Data Subject Access Requests

And why IT should care about them

Data Subject Access Requests (DSARs) were first introduced in 1998, and digital technology has made requesting them easier over time.

So what is a DSAR and why should IT professionals care? In short, companies and organisations of all sizes need to know what they are, and what to do if you receive one. The problem is that incoming DSARs can become a hot potato and bounce around HR, legal, IT, data protection, compliance and even marketing departments without clear accountability or ownership.

The Information Commissioner’s Office (ICO) publishes a useful guide on preparing for subject access requests, with one of the requirements being that you carry out a “reasonable search for the requested information”. On top of that, the timeline to respond is one month.

So even if the Data Protection Officer (DPO) is ultimately accountable for the request, without the right processes or tools in place, finding the requested information can be a minefield. No prizes for guessing the first point of call to get that information!

Enter IT!

And that’s usually where IT teams become involved in order to locate the personal data, while ensuring that other legal obligations are not infringed in doing so.

According to Kingsley Napley, “technical support is frequently required to identify and review data, and legal input may be needed.” For example, if an ex-employee asks to see all emails and correspondence they were copied on over a two year period, this could be hundreds of thousands of emails, not to mention direct chats and team collaborations in platforms such as Microsoft Teams or Google Workspaces.

How else can IT get sucked in?

As well as the normal jobs of keeping the lights on, ensuring that everyone has working devices, the network is secure, all files are safely backed up, and everything else that goes on in a day, there’s worse news for IT teams.

That’s because these kinds of data requests may not even be limited to DSAR cases. IT are increasingly being asked to help with locating data for internal complaints or enquiries such as:

  • One employee is accused of sexually harassing another via their organisation’s Microsoft
    Teams chats.
  • Instances in which an organisation’s emails are being sent to an unusual address.
  • A director suddenly starts getting lots of unsolicited calls from recruiters.
  • A firm’s customers start being approached by its rival’s salespeople
  • An industry news outlet gets hold of sensitive proprietary information about a company’s
    new product.
  • After one company acquires another, ensure employees aren’t still using old terminology
    from the acquired business.

▶ Read more in this article from our friends at Cryoserver.

Related Articles
Modern Workplace The AI-powered office of the future
The AI-powered office of the future

Creating your GenAI office.

Unified Communications Managing complex UC environments
Managing complex UC environments

The changing dynamics of UC and the impact on IT.

Unified Communications How to actually unify your workplace
How to actually unify your workplace

Get the inside track from Forrester

Modern Workplace The new era of AI-powered business
The new era of AI-powered business

Microsoft business applications launch event.

Unified Communications Improve your digital document experience
Improve your digital document experience

Find out the ROI of all-in-one

Modern Workplace Myth: Only data science experts can use AI
Myth: Only data science experts can use AI

What do you really know about AI?

Unified Communications Enabling digital workplaces
Enabling digital workplaces

How to drive workforce training programmes that work.

Unified Communications Digital transformation in practice
Digital transformation in practice

How Hackney Council serves its community from anywhere.

Unified Communications Rekindling intranets for the modern workplace
Rekindling intranets for the modern workplace

From static file repository to dynamic collaboration hub

Unified Communications IT's role in advertising data collaboration
IT's role in advertising data collaboration

Balancing personalisation with regulatory compliance.

Unified Communications A new era of contracting agility
A new era of contracting agility

The convergence of CLM and contract analytics

Unified Communications Collaboration - from Spiderman to the science lab
Collaboration - from Spiderman to the science lab

How Google Chat keeps teams connected.

Unified Communications Five ways to decide if you need Contract Management Software
Five ways to decide if you need Contract Management Software

A quick way to save 9% of annual revenue.

Unified Communications Improve business agility with DocuSign
Improve business agility with DocuSign

Good reasons to consider DocuSign for your e-signature solution.

Unified Communications Don't slip up with data security and compliance requirements
Don't slip up with data security and compliance requirements

How to fend off modern threats to connected devices.

Unified Communications If you had three wishes...
If you had three wishes...

We demystify digital signatures.

Unified Communications How IT can help legal operate efficiently
How IT can help legal operate efficiently

It's not IT's responsibility for departmental processes - but there is a key role to play.

Unified Communications Squeeze the waste out of routine processes
Unified Communications Compliance and Microsoft Teams
Compliance and Microsoft Teams

Why a certified recording solution is essential.

Modern Workplace eSignature's role in English Law
eSignature's role in English Law

How English Courts support eSignatures.

Modern Workplace Why it pays to use eSignature
Why it pays to use eSignature

eSignature has advantages for businesses of every shape and size. Find out more.

Unified Communications Four ways to get your business more mobile - and compliant
Four ways to get your business more mobile - and compliant

How to build an enterprise mobility strategy.

Modern Workplace Frictionless digital vs legacy
Frictionless digital vs legacy

Could you agree more with eSignature?

Unified Communications Galvanise your business with collaboration tools
Galvanise your business with collaboration tools

SMBs can drive business growth with cutting-edge technologies.

Unified Communications "Have 15 minutes back"
"Have 15 minutes back"

5 ways to get more from virtual meetings

Unified Communications UC or collaboration?
UC or collaboration?

And what does it mean for IT?

Modern Workplace There’s a time and a place for Mozart
There’s a time and a place for Mozart

3 key questions to digitally transform your call centre

Share this story

Rate the Article

Click the link below to rate this article

Rate this article

We're a community where IT security buyers can engage on their own terms.

We help you to better understand the security challenges associated with digital business and how to address them, so your company remains safe and secure.

Interested in what you see? Get in touch, and let's start a conversation Get in touch