Employee Subject Access Request: How to Handle a DSAR From an Employee
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
An employee subject access request is a request from a current or former worker to see the personal data you hold about them. You have one month to respond under the GDPR, or 45 days under California's CCPA, which since January 1, 2023 covers employee data too. It is the hardest kind of access request to answer well, because the data is scattered, much of it names other people, and a handful of narrow exemptions are easy to over-apply. Here is how to run one without tripping over any of the three.
General information, not legal advice. Employee requests turn on facts and on which framework applies, so take advice on the close calls.
Why employee requests are harder than customer ones
A customer access request usually resolves to a handful of systems: the CRM, the billing record, maybe the support desk. An employee's data does not sit still like that. It is in the HR platform, but also in payroll, in a manager's inbox, in performance and one-to-one notes, in recruitment records from before they were hired, in Slack messages, in the shared drive folder for their team, and in the disciplinary or grievance file if there is one. The request covers all of it, wherever it lives, not just the tidy HR record.
The second difficulty is that employee files are full of other people. A performance review quotes a colleague's feedback. A grievance names the person complained about. A reference names its author. You generally have to disclose the requester's own data while protecting everyone else's, which means redaction, not a straight export. The third difficulty is exemptions: a few specific categories can be withheld, and the temptation during a dispute is to reach for them too broadly.
Who can make an employee subject access request
More people than most employers expect. The right is not limited to current staff on the payroll.
| Requester | Covered? | Note |
|---|---|---|
| Current employee | Yes | The everyday case, often raised alongside a workplace issue. |
| Former employee | Yes | No time limit on asking; you still hold data long after they leave. |
| Job applicant | Yes | Under the CPRA, California applicants have the same rights; GDPR covers unsuccessful candidates too. |
| Contractor or board member | Yes (CCPA) | The CPRA extended rights to contractors and directors, not only W-2 staff. |
The California point is the one US employers still miss. Until the start of 2023, the CCPA exempted most workforce data. The CPRA removed that exemption, so a California employee, ex-employee, applicant, or contractor now has the right to know, access, correct, and delete their workplace data on the 45-day clock. The recruitment side matters here as well: the personal data you gather when you screen and rank candidates is in scope from the application stage, so an unsuccessful applicant can ask for it just as a hired one can.
How long do you have to respond to an employee SAR?
Under the GDPR you must respond within one month of receiving the request, extendable by two further months where the request is complex or the person has made several, provided you tell them within the first month and explain why. Under the CCPA a business has 45 calendar days, extendable by another 45 with notice. The GDPR month includes the time you spend verifying the requester, so a slow identity check eats into your response window.
The clock starts when the request arrives, in whatever form and to whoever it was addressed. An email to a line manager saying "please send me everything you have about me" is a valid request even if it never reaches HR. That is a common way employers blow the deadline: the request sits in a manager's inbox for two weeks before anyone recognizes it for what it is. Train managers to forward these on the day they land.
What you can withhold from an employee DSAR
Withholding is decided item by item, with a reason recorded for each, never as a blanket refusal. The main grounds:
- Other people's personal data. You can redact information that identifies third parties, unless they consent or it is reasonable to disclose without their consent. This is the biggest single job in an employee SAR.
- Confidential references. A reference given in confidence, whether you gave it or received it, can usually be withheld, though the rules differ by framework and the protection is narrower than people assume.
- Legally privileged material. Advice from your lawyers about the employee's situation is generally exempt.
- Management planning and negotiations. Information whose disclosure would prejudice your position in a negotiation with the employee, or reveal management planning such as a pending reorganization, may be withheld where disclosure would cause the specific prejudice the exemption protects against.
What you cannot do is withhold data simply because releasing it is inconvenient, or because there is a live dispute. An ongoing grievance or tribunal does not switch the right off, and a request made during a dispute is still a valid request. Treat the exemptions as a scalpel, applied to specific documents with documented reasons, not as a shield over the whole file. The guide to DSAR exemptions works through each ground and where regulators draw the line, so you can tell a defensible withholding from an over-reach.
Can you refuse an employee access request?
Rarely, and never just because the timing is awkward. You can decline a request that is manifestly unfounded or excessive, but regulators read that bar narrowly, and "we are in a dispute" does not meet it. You can charge a reasonable fee or refuse where a request is repetitive, again within tight limits. If you do refuse, in whole or part, you must tell the person, explain the basis, and inform them of their right to complain to the regulator. Silence is not an option.
The safer path in most contested cases is to respond on time while redacting and withholding specific items with reasons, rather than refusing outright. A documented partial disclosure is far easier to defend than a blanket refusal that a regulator or tribunal later unpicks.
How to run an employee subject access request
The sequence is the same as any DSAR, with the third and fourth steps doing most of the work:
- Log it and start the clock the day it arrives, wherever it arrived, and note whether the GDPR, the CCPA, or both apply.
- Verify the requester. With a current employee this is usually quick; with a former one it takes more care. The time counts against your GDPR month.
- Find every copy of their data. HR platform, payroll, manager inboxes, performance and grievance files, recruitment records, shared drives, chat. This is the step that decides whether the response is complete.
- Redact third parties and apply exemptions item by item, recording a reason for each withholding. Getting this right is a job of its own, and redacting third-party data in a DSAR covers when a colleague's name has to come out and when it can stay.
- Respond within the deadline, with the data, the redactions, and a note of anything withheld and why. Running all five steps in one queue is what subject access request software is for, rather than tracking a staff request in a spreadsheet next to customer ones.
Step three is where employee SARs are won or lost, and it is the same wall every data subject right runs into: you cannot disclose, correct, or delete what you cannot find. Employee DSAR software discovers where a worker's personal data lives across your connected systems and compiles it into one reviewable manifest, so a comment in a manager's inbox does not get left out of a response that claimed to be complete. A human then redacts the third-party data and approves the disclosure, so the judgment calls stay with your team and nothing is released on its own.
An employee access request is also a good moment to remember it is one of several rights a worker can exercise. The data subject rights overview maps the eight GDPR rights against California's six, so when an employee follows an access request with a correction or a deletion, you already know which clock and which rules apply.
Handled loosely, an employee SAR is where a routine HR matter becomes a regulator complaint: the missed inbox, the colleague's name left unredacted, the exemption stretched too far. Handled as a defined process, with discovery done properly and every withholding written down, it is just another deadline you meet.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.