An employee asks for ‘everything you hold about my performance’ after a difficult meeting. They have not mentioned data protection or completed a form, but the message may already be a subject access request. For an SME, the risk is rarely the personnel file alone: relevant personal information can sit across managers’ inboxes, messaging apps, payroll, CCTV, occupational-health records and supplier systems.
Recognise the request—whatever it is called
The right of access allows a person to obtain confirmation that their personal information is being processed, a copy of that information and specified supplementary information about the processing. A subject access request, or SAR, has no prescribed wording. It can arrive verbally, by email, through social media or to any part of the organisation. The employee does not need to cite Article 15, use the phrase ‘subject access’ or explain why they want the information.
‘Please send me the notes and messages about my capability review’ is likely to be clear. ‘Why was I not promoted?’ may be an ordinary employment query unless the context shows the person is asking for their personal information. Train managers to forward possible requests promptly to a central owner rather than debating the label or insisting on a standard form. A form can help clarify scope, but the employee cannot be required to use it.
Start the clock and control the scope
The normal deadline is without undue delay and no later than one month after receipt. If the corresponding date falls on a weekend or bank holiday, the deadline moves to the next working day. An extension of up to two further months is possible where a request is complex or the person has made numerous requests, but the employee must be told within the first month and given the reason. A large volume of information does not automatically make a request complex.
Log the request, receipt date, deadline, owner and scope immediately. Preserve potentially relevant information under your control and identify normal deletion processes that could remove it during the search. Seek proof of identity only when reasonably necessary and proportionate. For a known current employee, demanding a utility bill may add risk without establishing anything useful.
You may ask the employee to clarify the information or activities covered if that is reasonably required. The time limit pauses while you wait and resumes on the day after clarification arrives. Do not use clarification to delay a request that can already be understood. A grievance, tribunal claim or difficult relationship does not by itself remove the right of access.
Map where the employee’s personal information lives
Start with the scope, not a generic export of the HR folder. Depending on the request, search personnel, payroll, attendance, performance, disciplinary and grievance records; emails and workplace messaging; CCTV and access-control records; case-management or project systems; recorded calls; managers’ working notes; and information held by relevant processors. The employer remains responsible as controller when a payroll, HR or cloud provider holds information on its behalf.
The ICO requires a reasonable and proportionate search. Record the systems, custodians, search terms and date ranges considered, along with why any further search would be unreasonable or disproportionate. On personal devices or private messaging accounts, organisational information may still be in scope where staff are permitted to use them for work and there is good reason to believe relevant information is held there.
Do not assume every email mentioning the employee must be disclosed in full. Being copied into a thread does not make the whole thread their personal information. Identify the content that relates to the employee and retain enough context to make it intelligible. This is one reason a controlled review is safer than forwarding raw search results.
ICO: finding and retrieving information for a SAR ↗ · Related guide: workplace investigation records →
Review personal information—not just documents
The right is to the employee’s personal information, not automatically to every original document containing it. You may extract relevant information or provide redacted copies, provided the result is complete and understandable. Drafts, interview notes and managers’ opinions can still be personal information if they relate to the employee; labelling material ‘confidential’ does not create a general exemption.
Information about other people needs a structured review. First consider whether the other person can be removed or redacted. If not, consider consent and whether disclosure without consent would be reasonable in all the circumstances. Relevant factors include the type of information, any duty of confidentiality, the other person’s views and the effect of disclosure. A manager acting in their professional capacity may be treated differently from a vulnerable witness who gave information in confidence.
Other exemptions can apply, including legal professional privilege and limited protections for management forecasting, negotiations and confidential references. They are fact-specific, not blanket labels. Record the basis for each withheld item and disclose material that is not covered. Where privilege, litigation or a sensitive third-party interest is involved, obtain specialist data-protection or legal advice rather than relying on an HR assumption.
ICO: information about other people in a SAR ↗ · ICO: exemptions relevant to SARs ↗
Define the search before the deadline controls the case.
HR + SAFETY can help coordinate the HR records, case timeline and employee communications, working alongside your data-protection or legal advisers where specialist exemption advice is needed.
Discuss a live employee SARPrepare an intelligible and secure response
Supply the copy together with the required supplementary information, including purposes, categories, recipients, retention information, rights, source where the information was not obtained from the person, and relevant automated-decision information. An electronic request should ordinarily receive information in a commonly used electronic format unless the person asks otherwise.
Use an index so the employee can understand the response. Explain the search scope and, where appropriate, the basis for redactions or withheld material. Check the recipient’s address and use a secure delivery method appropriate to the sensitivity and volume—for example, an authenticated portal or encrypted file with the password sent separately. A careful review is undone if the response is emailed to the wrong person.
ICO: supplying information to the requester ↗ · UK GDPR Article 15: right of access ↗
Employer SAR checklist
For North East SMEs without a dedicated privacy team, preparation is the practical control: a clear route for managers, a current data map, supplier retrieval clauses and a response checklist make it far easier to handle a live SAR without losing control of the underlying employment issue.
- Recognise verbal and informal requests; do not insist on legal wording or a form.
- Log receipt, calculate the deadline and appoint a response owner.
- Acknowledge the request and clarify scope only where reasonably required.
- Verify identity proportionately and request evidence of a representative’s authority.
- Preserve relevant information and map each likely system, manager and processor.
- Document reasonable search terms, custodians, date ranges and decisions.
- Separate the employee’s personal information from unrelated document content.
- Review third-party information and exemptions item by item; record the rationale.
- Include the required supplementary information and make the response intelligible.
- Verify the recipient and transfer the response securely before the deadline.
An employee SAR is a data-rights process, not an extension of the grievance or disciplinary argument around it. Recognise the request early, define and document a proportionate search, review personal information carefully, apply redactions and exemptions on their facts, then deliver an intelligible response through a secure channel on time.
- ICO: right of access guidance ↗
- ICO: recognising a subject access request ↗
- ICO: responding to a subject access request ↗
- ICO: finding and retrieving information ↗
- ICO: supplying information to the requester ↗
- ICO: third-party information in a SAR ↗
- ICO: exemptions relevant to SARs ↗
- UK GDPR Article 15: right of access ↗
This guide provides general information for UK employers. It is not legal advice and should not replace advice based on the facts of a specific matter.
