provide you with expert advice and help you to build resilient SAR processes. Avoid the challenges Bristol City Council faced, and take action for you and your organisations future.

Need some help?

Let us know you need some help by contacting us. Use the Live Chat in the bottom right-hand corner of your screen or email us using the contact details below.

Charlotte Easton

Charlotte Easton
⭐ Account Executive
✉️ [email protected]

☎️ Use any of the numbers at the bottom of this page to get hold of me
🌐 Connect with me on LinkedIn

Final thoughts

Bristol City Council's situation is a cautionary tale, not a condemnation. It's a reminder that any organization can be caught out by the complexities of data protection. Take steps now to ensure you're not next.