Organisations should treat DSAR scope as broader than structured records alone. If personal data appears in emails, chat, notes, or recorded calls, those materials may need review and disclosure unless a lawful exemption applies. The practical control is to search across all systems, preserve relevant content, and train staff to avoid writing anything they would not want disclosed to the data subject.
What DSAR scope means when the data lives in messages and recordings
A DSAR is not limited to a customer database or HR system. If a request relates to a living individual, organisations usually need to search wherever that person’s personal data appears, including email threads, collaboration chat, shared documents, ticketing notes, and call recordings. The key question is whether the material contains personal data and is retrievable in a reasonable search.
That broader scope matters because internal communications often contain more context than formal records. A single message chain may identify the person, describe an incident, or include opinions about them, while a call recording may capture their voice, preferences, or other biographical details. The practical challenge is not just locating the content, but deciding whether any lawful exemption or third-party redaction applies before disclosure.
How to search, review, and preserve DSAR material
The operational model should start with a defensible search plan. Search terms, custodians, time windows, and system coverage should be set early so that teams do not narrow the request too quickly or miss shadow repositories such as personal inboxes, shared drives, or archived call platforms. If recordings are involved, confirm retention settings early so relevant files are not overwritten during processing.
Review should be content-led, not system-led. If a call transcript or email contains mixed personal data, teams need to separate what relates to the requester from what is exempt, out of scope, or belongs to another individual. Where possible, use structured review notes that record why a passage was disclosed, withheld, or redacted, because that audit trail is often as important as the final response.
For recordings, the control issue is often volume and sensitivity. A transcript may be faster to review than audio, but the recording itself can still matter where tone, voice, identity, or exact wording is relevant. Organisations should preserve the original file, work from a controlled copy, and ensure the review process does not alter the evidence trail.
Internal communications create disclosure and quality risks
Emails, chat, and recorded calls often contain personal data incidentally rather than by design, which makes them easy to overlook and hard to classify consistently. That is why the GDPR is relevant here, especially where access, retention, disclosure, and data minimisation decisions need to be justified under a documented process.
There is also a practical quality problem: teams sometimes assume that informal communication is outside DSAR scope, then discover too late that it contains statements about the requester, colleagues, clients, or witnesses. The most common failure is incomplete searching, followed by over-redaction or under-redaction because reviewers did not have enough context to assess the exemptions correctly.
Failure mechanism: A narrow search, poor retention control, or inconsistent review practice can leave relevant personal data undisclosed, or expose third-party information without proper redaction. Recordings add another failure mode because the source file may exist in a platform the DSAR team does not normally monitor.
Impact: The organisation can miss statutory deadlines, issue an incomplete response, or disclose data it did not mean to release. That creates legal, reputational, and operational risk, especially when staff rely on ad hoc judgment instead of a repeatable review method.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
GDPR provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art. 5 — Principles relating to processing of personal data | DSAR handling depends on lawful processing, minimisation, and disclosure discipline. |
| Art. 12 — Transparent information, communication and modalities for the exercise of the rights of the data subject | DSAR response handling is governed by how requests are processed and answered. | |
| Art. 15 — Right of access by the data subject | The question is directly about access requests for personal data across communications and recordings. | |
| Recommendation — Apply Art. 5 principles when searching, reviewing, and redacting requester-related content. Use Art. 12 to keep DSAR handling timely, clear, and procedurally consistent. Use Art. 15 to drive a full search across systems that may hold the requester’s personal data. | ||
Practitioner Guidance
What to prioritise: Start with system discovery and retention status before review. If a platform may hold emails, chat, attachments, or recordings, confirm whether the requester’s data is searchable there and whether the content can still be preserved in a defensible way.
What to verify: Make sure reviewers can explain why each item was included, withheld, or redacted. A good DSAR file should show search terms, custodians, system coverage, exemption reasoning, and any decision to exclude third-party material.
Common mistake: Treating “informal” communications as out of scope. In practice, the more conversational the channel, the more likely it is to contain personal data that must be assessed rather than assumed away.
Practitioner takeaway: The safest DSAR process is broad at search time, disciplined at review time, and conservative about retention so that internal communications and call recordings can be handled consistently when they contain personal data.