Information you retain in your organisation about individuals can be accessed by them, by simply sending a data subject access request. Depending on what you retain, this can leave the organisation exposed to risk and be a drain on resources to comply with these requests. As data subject access requests (DSARs) are on the rise, it’s important to be aware of how you can manage these to stay in control.
Definitive statistics can be hard to pin down but based on a global survey of 133,667 data privacy officers, published on the Privacy Engine website, 66% of DSARs came from employees and 13% from customers in 2023/24.
Our own experience at Loch reinforces this. We’ve seen a rise in the number of organisations coming to us for help in dealing with DSARs, from employees, ex-employees, and job candidates.
In this article we’ll look at what could be fuelling the rise in particular in employment related DSARs and what your organisation can do to minimise the disruption, how we help you to avoid falling foul of the ICO (Information Commissioner’s Office) and limit your exposure to complaints and Court claims.
When a DSAR is a sign of other things to come
A DSAR is a way for individuals to request a copy of personal data an organisation holds on them. They can be submitted purely to be disruptive and as a pressure tactic to achieve a settlement, or they could be indicative of a potential future claim. Either way, they could herald a significant amount of work for the receiving organisation. Once a DSAR comes in, searches will have to be made across personal records, payroll, emails, documents, WhatsApps, Teams, Slack messages and texts, as well as CCTV footage and personal equipment like smartphones.
If someone submits a DSAR to your organisation, it could be an initial fishing expedition so the individual can find out what data you have relating to them, and whether they can uncover information that opens up the potential for claims around for example breach of contract, unfair dismissal, discrimination or whistleblowing.
If you are already involved in any kind of dispute with a current or former employee, then you should be prepared for a DSAR coming in, if it hasn’t already. Aside from the potential of uncovering information of value, the knowledge that it will incur time and cause disruption as an organisation has to track down, collate and provide copies of the personal data (redacting the data relating to any third parties), means that DSARs are now being used as a form of leverage in ongoing disputes and settlement discussions.
The time consuming and disruptive nature of responding to a DSAR, particularly if a complaint is made to your organisation and then to the ICO, is likely to influence considerations about whether it is commercially sensible to increase a settlement package with the person making the DSAR agreeing to withdraw the DSAR rather than complete the process of responding.
New technologies increase the pressure
The post Covid era of increased hybrid working and a growing reliance on systems such as Teams, Zoom, Slack and WhatsApp has added another layer of complexity to DSAR compliance. Comments which might once have been shared verbally on an informal basis are now part of the written record and, unless they fall into the limited exemptions, will have to be included in any DSAR response.
What other factors may be increasing the pressure around DSARs? Here are a few things:
- The growing use of AI to formulate DSAR requests, increasing their complexity and making it easier to create DSARs.
- UK organisations are now required under the Data Use and Access Act 2025 to have a data protection complaints process in place, which could draw more attention to DSARs.
- From 1 January 2027, under the Employment Rights Act 2025, the qualifying period for unfair dismissal claims will drop from two years to six months. This could lead to an increase in DSARs being deployed as an opening gambit before Tribunal claims are made.
- Failure to have a data retention policy and regularly ‘housekeep’ information, to retain only information that is necessary, meaning the volume and variety of sources of information that has to be sifted though can be extensive.
Being prepared for a DSAR
Training your staff and having clear processes in place to manage DSARs is essential as the one month response time usually starts as soon as a request is received. In certain circumstances it can be extended for 2-3 months. It’s important to carefully consider what information is being requested and seek expert advice as it may be the request is too wide and could be narrowed down for another reason.
Our compliance team are experts in advising and dealing with DSARs and also recommend being proactive and checking you have the right processes in place to minimise the hassle from, and exposure to, DSARs.