In many jurisdictions, people have a right to ask an organisation what personal data it holds about them and to receive a copy. Handled well, a request is routine. Handled badly, it becomes a complaint to a regulator, or ammunition in a dispute that was already running. These are the seven mistakes that cause most of the trouble. Deadlines, exemptions and fees vary by jurisdiction, so check the rules that apply to you.
1. Not recognising the request
Requests rarely arrive labelled. "Can you send me everything you have on me?" in an email to a staff member, a line in a solicitor's letter, a comment on a social media post: any of these can be a valid request. If staff do not recognise them, the clock runs while the email sits in someone's inbox. Train everyone who deals with the public to pass on anything that looks like one, the same day.
2. Starting the clock late
Response deadlines usually run from receipt, not from when the right person noticed. Log the date received, confirm identity promptly if you genuinely need to, and record any clarification requested. Where the law allows the clock to pause, note exactly when it paused and restarted.
3. Searching too narrowly
The requester is entitled to their data wherever it sits, not just in the main database. Common gaps:
- Personal inboxes and sent items, not just the shared mailbox
- Messaging apps and chat channels used for work
- Notes, call logs and handwritten files
- Backups and archives, where your jurisdiction's rules include them
- Data held by processors on your behalf
Email scattered across individual inboxes is the hardest part of most searches; the hidden cost of using email as a filing system explains why. Knowing where your records live in the first place helps; see how to audit who has access to your files.
4. Over-redacting
Blacking out anything awkward, or anything mentioning a colleague, is tempting and usually wrong. Redaction should be justified item by item by an exemption or by the rights of third parties. Record the reason for each redaction; if the response is challenged, that record is your defence.
5. Under-redacting
The opposite mistake causes a data breach: sending a third party's personal data, a colleague's private comments, or another client's details. Redact properly, in a way that cannot be reversed by copying the text out of a PDF, and have a second person check before sending.
6. Sending data without the context
Most regimes require more than copies of documents: the purposes of processing, the recipients, the retention period, the source of the data and similar information. A pile of exported emails without that explanation is an incomplete response.
7. Not keeping a record of the response
Keep a file for each request: the request, identity checks, the search log (where you looked, with what terms, on what date), what was found, what was withheld and why, what was sent, how and when. If the requester complains or asks again, you will need to show what you did, and you cannot reconstruct it from memory six months later.
Make the next one easier
Every request exposes weaknesses: data in places nobody knew about, records kept longer than necessary. After each one, fix what you found. A working retention schedule (records retention schedule template) shrinks the next search, because data you have properly disposed of does not need to be found.