Following the wave of account restrictions over the summer, I advised affected supporters to submit a Subject Access Request (SAR). Unsurprisingly, the club’s responses have been completely substandard, evasive, and legally flawed. #MUFC must be held accountable to proper data protection standards, so I have put together a step-by-step guide.
This guide is specifically for #MUFC supporters who submitted a SAR regarding the ticketing investigation and received an incomplete, evasive, or inadequate response from the club’s Data Protection Team.
Under Article 15 of the UK GDPR and the Data Protection Act 2018, you are legally entitled to receive a complete copy of the personal data held about you, along with specific supplementary details about how and by whom it was processed.
The club is a data controller legally bound by these statutes. If their response falls short, you have the right to escalate the matter to the UK data regulator, the Information Commissioner's Office (ICO), and I strongly recommend you do so.
Here is an analysis of why the club's responses are failing basic legal standards, and the exact steps you should take to lodge a formal complaint.
Common Flaws in the Club's SAR Responses
If your disclosure letter matches those sent to other supporters, it likely contains one or more of the following serious compliance defects:
1. Blanket Refusal to Disclose IP Address Logs
The club has stated to supporters: "We are unable to provide you with those specific IP addresses, as this is personal data which we cannot verify as being about you."
- Why this is legally untenable: The club used those specific IP addresses and login events to flag, monitor, and restrict your account. If data is linked directly to your Supporter ID and used to make adverse decisions against you, it forms an integral part of your personal data record.
- The club cannot treat an IP address as reliable evidence to sanction you, whilst simultaneously claiming it is too detached to disclose under a statutory access request. Under ICO precedent, network identifiers linked to an account holder are personal data.
2. Narrative Summaries Instead of Underlying Technical Data
The club stated that it "used tooling to allocate unique identifiers to devices" and provided broad figures (e.g., that a device accessed a certain number of accounts).
- Why this is inadequate: A summary narrative written by an administrator is not personal data. Under Article 15, you are entitled to the actual data itself: the specific alphanumeric device fingerprint hashes, unique machine identifiers, and raw, timestamped access audit logs generated against your profile by their third-party software.
3. Conflating Data Compliance with Internal Ticketing Appeals
Several responses contain language actively nudging supporters to cooperate with the ticketing investigation: "If you have not already, we encourage you to reply to the email you received from the Club..."
- Why this is inappropriate: A SAR response is a formal legal instrument, not a commercial customer-service chaser. Using a statutory response to lobby on behalf of an internal ticketing department demonstrates a fundamental confusion between legal obligations and internal club administration.
4. Generic Privacy Policy Links Instead of Specific Article 15 Disclosures
Rather than detailing the specific third-party recipients (the external data analytics firm engaged to run the dragnet) and retention schedules, the club simply linked to its general website privacy notice.
- Why this fails: Article 15(1)(c) requires controllers to inform individuals of the specific recipients or categories of recipients to whom the personal data has been or will be disclosed. Pointing to a generic webpage does not satisfy this requirement.
Step-by-Step Escalation Process
Before the ICO will open an investigation, you must demonstrate that you have given the organisation an opportunity to resolve the issue directly.
Step 1: Send a Formal "Letter of Dissatisfaction" to the Club
Reply to the Data Protection Team ([email protected] or the address your SAR response came from). Keep your tone objective and factual.
State clearly:
- You do not accept that your SAR has been completed in full.
- You require unredacted copies of the specific IP addresses and timestamps linked to your Supporter ID, as they were directly relied upon to place restrictions on your account.
- You require the actual raw technical data: the specific unique device identifiers, machine hashes, and full login audit logs generated by their third-party tooling.
- You require the specific identity of the third-party data processor/firm that processed your account data on behalf of the club.
- Give the club a strict deadline of 7 to 14 days to provide this data or issue a final formal deadlock letter.
Step 2: Note the Strict ICO Time Limit
You have three months from your last meaningful contact with the club's Data Protection Team to submit your complaint to the regulator. Do not let the club drag out correspondence past this three-month window. Once the deadline passes without full disclosure, proceed immediately to Step 3.
Step 3: Lodge a Formal Complaint with the ICO
You can submit your complaint directly online via the Information Commissioner's Office (ICO) portal here: https://t.co/7CkbCKoKTq
When submitting the complaint, select "Data protection complaints" and provide the following evidence:
1. A copy of your original SAR request.
2. A copy of the club's inadequate response.
3. A copy of your follow-up letter challenging their omissions and any further replies received.
4. A concise summary explaining that Manchester United:
- Withheld relevant IP logs linked to your account, despite using those exact records to apply account sanctions.
- Refused to provide the underlying unique device identifiers and audit logs generated by external tooling.
- Failed to identify the specific third-party processors involved under Article 15.
ICO Contact Details:
Online Portal: https://t.co/7CkbCKoKTq
Helpline: 0303 123 1113 (Monday to Friday, 9:00 am to 5:00 pm)
Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
The Important Bit & Why This Matters
The club cannot demand strict adherence to rules from its supporters while adopting a pick-and-choose approach to statutory data protection law.
If Manchester United relied on automated tools, external data firms, and device tracking to disrupt the accounts of loyal match-goers, they are legally bound to hand over the full, unvarnished data trail upon request.
Reporting these systemic omissions to the ICO holds the club accountable and ensures the regulator scrutinises the methods, tools, and third-party data-sharing practices used throughout this investigation.
A revealing look at @MU_ST, the sham that is MUFC's Fan Advisory Board, and the Glazer-Rat regime's apparent cultivation of unwitting controlled 'opposition' 👇
(Starring @MU_ST, @MUSTChair, @ISLO_MUST, @OliWinton, @dipsMUFC & more!)
1/21
THOSE WERE THE DAYS will be available ONLY in print via a ONE-OFF print run, from the purchase links below.
Pre-order only.
Release date: Nov 28th
UK purchases: https://t.co/Sz3tqWP57o
Ireland/Europe purchases: https://t.co/Pn5n8sQXW9
Preview here: https://t.co/ecBcPzxQNl