A cloud accounting provider receives a data subject access request from a sole trader. The trader's account file contains the personal data of three of their suppliers, whose names and bank details were uploaded by the trader. The provider acts as processor for the trader's records but is the controller for the requester's own login and billing data. How should the provider lawfully respond to the access request regarding the supplier data held in the account file?
- ADirect the request to the trader as controller of the supplier records, while itself answering only for the personal data for which it is the controller. Correct
- BDisclose the supplier data in full, because the requester is the account holder and the right of access entitles them to everything stored under their account.
- CRefuse the request entirely as manifestly unfounded, because it would require disclosing the personal data of three other identifiable individuals.
- DAnonymise the supplier names and provide the rest of the account file to the requester within one month under the right of access.
Why A is correct: Correct: the provider is a processor for the trader's records, so the access right to the supplier data must be exercised against the trader as controller, and the provider answers in its own right only for data it controls, such as login and billing data.
Why B is wrong: This is tempting because the data sits under the requester's account, but the right of access only covers the requester's own personal data, not third parties' data the requester uploaded as a controller in their own right.
Why C is wrong: This overreaches: the presence of some third-party data does not make the whole request manifestly unfounded, and the provider must still address the requester's own personal data rather than refusing outright.
Why D is wrong: This sounds balanced, but the provider is not the controller for the supplier records and cannot decide to disclose them at all, anonymised or not; the access obligation for that data rests with the trader.