Skip to content

What a subject access request costs when you bought the list

The clock is one month, the first copy is free, and you have to say where the data came from. That last requirement is the one that cannot be met retroactively — and a €220,000 decision in Poland shows what happens when a company decides the alternative is too expensive.

Antiqore6 min read

A subject access request is a short email from someone who does not explain themselves and does not have to. What happens next is mostly clerical — unless one particular field was never recorded, in which case there is no amount of effort that produces the answer.

The clock and the price

ObligationThe rule
DeadlineOne month from receipt
ExtensionTwo further months where complex or numerous — but you must say so, with reasons, inside the first month
Cost to the requesterThe first copy is free
Refusing or chargingOnly where manifestly unfounded or excessive, and you must be able to show it

None of that is onerous for a company that knows what it holds. The difficulty is never the deadline. It is one line in the list of things you have to disclose.

The line that does the damage

Where the data was not collected from the person, Article 15(1)(g) entitles them to any available information as to its source.

For a list bought from an aggregator, the honest answer is often that you do not know. The vendor supplied a row. The vendor may itself have bought it. “Public sources” is not a source; it is a category, and a person asking where you got their mobile number is not asking for a category.

Everything else in a subject access request can be assembled after the fact. The source cannot, because it was never written down.

Why “too expensive” is not the escape it looks like

There is an exemption for cases where informing people would involve disproportionate effort, and it is the clause every list-based business reaches for. Poland’s supervisory authority tested it in its first GDPR fine, and the reasoning is worth reading carefully.

A data company had assembled roughly 7.5 million records on individuals from public registers. It emailed the people whose addresses it had. For the rest it decided that direct contact was too costly, and published a privacy notice on its own website instead.

The authority fined it around €220,000. Two findings matter more than the number:

  • A notice on your own website is too passive. Someone who does not know you hold their data has no reason to visit your site to find out.
  • The cost of informing people is part of the cost of acquiring the data. Deciding not to pay it is a commercial choice, not an impossibility — and the exemption is written for impossibility.

The decision was later narrowed on appeal as to which individuals were covered, but the principle survived: choosing not to spend the money is not the same as being unable to.

What a cheap request looks like

A request is inexpensive when the answer already exists. Searching systems, assembling a copy, redacting other people — all mechanical, all solvable with an afternoon. The expensive version is the one where you have to go and ask a vendor where a row came from, and wait, and receive “public sources”, and then write that to a person who will not find it satisfying.

The two obligations that arrive together — access under Article 15 and objection to direct marketing under Article 21 — are also the two that a team running legitimate-interest outreach is most likely to see. Suppression has to be global for the same reason it has to be global for deliverability: one list, honoured everywhere.

Why we built it the other way round

Our evidence standard says every company is researched from public sources at the moment of the request, and every claim carries the page it came from and the date it was read. That reads like a quality argument. It is also, and less romantically, the reason a subject access request is a lookup rather than a project.

It is the same reason there is no contact database to sell and nothing gets resold: a stored row whose origin you cannot state is a row you cannot defend. We would rather return fewer companies — and fewer confident-looking flags — than hold data we would struggle to explain.

Frequently asked questions

How long do you have to answer a subject access request?
One month from receipt. It can be extended by two further months where the request is complex or numerous, but you have to tell the person within the first month that you are extending and why. Silence is not an extension.
Do you have to say where you got someone's data?
Yes, when you did not collect it from them. Article 15(1)(g) requires any available information as to the source. If your list came from an aggregator that will not tell you the origin of a row, you cannot answer, and the inability to answer is itself the finding.
Can you charge for answering?
Normally no — the first copy is free. A fee or a refusal is only available where a request is manifestly unfounded or excessive, and the burden of showing that sits with you. It is a narrow door, not a pricing option.
Does the disproportionate effort exemption cover a bought list?
Far less than people assume. Poland's authority fined a data company around €220,000 for relying on it: the company had built a database of roughly 7.5 million records from public registers, decided that contacting people directly was too expensive, and posted a notice on its website instead. That was held too passive.
What makes a request cheap to answer?
Having recorded the source at the moment of collection. Everything else — searching systems, assembling a copy, redacting third parties — is mechanical. Provenance is the only part that cannot be reconstructed later, because the information was never captured.