HR manager reviewing a document with an employee across an office desk

Employee Subject Access Requests: What You Have to Hand Over When Staff Ask for Their Data

September 17, 20269 min read

The grievance lands on Monday. The subject access request lands on Tuesday.

If you employ people, this will happen to you. An employee falls out with a manager, a disciplinary starts, a redundancy consultation opens, and a week later an email arrives asking for "all the personal data you hold about me". Sometimes it comes from their solicitor. Sometimes it comes as a one-liner on a Friday afternoon.

In the 12 months before the ICO published its guidance for employers, it received 15,848 complaints about subject access. It wrote a dedicated employer Q&A because workplace requests kept going wrong. I have been handling these for clients for more than 10 years, and the same mistakes come up every time.

This article covers the employee-specific bits. If you want the general rules on the clock, the one-month deadline and what a SAR response has to contain, I covered those in How to Handle a Subject Access Request. Read that first if you have never dealt with one.

Why staff send them, and why that does not matter

Employees send SARs during disputes because it works. For the price of an email they get to see what managers have written about them, what HR has recorded, and what was said in the meetings they were not in. It is cheaper than tribunal disclosure and it arrives sooner.

Employers hate this, and a lot of them ask me the same question: can we refuse because they are only doing it to build a tribunal case?

No. The ICO's employer guidance says it outright: "You cannot simply refuse to comply because the worker is undergoing a grievance or tribunal process." Motive is irrelevant. The SAR and the grievance are two separate processes and you run both.

The same applies to settlement agreements. You cannot write a clause that makes an employee withdraw a SAR or promise never to make one. The ICO's position is that the right of access "cannot be overridden by a settlement or non-disclosure agreement", and any clause trying to do so is likely unenforceable.

It does not have to say "SAR"

The ICO is clear that a worker "can make a SAR verbally or in writing, including by social media", and can make it "to any part of your organisation".

So "Can I have a copy of my appraisal notes?" said to a line manager in a corridor is a subject access request. "What do you actually hold about me?" typed into a grievance form is a subject access request. A message to the company Facebook page counts.

The clock starts when the request arrives, not when HR finds out about it. If your line managers do not know what a SAR looks like, you will lose a fortnight before anyone opens a file.

What you actually have to search

This is where employers underestimate the job. An employee's personal data is not just their HR file. It is everywhere their name appears in a way that is about them.

In a typical SAR from a member of staff, the search covers:

→ The HR file, contract, absence records, appraisals and pay history
→ Emails between managers about the employee, including the ones they were never meant to see
→ Teams, Slack and WhatsApp messages on company systems where the employee is discussed
→ Notes from investigation meetings, grievance meetings and disciplinary hearings
→ CCTV footage, if they ask for it and can give you a date and time
→ Anything a manager has kept in a personal folder "just in case"

Emails are the biggest job. The ICO's view is that "the right of access only applies to the requester's personal information contained in the email", so an email that mentions them in passing while discussing a project is not automatically theirs. But an email where two managers discuss whether to manage them out is personal data, and they get it. You review each one. The ICO specifically says a "blanket" policy either way is not acceptable.

Personal email accounts and personal phones are usually outside the search, but only if your IT and acceptable use policies make clear the business is not the controller of what staff do on their own accounts. If your policies say nothing, expect an argument.

What you can hold back

You do not have to hand over everything. There are exemptions, but each one has to be applied to a specific document with a specific reason. "We are withholding the investigation file" is not a reason.

Other people's data. If a document contains information about another employee, you can withhold that part unless the other person consents or it is reasonable to disclose without their consent. In practice you redact rather than refuse. A salary review comparing five people is a good example: the requester gets their own line, not the other four.

Witness statements. If witnesses to a grievance were promised confidentiality, and disclosure would let the requester identify them, you have a strong basis for withholding. If the witness is the requester's manager giving a management account, you probably do not.

Confidential references. References you gave or received in confidence for employment, education or training purposes are exempt. Your privacy notice or staff handbook should already say references are treated as confidential.

Management planning. Information used for business planning, such as a redundancy selection pool that has not been announced, can be withheld if disclosure would prejudice the business. The ICO's own example is a restructure where releasing the pool early would cause "staff unrest". This is narrow. It does not cover routine HR discussion.

Negotiations. Your internal thinking about a settlement figure is exempt while the negotiation is live. Once the deal is done, the exemption falls away.

Legal privilege. Advice from your solicitor, and correspondence created for litigation, stays privileged. The Data (Use and Access) Act 2025 wrote this into UK law rather than leaving it to case law. Advice from a non-lawyer HR consultant is not privileged.

Person typing on a laptop at a desk

"It's too much work" is sometimes true, and rarely a defence

The ICO's guidance includes a worked example that will sound familiar to any small business. A company with 4 staff receives a SAR that would mean reviewing 3,000 emails. The employer thinks that is manifestly excessive.

The ICO's answer was not "refuse". It was:

→ Ask the worker to narrow the request
→ Review the emails where they appear only as a name, email address or signature and provide a summary of those rather than every copy
→ Deal with the substantive emails properly

Since 5 February 2026, when the Data (Use and Access) Act provisions commenced, the law says you must make a "reasonable and proportionate" search. That is helpful. It means you are not required to hunt through every backup tape. It does not mean "we have a lot of emails" gets you out of it.

The same Act let you stop the clock while you wait for clarification. If you need the employee to tell you which period or which systems they mean, the one-month period pauses on the day you ask and restarts the day after they reply. Use it. But you can only ask for clarification where you hold a large amount of information and it is reasonably required. The employee can also refuse to narrow it, in which case you search for everything.

The mistake that gets people prosecuted

On 3 September 2025 the director of a care home in Bridlington was convicted at Beverley Magistrates' Court under section 173 of the Data Protection Act 2018. A woman with lasting power of attorney had asked for her father's records, including incident reports and CCTV. The director blocked, erased or concealed records to stop them being disclosed. He was fined £1,100 and ordered to pay £5,440 in costs.

Small numbers. Read the section again. It is a criminal conviction against an individual, not a fine against the company.

Section 173 makes it an offence to alter, deface, block, erase, destroy or conceal information with the intention of preventing disclosure after a SAR has been received. It applies to the manager who "tidies up" the shared drive after the request lands. It applies to the director who tells IT to run the retention policy early.

If a SAR arrives during a dispute, the first instruction that goes out is a hold. Nothing gets deleted, not even under your normal retention schedule, until the response has gone out.

A pile of white shredded paper on a table

What a process that survives a grievance looks like

The businesses I work with that handle employee SARs well all do the same 6 things.

→ Every manager knows that a request for "my information" in any form goes to one named person the same day
→ That person logs the date received and the deadline before doing anything else
→ A litigation hold goes out to IT and the managers involved: nothing deleted, nothing edited
→ The search list is written down before the search starts: which mailboxes, which systems, which date range
→ Every redaction and every exemption is recorded against the document it was applied to, with the reason
→ The response goes out with a covering letter explaining what was withheld and why, and how to complain

The last one matters more than it used to. Since 19 June 2026 you have to have a data protection complaints process and acknowledge complaints within 30 days. An employee who thinks you have held back too much will use it.

Three things to check this week

→ If an employee asked their line manager for "everything you hold on me" tomorrow, would it reach the right person before the weekend?
→ Do your IT and acceptable use policies say who controls data on personal phones and personal email accounts?
→ Is there anyone in your business who could delete emails after a SAR arrives without a second person knowing?

I work with UK businesses as their outsourced DPO, and an employee SAR in the middle of a dispute is one of the most common reasons a client picks up the phone. If one has just landed and you are not sure where to start, drop me a message. Happy to have a no-obligation chat.

References

ICO, Subject access request Q and As for employers

ICO, A guide to subject access (updated 16 July 2026 for the Data (Use and Access) Act 2025)

ICO, Care home director found guilty of ignoring request for personal information, 3 September 2025

Clyde & Co, Criminal liability for obstructing data subject access requests: lessons from the Bridlington Lodge case, October 2025

Farrer & Co, 12 lessons from the ICO's new subject access requests Q&A for employers

DLA Piper, Commencement of the data protection provisions in the Data (Use and Access) Act, February 2026

Ashfords, The Data (Use and Access) Act: changes for data subject access requests

RWK Goodman, Subject access request 101: ICO's guidance for employers (source for the 15,848 complaints figure)

Data Protection Act 2018, section 173

Alex Goodman
Alex Goodman|DPO and GDPR expert|LinkedIn logo icon
Alex Goodman has over 10 years of experience in data protection. He has handled compliance for organisations across financial services, SaaS, healthcare, enforcement, charity, and children's data, first inside large regulated businesses and now as an independent adviser. He holds practitioner certifications in Data Protection Impact Assessments and Subject Access Requests, and is an accredited Counter Fraud Investigator.
Back to Blog

Alex Goodman is an experienced GDPR consultant and outsourced Data Protection Officer working with UK businesses to improve their DPO and GDPR compliance.

© 2026 - GDPR Consultant - All Rights Reserved.

Driven by expertise and personalised service, we’re here to guide you towards GDPR compliance every step of the way.

© 2026 - GDPR Consultant - All Rights Reserved.