Sunbathing or scaling? Founder tips to beat the quiet season
Summers can be slow for startups but Ava Shoraka and Yanki Kizilates are here to help founders gain momentum during thi...


Of course you ignore GDPR. Right up until you get an email “Send me all my data. Delete everything you have on me.”
Suddenly you discover their data is scattered across HubSpot, Slack, your database, email, analytics, AI tools… and 23 other systems nobody remembered existed. Sure, GDPR is not at the top of your priority list, but there are a few things you can do right now, and someone to have on speed dial, for when you inevitably get a GDPR data deletion request.
Meet Laura Brentnall from True North Data Governance who helps startups avoid the GDPR panic.
👉 Know where your data is
👉 Have the right policies and retention rules
👉 Make sure your privacy notice reflects what you actually do
👉 Have standard responses ready
👉 Review it all annually
And important advice: Don’t have difficult employee conversations on Slack or email, PICK UP THE PHONE. Because that Slack message, email or Teams chat may one day appear in a Data Subject Access Request.
GDPR doesn’t need to be scary. But discovering how your company handles data after the angry customer email arrives probably isn’t the best time to start.
The DSAR That Changes Your Day: Why Growing Businesses Need to Think About Information Governance Early
It’s a normal Friday afternoon. You’re focused on customers, recruitment, product development, cash flow and all the other priorities that come with running a growing business. Then an email arrives that immediately moves to the top of your to-do list.
An employee has submitted a Data Subject Access Request (DSAR).
As you begin reading, you realise it is more than a straightforward request for information. The employee is asking for:
To make matters more challenging, they remain employed by the business.
For many founders and business owners, this is the moment where uncertainty begins. What information are you expected to provide? Where is that information stored? Can you delete data relating to a current employee? What happens if some of the information sits within AI tools or systems that have never previously been considered as part of a DSAR process?
These are increasingly common questions, particularly for businesses experiencing rapid growth.
Where Does the Data Actually Exist?
Most organisations can quickly identify obvious sources of employee information.
The HR system, payroll records and personnel files are usually readily accessible.
However, employee data rarely exists in just one place. Depending on the individual’s role and length of service, relevant information may also be found within
The challenge is not necessarily that the information cannot be found. The challenge is knowing where to look and ensuring that searches are undertaken in a structured and defensible manner.
For businesses without a clear understanding of their information landscape, responding to a DSAR can quickly become a significant exercise.
Understanding Multiple Information Rights Requests
A common misconception is that if an individual requests deletion of their data, the organisation must immediately delete everything it holds.
In reality, information rights need to be assessed individually and within the context of the organisation’s legal obligations.
Whilst employees have rights under UK data protection legislation, employers often have legitimate reasons and legal obligations that require certain information to be retained and processed.
For example, organisations may need employee information for
Similarly, a request to restrict processing does not automatically prevent all processing activities from continuing.
Each request requires careful consideration to determine what information can be restricted, what information must continue to be processed, and what information can or cannot be erased.
This is where having established procedures becomes invaluable.
The Growing Impact of AI
Adding another layer of complexity is the increasing use of artificial intelligence within the workplace.
Many organisations now use AI-enabled tools to:
As awareness of AI grows, individuals are becoming more likely to ask whether their information has been processed through AI tools and whether AI-generated outputs containing their personal data exist.
Businesses therefore need to understand:
Organisations that have not documented their use of AI may find it difficult to answer these questions confidently when a DSAR is received.
What Does a Reasonable and Proportionate Search Look Like?
Another area that often causes concern is determining how far an organisation must go when conducting searches.
Contrary to popular belief, organisations are not necessarily expected to search every possible location regardless of cost, effort or likelihood of relevance. Think of their request as a wish list when thinking about whether the request (likely generated by AI) is reasonable and
The concept of reasonable and proportionate searches recognises that organisations must take a sensible and risk-based approach.
Factors that may influence this assessment include:
The key is being able to explain and justify the approach taken.
A documented search methodology is often far more valuable than an attempt to search every conceivable source without a clear rationale.
Preparation is Better Than Panic
For many businesses, the first DSAR is a wake-up call.
It highlights gaps in data retention, uncertainty around AI usage, incomplete data inventories and a lack of documented processes.
Organisations that respond most effectively are rarely those with the most sophisticated technology. They are the organisations that understand their information, maintain appropriate retention practices and have established governance frameworks that support compliance.
When those foundations are in place, a DSAR becomes a manageable process rather than a business disruption.
Exclusive Offer for SeedLegals Customers
At TNDGC Governance Consulting, we help start-ups, scale-ups and growing businesses build practical information governance frameworks that support growth while meeting regulatory obligations.
Whether you need support with:
SeedLegals customers receive a 15% discount on all retained consultancy services as well as a free 30 minute consultation.
This post was contributed by Laura Brentnall from True North Data Governance – reach out to her for all your GDPR questions.





