Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.
Endless identity verification
high likelihoodWe cannot action your request until you verify your identity. Please send a copy of your passport, a utility bill, and a selfie holding your ID.
What answers it
A controller may use reasonable measures to verify identity, but it may only ask for information it actually needs and already holds a basis to check. Demanding a passport scan from someone whose account you identify by email address is disproportionate and is itself a data-minimisation problem. Offer to verify through the same channel you already use to log in, state that you consider the demand excessive, and note that the response clock is running.
"We hold no personal data about you"
high likelihoodA search of our systems returned no personal data relating to you.
What answers it
Ask for that in writing, signed, together with a description of the systems searched and the search terms used. A nil return is a substantive answer that the controller must stand behind, and it is frequently wrong: it usually means one production database was searched and backups, CRM, marketing, support tickets, call recordings, and third-party processors were not. Name the systems you believe hold your data, including any you have interacted with.
Blanket confidentiality or trade-secret refusal
medium likelihoodThe information you have requested is commercially confidential / contains our trade secrets / is proprietary.
What answers it
Confidentiality and intellectual-property carve-outs are narrow and must be applied item by item, not as a blanket. The correct response is redaction of the protected element and disclosure of the rest, with a schedule explaining what was withheld and why. Ask for that schedule.
Refusal because the data mentions someone else
medium likelihoodWe cannot disclose these records because they contain the personal data of other individuals.
What answers it
The presence of third-party data is a reason to redact, not to refuse. The controller must consider whether it can disclose with the third party removed, whether the third party has consented, and whether it is reasonable to disclose without consent. A blanket refusal on this ground is not a lawful answer.
"Your request is manifestly excessive"
medium likelihoodYour request is manifestly unfounded or excessive, so we are refusing it / charging a fee.
What answers it
The burden of showing that a request is manifestly unfounded or excessive is on the controller, and it is a high bar — the regulator guidance treats it as exceptional, not as a routine response to a broad request. Ask the controller to state, in writing, the specific grounds and the evidence for them. If you have made only one request, say so. A single, first, ordinary request is not excessive.