New ICO Guidance For Employers Responding To Data Subject Access Requests

KG
K&L Gates
Contributor
K&L Gates fosters an inclusive and collaborative environment across our fully integrated global platform that enables us to combine the expertise of our lawyers and policy professionals to create teams that provide exceptional client solutions. With offices spanning across five continents, we represent leading global corporations in every major industry.
Today, the UK data protection regulator, the ICO, has published guidance to assist employers in responding to data subject access requests ("DSARs") from current and former employees.
UK Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

Today, the UK data protection regulator, the ICO, has published guidance to assist employers in responding to data subject access requests ("DSARs") from current and former employees. DSARs have become the primary tool for employees attempting to gain leverage against employers during a dispute or grievance process: they can be extremely time-consuming and resource intensive for employers to deal with, and it is a difficult balance to strike between upholding employees' right of access under the UK GDPR and applying exemptions from disclosure in an appropriate way.

The new guidance covers issues that often occur when employers try to strike this balance, and notably:

  • How the DSAR response process interacts with an ongoing tribunal or grievance process involving the employee making the request – The guidance makes clear that in this situation, the employer must deal with the DSAR, despite the risk that some of the personal data provided could circumvent the litigation disclosure process;
  • Enshrining one of the limited exceptions to oppose complying with a DSAR, by considering that where an employee offers to withdraw a DSAR in return for a higher settlement payment, this could be evidence that the DSAR is "manifestly unfounded".

A common issue for employers in responding to DSARs is how to handle the large amount of emails that a search may turn up on which the only relevant personal data is the employee's name and email address in copy. The guidance notes that context will be relevant, so employers should assess and determine in each case whether the content of such emails qualifies as the employee's personal data.

Overall, the new guidance is likely to provide welcome clarification for employers who find themselves in some of these common situations.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

New ICO Guidance For Employers Responding To Data Subject Access Requests

UK Privacy
Contributor
K&L Gates fosters an inclusive and collaborative environment across our fully integrated global platform that enables us to combine the expertise of our lawyers and policy professionals to create teams that provide exceptional client solutions. With offices spanning across five continents, we represent leading global corporations in every major industry.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More