Steven Railston
11.6K posts

Steven Railston
@StevenRailston
Manchester United reporter @MENnewsdesk. Contact: [email protected]. My views.








Thanks to every fan who got in touch to voice their anger at the club’s attempt to address touting. Clearly United have caught innocent supporters in the crossfire. Hopefully those cases can be given a proper investigation #mufc manchestereveningnews.co.uk/sport/football…











There seem to be a lot of people whose account restrictions are being upheld. I’ve only seen one that hasn’t been so far. All this comes with no real direction or confirmation on what the supporter has actually done. For anyone who can’t understand the reasoning due to insufficient information from the club and received an email telling them their sanction is being upheld, one of the next steps may be to raise a Subject Access Request (SAR). Under UK law, any organisation holding your personal data must provide a copy of that data upon request, free of charge, and usually within one calendar month. Crucially, "personal data" includes automated system logs, internal notes, telemetry data, and audit trails tied to your account. By forcing Manchester United to hand this over, you can bypass their vague customer service language and see the exact technical metrics (IP addresses, click rates, device IDs) that triggered their security flag. When filing a SAR during a ticketing dispute, you should not just ask for "all data." Be highly specific so they cannot delay their response by claiming the request is too broad. You should demand: - Ticketing Portal System Logs: All automated telemetry, access logs, user-agent data, and click-rate timestamps associated with your membership number between the specific investigation dates (March to July 12). - IP Address and Geolocation History: The complete list of IP addresses recorded by their servers logging into your account, alongside any internal flags raised regarding multiple locations. - Internal Communications and Notes: All internal emails, memos, CRM notes, or compliance review documentation mentioning your name or membership number. - The Specific Fraud/Bot Detection Criteria Applied: The exact technical reason your account was flagged (e.g., exceeding a certain number of page refreshes per minute, or concurrent logins from distinct IPs). Here is a template you can use for a Subject Access Request. You can email this directly to the club's Data Protection Officer or compliance team (usually dpo@manutd.co.uk or via their main customer service channel). ------ Subject: Formal Subject Access Request (UK GDPR) – Account Restriction Inquiry Dear Data Protection Officer, Re: Subject Access Request Name: [Your Name] Membership / Season Ticket Number: [Your Number] Email Associated with Account: [Your Email] I am writing to make a formal Subject Access Request pursuant to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. I recently received an email from the club’s ticketing compliance team stating that "sustained activity" on my account indicated a potential breach of terms, resulting in the temporary restriction of my account. The email failed to provide any specific technical data or evidence detailing what this activity entails. To ensure my right to fairness and transparency under the law, and to properly formulate my appeal, please provide me with copies of the following personal data held by the club regarding my account between March 1 and July 12: All digital access logs, telemetry data, server timestamps, page-refresh metrics, and user-agent records associated with logins to my account profile. The complete list of captured IP addresses and inferred geolocations used to access my account during this period. All internal communications, correspondence, memos, or system notes compiled by the ticketing, security, or compliance teams regarding my account or membership number. Any automated profiling or automated decision-making logic logs that directly triggered the flag and subsequent restriction on my account. As per ICO guidelines, I expect to receive this information without delay and at the latest within one calendar month of this request. If you require any standard identity verification to process this request, please contact me immediately via this email address. Yours sincerely, [Your Name] [Your Phone Number] ------ How to Leverage This in Your Appeal In your actual appeal email to appeals@manutd.co.uk (due by July 27), you should explicitly mention that you have submitted a SAR: "As the club has failed to outline the specific technical evidence behind these allegations, I have formally submitted a Subject Access Request (SAR) to the Data Protection Officer to obtain my account logs. Because the club’s deadline forces me to appeal before my legal data rights can be fulfilled, I expect the club to fully review my account profile manually and transparently provide the metrics they are relying on to justify this restriction."







