Info Gov

The First-tier Tribunal has struck out an application seeking to force the Information Commissioner to investigate a subject access complaint, in a decision that confirms the ICO's harm-based complaints prioritisation framework can dispose of a complaint without any engagement with the data controller and still count as an outcome beyond the reach of section 166 of the Data Protection Act 2018.

Judge Harris, deciding Damian Hamill v Information Commissioner [2026] UKFTT 1315 (GRC) on the papers on 16 September 2026, found the tribunal had no jurisdiction under Rule 8(2)(a) and that the application had no reasonable prospect of success under Rule 8(3)(c).

Hamill had complained to the ICO on 3 April 2026 about Denbighshire County Council's refusal to provide any information in response to a subject access request, the council citing the rights of other individuals, confidentiality expectations and the potential for harm.

On 27 May the ICO told him it had considered the complaint against its published framework and would not undertake a more detailed investigation, having identified no significant harm, wider impact or broader data protection concern. It would record the complaint for information purposes.

A review on 18 June upheld that position, adding that the ICO had not seen sufficient evidence that the council's reliance on exemptions was clearly incorrect, and directed him to the courts and the Parliamentary and Health Service Ombudsman.

The framework referred to is the revised approach to data protection complaints on which the ICO consulted in September 2025 and has since adopted, the aim of which is to focus resource where it can have the biggest impact and to reduce routine engagement with organisations on lower-risk cases.

Under this approach, the ICO assesses every complaint but investigates in detail only where criteria such as a high level of harm, a significant adverse impact on a substantial number of people, the involvement of vulnerable individuals or a link to its strategic priorities are met. 'Lower-risk' complaints are recorded and used to monitor complaint volumes by organisation. 

Hamill's application, lodged on 11 July, asked the tribunal to direct the ICO to conduct a full investigation into the council. He argued that:

  • the decision was inconsistent with the ICO's own published criteria, particularly on the assessment of harm;
  • that the review response had quietly dropped the significant harm criterion relied on in the first response without explanation;
  • that the ICO had not engaged with his evidence and legal analysis that the council had applied the wrong test for the exemption;
  • that a blanket refusal to disclose anything should itself have prompted suspicion and at least a request to the council to justify its position, and;
  • that the ICO had ignored the council's failure to respond at all to two later assertions of data protection rights.

The Commissioner applied to strike out on 10 August, arguing that the relief sought showed Hamill was using section 166 to have the tribunal substitute its own view on the appropriate level of investigation, that a challenge to the merits belonged in judicial review, that a desktop assessment with no external engagement was a legitimate form of investigation, and that any compliance order against the council had to be sought under section 167 in the civil courts.

Section 166 allows the tribunal to order the Commissioner to take appropriate steps to respond to a complaint, or to inform the complainant of progress or outcome, where the Commissioner has failed to do so.

Section 165(5) provides that appropriate steps include investigating the subject matter "to the extent appropriate". The tribunal reviewed the line of authority from Killock and Veale [2022] 1 WLR 2241 through R (Delo) v Information Commissioner in the High Court and Court of Appeal, Cortes and Smith [2025] UKUT 74 (AAC), all of which confine section 166 to procedural failings and reserve the scale and intensity of any investigation to the Commissioner's discretion, to be given weight as the view of an expert regulator.

Applying that authority, Judge Harris found that the responses of 27 May and 18 June, taken together, provided an outcome, answered all outstanding issues and demonstrated that the ICO had considered whether any other appropriate steps could be taken.

That was sufficient to satisfy section 165(4), and the fact that Hamill disagreed with the outcome did not render it wrong in law. Giving significant weight to the Commissioner's view, the judge concluded there were no further appropriate steps the ICO ought reasonably to take.

The relief sought was in effect a challenge to the substantive decision not to investigate further, the judge said, and on a section 166 application the tribunal has no power to direct the ICO to investigate in a particular way or at all, to take enforcement action or to determine whether there has been a breach of the UK GDPR. The judge refused an oral hearing as disproportionate to the narrow jurisdictional issue.

The decision does not address whether the ICO applied its own framework correctly. Hamill's central complaint, that the harm assessment was inconsistent with the published criteria and shifted between the two responses, was treated as a merits argument for the Administrative Court rather than a procedural failing, leaving judicial review as the only route by which the framework's application to individual complaints can be tested.

Also in this section

Sep 23, 2026

Hospital trust reports personal data breach to ICO after reused database script wipes maternity access logs

Nottingham University Hospitals NHS Trust has reported a personal data breach to the Information Commissioner's Office after a script intended to copy a radiotherapy database was run against its legacy maternity system instead, overwriting records for women and babies treated between September 2011 and November 2022 and permanently destroying most of the audit trail showing who accessed them.
Sep 11, 2026

ICO opens investigation into Police Scotland's handling of subject access requests

The Information Commissioner's Office has opened an investigation into Police Scotland's handling of subject access requests, seeking to establish whether the force has failed, or is failing, to comply with its obligations under Articles 12 and 15 of the UK GDPR and section 45 of the Data Protection Act 2018, including responding to requests within the statutory timescale.

InfoGov Masthead Newsletter 800