Employee Data Subject Access Request Software: Handle Employee and Ex-Employee DSARs
An access request from an employee or a former employee is the hardest kind to answer, because their data is spread across HR systems, manager inboxes, performance notes, and payroll, and a lot of it names other people. Obtainer finds where an employee's data lives across your systems, compiles it into one reviewable manifest, and drafts the response, while your team decides what is in scope and redacts before anything goes out.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
An employee data subject access request is a request from a current or former worker to see the personal data an employer holds about them. In the EU and UK, employees have had this right under the GDPR from the start. In the United States, it became a live issue on January 1, 2023, when California's CPRA removed the exemption that had kept most HR data out of scope, so California employees, job applicants, contractors, and board members now have the same rights to know, access, correct, and delete their data as any consumer. California is still the only state where that is true.
Nearly every other state copied Virginia's definition of a consumer, which covers a resident acting only in an individual or household context and expressly excludes a natural person acting in a commercial or employment context, so an employee request in Texas, Colorado, Connecticut or Virginia carries no statutory access right at all. Two narrow carve-outs do reach the workplace: Colorado's biometric amendment, in force July 1, 2025, applies to employee biometrics even though the rest of the Colorado Privacy Act does not, and Illinois BIPA has always covered biometric identifiers with a private right of action. Working out which of those applies before you start searching is what decides whether you are answering a legal obligation or a goodwill request. Employee requests are harder than customer ones for three reasons: the data is scattered across HR software, manager emails, performance and disciplinary records, and payroll; much of it references other people, such as colleagues who gave feedback or raised complaints, whose data you must usually redact; and some categories, like a reference given in confidence or material tied to an ongoing grievance or negotiation, may be exempt.
Obtainer runs the mechanical work: it intakes the request, helps verify the requester, discovers where the employee's personal data lives across your connected systems, and compiles one reviewable manifest, then drafts the response on the GDPR one-month or CCPA 45-day clock. Your team makes the calls that have to stay human, redacting third-party data and applying exemptions, and approves the disclosure at a review gate before anything is released. Obtainer helps you comply. It is not legal advice, and the scope and exemption decisions stay with your team. Self-serve from a planned $49/mo.
Last updated August 2026
What you get
Employee DSARs, built for privacy, legal, and ops teams
Built for scattered employee data
An employee's data does not sit in one HR tool. Obtainer discovers it across your connected systems, HR software, shared drives, and inboxes, and compiles it into one manifest, so a reference in a manager's email does not get missed.
Third-party data flagged for review
Employee files are full of other people: colleagues, complainants, referees. Obtainer surfaces the records so your team can redact the third-party data before disclosure, which is the step employee DSARs most often get wrong.
One clock, both frameworks
Whether the request falls under the GDPR one-month deadline or California's 45-day CCPA clock, each request carries its own countdown, so an employee request does not slip while a grievance runs in parallel.
Your team keeps the judgment calls
Exemptions, confidential references, and what belongs to an ongoing negotiation are legal decisions. Obtainer never makes them or releases anything on its own. A human reviews and approves, so you stay in control of what is disclosed.
How it works
From an intake request to a ready-to-review response in four steps
Intake and verify
Log the request, note whether it falls under the GDPR or the CCPA, and confirm the worker's identity before gathering records, so you disclose to the right person.
Discover the employee's data
Obtainer surfaces where the employee's personal data lives across your connected systems and compiles it into one reviewable source-system manifest.
Redact third parties and apply exemptions
Your team masks colleagues' data, withholds confidential references where the law allows, and decides what an ongoing grievance keeps out of scope.
Draft, approve, and respond
Generate the response from templates, have a person approve the final disclosure, and send it within the deadline. Helps you comply, not legal advice.
Reference
Which employees can actually make a data subject access request in the US
California is the only state whose comprehensive privacy law reaches employees. Nearly every other state copied Virginia's definition of a consumer, which excludes a person acting in an employment context, so an employee request in those states carries no statutory access right. The rules that do reach the workplace are narrow and sit outside the consumer-privacy framework.
| Jurisdiction | Employee access right? | What the law actually says | What it means for an employer |
|---|---|---|---|
| California (CCPA and CPRA) | Yes, in full | The employment exemption expired December 31, 2022. | Employees, job applicants, contractors and board members can request access, correction and deletion, on the same 45-day clock as any consumer. |
| Virginia, Texas, Colorado, Connecticut and the other Virginia-model states | No | Va. Code 59.1-575 defines a consumer as a resident "acting only in an individual or household context" and states it "does not include a natural person acting in a commercial or employment context". | An employee request carries no statutory access right in those states. Answering it can still be the right call for the relationship, but the clock is yours to set, not the statute's. |
| Maryland (MODPA) | No | Attorney General guidance reads the law as covering the individual or household context only, not the employment context. | Maryland is stricter than most states on data minimization and still leaves HR data out of scope. |
| Colorado biometrics (HB 24-1130, in force July 1, 2025) | Partial | The biometric duties apply in the employment context, unlike the rest of the Colorado Privacy Act. | Consent and a written biometric policy are required before collecting employee biometrics, and the permissible reasons for requiring that consent are restricted. |
| Illinois (BIPA) | Partial | Biometric identifiers only, with a private right of action. | Employee biometric exposure is litigated directly rather than routed through a consumer-rights process. |
| EU and UK (GDPR) | Yes | Employees and former employees have held access rights from the start. | A US employer with staff in the EU or UK answers on the one-month clock whatever its state law says. |
Frequently asked
Questions teams ask about employee dsars
Can an employee make a data subject access request?
Yes. In the EU and UK, employees and former employees have always had the right to access their personal data under the GDPR. In the United States, California's CPRA removed the HR-data exemption on January 1, 2023, so California employees, applicants, contractors, and board members can now request access to, correction of, and deletion of the personal data an employer holds about them.
Do employees have data privacy rights outside California?
Mostly no, not under the state comprehensive privacy laws. California is the only state whose law covers employees, applicants and contractors. Virginia, Texas, Colorado, Connecticut and the rest define a consumer as a resident acting only in an individual or household context and expressly exclude the employment context. Narrower workplace rules still bite: Colorado regulates employee biometrics from July 1, 2025, and Illinois BIPA covers biometric identifiers with a private right of action. Staff in the EU or UK keep full GDPR access rights regardless of any of this. Which state privacy laws apply to your business walks through the thresholds.
Can a former employee make a subject access request?
Yes, wherever the right exists at all. Neither the GDPR nor the CCPA ties the right to a current relationship, so an ex-employee has exactly the same right as a current one, and in practice ex-employees file more of them, usually around an exit or a dispute. The hard part is that their data has already been moved into archives, offboarded accounts, and departed-user mailboxes, which is where a search scoped to live HR systems quietly under-collects. Personal data discovery across systems is built for that spread.
How long do you have to respond to an employee subject access request?
The same clocks as any other request. Under the GDPR you have one month from receipt, extendable by two further months for complex requests if you notify the worker within the first month. Under the CCPA a business has 45 calendar days, extendable by another 45 with notice. Verification time comes out of the GDPR month, so start promptly.
Do you have to disclose emails about an employee?
Sometimes. An access request covers the employee's personal data wherever it lives, including emails that are about them, not just emails they sent. You do not hand over whole inboxes; you disclose the personal data within, redacting other people's data and anything covered by an exemption. Purely trivial mentions may fall outside the request, but a blanket refusal to search email is hard to defend.
Can you refuse an employee access request during a dispute?
Not simply because there is a dispute. An ongoing grievance, disciplinary, or tribunal does not switch off the right, and refusing on that basis alone is risky. Specific material may be exempt, for example a confidential reference or legally privileged advice, but each exemption is applied to specific data, with reasons recorded, not to the request as a whole. Take advice on the close calls.
What data can you withhold from an employee DSAR?
You can redact other people's personal data unless they consent or it is reasonable to disclose without it, and you can withhold data covered by a specific exemption, such as confidential references, legally privileged material, or information tied to management planning or negotiations where disclosure would prejudice it. Withholding is decided item by item with a documented reason, never as a default.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.