It usually arrives as a single sentence with no letterhead: please provide all personal data you hold about me. There is no fee, no form, no obligation to explain why, and the clock starts the moment it lands — including if it lands in a manager's inbox rather than yours.

In an employment dispute, a subject access request is frequently the opening move. It is cheap for the person making it and expensive for the business receiving it, and the way most small employers respond in the first week determines whether it becomes a fortnight of work or a genuine problem.

What the law actually requires

Under UK data protection law, an individual has the right to a copy of the personal data an organisation holds about them, along with information about why it is held, who it is shared with and how long it is kept.

You must respond without undue delay and within one month of receiving the request. Where the request is complex, or where you have received a number of requests from the same person, you can extend by up to two further months — but you must tell them within the first month that you are extending, and why.

In almost all cases you cannot charge a fee. Only where a request is manifestly unfounded or excessive can you charge a reasonable administrative fee or refuse it, and that is a high bar that employers routinely overestimate their chances of clearing.

Crucially, motive is irrelevant. A request made purely to make life difficult during a tribunal claim is as valid as one made out of curiosity, and the fact that the same information could be obtained through disclosure in the tribunal proceedings does not remove the obligation.

What counts as their personal data

This is where employers underestimate the scope. Personal data is not limited to the HR file. It is any information from which the person can be identified, wherever it happens to live.

That includes emails to and about them, the manager's notebook, notes of one-to-ones, appraisal drafts, recruitment scorecards, minutes that mention them, CCTV where they are identifiable, call recordings, records held in the payroll and rota systems, and messages on WhatsApp or Teams — including on a personal phone, if it is being used for work.

The uncomfortable version of that sentence is the one worth acting on: the messages managers send about a difficult employee in a private group chat are usually disclosable, and they are usually the most damaging thing in the response pack.

Write every email about an employee as though they will read it, because in a disputed exit they very often do — and the tone of it becomes evidence long before the facts do.

The exemptions, and their limits

There are genuine exemptions, and they are narrower than the internet suggests.

Legal professional privilege covers confidential communications between you and your solicitor for the purpose of giving or receiving legal advice, or in connection with litigation. Advice from your solicitor about the dismissal is generally protected. An email to your business partner saying you have taken advice is not.

Third-party data requires judgement rather than deletion. Where releasing the requester's data would also disclose information about another identifiable person — a colleague who gave a witness statement, for instance — you must decide whether it is reasonable to disclose without that person's consent, weighing any duty of confidentiality you owe them. Redaction of names and identifying details is the normal answer, not withholding the document entirely.

What is not an exemption: that the material is embarrassing, that the person is suing you, that it would take a long time, or that they already have a copy.

The one thing that turns a nuisance into an offence

Do not delete anything. Under section 173 of the Data Protection Act 2018 it is a criminal offence to alter, deface, block, erase, destroy or conceal information with the intention of preventing disclosure of data the requester would have been entitled to receive. The offence can be committed by the controller and by employees, officers and people acting under the controller's direction, and it has been prosecuted.

There is a defence where the deletion would have happened anyway under a routine retention policy in the absence of the request — which is a good reason to have a written retention schedule that is actually followed, and a very bad reason to invent one on the day the request arrives. The moment a request lands, suspend routine deletion.

A workable process for a small business

Log it. Record the date received and calculate the one-month deadline immediately. If it came to a manager, the clock started when it reached them, not when it reached you.

Acknowledge it and, if the scope is enormous, ask the requester whether they can narrow it. You are entitled to ask, they are not obliged to agree, and asking does not pause the clock unless you genuinely need the information to identify what they want.

Search systematically: email accounts, shared drives, HR and payroll systems, messaging platforms, the recruitment system, CCTV, and any personal devices used for work. Write down where you searched, because the record is your evidence of reasonableness if the response is challenged at the Information Commissioner's Office.

Review before you send. Apply privilege, redact third-party data, and read the pack as the recipient will read it.

Then send it with the required explanatory information: why the data is held, who it is shared with, retention periods, and their rights including the right to complain to the ICO.

The prevention is cultural, not technical

The businesses that find a subject access request stressful are usually the ones whose written record does not match the account they intend to give. If the file says one thing and the WhatsApp group says another, no amount of process will make the response comfortable.

Which means the real preparation happens months earlier, in ordinary management habits: contemporaneous, factual, unemotional notes; decisions recorded with reasons; warnings given properly and in writing rather than as a heated exchange nobody documented. That record is exactly what makes a grievance or a dismissal defensible in the first place — a grievance handled badly is expensive precisely because the paperwork never existed. A subject access request does not create the problem. It publishes it.

Common questions

How long do I have to respond to a subject access request?

One month from receiving the request, without undue delay. The month runs from the date the request reached anyone in your organisation, so a request sent to a line manager starts the clock even if it takes a week to reach you. Where the request is complex, or where the same person has made several requests, you can extend by up to a further two months — but you must tell them within the original month that you are extending and explain why. There is no requirement for the request to be in any particular form, to be labelled as a subject access request, or to give a reason.

Do I have to hand over WhatsApp messages and a manager's notes?

Generally yes. Personal data is any information from which the individual can be identified, regardless of where it is stored, so it covers emails about them, handwritten notes of meetings, appraisal drafts, minutes, call recordings, CCTV and messages on WhatsApp or Teams — including messages on a personal phone where it is used for work purposes. The main protections are legal professional privilege, which covers genuine communications with your solicitor, and third-party data, where you must weigh the other person's confidentiality and usually redact rather than withhold. Embarrassment is not an exemption.

Can I charge for a subject access request or refuse one?

In almost all circumstances you cannot charge a fee. Only where a request is manifestly unfounded or excessive may you charge a reasonable fee to cover administrative costs, or refuse it outright, and that threshold is high — a request made during a tribunal claim, or one that is simply large, does not meet it on its own. If you refuse, you must tell the person why and inform them of their right to complain to the Information Commissioner's Office and to seek a judicial remedy. Motive is irrelevant to whether the request is valid.

Can I delete emails after receiving a subject access request?

No, and doing so can be a criminal offence. Section 173 of the Data Protection Act 2018 makes it an offence to alter, deface, block, erase, destroy or conceal information with the intention of preventing disclosure of information the requester would have been entitled to receive, and it applies to the controller and to employees and officers acting under its direction. There is a defence where the deletion would have happened anyway under an established retention policy independent of the request. The safe course is to suspend all routine deletion the moment a request arrives and document that you have done so.