SUBJECT ACCESS REQUESTS – RIGHTS, LIMITATIONS AND POTENTIAL RISKS

What do you need to know about Subject Access Requests?

In a world driven by technology and data processing, information is exchanged daily across multiple digital platforms. In the workplace context, this means that organisations collect increasing volumes of data, from commercially sensitive information to day-to-day digital exchanged between employees. Employers in this context will be considered the “controllers” of the data shared within the organisation’s platforms, and must therefore tread carefully when storing, sharing or disposing of this information, as regulatory breaches may carry hefty fines and significant reputational damage.

At the same time, controllers must monitor and carry out training and due diligence when it comes to internal data being exchanged, especially where these pertain “personal information” – for example identity documents, employees’ letters and contracts, email exchanged about an employee’s performance and conduct, or even chats exchanged between colleagues about another employee who is clearly identifiable.

Data subject access requests (DSARs): overview

Under the UK GDPR and the Data Protection Act 2018, individuals can freely ask a data controller for access to their personal information at any time.

When this happens there may be unfortunate circumstances where the data obtained may provoke serious breakdowns in the employment relationship. For example, an employee may obtain private conversations between colleagues referring to them in disparaging terms, or “confidential” conversations with HR where their manager may have asked for advice on the quickest way to get rid of them.

As we can all appreciate, this can often be a ticking time bomb waiting to explode, and it will be unlikely that a defence could be provided in these scenarios. Furthermore, this would become even more problematic where an existing dispute is already at play, meaning that it could heighten the risk for litigation.

However, does this meant that employees could have unrestricted access to any data held within the organisation that they believe it is personal to them? The answer is no.

First and foremost, when a request is raised, individuals would need to provide an identifier (such as their full name, nick name, or abbreviation) and parameters that they wish their employer to apply for their search (such as dates, names of relevant individuals, likely locations such as personnel files, emails or workplace chats). Searches may be requested even without very specific parameters; however, considerations will need to be made by the employer in relation to the volume of data this may include.

Secondly, information must be reviewed and redacted before being provided to the employee, so as to ensure that information unrelated to that employee is removed, while ensuring that enough context should remain for their personal data to be understandable.

The identities of senders, recipients and other colleagues may be redacted where appropriate, and especially where disclosing the identity for the individuals carries a risk to breach their confidentiality.

Potential exceptions to the right to data

There are circumstances, where information relating to an individual may fall outside the right of access.

These include but are not limited to:

  1. Correspondence or documentation protected by legal professional privilege, such as confidential lawyer–client communications for the purpose of obtaining legal advice.
  2. Information identifying other people in witness statements or investigation records, where they have not consented and disclosure would not be reasonable without consent.

Nonetheless, it cannot always be assumed that this type of data or document is outside a requester’s reach. Each case must be evaluated on its merits, including whether appropriate redaction would allow for the document or data to be disclosed.

In addition to the above, in limited circumstances, employers may reject a request to provide data should the request be deemed as ’manifestly unfounded or excessive’. In this case, refusals must be justified and explained appropriately, including notifying the data subject of the right to complain to the Information Commissioner’s Office (ICO).

Computer screen displaying "The Matrix" code

Are there rules for how long a DSAR should take?

When a subject access request is received, the controller must first ensure that the identity of the requester is verified and will then have a duty to respond without undue delay and normally within one calendar month. In limited circumstances, the controller may extend this deadline by up to two months by notifying the requester before the one-month deadline has passed. 

Should clarification be reasonably required to identify the personal data or processing activities concerned, the response clock may be paused while this is obtained.

Necessary identity checks can affect when the response period begins; but unnecessary proof of identity should not be demanded from an employee whose identity is already clear.

Final considerations

Processing DSARs can take substantial time and effort to process, and it is critical that requests are handled promptly, carefully and appropriately. Therefore, any organisation should ensure that they have taken appropriate steps to deal with them, and to seek guidance immediately from a specialised body or professional should any questions or concerns arise.

At the same time, it is impossible for employers to predict when such requests may be made, which is why it is important that appropriate training, policies and procedures are in place to inform all staff of the expected conduct requirements as well as appropriate usage of company communication systems to reduce a liability risk.

If you need any help and support, please do not hesitate to contact the RELA Team on 01983 897003.

Lorenzo Orifici

Share This Article
Read More Articles
Any questions? Contact us

Appointments are available by telephone or via video call, so no matter where you are in England or Wales we can assist you.

Leave a Reply

The information contained in this blog post is provided for guidance and is a snapshot of the law at the time it is written. It is provided for your information only and should not be used as a substitute for obtaining legal advice that it specific to your particular circumstances.

The guidance should not be relied upon in any decision making process. It is strongly recommended that you seek advice before taking action.


Solicitor in Eastleigh | Solicitor in Salisbury | Solicitor Isle of Wight