By Kieron JH, The Reasonable Adjustment
The North East Combined Authority (NECA) has just sent me a Subject Access Request response that weighs in at roughly 428 MB. Not a typo. Nearly half a gigabyte for one person’s data.
If you want the one line version: I asked NECA what data they hold on me, and they responded with something closer to a corrupted backup of an email server than a lawful, usable SAR.
This is not my first run in with NECA’s approach to information rights. I have already written about their handling of freedom of information and public accountability: FOI: Newcastle vs NECA – A Reality Check, NECA and Transparency: Still Waiting, NECA, TRJ and Conflicts of Interest, and High Viz Politics and the Tokyo Trip. This SAR episode fits neatly alongside them.
The timeline
On 7 November 2025 I submitted a Subject Access Request to NECA, asking for the personal data they hold about me. Their written response is dated 5 December 2025, and arrived as a password protected PDF attachment.
At first glance, the attachment looked small, just over 1 MB. Once decrypted and saved properly, the real size appeared: 428,850 KB, or roughly 428 MB.
For scale, that is larger than many full PC games from the 2000s, and far beyond what any reasonable person would expect for a text heavy disclosure about a single resident.
The 428 MB problem
A typical SAR from a public body might be 5 to 15 MB. Even a chunky response with a few attachments might reach 40 MB. Four hundred and twenty eight megabytes is not a response, it is a data dump.
In practice, the file behaved exactly as you would expect:
- Applications crashed repeatedly when I tried to open or save it.
- The PDF could not be printed or converted cleanly, and choked tools that rely on machine readable text.
- Email threads, signatures, logos and banners were flattened into one continuous document of more than 200 pages.
- There was no index, no structure and no way to tell at a glance where one conversation ended and another began.
This is very hard to square with Article 12 of the UK GDPR, which requires information to be provided in a form that is clear, concise and intelligible, and with the ICO’s own guidance on supplying information to requesters in an accessible and easily searchable format (ICO: How can we supply information to the requester?; ICO: Right of access; GDPR Article 12). For a disabled data subject trying to understand how their information has been processed, it is close to unusable.
How do you create a SAR this big?
You do not get to 428 MB by running targeted searches across well managed systems. You get there by exporting entire mailboxes or repositories with no meaningful filtering at all.
Instead of:
- identifying which systems held personal data about me,
- applying sensible date ranges and keywords, and
- reviewing what was actually relevant,
someone has almost certainly clicked something close to “Export mailbox to PDF” and sent the result.
That raises obvious questions about data minimisation under Article 5(1)(c) and the way NECA is applying the right of access in practice (ICO: Subject access request resources; GDPR Article 15). If NECA are comfortable sending a half gigabyte, unstructured dump to one person, it prompts a more worrying question: what does their internal handling of everyone else’s data look like?
The password that tells its own story
The file was protected with the password “SAR711H”.
Translate that:
- SAR clearly labels what the file is.
- 7 is the day of the request.
- 11 is the month.
- H is the first letter of my surname.
Any member of staff who saw the covering email could guess that pattern in seconds. Anyone who has seen one NECA SAR password could probably guess the rest.
For transparency, I am sharing the exact password here at my own risk. I am fully aware that publishing a password relating to my own personal data is ironic and carries some risk. I am doing it deliberately, because the point is not this single token but the pattern and the culture behind it. If this is the standard convention, it demonstrates just how weak the supposed protection is.
Under Article 32, controllers are supposed to apply “appropriate technical and organisational measures” when transmitting sensitive personal data. The ICO’s own security guidance and password advice expects robust, non trivial protection for data in transit (ICO: A guide to data security; ICO: Passwords in online services). A password that simply encodes the date and a surname initial is not a measure. It is security theatre.
This is not an isolated admin hiccup
On its own, you might be tempted to write this off as clumsy but harmless. Set alongside NECA’s wider record, it looks more like a symptom.
We already know, from the Newcastle vs NECA FOI comparison, that neighbouring bodies can handle information rights with far more discipline. Newcastle City Council at least managed structured, document based disclosures instead of opaque silence.
We also know that NECA sits in the same ecosystem as The Recruitment Junction and its political champions, and that questions about funding and accountability have not always been welcomed.
When an authority with that background responds to a SAR by pushing out an unstable 428 MB file, protected with a password any intern could guess, it raises a different concern: not just about one resident’s request, but about the level of control NECA actually has over sensitive information and basic digital governance.
What a competent SAR should look like
A well handled SAR from a public body is not complicated. It should normally include:
- Information grouped logically, for example by system, time period or case.
- Clear filenames and an index so the data subject can navigate it.
- Reasonable file sizes that ordinary software can open and search.
- Evidence of data minimisation: relevant material, not entire mailboxes.
- Properly explained redactions with the exemptions relied upon.
None of that is ambitious. It is basic practice in organisations that take UK GDPR seriously, and it is consistent with the ICO’s expectations on clear, accessible disclosures (ICO: A guide to subject access; ICO: What is the right of access?).
Next steps and the regulator’s view
I have asked NECA to explain which systems they searched, which mailboxes and repositories were included, what keywords and date ranges they used, and whether any categories of record, such as Teams messages or draft documents, were excluded.
I have also contacted the Information Commissioner’s Office to ask how they view situations like this: SARs issued as huge, unstructured, unstable files with predictable passwords, rather than the clear and intelligible disclosures the law expects. Recent public statements from the Commissioner about people facing “lengthy, traumatic and demoralising” experiences when trying to access their own records suggest that this is not a niche problem any more, and that enforcement action is now firmly on the table for authorities that fall short.
If the regulator considers this acceptable, the public at least deserves to know that the bar is that low. If not, NECA will have some explaining to do.
Either way, this is not just about one bloated PDF. It is about whether regional authorities treat information rights as a legal duty to disabled residents and ex offenders, or as an inconvenient by product of their own public relations.





Be First to Comment