Employee DSARs increasingly arrive mid-dispute: during a grievance, an investigation, or ahead of a tribunal claim. The first thing to accept is that the dispute changes nothing about the obligation. The ICO’s guidance for employers is explicit that an ongoing grievance or tribunal process is not a ground for refusing a subject access request, and its view of settlement terms that purport to waive the right is dim. What the dispute does change is the material: investigation notes, witness statements, and HR files are the most third-party-dense documents an organisation holds, and producing them lawfully is a redaction exercise done properly, not a disclosure exercise done reluctantly.
What Counts as the Employee’s Data in These Files
More than people expect. The requester’s personal data is not limited to documents about them; it includes what colleagues, managers, and witnesses have said about them, opinions about them recorded in notes and appraisals, and messages discussing them in Exchange mailboxes and Teams threads. That is precisely why these bundles are hard: nearly every relevant document is mixed data, the requester’s information interleaved with someone else’s. The law’s answer to mixed data is not withholding the document; it is the third-party test, applied line by line.
The Third-Party Test, as the Statute Writes It
Paragraph 16 of Schedule 2 to the Data Protection Act 2018 says you are not obliged to disclose information to the extent that doing so would involve disclosing information relating to another identifiable individual, unless that person consents or it is reasonable to disclose without their consent. The reasonableness factors include any duty of confidentiality owed to the other person, the steps you took to seek consent, whether they can consent, and any express refusal. Two drafting details do a lot of work in employment cases. The statute says identifying the other individual as the source of information is itself information relating to them, which is the legal root of witness protection in these bundles. And it says a person can be identified using information the requester is likely to possess, which is why redacting a name in a five-person team often de-identifies nobody: if the context gives the witness away, the redaction has to reach the context, or the passage may need withholding. The ICO’s guidance on third-party information walks the same balance and adds a caution in the other direction: marking a document confidential does not by itself create a duty of confidence.
Witness Statements
A witness statement is typically the requester’s personal data, the witness’s personal data, and often a third colleague’s, in adjacent sentences. The workable approach is per-document and documented: identify what in the statement is the requester’s information, apply the paragraph 16 balance to the witness’s identity and to passages that identify them by context, record whether consent was sought and what the answer was, and decide disclosure, redaction, or withholding on that record. Assurances of confidentiality given to witnesses during an investigation weigh in the balance; they do not decide it on their own. What defeats organisations here is not the law but the bookkeeping, fifty statements each needing an individually reasoned decision, which is exactly the discipline an audit trail exists to hold.
Confidential References Are Different
One category gets a clean statutory answer. Under paragraph 24 of Schedule 2, a reference given or received in confidence for employment, training, education, volunteering, or appointment purposes is exempt from the right of access, in the hands of both the giver and the recipient. The ICO’s exemptions guidance confirms the exemption applies whichever side of the reference you sit on, and only where the reference was genuinely given in confidence, which is a policy you should be able to point to rather than an assumption made after the request lands.
The Mistakes That Generate Complaints
Four recur. Refusing or stalling because litigation is running, which the guidance forecloses. Blanket-redacting every name in every document, which over-redacts the requester’s own data, since what others said about them is generally theirs to receive even where the sayer’s identity is not. Forgetting the modern locations, because the grievance lives in Teams messages and chat exports at least as much as in the HR file, and a bundle missing them invites the response that the search was inadequate. And redactions that do not survive contact, a black rectangle over live text that copy and paste removes, which converts a lawful response into a disclosure incident. From 19 June 2026 each of these is also a statutory complaint you must investigate on the record.
The Microsoft 365 Mechanics
In most organisations these documents live in Exchange mailboxes, Teams chats, and SharePoint HR sites, which makes the collection step a scoped Purview or Content Search export over named custodians and date ranges, per the reasonable and proportionate standard. Our Microsoft 365 DSAR guide covers the export settings; the review stage is where the third-party work above actually happens, one document at a time.
How SafeRedact Fits
Files never leave your browser: documents are processed client-side, only extracted text is sent for AI detection, and no documents are stored on servers. Detection text is never used for training and is deleted within 30 days. DSAR mode lets you name the data subject whose information should be preserved while other individuals’ personal information is flagged for redaction across every file in the case. Every detection is reviewed by a human before anything is exported, and the output includes a processing summary and audit trail your privacy officer can stand behind if the ICO asks how the response was produced.
A Data Processing Agreement is available, and enterprise cases are priced per case, with the price set with you and shown before you download. See the enterprise overview or the enterprise FAQ for how cases run end to end.
Produce the Bundle Without Burning the Month
AI-assisted detection of third-party personal data, human review of every decision, and an audit trail that shows the balance was actually struck.
Start Your EvaluationRelated Guides
Microsoft, Microsoft 365, SharePoint, Exchange Online, OneDrive, Teams, and Purview are trademarks of Microsoft Corporation. SafeRedact is not affiliated with or endorsed by Microsoft. This page is informational, not legal advice; the legislation, court rulings, ICO guidance, and your counsel govern.