Insights
-
Why Most DSAR Redaction Processes Fail Under Scrutiny
Most DSAR redaction processes fail under scrutiny for a single reason: the decisions behind the disclosure were never recorded in a form that can be explained later. The redacted bundle usually survives. The reasoning behind it usually does not.
-
The Silent Risk of ‘Non-Relevant’ Documents in Disclosure
A decision that a document is “non-relevant” is still a disclosure decision — and if it is not recorded, it is often the hardest part of a DSAR or FOI response to defend later. Disclosed documents leave a trail. Excluded ones usually leave nothing.
-
CCTV and Video DSARs: Where Good Processes Break Down
CCTV and video DSARs fail more often than document-based requests because organisations improvise: footage is copied to unmanaged systems, redacted with editing tools, and disclosed without a record of what was reviewed or excluded. The medium is not the problem; the absence of process is.
-
Audit Trails Are Not Evidence Unless They Capture Reasoning
An audit trail is only evidence of a defensible disclosure process if it records why decisions were made, not just when files were opened, edited, or exported. Activity logs demonstrate process. They do not demonstrate judgement.
-
Why Speed Is the Wrong Primary Metric for Disclosure
Speed is the wrong primary metric for DSAR and FOI handling because timeliness is a statutory constraint, not the objective: a response delivered on time that cannot be explained afterwards still fails. Deadlines matter. Reasoned decisions matter more.
-
When Disclosure Becomes a Governance Issue Rather Than an Operational Task
Disclosure is a governance issue because every DSAR, FOI request, and legal disclosure produces organisational records of judgement that boards may later have to account for — yet in most organisations it is managed purely as an operational task. That gap is where disclosure risk lives.
-
How to Respond to a CCTV Subject Access Request: A Step-by-Step Guide
Responding to a CCTV subject access request involves six steps: verify identity, preserve the footage before it is overwritten, confirm the requester is identifiable, assess third parties, redact and record the decisions, and disclose securely within one calendar month.
-
How Long Do You Have to Respond to a DSAR — and Can You Pause the Clock?
You have one calendar month to respond to a DSAR, but since 5 February 2026 that month runs from the “relevant time” — the latest of receipt, requested ID, or fee — and you can pause the clock while you wait for information you reasonably need to identify what has been requested.
-
Third-Party Data in a DSAR: When Can You Withhold It?
You can withhold third-party information in a DSAR where disclosing it would identify another individual — unless they have consented, or it is reasonable to disclose without consent. In practice, redacting third parties is the default, and the decision must be recorded.
