Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Internal Communications
Governance, Ownership & Risk

Internal Communications

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Governance, Ownership & Risk

Internal communications are messages, notes, call records, and other exchanges created within an organisation. When they contain personal data, they may become part of a DSAR response. The key issue is not where the content sits, but whether it relates to an identifiable person and is covered by an exemption.

What Internal Communications Means in DSAR Handling

Internal communications are often ordinary operational records, but in a DSAR context they can become regulated material if they mention, identify, or profile a living individual. The practical test is whether the content is personal data and whether an exemption or restriction applies.

Why Internal Communications Can Enter a DSAR Scope

The label “internal” does not keep a message out of scope. Emails, chat threads, meeting notes, call records, and draft comments may all need review if they relate to an identifiable person. The key question is whether the content is about that person, not whether it was written for external publication.

This is why DSAR review teams usually search by people, projects, incidents, and decisions rather than by folder name alone. Internal exchanges can contain direct identifiers, indirect identifiers, opinions, performance commentary, health information, or other details that connect the record to an individual.

For a broader privacy lens, the same issue appears in the GDPR’s personal data and security principles, which frame the need to identify, classify, and protect records that can be linked to a person. EU General Data Protection Regulation (GDPR)

How Exemptions and Redactions Change the Outcome

Once an internal communication is identified as potentially responsive, the next step is not automatic disclosure. Parts may be withheld, redacted, or excluded where an exemption applies, such as legal privilege, management planning, or third-party rights, depending on the jurisdiction and the facts.

The important distinction is between the record being in scope and the record being fully disclosable. A document can be relevant to a DSAR, yet still contain passages that must be removed before release. That is why review quality matters as much as search completeness.

Operationally, this means teams need traceable review decisions, consistent redaction logic, and enough context to explain why one communication was disclosed in full while another was partially withheld.

Common Handling Errors with Internal Communications

One frequent mistake is treating internal language as inherently exempt because it was never meant for external eyes. Another is over-collecting and disclosing entire threads when only a small portion relates to the requester. Both errors create risk, either by missing responsive material or by exposing information that should have been protected.

Internal communications are also easy to misread when copied into wider threads or attached to case files. A short comment can become a significant disclosure issue if it includes opinions about conduct, health, discipline, or a complaint involving another employee or customer.

Good DSAR handling therefore depends on careful scope control, contextual review, and clear separation between relevance, exemption, and disclosure.

Risk and Threat Considerations

Internal communications create privacy and governance risk because they often contain the most candid version of an organisation’s view of a person. If search, review, or redaction is weak, the organisation can either fail to disclose material personal data or release sensitive internal commentary that should have been protected.

Failure mechanism: Teams rely on metadata, folder location, or sender intent instead of reviewing the substance of the communication, so personal data is missed or incorrectly released.

Impact: The organisation can produce an incomplete DSAR response, expose third-party information, or lose trust in its privacy handling process.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt. 5 — Principles Relating to Processing of Personal DataInternal communications become DSAR material when they contain identifiable personal data.
Art. 15 — Right of Access by the Data SubjectDSARs arise from the access right, which can reach internal records about the requester.
Art. 25 — Data Protection by Design and by DefaultReview workflows for internal communications must be designed to find and protect personal data reliably.
Recommendation — Apply Article 5 principles to classify internal communications, minimise unnecessary disclosure, and handle personal data consistently. Use Article 15 to locate and disclose internal communications that contain the requester’s personal data. Build redaction and review workflows that default to limiting exposure in internal communications.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingDSAR review depends on analysing internal records and documenting disclosure decisions.
AC-6 — Least PrivilegeOnly authorised reviewers should access internal communications during DSAR processing.
Recommendation — Review internal communication records and keep evidence of disclosure and redaction decisions. Restrict DSAR review access to the smallest set of staff needed to process the request.
ISO/IEC 27001:2022A.5.12 — Classification of informationInternal communications need classification so personal data and sensitive content are handled correctly.
A.5.34 — Privacy and protection of PIIThe term is directly about communications that may contain personally identifiable information.
Recommendation — Classify internal communications to guide retention, disclosure, and redaction decisions. Apply privacy controls to internal communications that contain PII and DSAR-relevant content.

Practitioner Guidance

What to watch for: Treat internal communications as potentially responsive whenever they mention a named person, an identifiable role, a complaint, a performance issue, or a decision that affects someone’s rights or interests. That is usually the point where review should become content-based rather than location-based.

Governance implication: DSAR ownership should define who decides scope, who applies exemptions, and who signs off redactions. Without that accountability, internal communications are the records most likely to be over-disclosed, under-disclosed, or reviewed inconsistently.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org