The Strategic Weaponisation of DSARs
Article 15 of the General Data Protection Regulation (GDPR) sets out a legal right enabling individuals to obtain access to their personal information being processed by organisations.
This is known as a Data Subject Access Request, DSAR, or SAR (this article refers to it as a DSAR). This right of access is widely used by customers, employees, and ex-employees, especially during a dispute, or a dismissal.
A DSAR can be made verbally or by writing, in any manner, including via social media. It can be addressed to any part of an organisation, rather than a specific person or contact point. Managing these requests typically falls to HR departments commanding significant resources and requiring careful attention.
The use of DSARs as a legal strategy in disputes and how to mitigate this risk
During employer/employee disputes, it is common for the aggrieved to submit a Data Subject Access Request (DSAR) seeking information to help their case. This situation, often seen in civil and employment litigation, necessitates careful and strategic handling.
Many organisations lack effective systems for storing and retrieving data, which can make managing DSARs challenging, leading to delays and errors, incomplete responses, or incorrect disclosure containing third-party data, resulting in data breaches.
The mishandling of a request can turn a simple DSAR dispute into multiple complex claims, not only resulting in time consuming complaints and reputational damage to the employer, but also compensation claims for infringement of rights for both material damages (e.g. loss of wages) and non-material damages (e.g. distress and anxiety). If mismanaged it can also provide the individual with a tactical and practical advantage.

The purpose of a DSAR
The right of access allows a person to confirm whether their personal data is being processed, and where it is, for access to that personal data, along with supplementary information, such as the purposes of processing and categories of data; and can also include information relating to the decision-making process concerning an individual’s grievance or redundancy.
The principle behind the right to access is generally deemed to be "purpose blind", as it is an absolute right, which cannot be avoided, unless of course an exemption applies.
While access requests seeking evidence or seemingly intent on causing delays and or a commercial advantage in a dispute matter are incredibly frustrating, they must not be ignored.
It is therefore important to ensure that both requests for personal data, and responses to such requests are carefully managed.
Exemptions
The Data Protection Act 2018 allows certain exemptions, for example data processed for the prevention, detection, investigation, or prosecution of criminal offences, and management forecasting, if disclosure would prejudice these purposes, or for matters involving public interest concerns or national security considerations. Exemptions can sometimes be complicated to apply, and if seeking to rely upon an exemption the reasoning needs to be carefully recorded and justified in case of challenge.
Conclusion
Effective DSAR management begins with robust processes and staff training. Strong, formal procedures should be followed to ensure your organisation:
- recognises a data subject access request (made in any manner);
- understands the strict deadlines, and how to apply an extension;
- undertakes thorough and accurate data searches, collation, and redactions;
- knows when and how to seek clarification, apply exemptions, and refusals;
- provides responses, which includes the information in scope; and
- complies with your legal obligations, with an awareness of the risks of inadvertently providing a tactical and or practical benefit to the applicant.
Organisations uncertain about DSAR management, especially those linked to litigation, should seek legal advice promptly.
To discuss further Contact KPDP Consultancy for a free 30-minute consultation.
This article is for general information only. It does not constitute legal advice and should not be relied upon as such. If you require further information regarding its content, please contact us at info@kpdpconsultancy.co.uk. Law as of April 2025.
