Startups made easy. Sorted.

4 min read

Most founders don't think about GDPR until someone asks for their data

Published:  Aug 27, 2026
Laura Brentnall

Of course you ignore GDPR. Right up until you get an email “Send me all my data. Delete everything you have on me.”

Suddenly you discover their data is scattered across HubSpot, Slack, your database, email, analytics, AI tools… and 23 other systems nobody remembered existed. Sure, GDPR is not at the top of your priority list, but there are a few things you can do right now, and someone to have on speed dial, for when you inevitably get a GDPR data deletion request.

Meet Laura Brentnall from True North Data Governance who helps startups avoid the GDPR panic.
👉 Know where your data is
👉 Have the right policies and retention rules
👉 Make sure your privacy notice reflects what you actually do
👉 Have standard responses ready
👉 Review it all annually

And important advice: Don’t have difficult employee conversations on Slack or email, PICK UP THE PHONE. Because that Slack message, email or Teams chat may one day appear in a Data Subject Access Request.

GDPR doesn’t need to be scary. But discovering how your company handles data after the angry customer email arrives probably isn’t the best time to start.

The DSAR That Changes Your Day: Why Growing Businesses Need to Think About Information Governance Early

It’s a normal Friday afternoon. You’re focused on customers, recruitment, product development, cash flow and all the other priorities that come with running a growing business. Then an email arrives that immediately moves to the top of your to-do list.

An employee has submitted a Data Subject Access Request (DSAR).

As you begin reading, you realise it is more than a straightforward request for information. The employee is asking for:

  • A copy of all personal data held about them
  • Restriction of processing
  • Erasure of their personal data

To make matters more challenging, they remain employed by the business.

For many founders and business owners, this is the moment where uncertainty begins. What information are you expected to provide? Where is that information stored? Can you delete data relating to a current employee? What happens if some of the information sits within AI tools or systems that have never previously been considered as part of a DSAR process?

These are increasingly common questions, particularly for businesses experiencing rapid growth.

Where Does the Data Actually Exist?

Most organisations can quickly identify obvious sources of employee information.

The HR system, payroll records and personnel files are usually readily accessible.

However, employee data rarely exists in just one place. Depending on the individual’s role and length of service, relevant information may also be found within

  • Emails
  • Teams and Slack conversations
  • SharePoint and cloud storage platforms
  • Performance and appraisal documents
  • Training records
  • Meeting minutes
  • Project documentation
  • Expense and finance systems
  • Recruitment records
  • Occupational health records
  • Manager notes
  • Customer relationship management systems

The challenge is not necessarily that the information cannot be found. The challenge is knowing where to look and ensuring that searches are undertaken in a structured and defensible manner.

For businesses without a clear understanding of their information landscape, responding to a DSAR can quickly become a significant exercise.

Understanding Multiple Information Rights Requests

A common misconception is that if an individual requests deletion of their data, the organisation must immediately delete everything it holds.

In reality, information rights need to be assessed individually and within the context of the organisation’s legal obligations.

Whilst employees have rights under UK data protection legislation, employers often have legitimate reasons and legal obligations that require certain information to be retained and processed.

For example, organisations may need employee information for

  • Payroll administration
  • Tax and pension obligations
  • Employment law requirements
  • Health and safety compliance
  • Contract management
  • Ongoing performance and workforce management

Similarly, a request to restrict processing does not automatically prevent all processing activities from continuing.

Each request requires careful consideration to determine what information can be restricted, what information must continue to be processed, and what information can or cannot be erased.

This is where having established procedures becomes invaluable.

The Growing Impact of AI

Adding another layer of complexity is the increasing use of artificial intelligence within the workplace.

Many organisations now use AI-enabled tools to:

  • Summarise meetings
  • Draft documents
  • Produce reports
  • Analyse feedback
  • Organise information
  • Support administrative activities

As awareness of AI grows, individuals are becoming more likely to ask whether their information has been processed through AI tools and whether AI-generated outputs containing their personal data exist.

Businesses therefore need to understand:

  • Where AI is being used
  • What personal data is entering AI systems
  • What outputs are generated
  • Whether those outputs contain personal data

Organisations that have not documented their use of AI may find it difficult to answer these questions confidently when a DSAR is received.

What Does a Reasonable and Proportionate Search Look Like?

Another area that often causes concern is determining how far an organisation must go when conducting searches.

Contrary to popular belief, organisations are not necessarily expected to search every possible location regardless of cost, effort or likelihood of relevance. Think of their request as a wish list when thinking about whether the request (likely generated by AI) is reasonable and

The concept of reasonable and proportionate searches recognises that organisations must take a sensible and risk-based approach.

Factors that may influence this assessment include:

  • The scope of the request
  • The systems likely to contain relevant information
  • Accessibility of records
  • The volume of information involved
  • The likelihood of discovering additional personal data
  • The effort required to retrieve information from legacy systems

The key is being able to explain and justify the approach taken.

A documented search methodology is often far more valuable than an attempt to search every conceivable source without a clear rationale.

Preparation is Better Than Panic

For many businesses, the first DSAR is a wake-up call.

It highlights gaps in data retention, uncertainty around AI usage, incomplete data inventories and a lack of documented processes.

Organisations that respond most effectively are rarely those with the most sophisticated technology. They are the organisations that understand their information, maintain appropriate retention practices and have established governance frameworks that support compliance.

When those foundations are in place, a DSAR becomes a manageable process rather than a business disruption.

Exclusive Offer for SeedLegals Customers

At TNDGC Governance Consulting, we help start-ups, scale-ups and growing businesses build practical information governance frameworks that support growth while meeting regulatory obligations.

Whether you need support with:

  • Data Subject Access Requests (DSARs)
  • Information rights management
  • Data retention and records management
  • UK GDPR compliance
  • AI governance and assurance
  • Staff awareness and training

SeedLegals customers receive a 15% discount on all retained consultancy services as well as a free 30 minute consultation.

This post was contributed by Laura Brentnall from True North Data Governance – reach out to her for all your GDPR questions.

Start your journey with us

  • Beulah
  • Brolly
  • Oddbox Transparent
  • Index Ventures
  • Seedcamp
  • Qured