top of page

Data Subject Access Requests: The Number One Data Protection Compliance Issue

Writer: Rock Consultancy
Rock Consultancy
Aug 13
2 min read

Updated: Aug 14



August 2026



The Data Protection Commission (DPC) 2025 annual report and case studies show that data subject rights compliance requires more than meeting the one-month deadline, it requires robust governance, clear decision-making and defensible processes.


Introduction

Data subject access requests continue to present one of the most significant operational and compliance challenges for organisations.


The DPC’s 2025 Annual Report (Annual Report) states that by the end of 2025, DPC had recieved “1,280 complaints solely related to the right of access, accounting for 42% of all complaints received through the year". The DPC's Annual Report confirms that alleged non-compliance with data subject access requests remains the “primary source of complaints”.


For organisations, the message is clear: a compliant data subject rights process cannot simply be a mechanism for responding within one month. It must enable the organisation to identify requests promptly, conduct appropriate searches, assess restrictions, document decisions and provide a meaningful and transparent response.


Details

The Annual Report and Case Studies provide valuable insight into where these processes can fail.


  • The Vodafone case highlights the need to have appropriate technical and organisational processes in place with supplier. In this case Vodafone’s supplier received five data subject access requests but failed to make Vodafone aware of any of the requests, leaving Vodafone in breach of its obligations. In this case, lack of procedure led to numerous failings under the GDPR.


  • The Cubic Telecom case demonstrates the importance of having all staff, including external support contractors, sufficiently trained on the data subject requests procedure.  In this case, an external support contractor mistakenly interpreted a customer’s data access request as an erasure request.


  • Exemptions must be proportionate and documented: Several cases highlight the need to carefully assess the applicability of exemptions and document decision making. Organisations need to consider whether partial disclosure, redaction or another proportionate approach can satisfy the request.


The DPC specifically advises organisations to maintain a schedule identifying withheld or redacted material, the reasons for each restriction and the relevant GDPR or Data Protection Act 2018 provision relied upon.


Key takeaways

The DPC’s 2025 Annual Report and Case Studies demonstrate that data subject rights requests compliance requires the following:


  • Robust procedure: which includes escalation paths, ownership, applying exemptions, communication with data subjects. 

  • Awareness and Training: for all staff, including contractors, to enable staff to identify a request and correctly handle data subject rights requests.

  • Supplier management: clear and communicated obligations to data processors on receipt of a data subject request.


Further Reading


At Rock Consultancy, we help organisations with data subject rights requests, from establishing and reviewing procedures to providing training, to assisting when a request is received or a complaint made to the regulator.  


For any queries on how Rock Consultancy can support your organisation with data subject rights requests, please contact us at info@rockconsultancy.ie 


Recent Posts

See All
bottom of page