Email and Subject Access Requests

Email and subject access requests do not go together well. Under the UK GDPR and Data Protection Act 2018, organisations are required to respond to a Subject Access Request (SAR) within one calendar month. While this timeframe may seem manageable in theory, the reality is that emails often present the biggest operational and compliance challenge in meeting that deadline.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Here’s why:

 

GDPR

 

Volume of Data

Emails are pervasive. Most employees send and receive hundreds, if not thousands, of emails every month. These emails may contain personal data—either in the body, attachments, or even in forwarded chains. Locating all potentially relevant emails across multiple inboxes, folders, and archives can be an overwhelming task, especially in large organisations.

Unfortunately the volume of data is not considered a valid reason for delaying or failing to respond to a subject access request so the volume of emails relating to a person can present a real challenge.

For example, every email sent to or from a person will have their personal data in it (email address) even it is:

  • an “all staff” email

  • a meeting invite

  • a reply to a previous email

Difficulty Identifying Personal Data

Unlike structured systems (like HR or CRM databases), emails are unstructured and vary wildly in format and language. Personal data may be embedded in threads, attachments, or within casual language. This makes automated filtering unreliable and manual review time-consuming. Misidentification can result in either over-disclosure (risking third-party data breaches) or under-disclosure (failing to meet SAR requirements).

Fortunately email, being electronic, can be searched via computer to collate emails. You should be careful to search by the full range of things that can lead to a person being identified, such as:

  • first or last name, or both

  • email address (whether sender or recipient)

  • job title

  • employee reference number or other designations

However, even when identified these emails will still need to be manually reviewed…

 

Redaction Challenges

Emails often include third-party data, opinions, or confidential business information. To comply with GDPR, organisations must redact or withhold such information where appropriate. Redacting emails is far from straightforward— long threads need to be carefully edited, metadata needs reviewing, and attachments must also be checked and redacted where necessary. The risk of accidentally disclosing more than is legally permitted is high.

You should also be careful to redact or remove anything that is exempt from disclosure under the Data Protection Act. Examples include:

  • confidential references (either given or received)

  • things subject to legal professional privilege

  • something that could cause serious harm (where the serious harm test would apply).

 

Duplications and Threads

Email chains are often forwarded and replied to multiple times, creating duplicates. Sorting through these chains, removing redundancy while preserving context, is laborious. Yet omitting relevant information due to deduplication errors can result in incomplete disclosure and potential non-compliance.

This is another reason why careful, manual review of emails is necessary before any disclosure of personal data can be done.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Search and Retrieval Limits

Many legacy email systems lack robust search capabilities or have inconsistent retention policies. This means that IT teams may spend significant time locating archived or deleted messages, restoring backup data, or reconstructing user inboxes. The administrative burden can be disproportionate, particularly when subject access requests span long time periods or involve former employees.

 

Resource Constraints

Email review demands input from IT, Legal, HR, and Data Protection teams. In smaller organisations, or those without dedicated SAR processes, managing this collaboratively within the one-month statutory deadline is difficult—especially if multiple subject access requests are received simultaneously or if a request is complex.

 

Risk of Overlooking Relevant Accounts

It’s not uncommon for organisations to forget that employees might store relevant emails in personal folders, shared mailboxes, or even local PST archives. Without comprehensive discovery protocols, relevant records may be missed, risking incomplete compliance and regulatory scrutiny.

 

Mitigation Strategies

To address these challenges, organisations should:

  • Implement SAR workflows that prioritise email discovery early in the process.

  • Use email archiving and eDiscovery tools capable of filtering, indexing, and redacting personal data within email messages.

  • Provide staff training to all email users (so, likely everyone) to ensure personal data is minimised in email communications where possible.

  • Maintain clear retention and deletion policies to limit the volume of historical data.

  • Encourage people making a subject access request to be as specific as possible about what they’re looking for.

 

Conclusion

Emails may seem like a mundane aspect of business communication, but when it comes to subject access requests, they can become a legal and logistical minefield. A proactive, technology-enabled, and well-documented approach is essential to navigating this complexity—and ensuring timely, lawful responses that uphold individuals’ data rights.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial