Friday, September 18, 2026
What can you redact from a subject access request?


In this article, we're going to discuss:
Responding to a subject access request (SAR, also known as DSAR) takes skilled judgement. Your team needs to decide what the person is entitled to receive and whether there’s data that needs to be redacted. This gets harder when an email contains information about several people or someone wants an internal comment removed because it’s uncomfortable to disclose.
Removing too much can leave the data subject without information they’re entitled to. Missing a redaction can expose someone else’s personal data. Your team needs time to review the records properly and a clear process for checking decisions.
This guide explains what you can redact from a SAR, when exemptions apply and what to check before sending your response.
What information can you redact from a SAR?
You can remove information that falls outside the data subject’s entitlement and withhold information where a relevant exemption applies. This can include information about other people or material protected by legal professional privilege.
Assess the specific information you intend to remove. An exemption covering one passage doesn’t automatically justify withholding the rest of the document.
Does a SAR entitle the data subject to the whole document?
A SAR gives the data subject access to their personal information, together with supplementary information about how you use it. It doesn’t automatically entitle them to every document containing their name.
For example, an employee’s name may appear in the distribution list for an email announcing an office closure. That identifies them as a recipient, but the announcement itself doesn’t describe their circumstances or performance. An email explaining why that employee was refused a promotion does: it contains an assessment and a decision about them, which need to be considered for disclosure.
You can provide extracts or redacted documents, but retain enough context for the data subject to understand their information. If you disclose an assessment score, include the scoring scale or an explanation of what the score means.
Can you redact information about other people from SAR requests?
You may need to redact information that identifies someone else. However, if they consent or disclosure is reasonable without consent, you must provide it unless another exemption applies. Removing a name may not protect their identity if a role or incident still identifies them.
You don’t always need to seek consent. Asking could reveal the data subject’s SAR or private information to someone who shouldn’t know about it. An employee may feel pressured to agree when their employer asks, so consent may not be freely given.
Without consent, assess whether disclosure is reasonable. Consider sensitivity, confidentiality, any refusal and its reasons, the importance of the information to the data subject, and the consequences for those involved. A refusal is relevant, but isn’t an automatic veto.
What the data subject already knows also matters. Information they’ve previously received may be more reasonable to disclose than something new. Knowing someone’s identity doesn’t mean they’re entitled to private details about them.
Should staff names always be redacted in a SAR request?
No. Consider what disclosing the name would reveal. If a complaint handler has already signed letters to the data subject, their name on a routine case note may reasonably remain visible: it identifies someone whose involvement is already known.
A different assessment is needed if naming a staff member would identify a confidential witness or expose them to a credible risk of harassment. Examine those circumstances before deciding whether to disclose their identity.
The staff member’s name and the contents of their note also need separate consideration. Where withholding the name is justified, you may still be able to disclose the information about the data subject. Check whether the remaining detail would identify the staff member anyway.
Can you withhold internal comments or confidential documents from SARs?
An “internal” or “confidential” label isn’t an exemption. An opinion about the data subject can be their personal information, even if it’s critical, disputed or embarrassing to the organisation.
For example, a note admitting that a customer’s complaint was overlooked doesn’t become exempt because disclosure might lead to criticism. Assess any actual exemption that applies, rather than removing the note to avoid explaining the mistake.
Can legal advice be redacted from a SAR?
Information protected by legal professional privilege may be exempt. This covers qualifying confidential legal advice and certain communications connected with contemplated or ongoing litigation. Scotland has corresponding protections for confidential legal communications.
Copying a solicitor into an email doesn’t automatically protect the whole conversation. Sending an existing document to a lawyer doesn’t, by itself, make that document privileged.
If you’re unsure, refer the particular communication to your legal adviser or compliance team. Ask whether the exemption applies to it and which passages can be withheld.
What other SAR exemptions could apply?
The Data Protection Act 2018 provides exemptions for particular circumstances, including:
Management forecasting or planning: relevant information may be exempt where disclosure would be likely to prejudice the conduct of the business or activity. This doesn’t cover everything written by management.
Negotiations with the data subject: records of your intentions may be exempt where disclosure would be likely to prejudice those negotiations.
Confidential references: an exemption can cover references genuinely given in confidence for specified purposes, including employment, training and education.
Crime prevention or detection: information may be withheld where disclosure would be likely to prejudice that purpose. Other records about the data subject may still be disclosable.
To check the conditions, use the ICO’s “What exemptions are relevant for SARs?” guidance, linked at the end of this article. Find the relevant exemption and check both the information it covers and any test you must meet. It also points to the applicable legislation.
Where the test involves likely prejudice, identify the actual harm disclosure could cause and explain the connection. A general concern that it “might cause problems” isn’t enough.
Common mistakes made when preparing SARs, and how to avoid them
Leaving redaction until the end. Difficult decisions may only become apparent when there’s little time left to resolve them. Flag documents that need legal advice or clarification as you gather them and assign those questions early. Your team can review the remaining records while waiting for answers.
Removing more information than necessary. If one passage qualifies for an exemption, check whether the rest can be disclosed. Ask reviewers to identify the specific information that needs protecting rather than excluding the whole document.
Applying redactions inconsistently. Removing someone’s name from one email won’t protect their identity if another document reveals it in connection with the same information. Check references across the response, including attachments and quoted email chains. Consistency means applying the same reasoning wherever the information appears, while recognising that different contexts may justify different decisions.
Using a generic explanation for every redaction. A standard covering letter can miss the reasons behind individual decisions. Adapt it to the response so the data subject understands what’s been withheld and why, where you can explain without revealing protected information.
What should you record about a redaction from a SAR document?
Another reviewer should be able to understand the decision from your case notes. Record:
The document and passage, including the filename and page or section.
What was removed and the exemption or other reason relied on.
Why that reason applies, including any assessment of consent, confidentiality or likely harm.
Who made or checked the decision and when.
Write the explanation during the review. For example, “third-party data” alone doesn’t show why disclosure was unreasonable; the note should explain the particular privacy concern and how it was assessed against the data subject’s right of access.
How do you check that a redaction is secure?
A black box over text may hide it visually while leaving the underlying information recoverable. Check the actual files approved for release:
Use a suitable redaction method. Highlighting, changing text colour or placing a shape over words doesn’t necessarily remove the content.
Keep the original securely and save a clearly named disclosure copy.
Open the saved copy and test whether searching, copying or removing an overlay reveals the redacted information.
Check comments, tracked changes, hidden sheets and embedded files where relevant.
Review the complete set of files for unredacted duplicates or attachments that reveal information removed elsewhere.
Confirm the recipient and exactly which files they’ll be able to access.
For sensitive or complex records, arrange a second review of the final files before sending them.
What should you say to a data subject when withholding information?
If you refuse all or part of a SAR, explain why and tell the data subject about their rights to complain to your organisation and the ICO, and to seek enforcement through the courts.
Where possible, describe the reason in terms they can understand. For example, if it accurately reflects your assessment: “We’ve removed a paragraph about a separate customer’s order because it contains no information about you.” The explanation should match the decision you actually made.
Sometimes detail would defeat the exemption. If disclosure would jeopardise a fraud investigation, explaining the evidence withheld could alert the data subject to the investigation and enable them to destroy evidence. A more general response may then be appropriate. That exception doesn’t justify vague explanations for routine redactions.
Spend less time on SAR admin
Your team’s time is better spent reviewing information than chasing documents or checking which version has been approved.
Complyr’s SAR/DSAR case management software keeps request details, documents, correspondence and actions in one case file. Configure review stages around your process, assign actions and use flags to highlight deadlines. Every change to the case file is timestamped, helping you review the work carried out.
Once your team has completed redaction and review, share response files in bulk through the secure case portal. External users access it with multi-factor authentication, and you control which files they can see. If the data subject can’t or doesn’t want to use an online platform, provide an alternative delivery method.
Book a demo to see how Complyr could reduce the admin involved in managing SARs.
Useful ICO guidance
Information about other people in a SAR explains how to address consent, confidentiality and reasonable disclosure.
What exemptions are relevant for SARs? sets out individual exemptions, their conditions and the relevant legislative provisions.