Guide · Data protection

Subject access requests and WhatsApp messages.

A subject access request arrives and someone asks the question every organisation dreads: does this cover the WhatsApp group? The short answer is that it covers work-related messages wherever they are held, including on personal phones. This is a plain summary of what an employer must disclose, what may be withheld, and what happens when the messages cannot be produced.

01

Does a subject access request cover WhatsApp messages?

Yes, where the messages are work-related and contain the requester's personal data. A subject access request under UK GDPR gives an individual the right to a copy of personal data an organisation holds about them. The right attaches to the data, not to the system it happens to sit in.

The ICO's position is that personal data held on personal devices is in scope when it is processed for the organisation's purposes. A manager discussing an employee in a work WhatsApp group is processing that employee's personal data on the employer's behalf, and the fact that it is a personal account on a personal handset does not remove it from the SAR.

What is not in scope is genuinely personal correspondence that has nothing to do with the employment. The dividing line is purpose, not location - which is precisely why a group that mixes rotas, social chat and comments about colleagues is so difficult to answer for.

02

What an employer must disclose

The obligation is to provide a copy of the requester's personal data, along with the supplementary information UK GDPR requires - the purposes of processing, the recipients, the retention period, and the individual's rights.

Three points that catch employers out:

  • Opinions count. Personal data is not only factual records. A message expressing a view about someone is their personal data, and unflattering opinions are not exempt for being unflattering.
  • The requester does not have to name a system. A request for "all my personal data" reaches the WhatsApp group whether or not the requester knows it exists.
  • The clock is one month, extendable by two further months for complex requests. Difficulty searching is not itself a reason to extend, though volume and complexity can be.

You are not required to hand over the whole chat. The duty is to disclose the requester's personal data within it, which in practice usually means extracts rather than a full export.

03

What can be withheld or redacted

A SAR is not an unlimited right of discovery, and there are legitimate grounds to withhold information.

  • Third-party data. Where disclosing the requester's data would reveal another identifiable person, you must decide whether it is reasonable to disclose without consent. That does not mean redact everything about everyone: you weigh the other person's rights against the requester's, and record the reasoning.
  • Legal professional privilege. Advice from a solicitor is exempt.
  • Management forecasting and negotiations. Narrow exemptions exist where disclosure would prejudice the business, such as an unannounced restructure.
  • Manifestly unfounded or excessive requests may be refused or charged for - but the bar is high, and "we think they are only after evidence for a tribunal" does not meet it. Motive is irrelevant to the validity of a SAR.

Redact rather than withhold wherever possible, and keep a record of what was withheld and why. If the requester complains to the ICO, that record is your answer.

04

Are WhatsApp messages legal proof in the UK?

They are admissible evidence and are relied on routinely in employment tribunals. Screenshots are accepted, though their weight depends on how credibly they can be authenticated - a full thread is stronger than an isolated screenshot, and metadata helps.

Two asymmetries are worth understanding before a dispute rather than during one.

First, the employee usually has the messages and the employer usually does not. An individual keeps their own phone; an organisation whose record lives on other people's phones cannot assemble its own side. In a tribunal that reads as the employer having no answer, not as the employer being neutral.

Second, a SAR is often the opening move in a dispute, and a poor response is itself damaging. An employer who discloses partially, late, or with unexplained gaps invites an adverse inference about what is missing - and the ICO takes a dim view separately from the tribunal.

05

What happens when the messages cannot be produced

This is the practical position most organisations are actually in, and it is worth being honest about the options because none of them is good.

You can ask staff to search their own devices and provide work-related messages. Many will cooperate. Some will not, and you cannot compel access to a personal phone - you can instruct an employee to comply with a lawful request, and enforcement against a refusal is a disciplinary matter that will look worse than the original problem. A leaver is beyond reach entirely.

You then have to answer the SAR anyway. The honest response is to disclose what you hold, explain what you have searched, and say what you could not reach. That is defensible once. It is not a position to be in twice, and an organisation that has been through it usually changes something afterwards.

The change that works is not a better search. It is that the conversations happen somewhere the organisation can search in the first place - which is a records decision taken before the request arrives, not after.

06

Reducing the exposure before a request arrives

  1. Decide where work conversations belong, and make that channel as immediate as the one people currently use. A rule alone moves nothing.
  2. Write it down. A short policy saying which channel carries what, and that personal-app messaging about colleagues, pupils or service users is not sanctioned.
  3. Give the retention schedule somewhere to apply. Personal data in an ungoverned group chat has no retention period, which is its own UK GDPR problem before any SAR arrives.
  4. Rehearse the search. Know today which systems you would search and who would do it. Most organisations discover the gap on the clock.

None of this recovers what already exists on personal devices. Nothing does.

07

Where to read the official guidance

The ICO's right of access guidance is the authority, and its employment guidance includes questions and answers written for employers. Acas covers the employment-relations side.

This page is a summary, not legal advice. A live SAR that touches a dispute is one to take advice on.

Why we publish this

ComplyChat exists because of the position in section 05. It gives work conversations a channel your organisation owns, on the record from the first message, filing into your own Microsoft 365 once your tenant is connected - so a request can be answered from your own record. There is no WhatsApp, Signal or Meta anything in the path, and we cannot see a personal phone or reach a conversation that has already happened.

How it works · Why us · Pricing · FAQ