IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Businesses warned of soaring cost of employee subject access requests

Report shows quarter of requests involve workers trying to find out what their company holds on them

Visual representation of GDPR and the UK's independence from the EU

Just under half of UK organisations have seen a rise in the costs associated with complying with subject access requests (SARs) coming from their own employees.

Research published to coincide with the one year anniversary of the General Data Protection Regulation (GDPR) showed that 71% of organisations have seen a rise in their own employees making official requests for personal information held. Two-thirds of them, (67%), meanwhile, have increased their level of expenditure in attempting to fulfil them.

Since GDPR was introduced on 25 May 2018, the legal time allowed to fulfil SARs was cut from 40 days under the Data Protection Act 1998 to 30 days. This has led businesses to take a variety of measures to cope with the greater workload, which has increased as a result of growing interest from data subjects to find out what information a company has on them, according to research by law firm Squire Patton Boggs.

The majority of organisations (83%) have implemented new guidelines and procedures, while 27% have hired staff specifically to deal with the higher volume of SARs. Moreover, a fifth of firms surveyed (20%) have even adopted new software to cope.

"The demands placed on organisations are considerable - just the initial process of identifying all the data held in respect of an individual can take weeks out of the one-month period for responding," the report said.

"Each request requires correspondence with the individual, arranging the data platform, IT searches of data held, review of potentially thousands of documents at least twice, redaction or exclusion of information that is privileged, relates to third parties or falls under another exemption set out in the GDPR, and returning to the individual along with a cover letter.

"For the most part, this whole process must take place within one month of receipt."

Just under a quarter of all businesses responding (24%) have seen their own employees making SARs seemingly just to find out what the organisation has on record about them. In most cases, however, organisations have experienced SARs from employees because they were connected to workplace grievances.

The report concluded that given the absence of guidance from the Information Commissioner's Office (ICO) on employee SARs, it is difficult to see the issue disappearing. This is mostly because workers can see the mechanism "as a strategic tool to use where there is a workplace dispute".

Specifically, it may incentivise employers to settle workplace matters more quickly, given the cost implications of SARs. Individuals may also benefit from information that would not otherwise be available to them for several months, the law firm argued.

The ICO has itself also seen a rise in the number of complaints made over SARs not being fulfilled within the statutory 30-day limit since GDPR has come into force.

One high-profile example of this centres on Twitter's failure to comply with an academic's SAR because it was deemed to take 'disproportionate effort'

In November last year, the ICO also received complaints about seven companies including Oracle and Equifax on behalf of Privacy International based on 50 unfulfilled SARs.

Squire Patton Boggs has recommended that all businesses implement clear policies and procedures to allow them to process SARs in accordance with GDPR, and avoid the subsequent attention of the ICO.

Featured Resources

The Total Economic Impact™ Of Turbonomic Application Resource Management for IBM Cloud® Paks

Business benefits and cost savings enabled by IBM Turbonomic Application Resource Management

Free Download

The Total Economic Impact™ of IBM Watson Assistant

Cost savings and business benefits enabled by Watson Assistant

Free Download

The field guide to application modernisation

Moving forward with your enterprise application portfolio

Free Download

AI for customer service

Discover the industry-leading AI platform that customers and employees want to use

Free Download

Most Popular

Why convenience is the biggest threat to your security

Why convenience is the biggest threat to your security

8 Aug 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022
The benefits of a hardware update for SMBs

The benefits of a hardware update for SMBs

2 Aug 2022