DSARs and Email: How to Search Employee Inboxes Compliantly
Why email is the biggest DSAR challenge, the legal basis for searching employee inboxes, keyword and date filtering strategies, redacting third-party data, and tools for large-scale inbox searches.
Last updated: 2026-07-19
Email Is the Hardest Part of Any DSAR
Ask anyone who has processed a DSAR for an organization with more than a handful of employees, and they will tell you the same thing: email is where the real pain is. CRM records are structured. HR systems have search functions. Even paper files are at least filed somewhere. But email is a sprawling, unstructured mass of conversations, forwarded threads, attachments, and one-line replies that contain personal data in unpredictable places.
Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy regulations are complex and change frequently. You should consult a qualified attorney for guidance specific to your business. The information here is based on the GDPR (in particular Articles 12 and 15), the UK GDPR / Data Protection Act 2018, and the CCPA, as of the date of publication.
The personal data of customers, employees, partners, and other individuals is woven through email threads across the organization. A single data subject's information might appear in dozens of employees' inboxes, in contexts ranging from sales conversations to internal complaints to casual mentions in a forwarded joke. Locating all of it, reviewing it, redacting third-party information, and delivering it within the statutory deadline is the single most labor-intensive part of DSAR compliance.
This guide covers the practical challenges of searching email for DSAR purposes, the legal framework for accessing employee inboxes, and the techniques and tools that make the process manageable.
Why Email Is Different
Volume
The average office worker sends and receives over 100 emails per day. For an organization with 50 employees, that is roughly 5,000 emails per day, 25,000 per week, over a million per year. A DSAR that covers multiple years of correspondence requires searching through an enormous volume of data.
Lack of Structure
Unlike a database, email has no schema. Personal data does not sit in labeled fields. It appears in subject lines, message bodies, signatures, forwarded threads, inline images, and attachments of every format. A name might appear in a greeting, a complaint, a meeting request, or a CC field. Automated search tools catch many occurrences, but not all.
Distributed Storage
In most organizations, email data about a specific individual is not in one place. It is spread across every employee inbox that ever corresponded with or about that person. A DSAR about a customer might require searching the inboxes of sales, support, billing, legal, and management staff — plus anyone who was CC'd on a relevant thread.
Thread Complexity
Email threads contain data about multiple people. A thread between a sales rep and a customer might also mention the customer's colleague, a competitor, and an internal manager. Every person named in the thread has privacy rights, and the data subject's right to receive the email does not override other people's right to have their information protected.
Legal Basis for Searching Employee Inboxes
Before you start searching employees' work email accounts, you need a clear legal basis for doing so. Employees have their own privacy rights, and accessing their inboxes — even for legitimate compliance purposes — requires justification.
Employer Access to Work Email
Under UK and EU data protection law, an employer generally has a legitimate interest in accessing work email accounts for business purposes, including legal compliance. The key considerations are:
- Purpose limitation — the search should be limited to what is necessary to respond to the DSAR. Browsing through employee emails for unrelated purposes is not justified.
- Proportionality — the scope of the search should be proportionate to the request. Searching every inbox in the organization when the data subject only interacted with two departments is not proportionate.
- Transparency — employees should be aware that their work email accounts may be accessed for compliance purposes. This should be covered in your employee privacy notice and acceptable use policy.
- Data protection impact assessment (DPIA) — for large-scale or sensitive inbox searches, a DPIA may be warranted, particularly if the search involves sensitive personal data or a large number of employees.
What Employees Should Know
Your employee privacy notice should state clearly that:
- Work email accounts are provided for business purposes
- The organization may access email accounts for legitimate business and legal compliance reasons, including responding to DSARs
- Searches will be limited to what is necessary for the stated purpose
- Personal emails sent from work accounts may be encountered during searches, and how such emails will be handled
If your privacy notice does not cover this, update it before conducting large-scale inbox searches. Employees discovering that their emails were searched without prior notice is a data protection complaint waiting to happen.
Search Strategy: Finding the Right Emails
A good search strategy balances thoroughness with efficiency. You need to find all relevant personal data without drowning in irrelevant results.
Step 1: Define Your Search Scope
Before running any searches, determine:
- Which employee accounts to search — identify everyone who is likely to have corresponded with or about the data subject. Start with obvious contacts (account managers, support staff, HR if the data subject is an employee) and expand if initial results suggest broader correspondence.
- Date range — if the data subject specified a time period, use it. If not, consider the full period of your relationship with the individual. Under GDPR and UK GDPR, there is no time limit on the right of access — if you hold the data, it is in scope regardless of age.
- Email platforms — confirm which email system or systems you are searching. If you migrated from one platform to another, archived emails on the old system may also be in scope.
Step 2: Build Your Search Terms
Effective email search for DSAR purposes requires multiple search iterations using different terms:
Primary identifiers:
- Full name (and any variations — "Robert Smith," "Bob Smith," "R. Smith")
- Email addresses (all known addresses, including personal addresses if used in correspondence)
- Phone numbers
- Account numbers, customer IDs, or other reference numbers
- Company name (if the data subject is a business contact)
Secondary identifiers:
- Postal address or partial address
- Job title (for employment-related searches)
- Nicknames or shortened names used in informal correspondence
- Misspellings of the name (common variants)
Step 3: Run Iterative Searches
Do not run a single search and call it done. Run multiple passes:
- Broad search — start with the data subject's primary email address and full name. This catches the majority of relevant emails.
- Variant search — search for name variations, nicknames, and alternative email addresses.
- Contextual search — search for identifiers like account numbers or reference numbers that may appear in emails where the data subject's name is not mentioned.
- Attachment search — if your search tool supports it, search within attachments for the data subject's information.
Step 4: Filter and Refine
Review initial results and filter out false positives:
- A search for "John Smith" will return results for every John Smith, not just the data subject. You need to distinguish between them.
- Common names generate massive result sets. Combine name searches with date ranges, specific correspondent addresses, or contextual keywords to narrow results.
- Automated emails (newsletters, system notifications, marketing blasts) may contain the data subject's name or email address but may be duplicative. Decide how to handle bulk automated communications — include representative samples rather than hundreds of identical notifications.
Redacting Third-Party Information
Email threads almost always contain personal data about people other than the data subject. The obligation to provide the data subject's personal data does not extend to disclosing other people's personal data.
What to Redact
- Names and contact details of other individuals mentioned in emails (other customers, colleagues, third-party contacts)
- Personal opinions expressed by identifiable individuals about other identifiable individuals
- Sensitive personal data of third parties (health information, financial details)
- Information that would identify a confidential source (in employment contexts, whistleblower information)
What You Probably Do Not Need to Redact
- Names of your own staff who dealt with the data subject in a professional capacity — the ICO has confirmed this is generally reasonable to disclose
- Information the data subject already knows — if the email was sent to them, they already have it
- Business information that is not personal data (pricing, product specifications, policy terms)
Practical Redaction Techniques
- PDF redaction — convert emails to PDF and use redaction tools (Adobe Acrobat, for example) to black out third-party information. Make sure you use actual redaction, not just black boxes overlaid on text — the underlying text must be removed, not just hidden.
- Copy and redact — copy the email content into a document and manually remove third-party data before including it in the response.
- Automated redaction tools — some eDiscovery and DSAR tools offer automated redaction based on pattern matching (names, email addresses, phone numbers). These can speed up the process but require manual review to catch false positives and missed items.
For a comprehensive guide to redaction, see our article on third-party data in DSARs.
Tools for Large-Scale Email Search
For organizations dealing with regular DSAR volume or large email archives, manual inbox-by-inbox searching is not sustainable. Several categories of tools can help.
Platform-Native Tools
- Google Vault — the eDiscovery tool built into Google Workspace (Business Plus and above). Allows searching across all Gmail accounts by keyword, sender, recipient, and date range. See our full guide on DSARs in Google Workspace.
- Microsoft Purview (formerly Compliance Center) — the eDiscovery and compliance tool in Microsoft 365. Supports content search across all Exchange Online mailboxes. See our guide on DSARs in SharePoint and Microsoft 365.
eDiscovery Tools
eDiscovery platforms like Relativity, Nuix, and Logikcull are designed for large-scale document and email review. They offer advanced search, deduplication, review workflows, and redaction tools. They are powerful but typically priced for legal teams and large organizations.
DSAR-Specific Software
Dedicated DSAR management tools (such as OneTrust, BigID, or Securiti) can integrate with email platforms to automate search and collection. They often include workflow management, automated redaction, and deadline tracking features tailored to DSAR compliance. See our DSAR software comparison for a breakdown.
Common Mistakes
Searching too few accounts. The data subject's personal data is not limited to the inbox of the person they corresponded with directly. CC'd, forwarded, and internally discussed emails may contain their information across the organization.
Relying on a single search term. Names are spelled differently, people use nicknames, and email addresses change. A single-term search will miss relevant data.
Failing to search attachments. Personal data in spreadsheets, PDFs, and Word documents attached to emails is in scope. If your search tool only searches email body text and subject lines, you are missing data.
Over-redacting. Redacting entire emails because they mention a third party, rather than redacting just the third-party information, is a common error and can lead to complaints that the response is incomplete.
Not documenting the search. If a data subject challenges your response or complains to the regulator, you need to demonstrate what you searched, how, and why. Record your search terms, the accounts searched, date ranges, and the number of results reviewed.
Ignoring archived and deleted email. Emails in archive folders, backup systems, and trash (if not yet permanently deleted) are in scope. "We only searched the active inbox" is not sufficient if the data exists elsewhere in your systems.
Building a Repeatable Email Search Process
If you handle DSARs regularly, formalize your email search process:
- Maintain a search checklist — a list of every email system and account type that needs to be searched, with instructions for each.
- Standardize search terms — create a template for building search queries based on data subject identifiers.
- Assign reviewers — designate people trained in identifying personal data and applying redaction correctly.
- Set review benchmarks — track how long email review takes per DSAR and use this to plan resources and manage deadline expectations.
- Document everything — keep records of searches, results, review decisions, and redaction rationale for every request.
For the full end-to-end DSAR process including intake, verification, and response, see our DSAR workflow guide.
References
- GDPR Article 15: Right of access by the data subject. GDPR Article 15
- UK GDPR: ICO guidance on the right of access. ICO right of access guidance
- ICO Employment Practices Code: Guidance on monitoring at work, including email. ICO employment practices
Last reviewed: July 2026. Privacy laws and email platform capabilities change frequently. Verify all guidance against the current regulatory framework and your email platform's documentation. Consult qualified legal counsel before making compliance decisions for your business.
Related Guides
- DSARs in SharePoint and Microsoft 365 — the Microsoft email and document search process
- DSARs in Google Workspace — Google-specific tools and process
- Third-Party Data in DSARs — when and how to redact
Get Your Email Search Process Right
Our DSAR Compliance Guide includes email search checklists, redaction templates, and process documentation designed for organizations that need a repeatable, defensible approach to handling personal data in email.