What is the Role of a Data Protection Officer in Employee Data and DSARs?
For HR teams, the Role of a DPO matters because employee personal data rarely sits only within the HR system. It may be spread across email, Teams, payroll systems, performance records, recruitment platforms and communications between managers.
In our experience, organisations that manage employee data effectively have a clearly defined DPO function.
Do we need a DPO to manage employee data?
Not every organisation is legally required to appoint a DPO but where organisations choose to appoint one they musts till follow the requirements under Articles 37-39 of the GDPR.
However, every organisation processing employee personal data still has obligations under UK data protection law. Where there is no suitable internal expertise, an outsourced DPO can provide ongoing oversight and advice without the cost of employing a full-time DPO.
The DPO does not replace HR or make employment decisions. Their role is to help ensure that the organisation understands the data protection consequences of those decisions and that appropriate processes are in place.
A common issue is that the Role of a DPO comes in late. This often follows a new HR system, monitoring process or AI tool. It is easier to identify and resolve data protection issues during the design stage. Addressing issues in the design stage is easier than after employee data is processed.
Can a DPO help with an employee DSAR?
Employee Data Subject Access Requests can become particularly difficult when they arise during a grievance, disciplinary process or dismissal.
The ICO makes clear that workers can make a DSAR verbally or in writing and can send it to any part of an organisation, so HR managers and other staff need to know how to recognise one and where it should be escalated. Appointing a DPO can give organisations a dedicated individual and inbox for DSARs to go into.
If employee information has been retained unnecessarily, duplicated across different systems or discussed extensively through informal communication channels, the problem becomes much harder once the one-month response period has started. The ICO confirms that controllers must respond to SARs and that the normal response period is one calendar month.
What problems can a DPO help prevent?
A DPO can help identify data protection risks before they become compliance problems. This may include advising on new HR software and technologies, carrying out or supporting DPIAs, ensuring the organisation’s RoPA accurately reflects its processing activities, and reviewing retention periods and secure deletion practices.
A common issue we see is when the way employee data is actually handled starts to move away from what the organisation’s policies say. For example, HR teams may begin using new communication channels, introduce new systems or retain information for longer than originally intended, while the employee privacy notice and internal procedures remain unchanged. Changes in the law, including the Data (Use and Access) Act 2025, can also mean existing documentation needs to be reviewed.
A DPO can help identify these gaps early, reducing the risk of them becoming an employee complaint, a difficult DSAR or an issue raised with the ICO.
Need ongoing DPO support?
Our legal DPO as a Service provides organisations with ongoing, solicitor-led data protection support without the cost of recruiting a full-time DPO.
Learn more about our DPO as a Service →
Why does this matter as employment law changes?
From 1 January 2027, ordinary unfair dismissal protection will generally arise after six months’ service rather than two years, and the existing limit on unfair dismissal compensatory awards will be removed.
We look at those reforms separately in our guidance on employment law changes and the potential impact on Data Subject Access Requests.
The important point for organisations is not that every employment dispute will result in a DSAR. It is that more employees will acquire ordinary unfair dismissal protection sooner, and organisations should be capable of dealing with an employee data request properly if one accompanies a dispute through correct policies and procedures.
That makes good HR data governance increasingly important.
When should HR involve the DPO?
The best time is before an employee data issue becomes contentious.
HR does not need to involve the DPO in every employment decision. But there should be a clear point of escalation where the organisation is dealing with a complex DSAR, employee monitoring, a new HR technology, a change in how employee information is used or a potential data breach.
In practice, we often find is, early involvement usually gives the organisation more options and more time to deal with the issue properly.
Can the DPO role be outsourced?
Yes, an organisation can appoint an external DPO rather than employing one internally.
For organisations without sufficient internal data protection resource, this can provide continuity between HR, legal, compliance and senior management.
At WDPS, our DPO as a Service for UK Organisations provides ongoing support with data protection governance, employee DSARs, DPIAs, policies, breaches and ICO matters.
One of the practical advantages of an ongoing DPO relationship is context. If a difficult employee DSAR arrives, the DPO already understands the organisation, its systems and its procedures rather than starting from scratch while the response deadline is already running.
Written by Clara Westbrook, solicitor and founder.
Speak to our team
Explore More Data Protection & Privacy Services
Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]





