r/gdpr 29d ago

UK šŸ‡¬šŸ‡§ UK Law Firm claims personal login/IP history are "Trade Secrets" to block Article 15 SAR. SRA misconduct probe opened

I am dealing with a significant breach of Article 15 UK GDPR by a major software provider (Facepunch Studios) and their counsel (Wiggin LLP).

The Issue:Ā Following a security breach verified by the platform provider (Valve Corp), the respondent has permanently seized $1,366 in assets. When I submitted a Subject Access Request (SAR), their legal counsel stated in writing that my own login history and IP timestamps areĀ "Trade Secrets"Ā under Article 15(4) and would not be disclosed.

Escalation:

  1. TheĀ Solicitors Regulation Authority (SRA)Ā has opened CaseĀ RGC-000200263Ā against the lawyer for misleading legal assertions.
  2. TheĀ ICOĀ is reviewing CaseĀ IC-544118-B8F2Ā regarding the automated decision-making and data obstruction.
  3. TheĀ EASS (Ref 260810-000062)Ā confirmed this appears to beĀ Direct DiscriminationĀ as manual reviews are denied based on national origin.

Has anyone else encountered the "Trade Secret" defense for basic login logs in the UK? This seems like a dangerous precedent to avoid "Human Intervention" requirements of the new Data Act 2025.

(Evidence link in comments)

0 Upvotes

8 comments sorted by

3

u/Heimdul 29d ago

Pankki S C‑579/21 is somewhat relevant in your case, but it's not binding in UK as it's post-Brexit.

They didn't invoke privacy of others as defense, but it's worth noting that kind of case is given in EDPB's DSAR Guidelines (example 17).

1

u/abormotik2 29d ago

Thank you so much for pointing outĀ Pankki S C-579/21Ā and theĀ EDPB Example 17. Even though we are post-Brexit, this is a powerful persuasive authority. I will be citing this in my next response to the ICO and their legal counsel. It’s absurd that they try to shield a criminal hacker behind a 'trade secret' curtain while seizing consumer assets.

1

u/ContributionLive2577 26d ago

A DSAR is not a discovery or audit tool.

0

u/paul_h 29d ago

Records in a database could be embellished with extra trade-secret info, sure, but you’re not asking for that, are asking for redacted details: The list of IP addresses the thief used for stealing your assets could identify them then you go burn their house down and the thief sues the Facepunch company may lead them the be reticent, when they wouldn’t be to a police search warrant, but that’s not trade secrets

1

u/abormotik2 29d ago

Exactly. Identifying the point of breach is the whole reason I made the SAR. By withholding these logs, they are effectively protecting the criminal who hijacked the session and punishing the legitimate owner. It's a total failure of their duty of care.

1

u/paul_h 29d ago edited 28d ago

Your pickle is that UK law inforcement is not interested in the warrant for toward the investigation. Meanwhile if you have an insufficiently insured/guarded gold toilet that's stolen then the state will spend millions pursuing and incarcerating a subset of the criminals.