Triage an incoming employee subject access request and confirm it is valid, scoped and correctly logged from day one.
Employee Data Subject Access Requests and HR Records Retention Schedules
Prepares HR and data protection teams to run a compliant, timely subject access request process for employee data and to build a retention schedule that keeps only what the organisation can justify holding.
Course Overview
An employee subject access request rarely arrives as a neutral question; it usually lands alongside a grievance, a disciplinary process or a departure, and it comes with a strict statutory deadline that does not pause for how inconvenient the timing is. Handling it well means knowing where employee data actually lives across HR systems, email, messaging platforms and manager notes, searching all of it, and redacting what belongs to other people without either over-disclosing or hiding behind exemptions that do not apply. This course gives HR and data protection professionals a working method for both sides of the same problem: responding to subject access requests within the statutory timeframe, and building a retention schedule that limits what a future request can even surface. Participants learn to triage incoming requests, run a defensible search across scattered data sources, apply exemptions and third-party redactions correctly, and respond within the one-month statutory window or justify a lawful extension. On the retention side, participants build a schedule that ties each record type to a retention trigger and period grounded in a genuine legal or business need, then map out secure disposal so old data stops being a liability. Participants leave with a DSAR intake and response workflow and a retention schedule template.
Expected Learning Outcomes
Run a defensible search across HR systems, email, messaging platforms and manager notes to locate all relevant data.
Apply third-party redactions and statutory exemptions correctly without over-withholding information the employee is entitled to.
Respond within the statutory one-month deadline, or justify and communicate a lawful extension for complex requests.
Recognise when a subject access request is being used tactically alongside a grievance or tribunal claim and respond accordingly.
Build a retention schedule that ties each HR record type to a specific retention trigger, period and disposal method.
Apply data minimisation principles to stop personnel files accumulating data with no current business justification.
Who Should Attend
HR managers and HR business partners who receive and coordinate employee data requests.
Data protection officers and privacy leads responsible for GDPR compliance in employment data.
Employee relations specialists managing requests linked to grievances, disciplinaries or exits.
HR records and information management teams building or updating a retention schedule.
In-house legal counsel advising on subject access requests connected to litigation risk.
HR shared-services teams responsible for locating and compiling employee data on request.
Course Modules
Select any module to see its sessions and points.
01Understanding the Employee Subject Access Right
2 sessions · 8 points
Session 1What Employees Are Entitled To
- Explain the scope of the right of access, including what categories of personal data an employee can request.
- Distinguish a subject access request from a related but different request, such as a grievance or a reference request.
- Identify the statutory response deadline and the limited circumstances that justify a lawful extension.
- Confirm validity requirements, including identity verification, without using them to create unnecessary delay.
Session 2Why DSARs Often Arrive at the Worst Time
- Recognise the pattern of subject access requests submitted alongside grievances, disciplinaries or post-termination disputes.
- Assess how a request's timing and context should shape the search and response process without changing the employee's underlying rights.
- Coordinate between HR, legal and the data protection lead when a request accompanies active or anticipated litigation.
- Avoid response delays or omissions that could later be read as an attempt to withhold evidence.
02Searching, Redacting and Responding
2 sessions · 8 points
Session 1Finding the Data Across Every System
- Map every system likely to hold relevant employee data, including HRIS, email, messaging platforms and CCTV.
- Design a consistent search protocol, including search terms and date ranges, that a non-specialist can follow correctly.
- Coordinate with IT and line managers to retrieve data held outside central HR systems, such as local files or notes.
- Document the search process itself so the organisation can demonstrate a reasonable and proportionate effort.
Session 2Redaction, Exemptions and the Final Response
- Identify third-party personal data within the results and apply a documented balancing test before disclosure or redaction.
- Apply recognised exemptions, such as management forecasting or confidential references, only where they genuinely apply.
- Compile a clear response pack that explains what has been withheld and why, in plain and proportionate language.
- Log the completed request, including search scope and redaction decisions, to support consistency in future requests.
03Building a Defensible Retention Schedule
2 sessions · 8 points
Session 1Deciding What to Keep and Why
- Inventory the HR record types the organisation holds, from recruitment data to post-termination correspondence.
- Attach a retention trigger, such as end of employment or end of a limitation period, to each record type.
- Set retention periods grounded in a genuine legal, contractual or operational need rather than an indefinite default.
- Distinguish records with a statutory minimum retention period from records the organisation could safely delete sooner.
Session 2Applying Data Minimisation in Practice
- Apply the storage limitation principle to personnel files that have accumulated data beyond any current purpose.
- Identify categories of data, such as old application materials or superseded contracts, that are commonly over-retained.
- Build sign-off and disposal steps that make secure deletion a routine part of the record lifecycle, not an afterthought.
- Balance retention against the practical need to defend the organisation in a future claim or investigation.
04Embedding the Process Across the Organisation
2 sessions · 8 points
Session 1Training Managers and Frontline HR Staff
- Train line managers to recognise a subject access request wherever it arrives and route it to the right team immediately.
- Brief managers on what they must preserve, and never delete, once a request or anticipated claim is identified.
- Build a short escalation guide that tells frontline HR staff exactly who to notify and by when.
- Run scenario exercises so staff practise recognising and triaging a request under realistic time pressure.
Session 2Governance, Auditing and Continuous Improvement
- Track subject access request volumes, response times and extension rates to identify process bottlenecks.
- Audit the retention schedule periodically against changes in legislation, contracts and business practice.
- Review closed requests for lessons that should update the search protocol or redaction approach.
- Report DSAR and retention compliance metrics to leadership as part of wider data protection governance.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
