Employee Data Subject Access Request Software: Handle Employee and Ex-Employee DSARs
An access request from an employee or a former employee is the hardest kind to answer, because their data is spread across HR systems, manager inboxes, performance notes, and payroll, and a lot of it names other people. Obtainer finds where an employee's data lives across your systems, compiles it into one reviewable manifest, and drafts the response, while your team decides what is in scope and redacts before anything goes out.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
An employee data subject access request is a request from a current or former worker to see the personal data an employer holds about them. In the EU and UK, employees have had this right under the GDPR from the start. In the United States, it became a live issue on January 1, 2023, when California's CPRA removed the exemption that had kept most HR data out of scope, so California employees, job applicants, contractors, and board members now have the same rights to know, access, correct, and delete their data as any consumer. Employee requests are harder than customer ones for three reasons: the data is scattered across HR software, manager emails, performance and disciplinary records, and payroll; much of it references other people, such as colleagues who gave feedback or raised complaints, whose data you must usually redact; and some categories, like a reference given in confidence or material tied to an ongoing grievance or negotiation, may be exempt. Obtainer runs the mechanical work: it intakes the request, helps verify the requester, discovers where the employee's personal data lives across your connected systems, and compiles one reviewable manifest, then drafts the response on the GDPR one-month or CCPA 45-day clock. Your team makes the calls that have to stay human, redacting third-party data and applying exemptions, and approves the disclosure at a review gate before anything is released. Obtainer helps you comply. It is not legal advice, and the scope and exemption decisions stay with your team. Self-serve from $49/mo.
Last updated July 2026
What you get
Employee DSARs, built for privacy, legal, and ops teams
Built for scattered employee data
An employee's data does not sit in one HR tool. Obtainer discovers it across your connected systems, HR software, shared drives, and inboxes, and compiles it into one manifest, so a reference in a manager's email does not get missed.
Third-party data flagged for review
Employee files are full of other people: colleagues, complainants, referees. Obtainer surfaces the records so your team can redact the third-party data before disclosure, which is the step employee DSARs most often get wrong.
One clock, both frameworks
Whether the request falls under the GDPR one-month deadline or California's 45-day CCPA clock, each request carries its own countdown, so an employee request does not slip while a grievance runs in parallel.
Your team keeps the judgment calls
Exemptions, confidential references, and what belongs to an ongoing negotiation are legal decisions. Obtainer never makes them or releases anything on its own. A human reviews and approves, so you stay in control of what is disclosed.
How it works
From an intake request to a ready-to-review response in four steps
Intake and verify
Log the request, note whether it falls under the GDPR or the CCPA, and confirm the worker's identity before gathering records, so you disclose to the right person.
Discover the employee's data
Obtainer surfaces where the employee's personal data lives across your connected systems and compiles it into one reviewable source-system manifest.
Redact third parties and apply exemptions
Your team masks colleagues' data, withholds confidential references where the law allows, and decides what an ongoing grievance keeps out of scope.
Draft, approve, and respond
Generate the response from templates, have a person approve the final disclosure, and send it within the deadline. Helps you comply, not legal advice.
Frequently asked
Questions teams ask about employee dsars
Can an employee make a data subject access request?
Yes. In the EU and UK, employees and former employees have always had the right to access their personal data under the GDPR. In the United States, California's CPRA removed the HR-data exemption on January 1, 2023, so California employees, applicants, contractors, and board members can now request access to, correction of, and deletion of the personal data an employer holds about them.
How long do you have to respond to an employee subject access request?
The same clocks as any other request. Under the GDPR you have one month from receipt, extendable by two further months for complex requests if you notify the worker within the first month. Under the CCPA a business has 45 calendar days, extendable by another 45 with notice. Verification time comes out of the GDPR month, so start promptly.
Do you have to disclose emails about an employee?
Sometimes. An access request covers the employee's personal data wherever it lives, including emails that are about them, not just emails they sent. You do not hand over whole inboxes; you disclose the personal data within, redacting other people's data and anything covered by an exemption. Purely trivial mentions may fall outside the request, but a blanket refusal to search email is hard to defend.
Can you refuse an employee access request during a dispute?
Not simply because there is a dispute. An ongoing grievance, disciplinary, or tribunal does not switch off the right, and refusing on that basis alone is risky. Specific material may be exempt, for example a confidential reference or legally privileged advice, but each exemption is applied to specific data, with reasons recorded, not to the request as a whole. Take advice on the close calls.
What data can you withhold from an employee DSAR?
You can redact other people's personal data unless they consent or it is reasonable to disclose without it, and you can withhold data covered by a specific exemption, such as confidential references, legally privileged material, or information tied to management planning or negotiations where disclosure would prejudice it. Withholding is decided item by item with a documented reason, never as a default.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.