GDPR for HR Coffee Break | September 2026
Published on 14 September 2026
Personal device disclosure obligations, managing DSAR requests, systemic compliance issues
At a glance
A High Court ruling confirms that personal devices used for work cannot automatically be shielded from disclosure on privacy grounds, with lessons for organisations in the context of data subject access requests.
A representative action against a political party shows how a single systemic DSAR failure can rapidly escalate into large-scale litigation, putting every employer on notice.
ICO enforcement action against the Metropolitan Police Service is a timely reminder that data breaches are rarely isolated: they typically reflect deeper cultural and organisational failings relevant to all employers.
Personal mobile phones - disclosure obligations
A High Court decision in June 2026 confirms two important points: that directors and employees using personal devices for company business cannot resist forensic disclosure of those devices on privacy grounds alone, and that deleted messages remain within scope if recoverable. The judgment has immediate implications for litigation disclosure practice.
Although it does not address data subject access requests (DSARs), it lends support to the view that personal data held on personal devices is potentially accessible and retrievable in a DSAR context. It is the latter point that is the focus of this article.
In Lloyds Developments Ltd v Accor HotelServices UK Ltd & Ors (2026), Lloyds Developments Ltd (in administration) claimed in excess of £180 million against Accor arising from a hotel development dispute. The directors of Lloyds had used personal mobile phones for relevant business communications. Despite repeated court orders requiring delivery of those devices to an independent reviewer, the directors persistently failed to comply. The court rejected the directors' privacy and proportionality arguments and ordered them to hand over the devices to an independent reviewer.
DSAR implications
Although the court was not considering DSARs, the principles established in this judgment can usefully be applied to a DSAR context based on general UK GDPR principles.
- Personal devices are within DSAR scope. If business-related personal data is processed on a personal device, it is capable of falling within a DSAR response regardless of whether the device is company-owned. Similarly, mixing personal and business data on a device does not make the business data inaccessible: it simply requires a proportionate process to separate the two.
- Deleted data cannot automatically be excluded from a DSAR response. Given that forensic recovery is at least possible, organisations should consider whether reasonable and proportionate steps to retrieve it are required, depending on the circumstances.
- Retention policies must explicitly address personal devices to avoid both litigation disclosure failures and DSAR non-compliance.
- Bring-your-own-device (BYOD) policies should be updated to address both litigation disclosure and DSAR obligations in respect of business communications on personal devices.
- Disclosure exercises carried out under the control of the device holder will not satisfy the court in litigation. Similar principles of independence and rigour are good practice in a DSAR context. However, depending on the individual DSAR context, the proportionality argument may be helpful to justify a device holder carrying out their own review.
- Promptly notify relevant individuals who control personal devices which contain (or are reasonably expected to contain) personal data in scope of the DSAR to ensure all relevant communications on personal devices are preserved.
When one data complaint becomes many: a GDPR representative action and what it means for employers
For employers who process large volumes of personal data about employees, former employees, and job applicants, a High Court ruling in June 2026 provides a significant compliance warning about the importance of properly responding to each and every DSAR.
In the month before the July 2024 general election, campaign group the Good Law Project Ltd (GLP) created an online tool allowing members of the public to send data protection notices to five major political parties. Over 11,600 individuals used the tool, of whom 1,746 sent a notice to Reform UK. Each notice exercised rights under UK GDPR and comprised a DSAR, an objection to processing, and a written notice requiring the party to cease processing special category personal data. Reform failed to respond to any notice within the statutory one-month deadline.
In response to a pre-action letter from GLP in October 2024, Reform sent a blind-copied (BCC) email response to the relevant individuals stating it held no records of them beyond the original notice and invoking an electoral roll exemption. GLP wrote twice more explaining why that response was inadequate but received no reply. Proceedings were issued in March 2025 on behalf of 51 individuals, seeking a court order to enforce their data subject rights and compensation for non-material damage (such as distress) suffered as a result of Reform's failures.
An ulterior motive does not in itself render a claim abusive
In June 2026, the High Court rejected Reform's application to strike out the claim, allowing the matter to proceed to a full trial. Reform had argued that the claim was politically motivated and the low value of the claims was an abuse of process. However, the High Court held that the critical question is whether the claim has a legitimate legal basis: as the individuals had received no adequate response to their DSARs, they were entitled to appropriate relief, regardless of the claimants' wider motivations.
Practical points for employers
- One systemic failure creates exposure at scale. A flawed DSAR process applied consistently across a workforce can be aggregated into a single representative claim. Advocacy groups, campaign organisations, or trade unions could use this model against employers.
- Non-material damage does not require financial loss. Distress, worry, and uncertainty caused by a late or inadequate response can found a compensation claim under Article 82 UK GDPR: employment disputes create precisely this kind of anxiety.
- The one-month deadline is non-negotiable. Missing it is itself a breach capable of grounding a claim. If more time is needed, notify the data subject with reasons within the first month.
- Templated or bulk responses will not suffice. Each DSAR requires an individualised, substantive response. Redundancy exercises or disciplinary processes are common examples where multiple requests may arrive in quick succession.
- Audit your DSAR process now. Review response times, scope of searches, exemption handling, and communication standards before a representative action is brought, not after.
- Engage with pre-action correspondence and complaints promptly. Reform's failure to reply to GLP's pre-action and follow-up letters was noted by the court. This obligation is reinforced under the Data (Use and Access) Act 2025, which introduces a new statutory requirement for controllers to establish and operate an internal complaints-handling process. Employers should ensure that data protection complaints, including those relating to DSARs, are dealt with through a documented process and receive a substantive response, as failure to do so will increasingly carry both regulatory and litigation risk.
When data protection failures reflect systemic weaknesses
The Metropolitan Police Service has again been the subject of Information Commissioner's Office (ICO) scrutiny, resulting in a reprimand and enforcement notice being issued (July 2026). The findings carry important lessons for all employers who handle personal data, which, in practice, means every organisation.
The case involved two separate data protection incidents that occurred in 2024. In the first, sensitive personal information (including a victim's new address, phone number, and witnesses' contact details) was accidentally included in unredacted legal documents served on a suspect in a Stalking Protection Order case. The suspect then used this information to contact the victim. In the second, an officer sent an email to 18 people connected to the Westminster "honeytrap" investigation using the "To" field rather than "BCC", exposing all recipients' email addresses to one another. ICO investigators found that these were not isolated mistakes, but reflected systemic weaknesses in the force's policies, procedures, and data protection assurance arrangements. This reflects a familiar pattern: data protection failures rarely occur in isolation and are often symptomatic of a culture in which safeguards are assumed rather than verified.
Actions for employers
- Consider, apply and check appropriate redactions before sharing sensitive information: In this case, serving legal documents without first removing sensitive details (such as the victim's address and witness contact information) had the potential to directly enable the very harm the police were trying to prevent. Always verify that documents are properly redacted before they are shared, whether that be day-to-day comms on sensitive matters or a response to a DSAR containing redacted information.
- Use the right tools for bulk communications: Putting recipients in the "To" field instead of "BCC" is a simple but serious mistake. Organisations must use appropriate technical controls for bulk or sensitive emails, and should consider system-level safeguards that make it harder for staff to make this error in the first place.
- Training must be monitored, not just mandated: Having a training policy means nothing if staff are not completing it. One police officer had not done data protection training in over four years. Organisations need to actively track completion, enforce deadlines, and check that training is actually changing behaviour, not just ticking a box.
- Look beyond the individual mistake: Both incidents were symptoms of deeper, organisation-wide weaknesses in data handling, not one-off human errors. When a breach occurs, ask why the conditions allowed it to happen, and audit your policies, procedures and compliance checks accordingly.
The overarching lesson is that robust compliance requires active monitoring, the right technology, and genuine accountability at every level.