
Can an insurer refuse to provide internal correspondence and case notes relating to an insurance claim where a subject access request (SAR) is made under the UK GDPR for such information?

Published on: 14 July 2021

This Q&A assumes that the organisation that has received the SAR is a ‘controller’ of the relevant data.

For an introduction to the United Kingdom General data protection Regulation, Retained Regulation (EU) 2016/679 (UK GDPR) regime, including key data protection terms and concepts, such as ‘personal data’, 'processing', 'data subject' and ‘controller’, see: Data protection toolkit.

As further explained in Practice Notes: The UK GDPR and DPA 2018 for insurers and Data subject rights—access, Article 15 of the UK GDPR gives individuals a right to obtain confirmation from a data controller as to whether or not personal data concerning them is being processed, and where it is, access to the personal data and certain further information. A request for such information is commonly known as a ‘subject access request’ (or a 'SAR' or 'DSAR'). In order to assist you with your research into points raised in your question,

