An examination of Subject Access Request (SAR) responses reveals how basic PDF printouts are used to withhold digital access logs and edit records, denying patients full transparency under UK GDPR Article 15.
Under established Information Commissioner’s Office (ICO) interpretations and binding case law, access logs and Change Data Capture (CDC) tables detailing who accessed a patient's medical file, when, and from which workstation constitute the personal data of that patient. Patients hold an explicit statutory right to know who processed their data.
When applicants submit precise SARs demanding full digital telemetry (access logs, revision flags, deletion records), information governance departments frequently employ three standard avoidance tactics:
Supplying a flat PDF printout of a recent discharge summary and asserting that it constitutes the "complete medical record."
Citing "legacy system limitations" or claiming audit logs represent "system machine data" rather than disclosable personal medical records.
Exporting records where technical provenance has been severed, making it impossible to verify if unauthorized personnel viewed the file.
Under UK GDPR Article 12(3), controllers must respond to SARs without undue delay and at the latest within one calendar month. Refusing to disclose audit logs on the grounds of administrative inconvenience constitutes a reportable breach to the ICO.