Software Outlook: Search to Export
Outlook: Search to Export
GDPR Guide

GDPR Requests: A Practical Guide for Companies

This page supports the GDPR request feature of Outlook: Search to Export. It explains what a GDPR data subject access request is, what your response must contain, what you may leave out, who may make a request and how often — and how the export created by the add-in fits into the process.

Disclaimer: This page is general information, not legal advice. GDPR enforcement details vary between EU/EEA member states and situations. When in doubt, consult your data protection officer or legal counsel.


What is a GDPR access request?

Under Article 15 of the EU General Data Protection Regulation (GDPR, Regulation 2016/679), any person (the data subject) has the right to ask an organisation:

  1. whether the organisation processes personal data about them, and if so,
  2. to receive a copy of that personal data, together with
  3. supplementary information about the processing.

This is commonly called a DSAR (data subject access request). E-mail is one of the most common places where personal data about a person accumulates: messages they sent to you, messages you sent to them, and messages that mention them.

A request is valid in any form — e-mail, letter, phone call, even verbally. It does not need to mention the GDPR or use any particular words. The clock starts when the request reaches you.

Deadlines

Who may make a request?

Important: the right of access covers the requester's own personal data only — never other people's (Article 15(4)).

How often, and what does it cost?

What the response must contain

Your response has two parts:

1. A copy of the personal data

For e-mail this typically means the messages (or relevant extracts) where the requester appears — as sender, as recipient, or discussed in the content. In practice, supervisory authorities and the EDPB Guidelines 01/2022 on the right of access expect you to make a reasonable, documented search of the systems where personal data of the requester can be found, including mailboxes used for business processes.

An access response does not always require handing over full copies of every e-mail. What matters is that the data subject receives the personal data concerning them in an intelligible form. A structured summary — for example a table of date, time, correspondent, subject and the opening lines of each message — is often an appropriate and proportionate format, supplemented with full copies where the content itself is the personal data.

2. Supplementary information (Article 15(1)(a)–(h) and 15(2))

Much of this can be a standard cover letter that accompanies the data export.

What you may (and must) leave out

The right of access is broad, but not unlimited:

Never delete data after receiving a request to avoid disclosing it — destroying requested evidence can constitute a GDPR infringement and, in some situations, a criminal offence.

A practical workflow

  1. Log the request and its date. Verify the requester's identity if in doubt.
  2. Scope the search: which mailboxes, systems and archives can contain the person's data? Document what you searched.
  3. Search and export. In Outlook, the GDPR request mode of Outlook: Search to Export finds all messages in the chosen date range where the person appears as sender or recipient, in both received and sent mail, and produces a structured Excel file with date, time, direction, contact, subject and (optionally) the first lines of each message. The summary sheet records the search term, the date range, the scope of the search and the generation time — useful for documenting how you searched.
  4. Review before disclosure. Go through the export: redact third-party personal data, trade secrets and privileged content. Decide which full messages need to be attached.
  5. Add the supplementary information (purposes, recipients, retention, rights — see above) in a cover letter.
  6. Deliver securely — encrypted or via a secure channel, to a verified address. If the request was made electronically, provide the response in a commonly used electronic form.
  7. Keep a record of what was disclosed, when, and what was redacted and why.

What the add-in does — and what it does not do

The GDPR request checkbox automates step 3: it searches both received and sent mail for the named person and never skips messages (the Skip marketing email option is disabled, because an access response must not silently omit data). The export's summary sheet states the scope of the search.

The add-in searches the default Inbox and Sent Items folders of the current mailbox. If your organisation uses subfolders, archive mailboxes, shared mailboxes or other systems (CRM, ticketing, chat), search those separately. The tool does not redact third-party data and does not generate the supplementary information — those steps remain your responsibility.

All processing happens locally on your computer. The add-in sends nothing to us or anyone else.

EU country notes: authorities and national derogations

The GDPR applies directly and identically in every EU member state: the deadlines, the free first copy, and the core content of Article 15 are the same everywhere. What varies by country is which supervisory authority handles complaints, which national act implements the GDPR, and which national derogations (based on Article 23 GDPR) may allow withholding specific material. Expand your country below. The full contact list is maintained by the EDPB.

Austria

Authority: Österreichische Datenschutzbehörde (DSB). National law: Datenschutzgesetz (DSG).

Access may be refused insofar as it would endanger a business or trade secret of the controller or a third party (§ 4(6) DSG) — a broader formulation than the GDPR baseline; document any reliance on it carefully. Data protection also has constitutional status in Austria (§ 1 DSG).

Belgium

Authority: Autorité de protection des données / Gegevensbeschermingsautoriteit (APD/GBA). National law: Law of 30 July 2018.

National derogations are mainly sector-specific (police, intelligence, certain public bodies). For private employers the GDPR baseline applies unchanged.

Bulgaria

Authority: Commission for Personal Data Protection (CPDP). National law: Personal Data Protection Act (ZZLD).

Derogations exist mainly for journalistic and academic purposes. For business mailboxes the GDPR baseline applies; the CPDP publishes guidance on handling access requests.

Croatia

Authority: Agencija za zaštitu osobnih podataka (AZOP). National law: Act on the Implementation of the GDPR (2018).

No major private-sector derogations to Article 15; follow the GDPR baseline and AZOP guidance.

Cyprus

Authority: Commissioner for Personal Data Protection. National law: Law 125(I)/2018.

Derogations concern mainly public-interest areas. For business mailboxes the GDPR baseline applies.

Czechia

Authority: Office for Personal Data Protection (ÚOOÚ). National law: Act No. 110/2019 Coll. on Personal Data Processing.

The act largely mirrors the GDPR baseline for private controllers; derogations concern journalism, research and public bodies.

Denmark

Authority: Datatilsynet. National law: Data Protection Act (databeskyttelsesloven).

Section 22 allows restricting data subject rights where the data subject's interest is found to be outweighed by essential private interests (including the controller's own) or public interests — a case-by-case balancing that must be documented.

Estonia

Authority: Andmekaitse Inspektsioon (AKI). National law: Personal Data Protection Act (2019).

Derogations exist for journalism and research. For business mailboxes the GDPR baseline applies.

Finland

Authority: Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto). National law: Data Protection Act (1050/2018).

Section 34 lists exceptions to the right of access — for example where disclosure could seriously endanger the data subject's health or care, or the rights of the data subject or another person. If you withhold data, you must state the reasons, and the requester can ask the Ombudsman to review the withheld material.

France

Authority: Commission Nationale de l'Informatique et des Libertés (CNIL). National law: Loi Informatique et Libertés.

CNIL has extensive guidance on workplace e-mail: messages marked or identifiable as an employee's personal/private correspondence enjoy special protection and should generally be excluded from employer searches. French law also lets heirs exercise certain post-mortem rights based on the deceased's instructions (arts. 84–86).

Germany

Authority: Federal BfDI plus 16 Länder authorities — for private companies, the authority of the Land where the company is established is competent. National law: Bundesdatenschutzgesetz (BDSG).

§ 34 BDSG excludes access where data are stored only because of statutory retention duties or purely for backup / data-protection-control purposes and access would take disproportionate effort. § 29 BDSG protects material covered by professional secrecy (including legal advice). Works-council (Betriebsrat) processing adds employer-specific nuances.

Greece

Authority: Hellenic Data Protection Authority (HDPA). National law: Law 4624/2019.

The law contains several derogations to Articles 12–22, some of which have been questioned at EU level — check current HDPA guidance before relying on a national exemption.

Hungary

Authority: National Authority for Data Protection and Freedom of Information (NAIH). National law: Act CXII of 2011 (Info Act).

NAIH maintains an active complaint practice on access requests. For business mailboxes the GDPR baseline applies.

Ireland

Authority: Data Protection Commission (DPC). National law: Data Protection Act 2018.

Notable exemptions: legal privilege, opinions given in confidence, and the Section 60 restrictions (e.g. data relating to negotiations with the requester, examination scripts). The DPC publishes detailed DSAR guidance for employers — useful reading even outside Ireland.

Italy

Authority: Garante per la protezione dei dati personali. National law: Personal Data Protection Code (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018).

Special feature: the rights of deceased persons can be exercised by heirs and others with a legitimate interest (art. 2-terdecies). The Garante also has significant case law restricting employer access to and retention of former employees' mailboxes.

Latvia

Authority: Datu valsts inspekcija (DVI). National law: Personal Data Processing Law (2018).

Derogations concern journalism and official secrets; for business mailboxes the GDPR baseline applies.

Lithuania

Authority: Valstybinė duomenų apsaugos inspekcija (VDAI). National law: Law on Legal Protection of Personal Data.

The GDPR baseline applies to private controllers; VDAI publishes guidance in Lithuanian.

Luxembourg

Authority: Commission Nationale pour la Protection des Données (CNPD). National law: Law of 1 August 2018.

The GDPR baseline applies; note that financial-sector professional secrecy interacts with access requests — seek advice in banking and fund contexts.

Malta

Authority: Information and Data Protection Commissioner (IDPC). National law: Data Protection Act (Cap. 586).

Restrictions are set out in subsidiary legislation for specific sectors; the GDPR baseline applies to business mailboxes.

Netherlands

Authority: Autoriteit Persoonsgegevens (AP). National law: GDPR Implementation Act (UAVG).

Article 41 UAVG implements the Article 23 GDPR restrictions (rights and freedoms of others, enforcement interests). Dutch courts have produced significant case law on what "a copy" requires — full documents are not always owed, but work notes about a person can be in scope.

Poland

Authority: Urząd Ochrony Danych Osobowych (UODO). National law: Act of 10 May 2018 on Personal Data Protection.

The GDPR baseline applies to private controllers; sectoral acts add specific exceptions.

Portugal

Authority: Comissão Nacional de Proteção de Dados (CNPD). National law: Law 58/2019.

The CNPD has declined to apply certain provisions of the national law as conflicting with the GDPR — rely primarily on the GDPR text and CNPD guidance.

Romania

Authority: National Supervisory Authority for Personal Data Processing (ANSPDCP). National law: Law 190/2018.

Derogations concern mainly journalism and national security; the GDPR baseline applies to business mailboxes.

Slovakia

Authority: Úrad na ochranu osobných údajov. National law: Act No. 18/2018 Coll.

The act largely restates the GDPR; the baseline applies to private controllers.

Slovenia

Authority: Information Commissioner (Informacijski pooblaščenec) — also the freedom-of-information authority. National law: ZVOP-2 (in force since 2023).

ZVOP-2 adds procedural detail (for example on identity verification) rather than new private-sector exemptions.

Spain

Authority: Agencia Española de Protección de Datos (AEPD). National law: Organic Law 3/2018 (LOPDGDD).

Heirs and relatives may access a deceased person's data (art. 3 LOPDGDD). The law also codifies digital rights in employment — including rules on monitoring employee devices and e-mail — which affect how mailbox searches should be conducted.

Sweden

Authority: Integritetsskyddsmyndigheten (IMY). National law: Data Protection Act (2018:218).

Chapter 5 contains a notable exception: the right of access does not extend to personal data in running text that has not yet been given its final form (drafts) or in memory notes — unless the material has been disclosed to a third party. Confidentiality (sekretess) rules can further restrict disclosure.

The GDPR also applies in the EEA countries Norway, Iceland and Liechtenstein through their own implementing acts and authorities (Datatilsynet, Persónuvernd, Datenschutzstelle).

Sanctions for getting it wrong

Ignoring or mishandling access requests is one of the most common causes of GDPR complaints. Infringements of the data subjects' rights (Articles 12–22) fall in the higher fine bracket: up to 20 million euros or 4 % of worldwide annual turnover, whichever is higher (Article 83(5)) — in addition to reputational damage and orders from the supervisory authority.

Sources and further reading