Employee DSARs: What the DPC’s 2025 Material Means for Employers

by

Employee access requests test far more than an employer’s ability to collect documents. They expose how workplace information is written, classified, retained and shared. The Data Protection Commission’s (“DPC”) latest material gives employers a clear warning: routine managerial opinions will not ordinarily be protected simply because they were expressed in confidence.

TheData Protection Commission’s Annual Report 2025 (published 30 June 2026),  records 16,160 new cases during 2025 — a 45% increase on the previous year. The DPC received 1,280 complaints solely related to the right of access, which it says accounted for 42% of all complaints received during the year. It also observed that many access complaints arise when the employment relationship is already deteriorating.

The figures matter. The more useful guidance for employers, however, appears in the DPC’s Case Studies 2025 (published 30 June 2026). They show how ordinary workplace records — appraisals, emails, witness material, sick certificates, CCTV and HR correspondence — can become central to a data subject access request (“DSAR”). Three themes recur: context matters, blanket exemptions are difficult to sustain and the quality of the response depends on the employer’s data practices before the request arrives.

Access is to personal data, but context matters

Article 15 GDPR gives an employee three related rights: confirmation that their personal data are being processed, access to those data and prescribed information about the processing. A DSAR is therefore not a general right to every document that mentions the employee.

Legislative wording — Article 15(3) and (4) GDPR

The controller shall provide a copy of the personal data undergoing processing.” The right “shall not adversely affect the rights and freedoms of others.”

That distinction should not be applied mechanically. In F.F. v Österreichische Datenschutzbehörde and CRIF GmbH, Case C-487/21, the Court of Justice of the European Union (CJEU) held that the copy must be a faithful and intelligible reproduction of the personal data. An extract, a full document or a database record may be required where the context is essential to understanding the data and exercising GDPR rights.

The DPC applied that principle in Case Studies 2025, Case Study 2. A pastoral centre held a counselling record containing the personal data of the requester and another person. It withheld the record in full because the material was inextricably linked. The DPC did not accept that mixed personal data justified an all-or-nothing response. The centre was required to provide an intelligible copy of the requester’s personal data, using proportionate redaction to protect the other person.

The practical question is whether the response allows the employee to understand the personal data, its context and how it has been used. A schedule may be enough in one case. In another, the relevant email chain, appraisal form, investigation note or CCTV clip may need to be supplied, subject to justified redaction.

Managerial opinions are likely to be personal data

Case Studies 2025, Case Study 4,  concerned a former employee of an Education and Training Board. The employer had responded to the DSAR but redacted one document and withheld two others. The disputed material contained managers’ views about the former employee’s work performance. The employer relied on Article 15(4) GDPR and section 60(3)(b) of the Data Protection Act 2018, arguing that the opinions had been given in confidence.

Legislative wording — section 60(3)(b)

The restriction concerns “an expression of opinion about the data subject by another person given in confidence or on the understanding that it would be treated as confidential”.

The full provision also requires the opinion to have been communicated to a person with a legitimate interest in receiving it. The DPC treated the confidentiality threshold as a high one. These were not comments supplied by a confidential external source or a colleague promised anonymity in exceptional circumstances. They were assessments made by managers as part of their ordinary role. The DPC’s position was direct: managers should ordinarily be able to stand over views expressed about an employee’s performance. It recommended release of the personal data.

That conclusion reflects the broad meaning of personal data. In Peter Nowak v Data Protection Commissioner, Case C-434/16, the CJEU held that examination answers and an examiner’s comments could both be the candidate’s personal data. Information may relate to a person because of its content, purpose or effect. It does not fall outside the GDPR merely because it is subjective, evaluative or disputed.

Employers should therefore assume that appraisal scores, capability assessments, promotion comments, interview notes, investigation findings and management conclusions may be accessible personal data where they relate to an identifiable employee. The answer is not to stop managers recording candid views, but to ensure comments are evidence-based, relevant, accurately attributed and written on the basis that the employee may later read them.

Disagreement does not automatically require rectification

Access and rectification are separate rights. An employee may strongly disagree with a performance opinion, but disagreement alone does not necessarily make the record inaccurate under Article 16 GDPR.

Case Studies 2025, Case Study 21 concerned clinical rather than employment data. The requester disputed professional views in a medical file and sought rectification. The DPC distinguished an incorrect fact from a genuine professional opinion recorded at a particular time. A factually incorrect entry should be corrected. An opinion does not become inaccurate merely because the individual disputes it; a supplementary statement may instead record the individual’s position without rewriting the historical record.

The same care is required in the employment context. An employer should correct an incorrect date, score, job title or attribution and test whether the facts underlying an opinion are accurate. Where the opinion was genuinely held and accurately recorded, linking the employee’s response to the original record may be more appropriate than altering the history of the file. Any refusal to amend must still be explained within the Article 12 framework.

Confidentiality is not a complete answer

Workplace DSARs often involve mixed data: the requester’s personal data, another person’s data and material that is not personal data at all. Article 15(4) requires a concrete assessment of any adverse effect on the rights and freedoms of others. It does not create an automatic exemption for witness statements, managers’ names or documents labelled confidential.

The DPC’s case studies show what a defensible assessment looks like:

  • In Case Study 1, a national school relied on Article 15(4) to redact third-party data and separately claimed legal privilege over specified material. The DPC reviewed the unredacted records and the school’s balancing exercise before accepting the restrictions. The school could connect each restriction to particular content and a particular legal basis.
  • In Case Study 2, the pastoral centre moved from complete withholding to an intelligible, redacted disclosure. The other person’s rights were protected without extinguishing the requester’s right of access.
  • In Case Study 8, an employer separated the requester’s personal data from third-party and non-personal material. The DPC accepted the redactions on the facts. Redaction is not objectionable in itself; unexplained or indiscriminate redaction is.

The EDPB’s Guidelines 01/2022 on the right of access set out the practical method. The employer should identify the specific right or freedom at risk, assess the likelihood and seriousness of harm, and consider whether redaction, partial disclosure, a summary or another intelligible format can reconcile the competing interests. Withholding an entire record should not be the starting point.

The DPC’s Annual Report 2025 recommends a schedule of redacted or withheld records. The schedule should identify the reason for the decision and the precise GDPR or Data Protection Act provision relied upon. This helps the employee understand the response and creates an audit trail if the DPC later examines it.

Employers should also distinguish external recipients from authorised internal access. RW v Österreichische Post AG, Case C-154/21 confirms that actual external recipients will generally need to be identified, unless they cannot be identified or the request is manifestly unfounded or excessive. J.M. (Pankki S), Case C-579/21 confirms a right to information about the dates and purposes of internal consultations, although staff identities are not automatically disclosable. Reliable audit logs are therefore important.

Privilege and legal claims require separate analysis

Section 162 of the Data Protection Act 2018 protects defined categories of material processed for legal advice or over which a claim to privilege could be made.

Legislative wording — section 162

It covers “personal data processed for the purpose of seeking, receiving or giving legal advice” and data over which “a claim of privilege could be made”.

Privilege and confidentiality are different. Copying a solicitor into an email does not, by itself, make it privileged. Nor does an internal investigation record become privileged merely because litigation is possible. The employer should examine the purpose and circumstances in which each record was created.

Section 60(3)(a)(iv) may separately restrict rights where personal data are processed in contemplation of, or for the establishment, exercise or defence of, an actual or prospective legal claim or proceedings, provided the restriction is necessary and proportionate. It should not be treated as a litigation-wide exclusion. The employer should identify the particular prejudice, apply the restriction only so far as necessary and record that analysis.

A broad or tactical request is usually still a request

Case Studies 2025, Case Study 3 concerned a small organisation faced with a broad request. It refused the DSAR as manifestly unfounded and excessive, principally because locating and reviewing the material would require substantial resources. The DPC did not accept that the burden, without more, met the high threshold in Article 12(5). The organisation ultimately engaged with the requester, agreed a more focused scope and supplied material in batches.

The employee’s motive will also usually be irrelevant. In FT v DW, Case C-307/22, the CJEU confirmed that the first copy had to be provided free of charge even though the requester’s purpose did not reflect the reasons described in Recital 63 GDPR. An employer should not reject a request merely because it appears designed to obtain material for a grievance, Workplace Relations Commission claim or civil proceedings.

There is, however, a narrow exception for abuse. In Brillen Rottler GmbH & Co. KG v TC, Case C-526/24, the CJEU confirmed in March 2026 that even a first request may be “excessive” under Article 12(5) where the controller demonstrates, in light of all the circumstances, that it was made with an abusive intention — for example, to manufacture the conditions for obtaining an advantage under the GDPR. Public information showing a pattern of requests followed by compensation claims may be considered. This remains a restrictive and evidence-dependent exception; a litigation-related motive alone does not establish abuse.

Where the employer processes a large quantity of data, it may invite the employee to identify the information or processing activities sought. The employer should describe the relevant data contexts — HR, payroll, performance, investigations, IT logs and CCTV, for example — so that the employee can make an informed choice. Clarification should not be used to reduce the scope unilaterally or, by itself, to stop the statutory clock.

Search where the data actually live

The EDPB Guidelines require controllers to search relevant IT systems and non-IT files using the identifiers by which information is structured. A name search alone may miss payroll numbers, email addresses, usernames, device IDs and records held under a job title. The DPC’s findings from the EDPB’s 2024 coordinated action likewise found that structured practices, workflow tools, search checklists and effective records of processing activities produced better results.

For an employee DSAR, the search plan may need to cover:

  • HR, payroll, absence, recruitment, performance and promotion systems;
  • email, approved messaging channels, shared drives and relevant managers’ files;
  • access-control, device, telephone, audit, CCTV and vehicle-tracking records, where within scope; and
  • processors such as payroll providers, HR platforms and outsourced service desks.

The search should be reasonable and defensible. Employers should record the custodians, systems, date ranges, search terms, exclusions and validation checks used. They need not recreate data lawfully and permanently deleted before the request.

In the Microsoft case reported in the Annual Report 2025, relevant data were deleted after the access request. The DPC’s concern was not that every request imposes indefinite retention. It was that deletion during the response process, in circumstances where the applicable process had not been explained clearly and fairly, undermined the handling of the right. Employers should therefore consider a focused preservation step when the DSAR is logged and document any routine deletion that continues.

Requests can arrive anywhere

A valid DSAR does not require a prescribed form or the words “subject access request”. The controller must recognise the substance of the communication.

The DPC’s decision concerned an access request sent to a legitimate customer-support address. The DPC concluded that a controller must be able to identify and route a valid request received through an ordinary operational channel: Annual Report 2025. The same failure appeared in Case Studies 2025, Case Study 36, where a request submitted through a general support channel was not classified as a GDPR request and was not progressed correctly.

An employer cannot solve that problem by naming one privacy inbox in a policy. HR, managers, reception, IT support and employee-relations teams should know how to identify and escalate a request for personal data. Contractors operating relevant channels need the same instruction. In the Vodafone matter, requests received by a service provider were not passed to and actioned by Vodafone. The reprimand reflected a failure of organisational arrangements, not simply an isolated inbox error.

Under Article 12(3) GDPR, the employer must respond without undue delay and, at the latest, within one calendar month. A further two months may be used where necessary because of complexity or the number of requests, but the employee must be told of the extension and the reasons within the first month. An extension should not be the default.

Identity checks must also be proportionate. Case Studies 2025, Case Study 13,  confirms that stronger verification may be justified where the request concerns particularly sensitive data and disclosure to the wrong person would have serious consequences. However, Article 12(6) permits additional information only where there are reasonable doubts about identity. An employer already communicating with an employee through an authenticated HR portal or established work account should not routinely demand certified identification.

Control how employee data are collected, used and shared

Several of the DPC’s 2025 case studies concern the employer’s underlying handling of personal data rather than the mechanics of a DSAR. Together, they show that an employer should be able to explain what it collected, why a particular person received it, whether a later use was compatible with the original purpose, and what controls applied when data left an approved system.

  • Sick certificates and health data: In Case Study 15, the organisation’s sickness-absence arrangements did not make clear what medical information employees should provide or who would receive it. Sick certificates containing health data were copied to a member of the finance team, although finance needed only absence dates. The organisation completed a data protection impact assessment and revised the process. Employers should route certificates only to the appropriate function and give payroll or finance the minimum information needed for pay administration.
  • Communications after termination: Case Study 18 concerned a former employee whose employer told residents that the person had been dismissed. The employer could not identify an Article 6 lawful basis and accepted that a neutral departure notice would have met the operational need. This engages both lawfulness under Article 6 and data minimisation under Article 5(1)(c) GDPR. Colleagues, clients or service users may need to know that an employee has left and whom to contact instead; they do not ordinarily need to know whether the departure followed a resignation, dismissal, disciplinary process or settlement.
  • CCTV access requests: In Case Study 32, a controller directed an individual seeking CCTV footage to An Garda Síochána. The DPC made clear that this did not discharge the controller’s Article 15 obligations. Even where Gardaí are investigating an incident or hold a copy, the controller must deal with the request and either disclose the requester’s personal data or identify and explain a lawful restriction.
  • Access to workplace CCTV: Case Study 35 arose from employees’ concerns about a live monitor visible to staff and remote access that had not been properly defined. Access to a live feed is itself processing. An employer should specify who may view the feed or recordings, for what purpose and in what circumstances, and prevent casual viewing by staff with no operational need.
  • Using footage for a new purpose: The DPC reprimanded the Irish Prison Service after security CCTV was used to examine an employee’s movements in a disciplinary context. The employer failed to demonstrate a lawful basis or why the use was necessary and proportionate, particularly where the employee had admitted the issue being investigated. Security cameras do not become a general management tool simply because footage is available. Employers should define any disciplinary use in advance and apply strict access and retention controls. The DPC’s CCTV guidance and the EDPB’s Guidelines 3/2019 should inform that assessment.
  • External AI tools: Case Study 28 concerned an employee who uploaded 32 candidate CVs to a free AI tool. The employer had no data-processing agreement with the provider and no policy governing external AI services. Employers should identify approved tools, prohibit the use of candidate or employee data in unapproved services, and train staff accordingly. Otherwise, the organisation may not know where the data are when it later needs to secure, delete or disclose them.

A defensible employer workflow

A sound process is easier to defend and less likely to miss data. Employers should test the following steps before a contentious request arrives:

  • Recognise and log immediately: Record the date, channel, requester, scope and statutory deadline. Allocate responsibility and acknowledge receipt.
  • Confirm identity and authority proportionately: Ask only for information needed to resolve a reasonable doubt. Verify representatives before disclosing data.
  • Map and preserve the data: Use the record of processing activities, retention schedule and system owners. Notify processors promptly and consider a focused preservation step.
  • Clarify where useful, but keep working: Give the employee a meaningful list of data contexts. Do not treat silence as withdrawal of a valid general request.
  • Search and validate: Document the systems, custodians, terms and date ranges used. Check likely gaps rather than relying on a single name search.
  • Review each restriction separately: Distinguish personal data, necessary context, third-party rights and privileged material. Record the balancing decision.
  • Respond intelligibly and securely: Provide the Article 15 information and personal data in an accessible format. Include a redaction or withholding schedule and complete a second-person quality check before release.

The practical point

The strongest DSAR response is prepared before the request arrives. Employers that know where employee data are held, control who can use them and require managers to write defensible records will be better placed to respond accurately and on time.

The DPC’s 2025 material also closes off several easy assumptions:

  • A managerial opinion can be personal data.
  • Confidentiality needs evidence.
  • Third-party rights require a case-specific balance.
  • A litigation-adjacent motive does not invalidate the request.

In practice, the response will be only as good as the organisation’s existing data governance.

AP LLP advises employers on workplace data governance, employee DSARs and the interaction between data protection, investigations, performance management and employment disputes.

This article was written by Robin Hyde (Partner) and Stephen Barry (Trainee).

Key sources

Similar Insights

Interim Measures Introduced For IRP Holders

Interim Measures Introduced For IRP Holders

On 13 July 2026, the Department of Justice introduced interim measures in response to the significant volume of applications for the renewal of Irish Residence Permits (“IRPs”) being processed through the Immigration Service portals. The Department has noted that the...

read more

A boutique business law firm, specialising in commercially driven areas of law. With combined teams in Galway and Dublin, we are able to offer clients across Ireland a fully integrated service

091 56 57 65

info@purdyandco.ie

Small Slider Image 1