Consider this illustrative situation: a customer writes to your collections team with a letter adapted from an online forum or an AI tool. It asks for a Deed of Assignment through a subject access request and claims that, without the deed, the debt cannot be enforced.
The short answer: a subject access request does not automatically entitle someone to the entire Deed of Assignment. The CSA explains that not receiving that document does not, by itself, make a debt unenforceable. A genuine request for personal data still needs proper handling.
For a compliance team, the practical challenge is preparing a response that explains the distinction, fits the account and remains traceable to the wording that was approved.
What prompted the CSA guidance?
On 29 September 2026, the Credit Services Association published a warning about misinformation surrounding Deeds of Assignment and subject access requests. The announcement was updated on 1 October.
The CSA warns that misleading claims circulating through online forums and generative AI tools can waste customers’ time and money and delay effective help with their finances.
Its consumer guidance followed discussions with the Information Commissioner’s Office. The ICO supports the general information about access rights; it does not regulate consumer credit or express a view on matters outside its remit.
That distinction matters when firms explain the guidance. It should not be presented as an ICO ruling that a particular customer’s debt is enforceable.
A mistaken claim can accompany a valid request
The right of access concerns a person’s personal data, subject to applicable limitations and exemptions. It does not automatically require full copies of original documents.
The ICO’s public guidance explains that organisations may provide extracted information or redacted documents. A response also needs the relevant information about how the organisation uses the person’s data; simply correcting the DOA claim is not a complete SAR response.
Operationally, teams need to recognise both parts of the incoming letter. One concerns the customer’s belief about the debt. The other may be a request to exercise an information right.
Routing the latter through the firm’s established SAR process helps avoid treating the whole letter as something to dismiss. An approved explanation can support that process, but it cannot replace the work required to fulfil the request.
One question, different account circumstances
The CSA distinguishes debt collection on a creditor’s behalf from debt purchase. In the first situation, the original creditor retains ownership; appointing a collector does not create a DOA. For purchased debt, the agreement transferring the debt is distinct from the notice of assignment informing the customer about the sale.
If your firm works with both account types, the approved response needs to reflect that distinction. Separate templates or appropriately controlled variants are possible approaches. The important point is that the explanation matches the account.
Approval alone cannot establish that match. Someone must identify the relevant circumstances and select the appropriate response.
Where the response can go wrong
The following are illustrative workflow risks, rather than findings reported by the CSA:
- An improvised explanation: an agent changes wording and accidentally dismisses the access request or makes an unsupported promise about closing the account.
- The wrong variant: the explanation describes a debt sale when the firm is collecting for the original creditor.
- An outdated version: a previously approved response remains in a local folder after revised wording becomes available.
- A gap in the record: when a complaint arrives, the team cannot connect the generated response to its template version and approval history.
These failures can affect the substance of the response as well as its governance. Compliance and legal teams still need to assess the wording and individual circumstances.
What a useful response should address
Rather than copying a ready-made legal reply, teams can use these questions when reviewing their own wording:
- Does it acknowledge the customer’s concern respectfully?
- Does it explain the relevant account circumstances and document distinctions clearly?
- Does it correct the specific misconception without implying that every debt is enforceable regardless of other issues?
- Does it recognise and route any genuine subject access request for proper handling?
- Does it offer a clear next step and appropriate access to free, independent debt advice?
The CSA points readers towards GOV.UK, MoneyHelper and the FCA’s information on free debt advice. Those resources can help inform signposting that the firm’s specialists review.
These are review prompts, not an exhaustive legal checklist. The customer may also raise a separate dispute that requires its own assessment.
Keeping the approved explanation connected to its use
Once specialists agree the wording, the team needs to manage how it is used. Useful checks include whether the template is current for that account type, who approved its version and whether each generated response can be linked to it.
A shared folder may hold approved documents, but teams also need clear ownership, version selection and records of use. Storage is not control. When source guidance changes, someone needs to assess whether the templates need updating.
CommsPliant supports this work. Teams approve versioned templates through human review and generate responses from the approved version. The CommsPliant Evidence Vault links each generation record to its template version and approval history. The platform does not determine the legal answer or confirm that the correct variant was selected. Generation evidence does not establish delivery, reading or customer understanding.
If a customer raised this claim today, could your team identify the appropriate approved response, handle their access request and trace the resulting generation record?