Handling a Data Subject Access Request
Handling a Data Subject Access Request
A Data Subject Access Request, often referred to as a DSAR or SAR, is a request from an individual asking to access personal information an organisation holds about them.
For employers, these requests commonly come from current or former employees and can involve information held across HR files, emails, Teams messages, meeting notes, performance records, grievance or disciplinary documentation and other systems.
A request can sometimes appear straightforward, but responding properly can involve a significant amount of work. It is also an area where mistakes can create data protection risks, particularly where information relates to other employees or contains confidential material.
There has also been an important recent change for UK organisations as from June 2026, they are required to have a process for handling data protection complaints, including complaints about how a subject access request has been handled. This makes it even more important that employers have a clear internal route for concerns to be raised and resolved. The same specific requirement does not currently apply in Ireland, but adopting a similar internal complaints process is a sensible approach.
Below are some practical steps to help organisations manage a Data Subject Access Request effectively.
Recognise the Request
A person does not need to use the words “Data Subject Access Request”, refer to GDPR or submit a particular form for their request to be valid.
A request could simply say:
· “Please send me everything you hold about me.”
· “Can I have a copy of my HR file?”
· “Please provide the emails discussing my performance.”
· “I would like copies of the notes from meetings about me.”
Requests can also be made verbally or electronically. This means managers and other employees need to know how to recognise a potential request and who it should be passed to internally.
Act Quickly
Once a request has been identified, record the date it was received and identify who will be responsible for coordinating the response.
In both the UK and Ireland, organisations will generally need to respond without undue delay and within one month. In certain circumstances, this can be extended by up to a further two months where the request is complex or a number of requests have been made. It’s wise not wait until the final week before beginning the process. A request involving several years of employment, multiple managers and large volumes of emails can very quickly become very time consuming, especially if redaction is required to protect other information.
Check the Individual's Identity Where Necessary
Before releasing personal information, you need to be satisfied that you are providing it to the correct person. Do not automatically request copies of passports or other formal identification where there is no genuine doubt about someone's identity. Any identification requested should be reasonable and proportionate to the circumstances. Where somebody is making a request on behalf of another individual, such as a solicitor or family member, check that they have appropriate authority to act on that person's behalf.
Understand What They Are Asking For
Some requests are very specific, others can simply ask for “everything you hold about me”.
Where an organisation holds a substantial amount of information, it may be appropriate to ask the individual to clarify what information they are particularly seeking.
For example:
· A particular period of time, seek a time period.
· Emails or correspondence involving particular individuals, seek names.
· Information relating to an employee relations matter, seek details.
· Performance or appraisal information, seek details.
· Information surrounding a particular decision.
There is also an important difference between the UK and Ireland when clarification is sought. Current UK rules allow the response period to be paused in certain circumstances, commonly referred to as ‘stopping the clock’ while necessary clarification is awaited. In Ireland, organisations should seek clarification where reasonably necessary but should not automatically use this as a means of delaying the response.
Identify Where Information May Be Held
Do not assume that all relevant personal information will be contained within the employee's HR file.
Depending on the request, information could be held within:
· HR systems.
· Payroll systems.
· Email accounts.
· Microsoft Teams, Zoom, Google Meet, Slack or other messaging platforms.
· Shared drives.
· OneDrive, Google Drive or SharePoint.
· Performance management systems.
· Meeting notes.
· Business-related AI Platforms.
· Grievance or disciplinary files.
· Occupational health records.
· CCTV.
· Business-related WhatsApp messages or other communication platforms.
Where work-related personal information is held through business communication channels, it may potentially fall within the scope of the request.
Think carefully about who may hold information relating to the person and identify appropriate search terms before beginning searches.
Carry Out Appropriate Searches
Organisations are required to carry out a reasonable and proportionate search when responding to a subject access request. It’s a good idea to keep a record of:
· The systems searched.
· The individuals asked to search information.
· Search terms used.
· Date ranges searched.
· Decisions made about the scope of searches.
This can be extremely helpful if the individual later challenges the response.
Remember: It Is Personal Data, Not Necessarily Every Document
A subject access request gives an individual a right to access their own personal data.
It does not automatically mean that they are entitled to receive every document in its entirety simply because their name appears somewhere within it. For example, an email chain may contain information relating to the requester alongside commercially sensitive information or personal information about several other people. The organisation needs to identify which information is the requester's personal data and consider what can appropriately be disclosed, redaction of other information contained within documents is often required.
Review Information Carefully
Retrieving the information is often only the first part of the process.
Everything identified should be reviewed before it is released, it is also a good idea to check it a couple of times.
Particular care should be taken where documents contain:
· Personal information relating to other individuals.
· Confidential information.
· Witness information.
· Information relating to other employees.
· Legally privileged material.
· Information which may fall within another relevant exemption.
For any circumstances where information can be withheld or redacted, exemptions should be considered individually and the reasons for relying on them should be documented.
If you are unsure whether information should be disclosed, it may be appropriate to seek specialist advice.
Protect Other People's Information
One of the biggest risks when responding to a DSAR is accidentally disclosing somebody else's personal data. It is very important to consider whether third-party information needs to be redacted or whether it is reasonable and lawful to disclose it in the circumstances.
Redaction needs to be completed carefully. It is important to ensure that information is actually removed and cannot simply be uncovered by copying text from a document or removing a visual black box.
Do Not Alter or Delete Information Because a Request Has Been Made
Once a request has been received, it is important that deleting, changing or concealing information to prevent it being disclosed doesn’t take place, as the intention of preventing disclosure can amount to a criminal offence.
Prepare the Response
The response should clearly explain what information is being provided and any supplementary information about how the individual's personal data is/was being processed if that is not already clear.
Where information has been withheld or redacted, consider what explanation should appropriately be provided as the reason for this, as this needs to be stated in the response.
The information should be presented in a way that is clear and accessible to the individual.
For UK organisations, the response should also tell the individual of how they can make a data protection complaint directly to the organisation as well as to the Information Commissioner's Office (ICO). This is now a specific requirement and should be built into standard DSAR responses.
Send the Information Securely
A DSAR response can contain a significant amount of sensitive personal information.
Take appropriate steps to make sure it is sent securely.
Depending on the circumstances, this could include:
· A secure document portal.
· Password protected files.
· Encrypted email.
· Secure file transfer.
Check the recipient details carefully before sending anything.
The last thing an organisation needs after completing a substantial DSAR exercise is to create a data breach by sending the response to the wrong person.
Keep a Record of the Process
Maintain a clear record of how the request was handled.
This could include:
· The original request.
· Date received.
· Identity checks where applicable.
· Any clarification correspondence.
· Searches undertaken.
· Information identified.
· Redactions and exemptions considered or undertaken.
· A copy of the response.
· Date the response was issued.
If the requester later complains to the Information Commissioner's Office in the UK or the Data Protection Commission in Ireland, having a clear audit trail will help demonstrate how the organisation approached the request.
Important UK Change: You Now Need a Data Protection Complaints Process
In June 2026, the Data (Use and Access) Act 2025 introduced a new legal requirement for UK organisations to have a process for handling data protection complaints. The change is intended to give individuals a quicker route to raise concerns directly with an organisation and, where possible, resolve them before the matter is escalated to the ICO, reducing unnecessary regulatory escalation.
A data protection complaint is broader than a DSAR. It could relate to how a subject access request has been handled, how personal information has been collected, used, stored or shared, the security measures used to protect it, or the use of monitoring technologies. If it is unclear whether somebody is making a data protection complaint, the organisation should ask them to clarify what they are unhappy about and what they want the organisation to look into.
UK organisations are now required to:
· Give people an accessible way to make a data protection complaint.
· Acknowledge receipt within 30 days.
· Take appropriate steps to investigate and respond without undue delay.
· Keep the complainant informed of the complaints’ progress.
· Tell the complainant the outcome without undue delay.
· Keep adequate records of the complaint and how it was handled.
There is no requirement to create a completely separate complaints procedure if an existing process can be adapted. However, individuals do not have to use the organisation's preferred form or channel. A complaint can be made in other ways, including verbally, and it still needs to be recognised and handled appropriately.
The ICO also confirms that organisations are required to tell people about their right to complain both when their personal information is collected and when responding to a subject access request. Employers should therefore review employee privacy notices, DSAR response templates and any existing grievance or complaints procedures to make sure the route for raising a data protection complaint is clear.
Although these particular requirements are UK-specific, organisations in Ireland may also wish to adopt a similar internal complaints process as good practice. A clear route for raising and resolving data protection concerns can improve governance, create a useful audit trail and may help resolve issues before they are referred to the Data Protection Commission.
Why is this important?
Data Subject Access Requests can become complicated very quickly, particularly where there are large volumes of information, ongoing employee relations matters or significant amounts of third-party data. Having clear processes for both DSARs and data protection complaints, acting quickly, and reviewing information carefully can make these issues considerably easier to manage and reduce the risk of avoidable escalation, and unnecessary legal and reputational risk.
At AHR we have extensive experience supporting organisations with data protection and HR matters. We can support employers with managing Data Subject Access Requests and the wider people implications that can arise from them. You can contact us for support with Data Protection or other HR/People matters via the following link: https://www.ahruki.com/contact/.
The following organisations provide helpful guidance on Data Subject Access Requests:
UK (including Northern Ireland): Information Commissioner's Office (ICO) https://ico.org.uk/
Ireland: Data Protection Commission (DPC) https://www.dataprotection.ie/en
Please note: This blog is for information purposes only, it’s not legal advice, and is only up to date at the time of publication.