Email and subject access requests do not go together well. Under the UK GDPR and Data Protection Act 2018, organisations are required to respond to a Subject Access Request (SAR) within one calendar month. While this timeframe may seem manageable in theory, the reality is that emails often present the biggest operational and compliance challenge in meeting that deadline.
Here’s why:

Volume of Data
Emails are pervasive. Most employees send and receive hundreds, if not thousands, of emails every month. These emails may contain personal data—either in the body, attachments, or even in forwarded chains. Locating all potentially relevant emails across multiple inboxes, folders, and archives can be an overwhelming task, especially in large organisations.
Unfortunately the volume of data is not considered a valid reason for delaying or failing to respond to a subject access request so the volume of emails relating to a person can present a real challenge.
For example, every email sent to or from a person will have their personal data in it (email address) even it is:
-
an “all staff” email
-
a meeting invite
-
a reply to a previous email
Difficulty Identifying Personal Data
Unlike structured systems (like HR or CRM databases), emails are unstructured and vary wildly in format and language. Personal data may be embedded in threads, attachments, or within casual language. This makes automated filtering unreliable and manual review time-consuming. Misidentification can result in either over-disclosure (risking third-party data breaches) or under-disclosure (failing to meet SAR requirements).
Fortunately email, being electronic, can be searched via computer to collate emails. You should be careful to search by the full range of things that can lead to a person being identified, such as:
-
first or last name, or both
-
email address (whether sender or recipient)
-
job title
-
employee reference number or other designations
However, even when identified these emails will still need to be manually reviewed…
Redaction Challenges
Emails often include third-party data, opinions, or confidential business information. To comply with GDPR, organisations must redact or withhold such information where appropriate. Redacting emails is far from straightforward— long threads need to be carefully edited, metadata needs reviewing, and attachments must also be checked and redacted where necessary. The risk of accidentally disclosing more than is legally permitted is high.
You should also be careful to redact or remove anything that is exempt from disclosure under the Data Protection Act. Examples include:
-
confidential references (either given or received)
-
things subject to legal professional privilege
-
something that could cause serious harm (where the serious harm test would apply).
Duplications and Threads
Email chains are often forwarded and replied to multiple times, creating duplicates. Sorting through these chains, removing redundancy while preserving context, is laborious. Yet omitting relevant information due to deduplication errors can result in incomplete disclosure and potential non-compliance.
This is another reason why careful, manual review of emails is necessary before any disclosure of personal data can be done.
Sign Up Here:
Many legacy email systems lack robust search capabilities or have inconsistent retention policies. This means that IT teams may spend significant time locating archived or deleted messages, restoring backup data, or reconstructing user inboxes. The administrative burden can be disproportionate, particularly when subject access requests span long time periods or involve former employees. Email review demands input from IT, Legal, HR, and Data Protection teams. In smaller organisations, or those without dedicated SAR processes, managing this collaboratively within the one-month statutory deadline is difficult—especially if multiple subject access requests are received simultaneously or if a request is complex. It’s not uncommon for organisations to forget that employees might store relevant emails in personal folders, shared mailboxes, or even local PST archives. Without comprehensive discovery protocols, relevant records may be missed, risking incomplete compliance and regulatory scrutiny. To address these challenges, organisations should: Implement SAR workflows that prioritise email discovery early in the process. Use email archiving and eDiscovery tools capable of filtering, indexing, and redacting personal data within email messages. Provide staff training to all email users (so, likely everyone) to ensure personal data is minimised in email communications where possible. Maintain clear retention and deletion policies to limit the volume of historical data. Emails may seem like a mundane aspect of business communication, but when it comes to subject access requests, they can become a legal and logistical minefield. A proactive, technology-enabled, and well-documented approach is essential to navigating this complexity—and ensuring timely, lawful responses that uphold individuals’ data rights. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
Search and Retrieval Limits
Resource Constraints
Risk of Overlooking Relevant Accounts
Mitigation Strategies
Conclusion
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: