Data Subject Access Requests: An HR Guide to Handling DSARs

A practical HR guide to handling data subject access requests — the one-month time limit, thorough searches, and applying exemptions with proper judgement rather than a blanket approach.

Learnsignal Education Team
6 min read
Updated

Under UK GDPR, anyone has the right to ask an organisation what personal data it holds about them and to receive a copy of it — a Subject Access Request, or DSAR. For HR teams, this is rarely a theoretical exercise. In practice, DSARs land on HR's desk most often from current or former employees, and they very frequently arrive alongside — or shortly after — a grievance, a disciplinary process, or the early stages of a dispute. Handling them properly matters both because it's a legal obligation and because how a DSAR is handled often shapes how the wider dispute plays out.

The Time Limit: One Month, Extendable in Complex Cases

The Information Commissioner's Office is clear on the standard timescale: organisations must respond to a subject access request without undue delay, and in any event within one calendar month of receiving it (or of receiving any information reasonably needed to confirm the requester's identity). Where a request is complex, or where an organisation has received a number of requests from the same individual, that period can be extended by up to a further two months — but the individual must be told about the extension, and the reason for it, within the original month, not after it has already expired. Employers shouldn't treat the extension as an automatic buffer; it's meant for genuinely complex requests, not routine ones that simply take longer than planned to action.

Why DSARs Are So Often Tangled Up With Disputes

It's a well-established pattern: an employee facing a disciplinary process, or midway through a grievance, submits a DSAR asking for "all personal data" the organisation holds about them. This isn't misuse of the right — it's a legitimate use of a legal entitlement, often motivated by wanting to see what's been said or recorded about them. But it does mean HR teams need to treat the DSAR as a serious, standalone legal obligation running in parallel with the dispute, not as a tactic to be resented or slow-walked. Treating a DSAR dismissively, or rushing a defensive, incomplete response because the requester is also "the difficult one right now", tends to backfire — both legally and in terms of how the dispute is ultimately resolved.

The scope of a DSAR is wide: it covers personal data about the individual wherever it's held, not just in the formal HR file. That can include emails, informal messages on collaboration tools, manager's notes, CCTV footage that includes them, and data held in systems outside HR's direct control. A search that only checks the obvious personnel file and misses emails or messages held elsewhere in the organisation risks an incomplete response — and if the requester already knows about a document that isn't included in the response, it can seriously undermine confidence in the whole process. A proper DSAR process needs a clear, documented search across the places personal data plausibly lives, not a single query of one system.

Exemptions: A Matter of Judgement, Not a Blanket Rule

Not everything found in a search has to be disclosed. Common exemptions and limitations that apply in an HR context include information that's actually about a third party (where disclosing it would reveal someone else's personal data and their rights need to be balanced against the requester's), material covered by legal professional privilege, and certain management information relating to negotiations with the requester. But these exemptions require a genuine, case-by-case judgement about what applies and why — not a blanket refusal to disclose anything sensitive, and equally not a blanket disclosure of everything found just to avoid the work of assessing it properly. Getting this wrong in either direction creates risk: over-redaction can trigger a complaint to the ICO or a legal challenge to the adequacy of the response, while under-redaction can breach a third party's own data protection rights.

Building a Repeatable DSAR Process

Because DSARs tend to arrive at inconvenient moments and under time pressure, having a clear internal process in place before one lands makes an enormous difference. That means knowing who owns the process, where personal data is likely to be found across the organisation's systems, who has authority to apply exemptions (usually with input from a data protection lead or legal advice rather than an individual manager deciding alone), and how the one-month clock is tracked from day one. Organisations that only think through their DSAR process once a request has already arrived tend to make avoidable mistakes under time pressure that a documented process would have prevented.

Frequently Asked Questions

Can we refuse a DSAR because we think the employee is only doing it to gather evidence for a grievance?

No — a request being linked to a wider dispute doesn't make it an abuse of the right, and it should still be handled properly and within the statutory timescale, alongside (not instead of) dealing with the underlying grievance or disciplinary matter.

Does a DSAR cover informal messages and manager's notes, not just the official HR file?

Yes, in principle — the right of access covers personal data wherever it's genuinely held, which can include messages on collaboration tools and informal notes, so a search limited only to the formal personnel file is unlikely to be adequate.

What happens if we miss the one-month deadline?

Missing the deadline without a valid, communicated extension is a compliance failure that can be raised with the ICO and can weaken the organisation's position in a wider dispute, so tracking the deadline from day one — and communicating an extension before the month runs out, if genuinely needed — matters far more than it might seem at first glance.

Should HR decide alone which exemptions apply?

It's safer to involve a data protection lead or legal advice, particularly where third-party data or privilege is in play — these judgement calls carry real risk in both directions, and getting a second, more specialist view reduces the chance of a costly mistake.

DSARs are one of the clearest points where data protection law and everyday HR practice meet, and they tend to arrive exactly when an organisation is least prepared for extra process — during a dispute, and sometimes alongside a formal concern raised through a whistleblowing disclosure. A clear process, a genuinely thorough search, and careful, case-by-case judgement on exemptions go a long way toward handling them properly, and this connects directly to the wider questions covered in our guide to employee privacy and monitoring at work, since monitoring data is very often exactly what a DSAR asks for. Learnsignal's workplace compliance CPD courses cover DSARs and related data protection obligations for HR teams who want a solid working grounding in this area.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Workplace & HR Compliance Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View Pricing