How to Handle a UK Subject Access Request: A Practical Guide for HR Teams

How to Handle a UK Subject Access Request: A Practical Guide for HR Teams

How to handle a UK Subject Access Request: a practical guide for HR, legal and privacy teams

Most Subject Access Requests do not arrive with a neat subject line saying “SAR”. They arrive as an email from a former employee, a grievance message, a request for “all emails about me”, or a short note asking for a copy of everything the organisation holds.

That is why the first few days matter. The legal deadline is important, but the operational problem is usually more immediate: who owns the request, where the data sits, which systems need to be searched, and how the team will avoid reviewing the same material three times.

In most cases, UK organisations must respond without undue delay and within one month. The ICO also expects a reasonable and proportionate search. If you need more information to confirm identity or a representative’s authority, the response period does not start until you have what you reasonably need. If clarification about the information requested is reasonably required, the clock can be paused while you wait for that clarification.

The practical takeaway is simple: do not spend the first week “working out what to do”. Put a process around the request on day one.

WindowPriorityPractical output
0-24 hoursRecognise, log and check identity or authorityCase record, owner and initial deadline
24-48 hoursConfirm scope and map searchesSystems, custodians, search terms and date ranges
48-72 hoursCollect and structure initial evidenceDocument inventory and review plan

The first 72 hours.

1. Recognise and log the request

A SAR can be made verbally or in writing and the requester does not need to use legal language. HR, managers, customer support and shared inbox owners should know that phrases such as “send me all the information you hold about me” may be enough to trigger the process.

As soon as the request is recognised, record the date received, requester, channel, wording, case owner and initial deadline. This sounds administrative, but it is one of the easiest ways to avoid deadline problems later.

2. Confirm identity, authority and scope

For a current employee writing from a known work account, identity may be obvious. A former employee, solicitor, family member or other representative may require proportionate checks. Do not ask for more identification than you need, but do not send sensitive records until you are satisfied that the recipient is entitled to receive them.

Then read the request closely. Is it actually asking for everything, or is it focused on a grievance, dismissal, recruitment process or particular time period? Where clarification is genuinely needed to identify the personal information requested, ask a specific question and record why you asked it.

A useful clarification is practical rather than defensive. For example: “Are you asking for all employment-related personal data, or specifically information relating to the grievance process between March and May?”

3. Build a search map before you start collecting files

The fastest way to make a SAR expensive is to start searching without a plan.

For an employee request, relevant sources may include the HRIS, personnel file, payroll, recruitment systems, absence records, grievance or disciplinary files, manager mailboxes, Teams or Slack, shared drives and case-management tools. For each source, record the owner, search terms, date range, export method, search date and any limitations.

This creates a defensible record of what was searched and stops HR, IT and legal from running overlapping searches without knowing what the others have done.

4. Review personal data, not just documents

A common mistake is to treat every document that contains the requester’s name as something that must be disclosed in full. That is not how the right of access works. The question is what personal information in the material relates to the requester.

Emails are the classic example. A long email thread may contain a few lines about the requester, information about several colleagues, confidential business material and duplicate content. The review should separate those issues rather than treating the whole email as one disclosure decision.

A simple document inventory helps. For each item, record the source, date, relevance, third-party data flag, redaction status and final action. That gives reviewers one working record instead of a folder full of files and memory-based decisions.

5. Treat third-party personal data as a separate review question

Employee and customer DSARs frequently contain information about other people: managers, witnesses, complainants, colleagues, clients, patients or service users.

The key question is not “does another person’s name appear?” It is whether disclosure would reveal information about another identifiable person and, if so, whether that information can be disclosed, redacted or withheld. Consent is relevant, but it is not the only factor; the organisation must also consider whether disclosure without consent would be reasonable in the circumstances.

6. Keep redactions and exemptions reviewable

Redactions should never be a last-minute black-box exercise. Use a working copy, record proposed redactions and keep the original record unchanged.

A useful redaction note should identify the document, location, type of information, reason for the proposed redaction, reviewer and final decision. The same discipline applies to exemptions: avoid blanket assumptions and record the reasoning where an exemption is relied on.

AI can help with repetitive work such as classification, duplicate detection, identifying possible third-party data and preparing redaction candidates. It should not make the final disclosure decision. Human reviewers remain responsible for scope, exemptions, redactions and release.

7. Run final QA before anything leaves the organisation

The final review should not simply ask “have we finished the documents?”. It should check that the response is complete, coherent and safe to send.

Before disclosure, confirm the scope used, systems searched, search limitations, third-party data decisions, redactions, exemptions, response pack, supplementary information and secure delivery method. Save the audit trail with the case.

A surprisingly high-risk failure is much simpler than a legal interpretation issue: sending the right response to the wrong email address. Build delivery checks into the QA step rather than treating them as an afterthought.

A practical SAR checklist for HR teams

Use this before closing a Subject Access Request

  • Request logged and case owner assigned.
  • Initial deadline calculated.
  • Identity and representative authority checked where necessary.
  • Scope understood and clarification requested only where reasonably required.
  • Search map completed.
  • Relevant systems searched and limitations recorded.
  • Document inventory created.
  • Personal data reviewed for relevance.
  • Third-party personal data assessed.
  • Redactions and exemptions reviewed and documented.
  • Final response pack checked.
  • Supplementary right-of-access information included or linked where required.
  • Delivery method and recipient details checked.
  • Audit trail saved.

When does external DSAR support make sense?

Not every SAR needs external help. A narrow request with a small, well-organised dataset may be perfectly manageable in-house.

Support becomes more valuable when a request is urgent, document volumes are high, the employee is in dispute with the organisation, several systems need to be searched, third-party data is extensive or the internal team simply does not have enough review capacity.

Seifti supports the operational side of Subject Access Requests: organising evidence, preparing review-ready packs, flagging third-party personal data, preparing redaction notes and creating audit-ready decision logs. Your HR, legal or privacy team keeps control of final legal and disclosure decisions.

For law firms handling DSAR matters for clients, Seifti can also work behind the scenes on white-label execution or help build a repeatable internal DSAR workflow, including templates, checklists and practical AI prompts.

DSAR support for UK HR, legal and privacy teams

We handle the operational work behind the request. You keep the legal and disclosure decisions.

See our DSAR support White-label DSAR support for law firms

FAQ

How long do UK organisations have to respond to a SAR?

In most cases, without undue delay and within one month. The deadline can be extended in certain complex cases or where the individual has made a number of requests. Identity checks and reasonably required clarification can also affect how the response period is calculated.

Do we have to provide every document that mentions the requester?

No. The right is to the requester’s personal information, not automatically to every complete document in which their name appears. Documents and email threads still need a proper relevance review.

Can an employee be asked to narrow a broad SAR?

You can ask for clarification where it is reasonably required to identify the information or processing activity covered by the request. You cannot force the requester to narrow the request simply because it is inconvenient or broad.

Can AI be used for DSAR review?

Yes, as an assistive tool. It can help classify files, identify duplicates, flag possible third-party data and prepare review notes. Final decisions on disclosure, exemptions and redactions should remain under human control.

Further reading

This article is general information about DSAR practice in the UK and is not legal advice. Disclosure decisions should be taken in the context of each request.

2 Comments

Post a Comment

Skip to content