Legal and accounting support for UK businesses and individuals
office@yudey.uk
Employer advice and HR processes guides · 6 min read

Employee data subject access requests

An employee subject access request concerns their personal data, not an automatic right to every whole document mentioning the workplace.

Jurisdiction: Great Britain — Northern Ireland has separate employment law.

An employee subject access request concerns their personal data, not an automatic right to every whole document mentioning the workplace. It can be made without legal terminology or a prescribed form, including during a grievance or litigation. [1]

Recognise and scope the request

Record when it arrived and route it promptly to the responsible person. Verify identity only where reasonably needed, and clarify the request where appropriate without imposing unnecessary obstacles. Identify relevant HR, payroll, email and messaging systems.

The ICO requires a reasonable and proportionate search. [1] Record the systems, custodians and search approach, including why any proposed search would be disproportionate. Do not use inconvenience alone to avoid searching relevant records.

Review the response lawfully

Assess third-party information and any applicable exemption individually. Legal privilege is not created by copying a lawyer into an ordinary business email. Explain any lawful restriction and provide the required accompanying information through a secure channel.

Check the response deadline and any permitted extension or pause under the current rules. Health records need particular care; tribunal disclosure is a separate obligation, so one process does not automatically replace the other. Preserve relevant data and do not delete material to avoid disclosure.

Recognise the request across ordinary communication channels Train managers to identify a request for the person's own information even when it arrives verbally, in a grievance email or through a representative. Record the original wording and receipt date and route it promptly to the responsible team. The requester does not need to cite the UK GDPR or use a prescribed form. The ICO's guidance updated in July 2026 reflects the Data (Use and Access) Act changes. [1] Apply the current rules to the request rather than an old checklist that adds unnecessary procedural barriers.

Confirm identity or representative authority where reasonably needed, using a proportionate method. A current employee known to HR should not automatically be required to send extensive identity documents simply because the standard form contains that field. If clarification is reasonably necessary to respond effectively, ask a focused question promptly. Do not force the person to narrow the request merely to reduce work. Keep the reason and dates of any valid clarification or identity step, and calculate its effect under current guidance instead of assuming every follow-up question pauses the deadline.

Plan a search that follows where the data is held Identify relevant HR, payroll, email, messaging and other systems, together with likely custodians and periods. Consider informal manager records where they contain the person's data. Record search terms and the reasons for including or excluding particular sources. The duty is to make a reasonable and proportionate search, not an unlimited search of every possible record or a cursory check of the personnel folder alone. If a proposed search is considered disproportionate, document the factual reasoning and obtain appropriate review rather than relying on inconvenience as a sufficient explanation.

Preserve relevant information while the request is handled and avoid deleting material to prevent access. Distinguish routine copies from source records and maintain enough context to understand the data. A name search can miss records using an employee number, initials or an informal reference, so consider how the organisation actually identifies people. If data has been archived or a system changed, assess the available retrieval route. The search record should allow another reviewer to understand what was done and why, particularly if the requester later identifies a source that appears to have been missed.

Review personal data and restrictions case by case Identify the requester's personal information within documents rather than assuming every whole document must be supplied or withheld. Assess third-party information and any applicable exemption individually. Legal professional privilege requires its own analysis; copying a lawyer into an ordinary business email does not automatically establish it. Keep reasons for redactions or withholding and review consistency across the response. A grievance or tribunal dispute does not itself remove the right of access, and the request should not be rejected merely because the employer believes the information may assist litigation.

Check the response timetable from the actual receipt and any permitted intervening step. The normal period is one month, with a possible further two months where the relevant conditions for complexity or multiple requests are met. Explain a justified extension within the required time. Do not treat staff absence or a large inbox as an automatic entitlement to more time. Keep responsibility for review and approval clear so a completed search does not sit awaiting a manager's signature while the response date passes unnoticed.

Deliver information that the requester can use safely Provide the required supplementary information as well as the personal data. Organise the response so documents, dates and redactions are understandable, and check that files open in an accessible format. Remove hidden comments, metadata or attachments that would inadvertently reveal information assessed as restricted. Use a secure delivery method suitable for the recipient and verify the destination. A secure portal is not a complete solution if the person cannot reasonably access it or download the information, so consider an appropriate alternative where necessary.

Retain the response, search record and reasoning for exemptions or restrictions. Explain relevant complaint and review rights where required, and address a supported concern about missing information promptly. Coordinate with litigation disclosure without treating one process as automatic compliance with the other. If the request reveals inaccurate personnel data, consider the appropriate correction separately. A complete access record should show recognition, timing, search, review and delivery, making the employer's handling accountable without disclosing more third-party or sensitive information than the law requires.

Frequently asked questions

Must an employee use a special form to make a subject access request?

No. A request can be made through ordinary channels if it is clear that the person seeks their own personal information, and should be routed promptly.

Can an employer force the requester to reduce the scope?

No. Reasonably required clarification is different from imposing a narrower request. Apply current guidance and record why any clarification is necessary.

Does copying a solicitor into an email automatically make it privileged?

No. Privilege depends on the nature and circumstances of the communication and requires specific assessment rather than reliance on the recipient list alone.

Can a subject access request be ignored because tribunal proceedings are underway?

No. Access and litigation disclosure are separate obligations. Assess the request and any genuine exemption under the applicable data protection rules.

What should be retained after the response is delivered?

Keep the supplied response, timing, search approach and reasons for redactions or exemptions, so any later question about completeness can be assessed accurately.

Official sources

Sources checked: 9 September 2026. Check the linked guidance for subsequent changes.

  1. ICO: Guide to subject access

General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.

Report a correction