
Rachel Rigg asks whether DSARs are used as “fishing expeditions”. Her Horsfield Menzies article then correctly explains that a DSAR is a data-protection right: a person asking what personal data an organisation holds about them and how it is being processed. Fine. Now place that beside Sam Butler Horsfield Menzies. I supplied medical records because Cepac was disputing disability. Butler went prospecting through the chronology for litigation leverage, got the fucking appointment wrong, and Horsfield Menzies then contacted my medical centre to find out when another doctor could see me. The employee asking for his own data gets the fishing metaphor. The solicitor following somebody else’s medical data all the way to the surgery apparently gets headed paper.
Rachel Rigg has handed Horsfield Menzies : Blog vs Behaviour an unusually generous headline. Her article, “DSARs AS A FISHING EXPEDITION – DO THEY WORK?”, examines employees who make data subject access requests before grievances, ACAS or Employment Tribunal proceedings in the hope that their own data might reveal useful evidence.
However, Rigg also supplies the sentence that matters: “A DSAR is a data protection right.” Quite. The person is asking an organisation what personal data it holds about them. They are exercising a statutory right over their own fucking information.
That makes the Sam Butler Horsfield Menzies file rather awkward.
Rachel Rigg Calls It Fishing
The Horsfield Menzies article carefully distinguishes a DSAR from disclosure in litigation. A DSAR concerns the requester’s personal data, while Tribunal disclosure serves the wider evidential exercise. They have different purposes, different scope and different restrictions.
That distinction is perfectly sensible. Unfortunately for Horsfield Menzies, purpose becomes a much more interesting word once you open the medical correspondence carrying Sam Butler’s name.
In February 2025, Cepac was disputing my disability and demanding medical evidence. I supplied medical records because the respondent wanted evidence about whether I was disabled and how my condition affected me. The reason for the disclosure was not mysterious, hidden or buried somewhere nobody could understand.
It was disability evidence.
Horsfield Menzies wanted proof. It got proof. Then Sam Butler started treating the file like a fucking prospecting licence.
Sam Butler Horsfield Menzies Finds The Rod
By 5 March 2025, Butler was asking the Tribunal for disclosure of medical records while Cepac continued to contest disability. Nine days later, his own correspondence defended the respondent’s use of information disclosed by me, expressly identifying “his medical information” and saying my medical history was relevant because I had made claims about the impact of my disability.
So far, so litigation.
Then the purpose starts to slide.
Instead of simply assessing the medical material for disability, Butler went into the chronology looking for something useful against my postponement position. An entry dated 17 February 2025 caught his eye. From that, Horsfield Menzies advanced the position that the appointment relevant to the 20 March hearing had only been requested on 17 February.
There was one problem.
It was the wrong fucking appointment. Prick.
The Wrong Fucking Appointment
Butler went into a medical chronology looking for litigation leverage, came back holding the wrong fucking appointment, and presented it to the Tribunal as fact. Except unfortunately for this offensive prick, he was fucking wrong.
The 17 February entry concerned a different appointment. I had already notified the Tribunal about the 20 March appointment on 16 February. Butler had gone digging through medical records supplied to establish disability, found something he thought could hurt me, fired it into the litigation and missed the fucking target.
By 14 March, Horsfield Menzies had to accept that I had indeed notified the Tribunal on 16 February and that the medical entry Butler had relied upon related to a separate issue and appointment. Then came the clerical aftercare. Butler insisted the firm had been careful about what was merely “apparent” from the documents and had “not made assertions of fact.”
That is a fascinating description of a factual position you have just had to correct.
There was no reprimand from the Tribunal. Naturally.
Accuracy Apparently Became Optional
There is an inconvenient data-protection principle lurking here too: accuracy. Article 5(1)(d) UK GDPR requires reasonable steps to ensure personal data is not incorrect or misleading as to a matter of fact. Moreover, the ICO says the more important the use, particularly where it may significantly affect somebody, the greater the effort that should go into checking accuracy.
Butler was not discussing whether Tesco had the wrong postcode for a Christmas catalogue. He was converting sensitive medical chronology into a proposition deployed in active litigation against the patient whose records he had received.
Yet he pulled out the wrong appointment.
More importantly, the error was not some harmless typo sitting forgotten in an internal note. Horsfield Menzies wanted to use appointment timing against my request to move a Tribunal hearing. The information mattered precisely because Butler wanted the Tribunal to do something with it.
He went fishing in special-category data and hooked the wrong fucking fact.
Then Horsfield Menzies Followed The File Out Of The Bundle
Getting the appointment wrong might have been the point where a sensible professional wondered whether this expedition had already travelled far enough.
Instead, Horsfield Menzies went further.
Butler’s 14 March email told the Tribunal: “We have spoken with the medical centre responsible for the Claimant’s appointment.” The medical material identified my healthcare provider. Horsfield Menzies then contacted that provider and came back with information about when another doctor could see me, whether that doctor would be at the same level as my existing clinician and how much longer I might wait for somebody more senior.
Read that sequence without the expensive stationery softening the edges.
I give an opposing law firm medical records because its client disputes my disability. The file identifies my healthcare provider and appointment information. The firm reads the chronology, gets an appointment wrong, then somebody rings the medical centre and asks enough questions to return with alternative appointment windows and clinician seniority.
Not “stalking” as some criminal-law label. We’ll leave the overstepping of boundaries to Employment Judge James. Stalkery in the ordinary human sense that makes your skin crawl when you read the sequence.
That is invasive as fuck. I keep my blinds closed on an evening now, just in case Butler’s in the bushes.
The Patient Becomes Scheduling Data
The coldest part is what happened next. Butler did not return from this little excursion merely to admire the information. He used it.
Horsfield Menzies told the Tribunal that another appointment could be arranged with a doctor at the same level in early April, while a more senior clinician could apparently become available a few weeks later. Consequently, Butler suggested it would be “more expedient” for me to reschedule my medical appointment than for the Tribunal to reschedule the preliminary hearing.
There is the conversion.
The patient becomes a diary problem. A doctor becomes a “level”. Treatment becomes a movable booking. Meanwhile, the opposing solicitor’s timetable remains fixed furniture while the disabled claimant’s healthcare gets dragged around the room looking for somewhere less inconvenient to put it.
That is what makes the episode so fucking ugly. Medical information supplied because a company demanded proof of disability became operational intelligence about how easily the claimant’s treatment could be moved out of the company’s way.
Professional language can make almost anything look sanitary.
The underlying behaviour still stinks.
The DSAR Was The Right. This Was The Expedition.
Now return to Rachel Rigg’s article.
Her hypothetical employee sends a DSAR because they want to know what personal data an organisation holds about them. They may hope it reveals something relevant to a grievance or future claim. Horsfield Menzies chooses “fishing expedition” for the headline, even while Rigg correctly explains that the DSAR itself is a data-protection right.
By contrast, Sam Butler received somebody else’s special-category medical data during litigation and treated individual healthcare entries as collateral ammunition. When one entry looked useful, he deployed it. When the underlying appointment turned out to be different, the expedition did not end. Horsfield Menzies followed the information outside the document and into the medical practice.
Rachel Rigg’s fisherman asked what data an organisation held about him.
Sam Butler followed mine upstream until he found the fucking surgery.
If Horsfield Menzies wants a case study on fishing, it already had one in the office.
The Law Has A Name For The Problem: Purpose Limitation
The uncomfortable legal principle here is not complicated. Article 5(1)(b) UK GDPR is purpose limitation. Personal data must be collected for specified, explicit and legitimate purposes. It does not become general-purpose ammunition merely because the recipient later spots another way of using it.
The Data (Use and Access) Act 2025 also put the modern rules on further processing into the UK GDPR through Article 8A. In plain English, purpose does not evaporate when the PDF lands in a solicitor’s inbox. Where a controller wants to reuse personal information for a different purpose, the law requires that reuse to satisfy the purpose-limitation rules and still have a lawful basis.
That matters because Horsfield Menzies itself explained why my medical history was relevant: disability and its claimed effects.
However, the chronology then became material for an argument about when I had arranged a particular appointment. Afterward, the healthcare trail led beyond the document itself and into contact with the medical centre, producing fresh information about alternative treatment availability.
That is exactly the kind of movement data-protection law calls function creep when a defined source of information starts acquiring additional jobs.
Possession is not purpose.
My medical file was evidence of disability. It was not Sam Butler’s fucking search warrant.
Health Data Is Not Free Litigation Scrap
There is another layer. Health information is special-category data, which receives additional protection under UK GDPR. An organisation needs an Article 6 lawful basis for the processing and must also satisfy an Article 9 condition.
Horsfield Menzies may reach for Article 9(2)(f), covering processing necessary for legal claims. Fine. Litigation still does not function as a magic spell that turns every clinical breadcrumb into fair game.
The ICO says necessity means more than something being useful, habitual or part of normal procedure. Processing must be a targeted and proportionate way of achieving the relevant purpose. If the same objective can reasonably be achieved through a less intrusive route, necessity is not established.
So Horsfield Menzies can answer the obvious questions.
What made mining a medical chronology for appointment timing necessary and proportionate? Why did an opposing law firm need to ring the claimant’s medical practice when the Tribunal already knew the healthcare appointment existed? What lawful basis covered that specific processing, and what Article 9 condition did Horsfield Menzies rely upon for turning medical evidence into appointment intelligence?
“We were litigating” is not the end of the analysis.
Neither is “we already had the records.”
That is why data protection has principles instead of a fucking finders-keepers rule.
Data Minimisation Meets Sam Butler
Purpose limitation does not stand alone either. The ICO links the handling of special-category data directly to data minimisation. In ordinary language: use what you actually need for the identified purpose, not every intimate fact that happens to be lying around inside the file.
Horsfield Menzies had a legitimate forensic question available to it. Did my evidence establish disability and the effects relied upon? The firm could argue about the adequacy of that evidence, and it did.
Likewise, Cepac could oppose postponement using the material already before the Tribunal. Butler was perfectly capable of writing a submission saying the company wanted the hearing to proceed without first becoming an amateur receptionist for my healthcare arrangements.
So what required the extra step of turning the medical file into a lead?
By the time Horsfield Menzies was asking a practice when different doctors could see the patient, the exercise had travelled a considerable distance from simply reading disability evidence. Medical data had stopped behaving like evidence of impairment and started behaving like a private scheduling database for the opposing solicitor.
For a law firm publishing guidance about the boundaries of data rights, that is some fucking performance.
“Without Disclosing Any Personal Information”
Butler’s email took care to say that Horsfield Menzies contacted the medical centre “without disclosing any personal information.”
Lovely sentence.
It also answers the narrowest possible question while leaving the larger one sitting in the room tapping its foot. The issue is not merely what Horsfield Menzies told whoever answered the phone. The issue is how the firm got there, why it was making the call and what it did with the information obtained.
Something identified the medical centre. Something supplied the healthcare context, told Horsfield Menzies which appointment mattered enough to investigate.
That something was my medical information.
The phone call did not fall out of the sky. Nor did the alternative appointment details spontaneously appear in Butler’s correspondence.
It was the next cast of the fucking line.
The Firm Wanted More Medical Evidence Too
The entitlement looks worse when you remember that Horsfield Menzies was simultaneously arguing that the medical evidence supplied was inadequate and that Cepac remained entitled to contest disability.
In other words, this was not a firm reluctantly holding sensitive records it never wanted. Butler had actively sought further medical disclosure while Cepac’s position kept the evidential burden on me to produce more.
That creates a fairly poisonous arrangement from the claimant’s side. Hand over intimate healthcare information because the respondent demands proof. Then discover that individual entries may become collateral arguments and the healthcare provider itself may receive a phone call from the opposing lawyers.
After that, “provide more medical evidence” does not sound quite as clinically neutral.
It sounds like asking somebody to refill the tackle box.
The Complaint Reached The Owners
None of this was discovered retrospectively after everybody had packed the file away. I complained about it in March 2025.
The complaint went directly to Angus Menzies, Simon Horsfield and Daniel Rubin. Among other matters, it raised the use of my medical information, the contact with the medical centre and Butler’s conduct. I followed up asking for confirmation of an investigation and an outcome.
No completed investigation outcome was communicated to me.
That contrast deserves to be framed.
Horsfield Menzies could search my litigation history. It could inspect my medical chronology. Butler could extract appointment information. The firm could contact the healthcare provider and return with information about alternative clinicians and dates.
Yet when scrutiny turned around and pointed at Sam Butler, the investigative appetite became remarkably fucking delicate.
The complaint did not disappear.
It just blogged instead.
The Firm That Calls DSARs Fishing Had A Trawler In My Medical File
This is why Rachel Rigg’s article is such a gift.
The blog presents a familiar employer-side concern: workers may use DSARs hoping to uncover useful evidence. Fine. Rigg then reminds readers that a DSAR has a defined legal purpose and scope.
TCAP has no argument with that principle.
Horsfield Menzies should try applying it while looking in a mirror.
The worker requesting their own data is exercising a statutory right. Sam Butler was the solicitor sitting on somebody else’s medical file, extracting appointment chronology for tactical use, getting the chronology wrong and then participating in a process that reached beyond the record into the claimant’s medical centre.
One of those people was asking to see their own information.
The other one had the fucking fishing rod.
Wrong Fisherman
Horsfield Menzies likes boundaries when it writes about data protection. DSAR here. Litigation disclosure there. Different frameworks. Different purposes, and different restrictions.
Excellent.
Now apply that discipline to Sam Butler Horsfield Menzies.
My medical records entered the case because Cepac disputed disability. Butler mined them for appointment timing and got the wrong appointment. Horsfield Menzies then contacted my medical centre, obtained fresh information about alternative doctors and availability, and Butler used that information to argue that my healthcare should move instead of the hearing.
Meanwhile, data-protection law asks questions about purpose, lawful basis, necessity, proportionality, minimisation and accuracy. Those are not decorative words for professional websites. They become rather more important when the person holding special-category health data decides to make it do another job.
Rachel Rigg wrote the headline.
Sam Butler, invasive pig, cast the line.
And if Horsfield Menzies still wants to know whether fishing works, perhaps it can start by explaining what the fuck its solicitor was doing with my medical file.
Lee Thompson – Founder, The Cummins Accountability Project
Sources
- Horsfield Menzies – Rachel Rigg – DSARs As A Fishing Expedition – Do They Work? – Rigg identifies a DSAR as a data-protection right and distinguishes its purpose and scope from Employment Tribunal disclosure.
- ICO – Principle (b): Purpose limitation – current guidance on Article 5(1)(b), compatible reuse, lawful basis and the additional Article 9 requirement for reused special-category data.
- Data (Use and Access) Act 2025 – Section 71 explanatory notes – explains the current Article 8A framework governing further processing and purpose limitation.
- ICO – Rules on special-category data – confirms that health data requires an Article 6 basis and an Article 9 condition, including the legal-claims condition, and explains the necessity requirement.
- ICO – Principle (d): Accuracy – explains the duty to take reasonable steps over inaccurate or misleading personal data, with greater effort where the use may significantly affect an individual.
- Sam Butler, Horsfield Menzies – correspondence dated 5 and 14 March 2025 concerning medical disclosure, the 17 February entry, acceptance that it concerned a different appointment, contact with the medical centre, alternative clinician availability and the suggestion that the medical appointment should be rescheduled.
- TCAP source register – Horsfield Menzies medical-centre contact and the 23-24 March 2025 complaint to Angus Menzies, Simon Horsfield and Daniel Rubin.
- TCAP – Brochure Sam vs File Sam
- TCAP – Angus Menzies, Simon Horsfield And The Sam Butler Complaint
