Part 13
A Case Study in Banking Safeguarding Misuse

Introduction
When a bank and a regulator rely on evidence the customer is not permitted to see, safeguarding loses transparency and becomes structurally unsafe. This update explains how undisclosed internal documents shaped the Financial Ombudsman’s investigation, why the complainant was advised to submit Subject Access Requests (SARs) to both Halifax and the Ombudsman, and how the resulting disclosures revealed contradictions, reframing, and procedural failures that had previously been hidden from view.
The complaint was referred to the Financial Ombudsman Service (FOS) on 26 March 2026, following Halifax’s Final Response dated 11 March 2026. On 14 May 2026, the Investigator introduced himself and confirmed that he had received Halifax’s evidence bundle. On 10 June 2026, he issued his formal view, stating that he had “listened to the calls” and “reviewed the branch notes” supplied by Halifax — evidence the complainant had never been shown.
Halifax also stated that some documents had been provided to the Ombudsman “in confidence,” and the Investigator relied on these materials when forming his decision. Because the complainant was not permitted to see the evidence used to justify the outcome, and because Halifax refused to disclose the same material directly, the complainant was advised to submit Subject Access Requests (SARs) to both Halifax and the FOS.
The purpose of these SARs was to obtain the same evidence already used in the investigation, to understand how decisions were made, and to identify whether information had been withheld, misinterpreted, or relied upon without the complainant’s knowledge.
Section 1 — Why the SAR Was Submitted
The SAR was triggered by three factors:
This included internal notes, staff statements, fraud‑workflow outputs, and documents marked “strictly confidential.”
He stated he had “listened to calls” and “reviewed branch notes,” but did not disclose or summarise them.
They stated that certain documents could not be shared, despite being about the complainant and used in the investigation.
Because the complainant could not meaningfully respond to evidence she had never seen, the SAR became essential.
Section 2 — What Halifax Disclosed
Halifax’s SAR response arrived on 26 July 2026. The material was extensive and not provided in any logical order, so the complainant organised the documents into eight structured files. Files 1–5 contained historical account information and routine banking records arranged chronologically for completeness. The core evidence relevant to the investigation was contained in three files:
File 6 — Internal notes and system records
File 7 — Halifax’s submission to the Financial Ombudsman
File 8 — Confidential documents provided to the Ombudsman
Together, these files revealed:
These disclosures contradicted Halifax’s complaint response and the Ombudsman’s decision.
Section 3 — File 5 Findings: Internal Notes and Reframing
File 5 showed that Halifax’s internal notes did not accurately record what occurred.
Instead, they reframed:
3.1 Timeline updates as “conflicting reasons”
A normal change in circumstances was recorded as inconsistency.
3.2 Documented hearing‑loss support needs as “no trouble communicating”
This contradicted Halifax’s own support‑needs record.
3.3 Emotional distress as “some inconvenience”
Minimising the impact of public questioning and warnings.
3.4 A failed callback as “no error”
Despite internal notes confirming the failure.
3.5 Recording the presence of a second adult
Halifax’s internal notes confirm that staff recorded the presence of a second adult who accompanied the complainant. The notes also clarify that this individual was her son and was well known to a staff member.
Section 4 — File 6 Findings: Halifax’s Submission to the FO
File 6 revealed how Halifax constructed its narrative for the Ombudsman.
4.1 Conflicting reasons were emphasised
Halifax’s submission to the FO emphasised several different explanations for refusing the withdrawal. This conflicted with their own internal notes, which alternated between stating that the withdrawal was declined, not declined, and may be declined by the fraud team.
4.2 Safeguarding concerns were implied
Despite no fraud system flags or safeguarding notes, Halifax’s submission suggested that staff had concerns about the customer’s safety, even though no such concerns were recorded at the time.
4.3 Warnings were reframed as “managing expectations”
Halifax described their repeated warnings about fraud checks and possible account freezes as “managing expectations,” despite these warnings having a clear intimidating impact on the customer.
4.4 Emotional harm was minimised
Halifax acknowledged that the customer became distressed during the incident, but their submission downplayed the emotional impact and did not consider how the handling of the withdrawal contributed to that distress.
4.5 Refusal of privacy was reframed as “branch safety protocol”
Halifax explained that a private room could not be used because moving cash through internal areas posed a risk to staff. While staff safety is important, this reasoning conflicted with the bank’s repeated claims that they were concerned for the customer’s safety. Requiring the withdrawal to take place at a public counter increased the customer’s exposure, not reduced it, and did not align with the stated safeguarding concerns.
4.6 A goodwill payment was offered while denying any error
A contradiction carried into the FO submission.
This file showed how Halifax’s internal assumptions became the foundation of the FO’s decision.
Section 5 — File 7 Findings: Confidential Evidence Provided to the FO
File 7 contained documents Halifax marked “strictly confidential,” including:
5.1 Misuse of Spending History
Routine purchases and lawful withdrawals were presented as behavioural indicators, despite having no relevance to fraud risk.
5.2 Procedural Flags Used as Justification
“EBI required,” “customer refused evidence,” and “declined transaction” were used to support Halifax’s narrative.
5.3 Confidentiality Used to Prevent Visibility
Marking documents “strictly confidential” prevented the complainant from seeing how her behaviour was being interpreted.
These documents were relied upon by the FO but withheld from the complainant.
Section 6 — Safeguarding & Vulnerability
The SAR revealed that Halifax recorded no safeguarding concerns about the complainant or the second adult present during the branch visits. Despite this, the
FO decision introduced a safeguarding concern that did not exist in Halifax’s evidence.
The Investigator stated:
“Another adult was present… so I can understand why the bank had concerns.”
This interpretation was:
The second adult had a legitimate reason to be present and was attending the branch for their own banking business. They were present at both visits — not one — and Halifax raised no concerns about their presence.
Section 7 — Procedural Fairness
The SAR disclosures and the Investigator’s written decision highlighted multiple procedural issues in how the complaint was handled.
7.1 Reliance on undisclosed evidence
The Investigator relied on internal Halifax material that had not been shared with the complainant, limiting transparency and preventing meaningful response.
7.2 Refusal to consider new evidence
Additional evidence raised during the investigation was not reviewed, contrary to DISP 3.6.1R, which requires all relevant material to be considered, even if it emerges later.
7.3 Misinterpretation of vulnerability
The reasoning applied did not align with FCA FG21/1, particularly in relation to recognising and responding to documented support needs.
7.4 Minimisation of emotional harm
Distress was reframed as “inconvenience,” which did not reflect the safeguarding context or the seriousness of the harm experienced.
7.5 Continued involvement after escalation
After the complainant formally requested Ombudsman review on 15 June 2026, the Investigator continued to act as the case handler. He reviewed escalation reasons, requested calls, issued instructions, set deadlines, managed evidence submissions, provided procedural updates, and later communicated the closure of the case. This is inconsistent with standard FOS procedure and raises concerns about independence, role boundaries, and whether the Ombudsman conducted a genuinely separate review.
7.6 Investigator issuing the Ombudsman’s decision
The Ombudsman’s final decision was delivered by the Investigator, who temporarily changed his job title from “Investigator” to “Decision Help” for this communication. He then reverted to “Investigator” when responding to the complainant’s rejection of the decision. This role-switching is inconsistent with FOS workflow and undermines confidence in the independence and integrity of the Ombudsman’s decision-making process.
Section 8 — Evidence Handling Across Both Stages
To understand how both Halifax and the Financial Ombudsman Service handled the complaint, the complainant submitted Subject Access Requests (SARs) to each organisation. Halifax’s SAR revealed multiple inconsistencies, reframed notes, and confidential material that had been provided to the FO without the complainant ever seeing it.
These findings made it necessary to request a full FO SAR to understand how this material was interpreted, used, and relied upon during the investigation — especially given the Investigator’s unusual involvement in finalising and closing the case, and the FO’s attempts to divert the complainant away from obtaining a SAR.
Section 9 — FO SAR Non‑Compliance and Formal Notice Issued
The complainant submitted a full Subject Access Request (SAR) to the Financial Ombudsman Service on 26 July 2026. Under UK GDPR, the FO was legally required to provide a response by 26 August 2026.
Despite this statutory obligation, no disclosure was provided, and the deadline passed without explanation or extension. This failure constitutes a breach of Article 12(3) GDPR, which requires organisations to respond to SARs within one calendar month.
In addition, the FO’s earlier correspondence attempted to limit the scope of the SAR by stating that it would not provide:
This interpretation is incorrect under GDPR.
Under Article 4(1) and Article 15, any information used to:
…is legally classified as personal data, even if the complainant’s name does not appear on the page.
Because the FO both missed the statutory deadline and indicated an intention to unlawfully withhold personal data, the complainant issued a Formal Notice: Late SAR Response & Unlawful Withholding of Personal Data on 29 August 2026, requiring:
The complainant also notified the FO that failure to comply would result in escalation to:
Despite these warnings, the FO did not provide the outstanding SAR. This failure set the stage for the events that unfolded in September 2026.
Section 10 — September 2026 FO Correspondence:
Contradictions, Withheld Data & Second GDPR Breach
The events that followed in September 2026 revealed further procedural failures within the Financial Ombudsman Service (FO), including contradictory statements, partial admissions, and continued non‑compliance with UK GDPR. These developments provide additional evidence of structural safeguarding concerns and reinforce the pattern already documented across Halifax and the FO.
10.1 — 01 September 2026: FO Issues an Incomplete SAR Response
On 01 September 2026, the FO stated that it had “processed” the complainant’s Subject Access Request (SAR). The disclosure consisted almost entirely of:
Crucially, the FO did not disclose: :
The FO applied exemptions that do not apply to closed cases, including claiming that disclosure would “prejudice the discharge of statutory functions.” This interpretation is inconsistent with UK GDPR and with the FO’s own published guidance.
10.2 — 03 September 2026: Final Notice Issued for Incomplete SAR
On 03 September 2026, the complainant issued a Formal Notice – Incomplete SAR Response, listing all missing categories of internal personal data and providing evidence that the FO held these records. The notice highlighted:
The complainant gave the FO 14 days to provide a complete SAR response, warning that failure to comply would result in escalation to the Information Commissioner’s Office (ICO).
10.3 — 07 September 2026: FO Contradiction & Partial Admission
On 07 September 2026, the FO responded with two contradictory statements:
“I’m satisfied that we have shared all personal data held on our systems” followed immediately by:
“The History & Actions of the complaint may include some of your personal data… please advise if you would like me to add these.”
The FO’s admission that “History & Actions” contains personal data confirms that the original SAR response was incomplete and non‑compliant.
10.4 — 07 September 2026: Complainant Requests Missing Internal Data
Later the same day, the complainant formally requested:
This request reset the FO’s obligation to provide the missing personal data.
10.5 — Continued FO Non‑Compliance After 07 September
As of the date of this update, the FO has still not provided:
The FO’s silence after 07 September demonstrates ongoing non‑compliance and avoidance.
10.6 — Why These September Events Matter
The September correspondence reveals:
These behaviours mirror the same patterns documented earlier:
The September events confirm that safeguarding failures occurred not only at branch level, but also within the regulatory process itself.
10.7 — ICO Escalation Trigger
The FO’s continued failure to provide the missing internal personal data within the 14‑day deadline triggers escalation to:
This escalation is now active.
The claimant’s need is straightforward: to understand how the FO came to its decision. If that decision was shaped by mistakes, omissions, or withheld evidence, the complainant has no real path to challenge it. That absence of remedy is part of the wider problem this case exposes.
With the FO still withholding key records, the investigation cannot yet be completed. Part 14 will follow once the missing data is disclosed — or once the matter is escalated formally to the ICO.
These September events did not occur in isolation; they built upon the underlying issues raised in the original complaint.
As the FO has still not disclosed the missing records, the investigation remains open.
To understand why these September events matter, it is necessary to return to the substance of the original complaint.
What the Complaint Was Actually About
The complaint concerned Halifax’s conduct during two lawful cash withdrawal attempts. It focused on the bank’s refusal to allow access to the complainant’s own money, the demand for documentation that had no legal basis, the public questioning about private financial matters, the misuse of fraud mechanisms, and the distress caused by being interrogated in an open banking hall.
The complaint also raised concerns about Halifax’s contradictory explanations, failure to recognise documented support needs, and the emotional harm caused by the refusal of privacy. It did not relate to the complainant’s son, her explanations, or the purpose of the withdrawal. These elements were introduced later by the Investigator and did not reflect the substance of the original complaint.
Explaining the Pattern
The events across Halifax, the Investigator, and the Financial Ombudsman Service reveal a consistent pattern of misdirection. At each stage, the focus shifted away from Halifax’s conduct and toward the complainant, her statements, and her son’s presence. Safeguarding concerns were reframed as suspicion, emotional harm was minimised as “inconvenience,” and procedural obligations were narrowed or avoided.
The Investigator restricted the scope of the complaint, relied on confidential evidence the complainant could not see, and later attempted to redirect her into a “service complaint” route that would not examine the substantive issues.
The Financial Ombudsman’s SAR response continued this pattern, steering the complainant away from full disclosure and signalling an intention to limit searches and withhold internal records. Taken together, these behaviours raise concerns about transparency, independence, and whether the regulatory process was applied proportionately and fairly.
Conclusion
The findings in Part 3 reflect what can be evidenced from Halifax’s SAR, the Investigator’s correspondence, and the Ombudsman’s written decision. Halifax’s disclosures have already revealed inconsistencies, reframed notes, and confidential material that shaped the FO’s investigation. However, full cross‑matching of evidence across both stages cannot be completed until the Financial Ombudsman Service provides its outstanding SAR.
The FO SAR will confirm how Halifax’s internal material was interpreted, relied upon, or misapplied; how vulnerability and safeguarding concerns were assessed; and whether the Ombudsman’s decision was based on independent review or on the Investigator’s reasoning.
Part 13 closes at a point where key FO records remain withheld.
CURB will publish the next stage of this case once those records are disclosed and cross‑referenced with Halifax’s SAR — which has already revealed serious data‑handling breaches — or when regulatory escalation advances.
Design & Copyright Owner Maureen Booth-Martin (MBM) © All rights reserved