GetMySAR

Employers

Subject Access Request to an Employer

Your employer holds a great deal more about you than your personnel file, and you can ask for it — the emails managers sent about you, the grievance and disciplinary papers, the notes behind a decision. You do not need a reason and you do not need permission. What this page is mostly about is the three things that trip people up: which organisation actually holds what you want, what can lawfully be kept back, and why none of this pauses an employment tribunal deadline.

GetMySAR is an independent service. We are not Acas, not the Labour Relations Agency, not a law firm and not connected to any employer. Nothing here is legal advice. Every route on this page is one you can use yourself, and asking your employer for your own records is free.

Which organisation do I send it to?

Usually your employer, and usually just the one request. But two common arrangements split the answer, and they split it in opposite directions — so it is worth thirty seconds before you send anything.

1. The employer itself — the personnel file, emails and everything HR holds

Your current or former employer is the data controller for your employment records, and that stays true even if it has handed the work to somebody else. Where an employer has outsourced HR or payroll, the ICO’s position is that the employer is still the controller and the outsourcing company is only a processor — and that the employer must be able to deal with your request “irrespective of whether the request is sent to you or the processor”. So address it to the employer. A payroll bureau is not a second organisation you have to chase.

2. Occupational health — usually a separate request to a separate organisation

This is the one that surprises people, and it is the exact opposite of payroll. The ICO says that where an occupational health provider is acting in its professional capacity with its own medical obligations, it is likely to be the controller rather than a processor — and that it must therefore answer subject access requests itself. Your employer is the controller only for what it received. So the report your manager read comes from your employer; the underlying file, the notes and anything the clinician did not pass on comes from the provider, and that is a second request. Workplace pension and health insurance schemes are run by third-party organisations too.

3. Proof of where you worked and when — HMRC, not your employer

If what you need is evidence of your employment history rather than the contents of a file, do not start with a subject access request. HMRC publishes an employment history service and points people to it for a compensation claim, a loan application or a work visa renewal. The current and past 5 years’ employment is in your personal tax account and the HMRC app, and there is a paper form for a record from any year. That matters most when the employer no longer exists — a dissolved company has no one left to answer a request, and HMRC still has the record. More on making a subject access request to HMRC.

Making a subject access request as an employee or ex-employee

The right is the same whether you still work there or left ten years ago, and there is no special form. The ICO tells employers that a request can be made verbally or in writing, to any part of the organisation, without naming a particular person, and without using the words “subject access request” or citing any legislation. Its own examples of a valid request include “Please send me my HR file” and “Can I have a copy of the emails sent by my manager to HR regarding my verbal warning?”.

The ICO’s list of what an employer is likely to be keeping, from its guidance on employment records, is a good checklist to ask against: personnel files, sickness and injury records, disciplinary and grievance records, training records, appraisal or performance review records, payroll information, pension information, interview notes, emails, references, and equality and diversity information.

Ask for the messages, not just the file. This is where requests are most often answered too narrowly. The ICO tells employers that if they use platforms such as Facebook, WhatsApp, Twitter and chat channels on Microsoft Teams for business purposes, they are the controller for what is on them and “must search these platforms for any personal information if it falls within scope”. CCTV of you is your personal data too — where an employer’s system cannot blur other people, the ICO’s own worked example is that it should provide stills with the other identities redacted rather than refuse. An email you were copied into is not automatically all yours, but the ICO is clear that your name and email address in it are, and that a business subject does not stop the rest being about you.

Naming the systems, the people and a date range is the single most useful thing you can do. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.

A grievance, a tribunal claim and a subject access request are three separate things

They often arise from the same argument, so it is easy to assume they are stages of one process. They are not, they run on separate clocks, and only one of them gets you your records.

A grievance is how you complain. Acas describes it as a formal way for an employee to raise a problem or complaint to their employer, normally in writing, with a meeting and a right of appeal. It asks your employer to do something about a situation. It does not oblige anyone to hand over documents.

Tribunal disclosure is how documents move once a claim exists. It is ordered by the tribunal, it runs to the tribunal’s rules, and what it produces is a bundle for the case.

A subject access request is neither. It is a data-protection right you can use at any point, before a grievance, during one, after a claim is settled, or with no dispute at all.

The one thing on this page worth acting on today: none of this pauses a tribunal deadline. Acas states plainly that going through grievance, disciplinary or appeal procedures does not change your time limit, and that if those procedures take a long time you still need to notify Acas before the limit runs out. A subject access request does not change it either — and an employer has a month, extendable to three. Most claims currently have to reach Acas within three months minus one day of what happened, though a few have six, and Acas has said the limits increase to six months in October 2026. Work out your own date from Acas rather than from us, and do not wait for the records before you start the clock. In Northern Ireland it is the Labour Relations Agency you notify, not Acas, and the claim goes to an industrial tribunal or the Fair Employment Tribunal.

Acas holds records of its own about your conciliation — and they are not the same thing as your HR file, are covered by legal privilege, and are destroyed sooner than most people expect. If you want those rather than your employer’s records, that is a subject access request to Acas.

What an employer cannot use as a reason to refuse

These come from the ICO’s subject access request questions and answers for employers, which is written to tell employers what they must do. It is a better thing to quote back than anything written for employees.

A settlement agreement or NDA does not sign the right away. The ICO’s answer is that the right “cannot be overridden by a settlement or non-disclosure agreement”, and that if a settlement agreement limits it, “it is likely this part of the settlement agreement will be unenforceable under data protection legislation”. Signing one does not waive your information rights.

A live grievance, disciplinary or tribunal is not a reason either. An employer “cannot simply refuse to comply because the worker is undergoing a grievance or tribunal process” and believes the information is wanted for litigation. If it wants to hold something back it has to identify an exemption and justify it.

Nor is “we already gave it to you in the tribunal bundle”. The ICO gives four reasons, and the third is the one nobody expects: the bundle may not contain everything the employer holds about you; you may only have been allowed to view it rather than keep a copy; disclosure goes to your legal representative rather than to you, so the employer cannot assume you have it; and there may be material that was not disclosable then or did not exist yet.

Wanting the information for a claim is not, in itself, an abuse of the right. An employer can refuse a request that is manifestly unfounded or excessive, but the bar is real: in an ICO case study, a telecoms company refused a batch of requests from redundant workers it believed were coordinating on Facebook, and the ICO decided it had not demonstrated the purpose was disruption and told it to comply. The ICO’s own worked example of a request an employer may properly refuse on that ground runs the other way: offering to withdraw the request if the employer improves your financial package.

What can lawfully be held back

Some things genuinely can be withheld, and knowing which is the difference between a productive complaint and a wasted month. Four exemptions in Schedule 2, Part 4 of the Data Protection Act 2018 do most of the work in employment. They have to be applied case by case and the employer has to be able to justify each one.

References, given or received (paragraph 24). A reference given in confidence is exempt, for employment, training, volunteering, appointment to office or providing a service. The catch that surprises people is that it applies at both ends: the ICO states the exemption “applies regardless of whether you give or receive the reference”, so asking your new employer will not get it either. The lever is the word confidential. The ICO tells employers this only covers references they give in confidence and that they should say so in a privacy statement, staff handbook or policy — so it is fair to ask whether the employer actually treats references as confidential, and where it says so. Where that is unclear the ICO says to decide case by case, weighing your interest in checking the reference is accurate.

Management forecasting and planning (paragraph 22). Where disclosure would be likely to prejudice the business. The ICO’s worked example is a restructure: staff who hear redundancies are coming and ask whether they are in the selection pool can be told that the employer will neither confirm nor deny it. That is a lawful answer here, not evasion.

Negotiations with you (paragraph 23). Records of the employer’s intentions in a negotiation with you, where disclosure would prejudice it — settlement and severance discussions, in practice. This one usually expires, and that is the useful part. The ICO says it is “only likely to apply whilst the negotiations are ongoing”, and its worked example has the employer withhold during the talks and then disclose on a second request after the settlement is agreed, because it could no longer evidence any prejudice. If you were refused mid-negotiation, asking again afterwards is a real option.

Legal professional privilege (paragraph 19). Advice between the employer and its lawyers. Not everything sent to a lawyer — it has to be confidential and made for the dominant purpose of getting or giving legal advice, or for actual or likely litigation.

Other people in your records. Colleagues have rights too, so expect redactions, but an employer must still disclose what it can. The ICO offers a lever worth knowing: in a work context it says the factors include a person’s seniority and role, and that “in general, it is more likely to be reasonable to disclose information about an employee acting in a professional capacity than a private citizen”. A manager’s name blacked out of a decision about you is worth querying. Witness statements given on an assurance of confidentiality are a harder case, and whistleblowing reports are harder still, because the Public Interest Disclosure Act 1998 protects the person who made them. More on when a request can be refused or limited.

When a subject access request is the wrong tool

You want the reference itself. See paragraph 24 above. Neither the employer who wrote it nor the one who received it has to hand it over if it was given in confidence. What you can do is ask for the rest of your file and, if something in it is wrong, ask for it to be corrected — the ICO tells employers they must be as open as possible and that you have a right to challenge information you consider inaccurate or misleading, “ particularly when, as in the case of a reference, it may adversely affect them”.

You want the decision changed. A subject access request tells you what is recorded. It does not reverse a dismissal, a grievance outcome or a pay decision. Those are the grievance and appeal routes, and then a tribunal.

You want proof of employment for a third party. Employment dates and earnings go through HMRC, above. A subject access response is not a document designed for an employer, lender or embassy to accept.

The records are about someone who has died. The right of access applies to living people, so this is not a subject access request and our own form does not accept one. There is a route worth knowing about here: HMRC will supply the employment history of someone who has died to a person legally entitled to claim damages on behalf of their estate, for a personal injury or fatal accident claim or under the Diffuse Mesothelioma Payment Scheme. For health records, see getting medical records, which covers the Access to Health Records Act 1990 route.

You want a criminal record check. That is a DBS check, a Disclosure Scotland disclosure, an AccessNI check or an ACRO police certificate, none of which is a subject access request — see police records.

It is your NHS employment file. Your records as an NHS employee sit with the trust or board that employed you, and are handled by human resources rather than by the department that answers patient requests. That is this page’s route, not the NHS patient records one.

No employer can make you do this for them

This is the one part of the subject worth knowing even if you never make a request. Under section 184 of the Data Protection Act 2018 it is a criminal offence for someone to require you to obtain and hand over certain records about yourself in connection with recruitment, your continued employment, or a contract to provide services. It is called enforced subject access.

Three details do the work. The records covered are defined in Schedule 18 and are broader than most people assume: health records, records of convictions or cautions obtained from the police, and records of certain statutory functions — which includes the Disclosure and Barring Service and the benefits records held by the Secretary of State. A record saying that nothing is held about you counts as one too, so being asked to produce a “nothing recorded” letter is caught as well.

Second, it covers being asked, not only being ordered: section 184(5) catches a person who asks knowing, or being reckless as to whether, it would be reasonable for you to feel obliged to comply. Third, “employment” here is wide, and expressly includes work under a contract for services, apprenticeships, work experience as part of a training course and voluntary work.

An employer wanting a criminal record check has a lawful route to it — a DBS check, a Disclosure Scotland disclosure or an AccessNI check — and section 184(4) says the existence of those routes is why helping to prevent, investigate or detect crime cannot be used to justify demanding your records instead. More on enforced subject access requests, and police records covers which check an employer should be asking for.

What to expect once you have sent it

What it costs. There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies. You do not have to say why you want it, and you should not be asked to justify it.

How long they have. An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why. A long employment record is exactly the kind of thing that attracts an extension, so assume three months rather than one if you have been there twenty years.

Proving who you are. An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it. An employer that already knows perfectly well who you are has less room to ask than a stranger would.

Narrowing it down. An employer can ask you to specify what you want, and the clock pauses until you answer — but the ICO says it should only do that where the clarification is genuinely needed and it holds a large amount of information about you, and that if you decline to narrow the request it must still carry out reasonable searches. Answer quickly if you are asked.

If the answer is late or incomplete. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office. Our free subject access request response checker walks through what a complete answer should contain. Note this is a different door from the employment one: a complaint about how your request was handled goes to the ICO, while a complaint about the underlying treatment is the grievance and tribunal route.

If you have not made a request before, what a subject access request is covers what counts as your personal data, and our free letter template is wording you can send yourself at no cost.

Where this comes from

Every fact here was checked against the publishing organisation’s own page on 7 August 2026, and those pages are linked from the text above so you can read them yourself rather than take our word for it: the ICO’s subject access request questions and answers for employers, its employment records and workers’ health guidance, Acas on employment tribunal time limits and on grievance procedure, the Labour Relations Agency and nidirect for Northern Ireland, GOV.UK on employment history, and sections 184, Schedule 18 and Schedule 2 Part 4 of the Data Protection Act 2018 on legislation.gov.uk. Tribunal time limits are changing in October 2026 and the ICO’s employment guidance is under review for the Data (Use and Access) Act, so check the linked pages for anything you are about to rely on — tell us if something here is out of date.

Last checked 7 August 2026

If a subject access request is the right route

You can make one yourself, free — an email to HR naming what you want is enough, and there is no form to fill in. If you would rather not handle the wording, the sending and the chasing, GetMySAR prepares, sends and follows up your request for a fixed £20 fee. If you are thinking about a tribunal claim, notify Acas or the Labour Relations Agency within your time limit first and treat the records as a separate job — we cannot extend that deadline, and neither can your employer’s reply.