Last updated: 5 September 2026
TL;DR: A subject access request is an employee’s right to a copy of the personal data you hold about them. You must respond without undue delay and within one month, extendable by up to two further months for complex requests if you tell them within the first month. There is normally no fee, and the request does not have to be in writing or use any particular words.

They almost never arrive out of nowhere. A subject access request usually follows a grievance, a disciplinary process or a resignation, and it lands in a practice manager’s inbox on a Friday afternoon with a deadline already running. Knowing what it is before that day is most of the work.
It is an individual’s right under UK GDPR to obtain a copy of the personal data an organisation holds about them, together with information about how and why it is being used. Applied to employment, it means your staff records, and quite a lot more besides.
The ICO’s guidance for employers is direct: employers must respond to a SAR from a worker without delay and within one month of receipt of the request.
It covers far more than the personnel file. Emails mentioning the person, WhatsApp messages between managers about them, rota notes, appraisal drafts, CCTV footage and handwritten interview notes can all be personal data.
Employment records are also covered by wider data protection obligations. The ICO publishes specific guidance on collecting and keeping employment records, and a practice that follows it will find a subject access request far easier to answer.
That breadth is why the request is often used tactically after a dispute. It is a legitimate right regardless of motive, and you must respond to it properly even when you can see exactly why it has been sent.
A subject access request is identified by content, not by format. It does not need to be in writing, does not need to mention data protection or UK GDPR, and does not need to be sent to a particular person at the practice.
The corridor version is the dangerous one, because nobody logs it and the clock starts anyway. Train anyone who might receive one, which in a small practice means every manager and the reception lead, to forward it the same day.
Log the date the subject access request was received immediately. If you later need to argue about timeliness, the receipt date is the first thing anyone will ask for.

One month from receipt of the subject access request, without undue delay. The ICO allows the period to be extended by up to two further months where the request is complex or where the person has made a number of requests, but you must tell them within the first month and explain why.
That notification requirement catches practices out. An extension taken quietly, without telling the individual inside the first month, is simply a missed deadline with extra steps.
There is normally no fee. You may be able to charge a reasonable administrative fee for manifestly unfounded or excessive requests, or for further copies, but charging as a matter of course is not permitted.
Plan for the subject access request search taking longer than you expect. In a practice where four managers use email, WhatsApp and a rota system, a thorough search is a week of work rather than an afternoon.
In more places than your HR folder. This is where a subject access request becomes genuinely difficult, and where practices with informal systems pay for that informality all at once.
Point three is the one that hurts. Practice WhatsApp groups are used everywhere for shift swaps and running commentary, and messages about a colleague in those groups are disclosable and frequently regrettable.
Consolidating records makes this manageable. Our guide to digital staff records and our piece on GDPR and staff records both cover how to keep the search from becoming an archaeology project.

Less of a subject access request than you would like, and the decisions need to be reasoned rather than instinctive. The general rule is that you disclose personal data about the requester, redact where necessary and record why.
Opinions about the requester are usually disclosable even when they are unflattering. A manager’s note saying someone is difficult to work with is that person’s personal data, and it is a poor discovery to make during a grievance.
Redact carefully rather than broadly. Blanking whole documents because they mention a colleague is not redaction, and a response that arrives as a wall of black boxes tends to produce a complaint to the ICO rather than closure. Redact the third party detail and disclose the rest.
Never delete anything after a request arrives. Deleting records to avoid disclosure is a serious matter, and in a small practice it is usually obvious that it has happened.
Received a request and not sure where to start? A free 30-minute HR health check will map your data and the deadline. Book your HR health check.
By changing how you write things down, long before anyone asks. Every practice that has been through a difficult one comes out with the same conclusion, which is that the problem was never the process.
Rehearse it once. Pick a member of staff at random, run the search you would run for a real subject access request, and time it. Most practices discover two systems they had forgotten and one mailbox nobody can access, which is a far better discovery to make in a quiet week.
Retention is the underrated one. A practice that still holds every email from 2015 has given itself a far larger job than one with a documented retention schedule that is actually applied.
Without undue delay and within one month of receipt. The ICO allows an extension of up to two further months where the request is complex or the person has made a number of requests, but you must tell them within the first month and explain why you need longer.
Normally no. A reasonable administrative fee may be charged for manifestly unfounded or excessive requests, or for further copies of the same information, but a fee cannot be applied as standard practice and should not be used to discourage a request.
Yes, where they contain personal data about the requester and relate to practice business. Using personal devices does not put messages outside the scope. This is the single strongest argument for keeping personnel discussion out of the rota WhatsApp group.
Motive is generally irrelevant. There is a narrow route for requests that are manifestly unfounded or excessive, but it is not a way to avoid an inconvenient request during a dispute. Take advice before relying on it, and respond within the deadline either way.
Yes. The right belongs to the individual, not to current staff, so a request from someone who left two years ago engages the same duty and the same deadline for whatever data you still hold about them.
A subject access request is not really a data protection problem. It is a record-keeping habit problem that becomes visible on a one month deadline, usually at the worst moment in an already difficult employment situation.
Log the subject access request the day it arrives, name an owner, search properly and write every note from now on as if the subject will read it. Our policy library and HR consultancy cover the process and the retention schedule behind it, and the free HR health check is the fastest way to see how exposed you are.
The Vet HR Team provides HR consultancy and white-labelled staff systems exclusively to UK veterinary practices. Check current ICO guidance, and take legal advice on complex or contested requests.
Read next: Data Breach in a Veterinary Practice.
Contracts, rotas, holiday, a difficult conversation. Tell us what you are dealing with and we will come back within one working day. Nothing to sign up to.
Got it. We will come back to you within one working day. If you do not see a reply, please check your spam folder.