The Dual Role of the DSAR in Employment Relations
In standard day-to-day operations, an employee might submit a DSAR simply to review HR files, performance appraisals, or training logs. However, when workplace friction arises, such as during a disciplinary procedure, a restructuring process, or a constructive dismissal claim, the DSAR frequently shifts from a transparency tool into a pre-litigation pre-litigation information request mechanism.Malta's Code of Organisation and Civil Procedure and Industrial Tribunal procedures do not feature the extensive pre-trial disclosure protocols common in Anglo-American jurisdictions, therefore employees routinely utilise the GDPR to compel employers to expose internal emails, managerial notes, and decision-making trails before initiating formal proceedings.
Key Obligations and Case Law for Maltese Employers
When responding to an employee DSAR, Maltese companies and HR teams must navigate several strict statutory requirements enforced by the Office of the Information and Data Protection Commissioner (IDPC) and European case law:1. Strict Timelines & Zero Cost: Employers must comply with a DSAR without undue delay and at the latest within one month of receipt. While this period can be extended by up to two additional months for particularly complex requests, the employer must notify the employee within the first month with a clear justification for the extension. Employers cannot charge a fee for fulfilling a request.
2. "Data" vs. "Documents" & CJEU Guidance: A frequent point of contention before the IDPC is the crucial distinction between providing personal data and handing over entire corporate files. Following the landmark CJEU ruling in FF v ÖBB-Infrastruktur AG (Case C-487/21), employees are entitled to receive faithful and intelligible extracts or full copies of documents only where necessary to exercise their GDPR rights effectively. Employers may extract and present personal data snippets in a clear format rather than supplying raw, unredacted corporate files.
3. Internal Workplace Emails (IDPC Case Law): In line with recent IDPC enforcement decisions, the Article 15 right of access explicitly extends to internal emails exchanged among managers and colleagues that mention or concern the employee. Employers cannot refuse access simply because data resides in internal email correspondence.
4. Mixed Data & Third-Party Privacy: Internal workplace communications rarely discuss an employee in isolation. Under Chapter 586, an employer must safeguard the privacy rights of third parties. Disclosing opinions, names, or performance assessments of co-workers without consent can constitute an independent data breach; thus, employers must redact third-party identifying information before disclosure.
Navigating Exemptions: Protecting Business & Legal Integrity
Maltese employers facing a broad or adversarial DSAR are not without legal defences. Both the GDPR and national legislation outline specific exemptions where data can and should be withheld or redacted:- Legal Professional Privilege (LPP): Communications between an employer and their legal advisors, whether external advocates or in-house counsel, seeking or giving legal advice, or prepared for contemplated litigation before the Industrial Tribunal or Maltese Courts are fully exempt. Draft responses to legal notices, strategy discussions, and risk assessments remain protected from disclosure.
- Confidential Management & Restructuring Planning: Personal data processed for management forecasting or corporate planning, such as confidential restructuring models, unannounced succession plans, or early-stage redundancy scoring, may be withheld if disclosure would prejudice the conduct of the business.
- Confidential References: Confidential references written or received for employment, appointment, or promotion purposes are exempt from access requests to preserve candour in recruitment and evaluation processes.
- Negotiations & Settlement Discussions: Records reflecting the employer’s intentions regarding ongoing exit negotiations or "without prejudice" discussions with the employee can be withheld if disclosure would jeopardise those settlement efforts.
Managing "Manifestly Unfounded or Excessive" Requests
When an employee submits a blanket demand for "every email, chat log, and document mentioning my name over a 10-year period," employers often struggle with the sheer operational burden.Under GDPR Article 12(5), an employer can refuse to act on a request if it is manifestly unfounded or excessive. However, as reinforced by IDPC case law, the threshold set by the Commissioner and European courts is remarkably high. Recent IDPC rulings highlight that controllers strictly bear the burden of proof and must formally justify and document any refusal or limitation applied to a DSAR. An employer cannot refuse a request merely because it is large, inconvenient, or time-consuming, instead, employers should write to the employee inviting them to narrow the scope of their request by specifying relevant date ranges, key personnel involved, or specific HR events.
Practical Action Plan for HR & Legal Teams in Malta
To ensure compliance while mitigating litigation risks, Maltese employers should maintain a structured internal DSAR protocol:- Maintain a Central Log & Verify Identity: Immediately log the receipt date and confirm the requester's identity before extracting any records.
- Conduct Targeted Searches: Coordinate with IT to run precise keyword searches across email servers, internal messaging tools, and physical HR files using agreed parameters.
- Establish a Redaction Log: Document every instance where third-party information is redacted or where a legal exemption, such as LPP, is applied. This audit log is essential if the employee lodges a formal complaint with the IDPC.
- Distinguish Data from Advice: Ensure internal managers understand that routine correspondence regarding employee performance may eventually be disclosed under a DSAR, reinforcing the need for objective, professional workplace documentation at all times.

