How-to
Refusing a request and handling appeals
When you can refuse, what the requester sees, and how the appeal process runs.
Jump to section
Refusing a request and handling appeals
Not every request can be fulfilled. Some are manifestly unfounded, some ask for data you're legally required to keep, and some come from people you can't identify. Refusing is legitimate, but it must be reasoned, recorded, and appealable.
Refusing
Reject the request from the detail page and record the reason. The requester receives a refusal email that explains the decision and tells them how to appeal. The reason you record is part of the permanent audit trail, so write it as if a regulator will read it. One day one might.
The appeal window
The requester can appeal once, from their tracking page:
- US (California) requests: within 60 days, as the state laws that mandate appeals require.
- UK and EU requests: within one calendar month.
Deciding an appeal
Appeals are decided by a DPO (the role, not necessarily your registered officer). Ideally someone other than the person who refused. Two outcomes:
- Uphold: the refusal stands. The requester is told, and the email includes how to escalate externally, to the ICO for UK requesters or their state Attorney General for California requesters.
- Overturn: the request reopens with a fresh deadline (45 days for US requests, your default SLA otherwise) and goes back into the normal flow.
Open appeals appear in the daily digest so they're never forgotten.
A note on tone
Most appeals happen because the refusal email felt like a brush-off. You can edit the refusal and appeal email wording under Settings, then Email templates. A clear, human explanation of why you refused prevents more escalations than any legal boilerplate.