top of page

Responding to a request for personal data

  • Aug 29
  • 3 min read

Updated: 5 days ago

Introduction


An email arrives from a former employee, or a customer in dispute, asking for all the information the business holds about them. It does not use any formal terminology and it does not need to.

The clock has started. Most frameworks give a fixed period, frequently around a month, to respond in full, and the search covers email, systems, paper files and anything else. A small business receiving its first request typically loses two weeks working out what it is before beginning, and the deadline does not move. Nothing about the request being informal or inconvenient extends it.


1. Responding to a request for personal data starts when it arrives, not when you recognise it


Recognition is the first problem.

A request can be made verbally, by email, through social media, and without any particular wording. Anybody in the business might receive one, which means everybody needs to know to pass it on immediately. A request sitting unrecognised in somebody's inbox for a fortnight has still consumed half the period.


2. Know your deadline and the grounds for extending it


Fixed and short.

Establish the period in your jurisdiction and whether it can be extended for complex requests, and on what notice. Extensions generally require you to tell the person within the original period, so missing that removes the option.


3. Verify who you are dealing with


Reasonable and not obstructive.

Confirming identity is legitimate, particularly where you would be disclosing sensitive information. It should be proportionate, and using it to delay is a well-recognised tactic that regulators treat poorly.


4. Clarify the scope where it is genuinely unclear


Once, and helpfully.

Asking what period or what type of information they are interested in can narrow a broad request substantially. Ask early, ask once, and note whether the clock pauses in your jurisdiction while you await a reply.


5. Search everywhere, including email


The largest part of the work.

Systems, mailboxes, shared drives, messaging applications, paper files and backups where reasonably accessible. Email is usually the biggest source and the one businesses most often overlook. Years of correspondence mentioning one individual takes real time to search and review.


6. Redact other people's information


The exercise that takes the time.

Where a document contains information about other individuals, their data generally must be protected unless disclosure is reasonable. This applies constantly to email threads and internal notes.


7. Know what you may withhold


Exemptions exist and are limited.

Legal privilege, information relating to negotiations, and certain other categories may be exempt depending on your jurisdiction. These are narrower than businesses hope, and withholding on an incorrect basis is worse than disclosing.


8. Respond properly and keep a record


Both the content and the evidence.

The information, an explanation of what you hold and why, and details of their other rights. Keep a record of what was searched, what was provided, what was withheld and why.


9. Expect it to arrive alongside a dispute


The usual context.

Requests frequently accompany an employment issue or a customer complaint. That does not change the obligation, and handling it correctly and separately from the dispute is both required and strategically sensible.

Prepare before you receive one: know who in the business handles it, where data lives, and what the deadline is. Half an hour of preparation converts a genuine crisis into an administrative task, and the businesses that struggle are those starting from nothing on the day it arrives.


Conclusion


Treat the deadline as starting on receipt, whatever form the request took.

Make sure everybody knows to pass requests on immediately, establish your jurisdiction's time limit and extension rules, verify identity proportionately rather than as a delaying tactic, clarify scope once and early, search every location including email and messaging, redact third-party information, apply exemptions narrowly and only where they genuinely fit, respond with an explanation and keep a record of the search, and prepare in advance so the first request is not also the first time you consider it.


Related reading


 
 
 

Comments


bottom of page