Skip to main content

Insight article

September 28, 2018

Employee data subject access requests

An individual’s right of access to data which is collected about them is set out in the new Data Protection Act 2018.

Under the Act, a “data subject” can make a data subject access request (a DSAR), and a “data controller” has a duty to comply, subject to some exceptions.

Although responding to a DSAR can be time-consuming and expensive, the obligations of transparency under the Act mean that you must be willing to explain how you are handling the request and to confirm this to the employee within the required time limit. If you do not, the employee may feel aggrieved and believe that you have failed to comply with the Act’s requirements, leaving you vulnerable to a potential complaint being made to the ICO or a court order to comply with the DSAR.

It is, therefore, important to respond to a DSAR in an appropriate manner.

What to do if you receive data subject access requests from employees

You should make an initial assessment to consider:

  1. whether or not you store or process data concerning the employee;
  2. whether you intend to respond;
  3. the scope of the request; and
  4. the proposed approach to finding the data and dealing with the response.

In general, regardless of any suspicions about the employee’s motivation, you should approach compliance in a positive and helpful way:

  1. you must facilitate the exercise of the DSAR;
  2. the request must be handled fairly and transparently;
  3. information must be provided in a concise, transparent, intelligible and easily accessible form, using clear and plain language.

In the employment forum, DSARs are frequently made in the context of an ongoing dispute or a tribunal or court claim. An employee may be genuinely motivated by a wish to find out what data is being processed and to ensure that it is accurate. However, the employee may also see the trouble and expense to which you may be put by dealing with a DSAR as offering useful leverage in a dispute and in achieving a settlement.

Your response

Your response should be in writing or, if appropriate, by electronic means. If the request was made originally by electronic means, information should be provided “in a commonly used” electronic form unless otherwise requested by the employee. At the employee’s request, the information may be provided orally as long as you are certain of the identity of the individual making the request. However, oral requests are rare.

Except in perhaps very straightforward cases, it would be sensible to take legal advice before either substantively responding to a DSAR or indicating a refusal to deal with such a request.

Are there any exceptions to the DSAR?

Under the Act, there is no obligation to comply with a DSAR in relation to the following:

Personal data in respect of which a claim of legal professional privilege could be maintained in legal proceedings. This applies only to documents which carry legal professional privilege for the purposes of English law.

Reference

A reference given (or to be given) in confidence for employment, training or educational purposes. The exemption covers the personal data within the reference, whether processed by the reference giver or the recipient.

Management

Personal data is processed for the purposes of management forecasting or management planning in relation to a business or other activity to the extent that complying with a DSAR would prejudice the conduct of the business or activity. For example, it is likely to prejudice the conduct of a business if information on a staff redundancy programme is disclosed before it is announced to the rest of the workforce.

Records of Intent

Personal data consisting of records of intentions in relation to negotiations between the employer and employee to the extent that compliance with the DSAR would be likely to prejudice the negotiations.

Other

Other exceptions relate to regulatory functions, judicial appointments and proceedings, the honours system, criminal investigations, tax collections and various corporate finance services.

What happens if you do not respond to a DSAR?

Other than in exceptional cases, you will be under a duty to take action on a request by responding. There are, however, some circumstances in which you may decide not to take action. Examples might be where:

  • the person to whom the DSAR was addressed is not the data controller (perhaps because it is acting as a data processor or someone else is the controller);
  • the request is unfounded or excessive; and/or
  • you can demonstrate that the request infringes the EU doctrine of abuse of rights.

If so, you must tell the employee without delay and, at the latest, within one month of receipt of the request. You must give reasons for not taking action. You must tell the employee of the possibility of complaining to the supervisory authority and taking legal proceedings.

Except in clear circumstances and in which you are confident you can justify a decision not to take action on a request (as might be the case if you are not the controller), you should engage with the employee and seek to limit the request.

For more information on data subject access requests, speak to employment lawyer Karen Cole today.

Note: This article is not legal advice; it provides information of general interest about current legal issues.

Stay in touch

Subscribe to our newsletter

Stay in touch

By completing your details and submitting this form you confirm you are happy for us to send you marketing communications and that you agree to our Website Privacy Policy and Legal Notice and to us using Mailchimp to process your data.


Sending

News/Insight

  • Double jeopardy of digital asset inheritance planning amid probate delays
    Hidden digital assets and mounting interest on inheritance tax bills are creating a costly double risk for families dealing with estates following the death of a loved one, as probate delays continue to impact thousands across England and Wales, addi


    Read more
  • Deal or no deal? Keeping negotiations on track
    How to keep commercial deals on track with Heads of Terms, NDAs and exclusivity, improving efficiency, reducing risk and avoiding delays.


    Read more
  • Rights and wrongs: How AI is reshaping Employment Tribunal claims
    AI may be a familiar presence in the workplace, but it’s now starting to appear somewhere less expected: the Employment Tribunal (ET). Grayson Stuckey explores this trend – and what it means for employers.


    Read more
  • Renters’ Rights Act: why process and paperwork matter more than ever for landlords
    The Renters’ Rights Act has now passed into law, marking one of the most significant shifts in the private rented sector in a generation. Most of the new measures will take effect in May 2026, with a national landlord database to follow later in th


    Read more
  • Understanding the Roles of Executors and Trustees
    When making a will, you place significant trust in those appointed to carry out your wishes. Executors and trustees are key roles, often held by the same people, but their responsibilities differ. Understanding these roles and their obligations helps


    Read more

What they say...

  • W Sandover, April 2026
    Boundary Wall dispute “Although (for complex, not relevant) reasons, this matter never reached the point of either negotiations or a court case, Barker Gillette staff provided us with excellent support. I would certainly go back to them in the

  • Client, April 2026
    Excellent suppy “Karen Cole supported me through a difficult time with warmth and professionalism. She made the entire process as smooth as possible, responding quickly to communication and giving clear advice. I would highly recommend Karen to

  • Client, April 2026
    So helpful! “Pippa Marshall listened and offered supportive, practical advice. She was very friendly, easy to talk to and did not pressure me to make any costly decisions during my free 30-minute consultation. I would definitely recommend Pippa

  • Nika Franke-Matthecka, April 2026
    “We had an excellent experience working with Michael Davies and his team on the sale of our property. They were efficient, knowledgeable, and highly diligent throughout the entire process. Communication was always prompt and clear, which made w

  • Paul Woodman, March 2026
    Will writing “Excellent service from start to finish. Efficient and good value. Charlotte was very professional, knowledgeable and understanding.”

Read more
Send this to a friend