Insight

Employee DSARs: Courts Reinforce Limits on Litigation Disclosure

July 22, 2026

As employers increasingly deploy AI-enabled HR systems, workforce analytics, and digital workplace technologies, the volume of employee data continues to grow, making data subject access requests (DSARs) increasingly complex. At the same time, DSARs have become an established feature of workplace disputes, routinely accompanying grievances, disciplinary processes, whistleblowing complaints, and Employment Tribunal claims.

Against that backdrop, a series of recent EU and UK decisions provides a timely opportunity for employers to revisit how they approach employee DSARs. While these developments do not fundamentally alter UK law, they reinforce an important principle: the right of access exists to promote transparency and help demonstrate compliance with the GDPR, not to create an alternative disclosure regime for employment litigation.

THE ESTABLISHED UK POSITION

The starting point under Article 15 of the UK GDPR remains unchanged. Individuals are entitled to obtain confirmation that their personal data is being processed and to receive a copy of that personal data together with prescribed information about that processing.

The English Court of Appeal[1] has previously confirmed that a collateral litigation purpose does not, of itself, justify refusing a DSAR. Although the existence of litigation may be relevant where enforcement proceedings are brought, it is not, without more, a basis for denying the right of access.

Similarly, both the courts and the Information Commissioner’s Office (ICO)[2] have recognised that Article 15 creates a right of access to personal data rather than a freestanding right to documents, although providing copies of documents may sometimes be necessary to enable an individual to understand or exercise that right effectively. Although well established in principle, that distinction has become increasingly blurred in practice as employment-related DSARs often involve reviewing substantial volumes of emails, investigation records, and HR documentation.

EU COURTS REINFORCE DISTINCTION BETWEEN ACCESS RIGHTS AND DISCLOSURE

Recent EU decisions suggest a growing judicial willingness to reinforce the distinction between the right of access and litigation disclosure.

In Brillen Rottler GmbH & Co KG v TC (Case C-526/24), the Court of Justice of the European Union (CJEU) confirmed that, in exceptional circumstances, even a first DSAR may be refused where it is manifestly unfounded or excessive under Article 12(5) of the GDPR. Significantly, the court held that “manifestly excessive” is not limited to repeated requests. On the facts before it, Article 12(5) was capable of applying where there was objective evidence that the right of access was being abused, for example through a systematic pattern of requests designed not to verify the processing of personal data but to pursue financial compensation.

The court emphasised, however, that this remains a narrow exception. The burden rests on the controller to establish objective evidence of abuse, and the fact that a request is connected with litigation or may ultimately support a compensation claim is not, without more, sufficient to justify refusal.

The French courts have reached similar conclusions regarding the proper scope of Article 15. In Cour d'appel de Paris, Pôle 6 Chambre 2, 18 December 2025, No. 25/04270, building on the earlier decision of the Cour de cassation of 18 June 2025 (No. 23-19.022), the Paris Court of Appeal rejected an employee’s attempt to obtain copies of all emails sent and received through their professional mailbox.

The court confirmed that professional emails are not automatically, or in their entirety, an employee’s personal data simply because they pass through that employee’s mailbox. It also emphasised that Article 15 should not be used to circumvent procedural rules governing disclosure or evidence gathering and reaffirmed that employers must balance access rights against the privacy rights of colleagues and the protection of confidential business information and trade secrets.

The decision reinforces the principle that a DSAR is intended to enable individuals to verify the lawfulness of the processing of their personal data, not to obtain wholesale disclosure of business records for use in litigation.

UK COURTS ARE ALSO SCRUTINISING HOW EMPLOYERS RESPOND

Recent UK authority reflects a similar emphasis on the quality of a controller’s response.

In Michael Ashley v The Commissioners for His Majesty’s Revenue and Customs [2025] EWHC 134 (KB), the English High Court examined the scope of a complex subject access request, what constituted the claimant’s personal data, the adequacy of searches conducted by HMRC, the UK’s equivalent of the US Internal Revenue Service, and the application of various exemptions.

The judgment provides several practical reminders. The court criticised HMRC’s search methodology for failing adequately to consider whether relevant personal data was held elsewhere within HMRC, including by the Valuation Office Agency. It reaffirmed that whether information constitutes personal data depends on its content, purpose, and effect, rejected blanket reliance on statutory restrictions and legal professional privilege without sufficient justification, and emphasised that personal data must be provided in an intelligible form rather than through heavily redacted extracts devoid of meaningful context. Although the decision turned on its own facts, it demonstrates that courts are willing to scrutinise not only the outcome of a DSAR response but also the methodology and evidence underpinning it.

Although EU decisions are not binding on UK courts following Brexit, they are likely to be persuasive given the close alignment between the relevant provisions of the EU GDPR and the UK GDPR. Together with Ashley, they reinforce principles already reflected in UK law and ICO guidance: Article 15 is a right of access to personal data, not a general entitlement to inspect business records or an alternative mechanism for obtaining disclosure in employment disputes. More broadly, they reflect an increasing judicial focus on ensuring that controllers adopt, and can demonstrate, a reasonable, proportionate, and well-documented approach to responding to DSARs.

PRACTICAL IMPLICATIONS FOR EMPLOYERS

These developments should not be interpreted as creating a general right to refuse employee DSARs. The threshold for relying on Article 12(5) (which sets out the key circumstances allowing a controller to decline to respond to a DSAR) remains high, and employers should continue to approach refusals with considerable caution.

The more significant message is that employers should be able to justify the decisions taken throughout the response process. That means ensuring searches are reasonable and proportionate, distinguishing requests for personal data from requests that are, in substance, seeking litigation disclosure and documenting how the request was interpreted, why particular systems were searched, and how any exemptions or limitations were applied. As Ashley demonstrates, these aspects of a DSAR response may themselves become the subject of judicial scrutiny.

Where requests are particularly broad or unclear, employers should continue to engage constructively with individuals to clarify scope and agree appropriate search parameters. The emphasis is not on finding new grounds to refuse requests but on responding in a way that is demonstrably reasonable, proportionate and consistent with the purpose of Article 15.

A BROADER SHIFT IN WORKFORCE DISPUTES

The real significance of these developments lies in what they reveal about the changing relationship between employment litigation and data protection.

DSARs have become a routine feature of workplace disputes and are frequently used alongside grievances and UK Employment Tribunal claims. The recent authorities suggest growing judicial recognition that the right of access should facilitate transparency, not operate as an alternative disclosure regime. As employers continue to adopt AI-enabled HR systems, automated decision-making tools, and workforce analytics, the volume of workforce data will only increase, making a proportionate and well-documented approach to DSARs increasingly important.

KEY TAKEAWAYS FOR EMPLOYERS

The recent decisions do not fundamentally alter the law governing DSARs in the UK, nor do they create a general right to refuse tactical DSARs. Employees continue to enjoy broad rights of access, and employers should continue to approach requests carefully and in accordance with the UK GDPR.

What these authorities do suggest, however, is an increasing willingness to scrutinise how organisations respond to DSARs. The focus is shifting beyond the outcome of the response to the quality of the decision-making process itself. Employers should therefore take the opportunity to review whether they

  • have documented and proportionate search methodologies;
  • distinguish clearly between requests for personal data and requests that, in substance, seek litigation disclosure;
  • engage early with individuals to clarify broad or ambiguous requests;
  • document decisions on search scope, repositories searched and any limitations applied; and
  • ensure HR, legal, privacy and litigation teams adopt a coordinated approach to responding to employee DSARs.

As recent case law demonstrates, compliance with Article 15 is not measured simply by the volume of information disclosed. Increasingly, organisations will need to be able to demonstrate that their approach to identifying personal data, scoping searches, and applying exemptions was reasonable, proportionate, and capable of withstanding judicial scrutiny.

Contacts

If you have any questions or would like more information on the issues discussed in this Insight, please contact any of the following:

Authors
Matthew Howse (London)
Louise Skinner (London)

[1] Dawson-Damer & Ors v Taylor Wessing LLP [2017] EWCA Civ 74; Ittihadieh v 5-11 Cheyne Gardens RTM Company Ltd & Ors [2017] EWCA Civ 121 (heard together with Deer v University of Oxford).

[2] Ittihadieh (as above); F.F. v Österreichische Datenschutzbehörde and CRIF GmbH (Case C-487/21); ICO, Right of access guidance.