Employee DSARs: What HR Should Do First

Employee DSARs: What HR Should Do First

Employee DSARs: what HR should do first when a current or former employee makes a Subject Access Request

Employee DSARs often arrive when HR and legal are already dealing with a sensitive workplace issue. The request itself may be only one sentence, but the search can touch years of emails, HR records, manager notes, payroll information, Teams messages and documents about other employees.

The answer is not to search everything immediately. The answer is to control the request before the document volume controls you.

What makes an employee DSAR different?

Legally, an employee SAR is still a Subject Access Request. Operationally, workplace requests tend to be harder because the information is spread across systems and mixed with information about managers, colleagues, witnesses and business decisions.

SourceWhy it becomes difficultPractical review focus
Manager emailsHigh volume and mixed contentIsolate personal data, duplicates and third-party information
Grievance or disciplinary filesWitnesses, complainants and sensitive allegationsReview third-party data and exemptions case by case
HR and payroll systemsStructured data across several modulesConfirm scope, export method and completeness
Teams or SlackInformal comments and multiple participantsReview context, not keyword hits alone

Employee DSAR risk areas.

The first 24 hours: what HR should actually do

When the request arrives, focus on control rather than collection.

Day one

  • Log the exact wording and date received.
  • Assign one case owner.
  • Calculate the initial response deadline.
  • Check whether identity or representative authority needs confirmation.
  • Read the request for obvious scope limits, dates or subject matter.
  • Identify the likely systems and people who will need to help with searches.

In most cases, UK organisations must respond without undue delay and within one month. The ICO’s current guidance also confirms that you may ask for clarification where it is reasonably required, and that the response period can be paused while you wait for that clarification. You cannot force the employee to narrow the request simply because it is broad.

Do not start with “all emails mentioning their name”

This is one of the most common ways an employee DSAR becomes unmanageable. An email search can return thousands of hits, but a hit is not the same thing as disclosable personal data. The requester may be copied on a thread that is mostly about a business issue, or a long exchange may contain only a few lines that actually relate to them.

Build a search map first. Typical sources include the HRIS, personnel file, payroll, grievance and disciplinary records, manager mailboxes, collaboration tools, shared drives and case-management systems. For each source, note who owns it, the search terms used, the date range, when the search was run and any limitations.

Which employee records need the most care?

Grievance notes, witness statements, investigation reports, manager comments, redundancy scoring, sickness records, confidential references and legal advice usually deserve closer review. Some may be disclosable, some may need redaction and some may require an exemption assessment. Avoid blanket rules.

Third-party personal data is usually the hardest part

Employee records rarely concern one person only. A grievance file may contain the requester’s personal data alongside information about the complainant, witnesses and managers. An email may discuss several employees.

The review question is whether disclosure would reveal information about another identifiable person and, if so, whether it is appropriate to disclose it, redact it or withhold it. A name is only part of the analysis: someone may be identifiable from their role or the surrounding facts even after their name is removed.

Where AI can genuinely help

AI is useful when it removes repetitive review work rather than trying to replace the decision-maker. It can help classify documents, detect duplicates, identify names and identifiers, surface likely third-party data and prepare redaction candidates or review summaries.

But the guardrails matter. Sensitive employment data should only be processed through approved tools and environments, and the final decisions on scope, exemptions, redactions and disclosure should remain with qualified human reviewers.

Final employee DSAR QA checklist

Before the response leaves the organisation

  • Scope and deadline documented.
  • Relevant systems and custodians searched.
  • Search limitations recorded.
  • Emails reviewed for personal data, not just keyword hits.
  • High-risk HR records received appropriate review.
  • Third-party personal data assessed separately.
  • Redactions and exemptions documented.
  • Final pack checked for residual personal data.
  • Supplementary right-of-access information provided.
  • Delivery method and recipient details checked.
  • Decision trail saved.

When to bring in external help

A straightforward request with a small dataset can often be handled internally. External support becomes more useful when the employee is in dispute with the organisation, the search returns thousands of emails, several systems are involved, third-party data is extensive, the deadline is tight or the internal team simply does not have review capacity.

Seifti helps HR, legal and privacy teams organise the evidence, structure document review, flag third-party data, prepare redaction notes and create a review-ready response pack.

For law firms advising clients on DSAR matters, Seifti can also provide white-label operational support or help build an internal DSAR delivery system with workflows, templates, checklists and practical AI prompts.

Employee DSAR support without adding headcount

We structure the searches, the review and the redaction notes. Your team keeps the final call.

See our DSAR support White-label DSAR support for law firms

FAQ

Can a former employee make a SAR?

Yes. The right of access is not limited to current employees.

Do we have to disclose every email that mentions the employee?

No. The review is about personal information relating to the requester, not every complete document that contains their name.

Can we ask the employee to clarify the request?

Yes, where clarification is reasonably required to identify the personal information requested. It should be specific and genuinely necessary.

Should we automatically redact colleagues’ names?

No. Third-party information needs a case-specific assessment.

Further reading

This article is general information about DSAR practice in the UK and is not legal advice. Disclosure decisions should be taken in the context of each request.

No Comments

Post a Comment

Skip to content