Disclosure failures rarely arise from bad faith or poor intent. They occur when reasonable decisions are made without being recorded in a way that can withstand later scrutiny.
Most DSAR redaction processes fail under scrutiny for a single reason: the decisions behind the disclosure were never recorded in a form that can be explained later. This applies to any UK organisation answering subject access requests under Article 15 of the UK GDPR — public authorities, employers, insurers, schools, and sports bodies alike. The redacted bundle usually survives. The reasoning behind it usually does not.
DSARs are often treated as a delivery exercise: speed, volume, and a final bundle of documents that appears compliant. In practice, DSAR handling is not primarily about output. It is about record creation. Every DSAR creates a record of decision-making that may later be examined, challenged, or reconstructed under pressure — and many organisations only realise this when scrutiny arrives.
What does “scrutiny” actually mean for a DSAR?
Scrutiny arrives in two main forms: a complaint — since 19 June 2026, made first to you as controller under the new section 164A complaints procedure, and escalated to the Information Commissioner’s Office only if the requester remains dissatisfied — or litigation in which the DSAR response becomes evidence. Most DSAR failures do not arise because organisations act recklessly or in bad faith. They arise because decisions that felt reasonable at the time were never captured in a form that could be explained later. When a complaint is raised, or when the ICO becomes involved, organisations are asked to justify not only what was disclosed, but what was withheld, filtered out, or deemed non-relevant. The ICO’s right of access guidance makes clear that controllers are expected to be able to explain the searches they carried out and the exemptions they applied under the Data Protection Act 2018. At that point, informal processes begin to unravel.
Why is redaction only half of the disclosure decision?
A common weakness lies in the distinction between redaction and disclosure reasoning. Redaction tools typically focus on obscuring information within documents that are otherwise accepted as in scope. That is only part of the disclosure picture. The more consequential decisions often occur earlier: which documents were included at all, which were excluded, and why. These decisions are frequently made quickly, by different reviewers, using informal criteria that are understood at the time but never formally recorded. Those unrecorded exclusions are the subject of the silent risk of “non-relevant” documents.
When those criteria are not documented, organisations are left attempting to reconstruct their reasoning retrospectively. This is where hindsight risk emerges. Decisions that were made sensibly in context can appear arbitrary when viewed later without supporting records. Staff move on. Emails are deleted. Spreadsheets are overwritten. The final redacted documents remain, but the reasoning that led to them does not.
Why can’t fragmented tooling be audited?
It is common to see DSAR handling spread across shared drives, email threads, spreadsheets, and basic PDF editors. Each component may function adequately in isolation, but together they form a process that cannot be audited coherently. When asked to explain how a particular decision was reached, organisations are forced to piece together fragments rather than refer to a structured record.
This becomes particularly problematic where multiple reviewers are involved, or where cases extend over time. Without a single environment that records who reviewed what, when, and on what basis, organisations struggle to demonstrate consistency. Inconsistency is rarely deliberate, but it is difficult to defend once exposed.
What do regulators and complainants actually ask?
Under scrutiny, the focus shifts. Regulators and complainants are not only interested in whether personal data was properly redacted. They want to understand how relevance was assessed, how exemptions were applied, and whether decisions were reasonable and proportionate at the time they were made. Since the Data (Use and Access) Act 2025, the searches themselves need only be reasonable and proportionate — but you must be able to show that the ones you carried out met that standard. A final bundle of redacted documents answers none of those questions on its own.
What does a defensible DSAR process look like?
The organisations that fare best under scrutiny tend to share one characteristic. They treat DSAR handling as a governance process rather than a clerical task. They recognise that disclosure creates an evidential trail, and they use systems and methods that preserve that trail deliberately — an audit trail that captures reasoning, not just activity.
This is where structured disclosure platforms make a material difference. Systems that capture review history, record exclusion decisions, and preserve reasoning alongside documents fundamentally alter the risk profile of DSAR handling — this is the approach Redaktr describes as defensibility. They allow organisations to demonstrate not just what they disclosed, but how they approached the task as a whole.
The issue is rarely whether decisions were defensible when they were made. The issue is whether they can still be demonstrated as defensible later. DSAR processes fail under scrutiny when they are not designed with that reality in mind.
Frequently asked questions
Since 19 June 2026, the requester complains first to you as the controller under section 164A of the Data Protection Act 2018; you must acknowledge it within 30 days and respond without undue delay. If they remain dissatisfied, the ICO can then ask how you searched for their personal data, what you withheld, and on what basis — and it expects contemporaneous records rather than explanations reconstructed after the event.
No. The right of access is to the requester’s personal data, not to documents as such, and exemptions in the Data Protection Act 2018 may apply — for example third-party data and legal professional privilege. What the organisation must be able to do is explain how it decided what fell outside scope.
At the point they are made: who reviewed each document, what was redacted or excluded, and on what basis. A structured case record created during the review is far more defensible than email trails and spreadsheets assembled after the event.
