# O’Brien v DPC: Litigation, Privilege and Confidentiality in DSAR Responses

Canonical URL: https://xpertdpo.com/obrien-v-dpc-dsar-litigation-privilege-confidentiality/

Content type: Article

Published: 2026-08-27T19:07:49+01:00

Updated: 2026-08-27T19:07:51+01:00

Author: Philipa Jane Farley, Head of Legal and Operations

Summary: The Irish High Court has clarified how litigation, legal privilege and third-party confidentiality can restrict DSAR responses, while leaving an important Article 23 question open on appeal.

## Article

*A practical analysis for DPOs, privacy teams, legal and compliance leaders handling access requests connected with disputes, threatened proceedings or confidential third-party information.*

 A data subject access request does not become invalid because it arrives during litigation. It is not converted into discovery, and the fact that a requester may also want information for a dispute does not remove the right of access.

 It is equally true that access rights do not operate in isolation from fair-trial rights, legal privilege, confidentiality or the rights of other people. The difficult work is in identifying which legal route applies to which information, and showing why a particular restriction is necessary rather than merely convenient.

 The Irish High Court addressed that boundary in [*O'Brien v The Data Protection Commission and Others* \[2026\] IEHC 250](https://ww2.courts.ie/view/Judgments/6badc2eb-8c85-4189-9194-2ae746c89d8a/6d3db5a9-4325-48f1-a7cb-b439c9b970a9/2026_IEHC_250.pdf/pdf). The judgment gives controllers useful clarification on litigation-related restrictions, legal professional privilege and third-party confidentiality. It also leaves an important EU-law question for [the appeal now under way](https://www.matheson.com/insights/irish-high-court-clarifies-dsar-exemptions-under-the-gdpr-and-data-protection-act-2018/).

### The dispute behind the decision

 The case arose from a dossier prepared about businessman Denis O'Brien by Red Flag Consulting Limited for an unidentified client. O'Brien had already brought civil proceedings connected with the dossier and had unsuccessfully sought to establish the client's identity through the earlier litigation.

 In June 2018, he submitted a data subject access request to Red Flag. He asked for his personal data and for information about the recipients, or categories of recipients, to whom that data had been disclosed.

 Red Flag supplied a limited set of personal data but withheld information that would reveal or tend to reveal its client's identity. It relied on three distinct legal grounds:

- section 60(3)(a)(iv) of the Data Protection Act 2018, concerning necessary and proportionate restrictions connected with legal claims or proceedings;
- section 162 of the 2018 Act, concerning legally privileged material; and
- Article 15(4) GDPR, under which the right to obtain a copy must not adversely affect the rights and freedoms of others.

 O'Brien complained to the Data Protection Commission in July 2020. Following an extensive written process, the DPC upheld Red Flag's position in November 2022 and dismissed the complaint. He appealed to the High Court under section 150 of the 2018 Act. Lankford J dismissed each ground of appeal.

### Three legal routes, not one broad exemption

 One of the most useful features of the judgment is that it does not collapse litigation, privilege and confidentiality into a single exemption.

 Section 60 can restrict specified GDPR rights where the restriction is necessary and proportionate in contemplation of, or for the establishment, exercise or defence of, a legal claim or legal proceedings. Section 162 concerns the more familiar and narrower category of legal professional privilege. Article 15(4), meanwhile, requires a balance between the data subject's right to a copy and the rights and freedoms of other people.

 Those routes may overlap in a difficult DSAR, but they do different work. A controller should therefore identify the personal data in question, the particular aspect of the access right being restricted and the legal basis for that restriction. A general statement that material is "litigation-related" does not complete the analysis.

> **XpertDPO view:** Litigation does not switch off access rights. It changes the balancing exercise and increases the need for a clear, evidence-based decision record.

### Section 60 can extend beyond privileged material

 O'Brien argued that section 60(3)(a)(iv) was incompatible with [Article 23 GDPR](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679). Article 23 allows Member States to restrict certain GDPR rights through legislation where the restriction respects the essence of fundamental rights, is necessary and proportionate in a democratic society, and safeguards one of the listed objectives. Those objectives include the enforcement of civil-law claims.

 Article 23(2) also identifies safeguards that restrictive legislation should contain "where relevant", including provisions about the purposes of processing, categories of data, scope of the restriction, safeguards against abuse, controller categories, storage periods, risks to data subjects and notification of the restriction.

 The High Court upheld the compatibility of section 60. It considered the express necessity and proportionality requirement, the defined legal-claims context and the identification of the affected GDPR rights sufficient. It rejected the argument that every element listed in Article 23(2) must appear in every national legislative measure.

 The Court also rejected the suggestion that section 60 merely restated legal privilege. It held that [section 60](https://revisedacts.lawreform.ie/eli/2018/act/7/section/60/revised/en/html) and [section 162](https://revisedacts.lawreform.ie/eli/2018/act/7/section/162/revised/en/html) provide separate grounds for limiting access. Section 60 is capable of protecting interests arising in the conduct of legal claims even where the material does not satisfy the common-law test for privilege.

 That is significant, but it should be read carefully. Section 60 is not an automatic shield for an entire litigation file. The statutory language still requires the controller to show that the particular restriction is necessary and proportionate. The existence of a dispute is context, not a conclusion.

### The DPC does not have to test every privilege claim in court

 O'Brien also argued that the DPC should have used [section 151 of the 2018 Act](https://revisedacts.lawreform.ie/eli/2018/act/7/section/151/revised/en/html) to ask the High Court to decide whether the withheld material was genuinely privileged.

 Section 151 gives the DPC or an authorised officer a route to seek a court determination, but only where the statutory reasonable-grounds conditions are met. O'Brien had said that he was not seeking privileged material, and he had not identified particular documents or evidence showing that privilege had been wrongly claimed. The Court accepted that the DPC was not required to inspect the full document set or invoke section 151 as a matter of course. This ground was not ultimately pursued at the hearing.

 For complainants and controllers, the practical point is the same: a privilege dispute needs specificity. A bare assertion of privilege is weak, but so is a bare assertion that privilege must have been misapplied.

### Confidentiality can fall within the rights of others

 The third issue concerned Article 15(4). O'Brien argued that client confidentiality was not a basis for restricting his right to receive a copy of his personal data and that Red Flag had effectively imposed a blanket refusal.

 The Court disagreed. It accepted that Red Flag's client's confidentiality and privacy interests could fall within the "rights and freedoms of others". It also accepted the DPC's finding that Red Flag had withheld only information that identified, or tended to identify, the client. Other personal data had been supplied. On those facts, the response was a targeted restriction rather than a blanket refusal.

 That distinction matters. The [EDPB's Guidelines on the right of access](https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en) recognise that confidentiality, trade secrets, intellectual property and the personal data of others may be relevant under Article 15(4). They do not justify refusing an entire request where redaction, partial disclosure or another less restrictive measure can protect the competing interest.

> **XpertDPO view:** Confidentiality is a relevant interest, not a self-proving exemption. The controller still needs evidence of the interest, the adverse effect disclosure would cause and the alternatives it considered.

### Recipient identities remain the starting point

 The judgment should also be read alongside the CJEU decision in [*RW v Österreichische Post*, C-154/21](https://juris.curia.europa.eu/juris/document/document.jsf?docid=269146&doclang=en). The CJEU held that Article 15(1)(c) ordinarily requires a controller to give the data subject the actual identity of recipients where the recipients can be identified. Categories alone are generally sufficient only where identification is impossible or the controller demonstrates that the request is manifestly unfounded or excessive.

 *O'Brien* does not replace that starting point. It shows how recipient identities may nevertheless be withheld where a valid Article 23 legislative restriction applies and its use is justified on the individual facts.

 This is why a response should distinguish between:

- information about recipients under Article 15(1)(c); and
- the copy of personal data supplied under Articles 15(3) and 15(4).

 They are related parts of the access right, but the legal route for restricting them may differ.

### The Article 23 question is not entirely settled

 The High Court's interpretation of Article 23(2) is the most contestable part of the judgment.

 The [EDPB's Guidelines 10/2020 on Article 23 restrictions](https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en) say that, as a rule, all of the Article 23(2) requirements should be included in the legislative measure. Where an element is not relevant, the EDPB expects the legislator to justify that conclusion. It also stresses that the reason for and reach of a restriction should be understandable to the people affected.

 There is comparative authority pointing in the same strict direction. In the United Kingdom, the Court of Appeal held in [*Open Rights Group v Secretary of State for the Home Department* \[2021\] EWCA Civ 800](https://www.bailii.org/ew/cases/EWCA/Civ/2021/800.html) that the original immigration exemption lacked the legislative safeguards required by Article 23. An amended exemption was subsequently found incompatible in [*The 3million v Secretary of State for the Home Department* \[2023\] EWCA Civ 1474](https://www.judiciary.uk/judgments/the-3million-v-secretary-of-state-for-the-home-department/). Those decisions are not binding in Ireland and concerned materially different legislation and circumstances. They nevertheless illustrate the scrutiny that broad rights restrictions can attract.

 The Irish High Court distinguished that line of authority. Its view was that the legal-claims category covers an exceptionally wide range of circumstances and therefore requires some operational flexibility, with necessity and proportionality assessed in the individual case.

 There is a respectable argument on each side. A highly prescriptive statutory measure may struggle to anticipate every form of civil claim. But an open-textured restriction places more of the protective work on controllers, the DPC and, ultimately, the courts. That is precisely why the quality of the individual proportionality assessment matters.

 At 27 August 2026, the [Court of Appeal record identifies the appeal as A.AP.2026.0000123 and lists it for directions on 16 October 2026](https://procedures.courts.ie/app/legal-diary/listing-types?listing_type=d144204c-c52a-ee11-bdf5-000d3ab780dd). No appellate judgment has been published. Organisations can rely on the High Court judgment as current Irish authority, but policies and template refusal language should not be rewritten as though every point is finally settled.

 A separate point about the standard of DPC appeals should not be overstated. In [*LinkedIn Ireland Unlimited Company v Data Protection Commission* \[2026\] IEHC 235](https://ww2.courts.ie/view/Judgments/fe952110-0f6c-4236-95d7-97809d8447be/c25c575d-5e94-4d9b-9321-4d1bdb1839a3/2026_IEHC_235.pdf/pdf), Cahill J said that *O'Brien* had applied the established serious-and-significant-error approach without argument on that point. She did not treat it as deciding the standard applicable to LinkedIn's different section 142 appeal, which involved administrative fines. That later observation qualifies how broadly *O'Brien* should be cited on appeal standards; it does not disturb its substantive findings on the DSAR restrictions.

### What the judgment does not mean

 The decision does not mean that:

- a DSAR can be refused merely because litigation is pending or contemplated;
- the requester's suspected motive determines whether Article 15 applies;
- every document held by lawyers or placed in a litigation folder is privileged;
- a duty of confidentiality automatically outweighs the data subject's rights;
- section 60 and section 162 can be cited interchangeably;
- Article 15(4) permits a blanket refusal without considering redaction or partial disclosure; or
- the DPC must refer every contested privilege claim to the High Court.

 It means that litigation-related interests, privilege and third-party confidentiality can justify carefully bounded restrictions where the correct legal test is applied and the decision can be evidenced.

### A practical response model for litigation-linked DSARs

 For a complex request, the controller should maintain a restriction and redaction schedule that records:

1. the personal data or document under review;
2. the part of Article 15 engaged, including whether the issue concerns recipient information or a copy of the data;
3. the precise statutory or GDPR ground being considered;
4. the legal claim, third-party right or confidentiality interest said to be at risk;
5. the adverse effect that disclosure would cause and the evidence supporting it;
6. why the restriction is necessary for the identified purpose;
7. whether redaction, pseudonymisation, partial disclosure or a narrower answer would protect the interest;
8. the proportionality balance and approval route; and
9. the review point, particularly where proceedings or confidentiality circumstances may change.

 The response to the requester should then explain the restriction as clearly as the protected interest permits. Generic references to "legal reasons", "confidentiality" or "ongoing proceedings" are unlikely to demonstrate that the organisation has completed the necessary analysis.

> **Operational point:** The strongest DSAR file is not the one with the longest legal note. It is the one that connects each material restriction to the data, the risk, the evidence, the alternative considered and the decision made.

 The operational difficulty in cases like this is often not identifying a potentially relevant provision. It is preserving the reasoning across privacy, legal, HR, IT and the business so that the organisation can reconstruct what happened months or years later.

 That record should connect the original request, scope decisions, search protocol, records reviewed, privilege assessment, third-party balancing, redaction log, disclosure bundle, response letter, internal approvals and subsequent challenges. This is particularly important where an access dispute may become a DPC complaint or form part of wider proceedings.

 Our practical guidance on [complex DSAR triage, redaction and escalation](https://xpertdpo.com/complex-dsar-triage-redaction-escalation/) sets out the wider handling route. The same underlying discipline also matters when a requester uses AI assistance to generate repeated or expanded challenges: the organisation should respond to the material data protection issues while keeping the evidence trail anchored to the original request and decisions. See [AI-Assisted Complaints and Rights Requests](https://xpertdpo.com/ai-assisted-complaints-rights-requests/).

### Our view

 *O'Brien* is a useful correction to two oversimplifications.

 The first is that a DSAR can be treated as an alternative discovery procedure without regard to any competing litigation interest. The second is that the existence of litigation allows the controller to remove the request from ordinary access-rights governance. Neither is correct.

 The right approach is more exacting. Access remains the starting point. Privilege must be analysed as privilege. Confidentiality must be evidenced and balanced. A section 60 restriction must be tied to the identified legal claim and shown to be necessary and proportionate. Information outside the restriction should still be provided.

 For DPOs, this is a governance case as much as a legal interpretation case. The quality of the outcome depends on whether the organisation can separate the issues, obtain legal input where needed, preserve independent DPO challenge and maintain a record capable of explaining the decision to the requester, the DPC and a court.

### Where XpertDPO support fits

 Complex or contested access requests often need more than workflow management. They need senior judgement on scope, searches, privilege boundaries, third-party rights, redaction, proportionality, escalation and the evidence supporting the final response.

 [XpertDPO's Complex DSAR Support](https://xpertdpo.com/data-subject-access-request-dsar-support/) helps organisations bring those elements into a controlled decision route. Where the in-house DPO or privacy lead needs confidential challenge or additional specialist depth before the organisation commits to its position, [DPO Support](https://xpertdpo.com/dpo-support/) provides a senior escalation and second-opinion layer around the existing team.

### Sources

- [*O'Brien v The Data Protection Commission and Others* \[2026\] IEHC 250](https://ww2.courts.ie/view/Judgments/6badc2eb-8c85-4189-9194-2ae746c89d8a/6d3db5a9-4325-48f1-a7cb-b439c9b970a9/2026_IEHC_250.pdf/pdf)
- [Data Protection Act 2018, section 60, revised text](https://revisedacts.lawreform.ie/eli/2018/act/7/section/60/revised/en/html)
- [Data Protection Act 2018, section 151, revised text](https://revisedacts.lawreform.ie/eli/2018/act/7/section/151/revised/en/html)
- [Data Protection Act 2018, section 162, revised text](https://revisedacts.lawreform.ie/eli/2018/act/7/section/162/revised/en/html)
- [EDPB Guidelines 01/2022 on data subject rights: right of access](https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en)
- [EDPB Guidelines 10/2020 on restrictions under Article 23 GDPR](https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en)
- [CJEU, *RW v Österreichische Post*, C-154/21](https://juris.curia.europa.eu/juris/document/document.jsf?docid=269146&doclang=en)
- [UK Court of Appeal, *Open Rights Group v Secretary of State for the Home Department* \[2021\] EWCA Civ 800](https://www.bailii.org/ew/cases/EWCA/Civ/2021/800.html)
- [UK Court of Appeal, *The 3million v Secretary of State for the Home Department* \[2023\] EWCA Civ 1474](https://www.judiciary.uk/judgments/the-3million-v-secretary-of-state-for-the-home-department/)
- [High Court, *LinkedIn Ireland Unlimited Company v Data Protection Commission* \[2026\] IEHC 235](https://ww2.courts.ie/view/Judgments/fe952110-0f6c-4236-95d7-97809d8447be/c25c575d-5e94-4d9b-9321-4d1bdb1839a3/2026_IEHC_235.pdf/pdf)
- [Court of Appeal legal diary, appeal record A.AP.2026.0000123](https://procedures.courts.ie/app/legal-diary/listing-types?listing_type=d144204c-c52a-ee11-bdf5-000d3ab780dd)
- [Matheson, Irish High Court clarifies DSAR exemptions](https://www.matheson.com/insights/irish-high-court-clarifies-dsar-exemptions-under-the-gdpr-and-data-protection-act-2018/)

## General Information Only

This article is provided for general information and does not constitute legal, regulatory, or professional advice. Data protection obligations depend on the specific facts, context, and jurisdiction involved. You should not rely on this content as a substitute for advice tailored to your organisation.

If you would like support with a specific issue, please contact us: https://xpertdpo.com/contact/
