A DSAR rarely arrives as a neat bundle of documents ready for release. It may require a search across email, HR files, case-management systems, meeting notes, CCTV and shared drives, with the requester’s personal data embedded alongside information about colleagues, customers and confidential business activity. Knowing how to redact a DSAR is therefore not a formatting exercise. It is a controlled disclosure process in which every withheld item must be considered, justified and applied securely.
For UK organisations, the central challenge is to give the data subject meaningful access to their personal data while protecting the rights and freedoms of others, confidential information and material that falls within a relevant exemption. The result must be accurate, complete enough to meet the request, and capable of standing up to a complaint, internal review or ICO scrutiny.
Start with scope, not the redaction tool
Redaction should begin only after the request has been understood and the relevant data sources have been identified. Confirm the requester’s identity where necessary, clarify the scope if the request is broad or ambiguous, and establish the statutory deadline. A DSAR normally requires a response without undue delay and within one month, subject to limited extensions where the request is complex or numerous.
Create a defensible search plan. Record which systems, custodians, date ranges and search terms were considered, including any sources excluded and why. This matters because a redaction log cannot compensate for an incomplete search. If a request later becomes contentious, the organisation should be able to explain both how it found information and how it decided what could be disclosed.
At this stage, separate data that is plainly outside scope from material that contains the requester’s personal data. A document does not become disclosable in full merely because it mentions the requester. Equally, the presence of third-party information is not an automatic reason to withhold the whole document. The task is to assess whether the requester’s personal data can be provided without unjustifiably disclosing other protected information.
Identify what needs protection
The most common DSAR redactions concern third-party personal data. Names, contact details, employee identifiers, opinions attributable to colleagues and information that could identify another individual may all need careful assessment. Identifiability is contextual: removing a name may not be enough if job title, location, dates and events make the person obvious to the requester.
Other categories may require withholding or redaction depending on the facts and the applicable legal basis. These can include legally privileged communications, confidential references, information relating to management forecasting or planning, negotiations, crime or regulatory functions, and information subject to a statutory restriction. The Data (Use and Access) Act 2025 and the UK GDPR framework should be considered alongside any sector-specific duties and relevant employment, safeguarding or public-sector obligations.
Do not treat exemptions as labels that can be applied in bulk. Their availability often depends on the purpose of the information, the likely effect of disclosure and the precise wording of the exemption. Legal advice is particularly prudent where the material concerns disciplinary proceedings, whistleblowing, litigation, safeguarding, criminal allegations or senior-level decision-making.
Apply the third-party data test properly
Where information identifies another individual, consider whether that person has consented to disclosure, whether it is reasonable to disclose without consent, and what impact disclosure may have on them. The requester’s relationship with the third party, the nature of the information, expectations of confidentiality and any duty of confidence will all affect the assessment.
This is not simply a privacy-versus-transparency calculation. Over-redaction can deny a data subject meaningful access to personal data about them, while under-redaction can expose colleagues or customers without a lawful basis. Record the reasoning, particularly where the decision is finely balanced. A short, contemporaneous note explaining why disclosure was or was not reasonable is far stronger than a retrospective explanation after a challenge.
How to redact a DSAR securely
Once disclosure decisions have been made, the technical application of redactions must match those decisions exactly. Highlighting text, drawing black boxes over a PDF or changing font colour is not redaction. These methods can leave underlying text searchable, selectable, recoverable from layers or present in document metadata.
A secure process permanently removes the protected content from the disclosed copy. It should also identify non-visible data that could reveal information, including comments, tracked changes, hidden text, headers, file properties, embedded objects and document revision history. For images and CCTV, the same principle applies: blurring or masking must not be reversible, and the source file must remain protected from accidental release.
Use a purpose-built redaction environment where possible, rather than a collection of desktop tools, edited copies and spreadsheets. The system should preserve the original, generate a controlled redacted version and prevent users from exporting material before redactions are applied. Role-based access, secure storage and clear separation between source and disclosure copies reduce the risk of a hurried or unauthorised release.
Each redaction should be assigned a clear reason code, such as third-party personal data, legal professional privilege or confidential information. The reason does not need to reveal protected details, but it should allow reviewers and decision-makers to understand the basis for withholding. Consistent reason codes are especially valuable where a DSAR contains hundreds of documents and several reviewers.
Build an auditable review workflow
A defensible DSAR process distinguishes between review, approval and release. The person applying a redaction may identify an issue, but a suitably authorised colleague should approve complex or high-risk decisions. This separation reduces inconsistency and helps prevent one reviewer’s assumptions from becoming the organisation’s final position.
Maintain an audit trail that records the document reviewed, the redaction applied, its rationale, the reviewer, any approval decision and the date of each action. Keep the working record securely, together with the search methodology and correspondence about scope or identity. If the requester complains that information has been withheld improperly, these records allow the organisation to investigate quickly rather than reconstruct decisions from emails and memory.
For substantial requests, use sampling and quality assurance before release. A second reviewer should test whether redactions are complete, whether the stated reason is correct, whether metadata has been removed and whether files open as intended. Check also that no unredacted original has been placed in the disclosure folder by mistake. The more sensitive the information, the more valuable a formal release checklist becomes.
Explain the response without exposing more data
The response should provide the requester with their personal data in an intelligible form and include the required supplementary information. Where material has been withheld, explain the position at a level that is meaningful but does not undermine the redaction itself. A generic statement that information has been removed is rarely helpful; a concise indication that third-party data or privileged material has been withheld will often be more appropriate.
There will be cases where providing an extract, summary or contextual explanation is more practical than releasing a heavily redacted document. That approach should not be used to avoid disclosure, but it can help where a document would otherwise be unintelligible or where the requester’s personal data can be accurately conveyed in another form.
Keep a record of exactly what was sent, when it was sent and by what secure delivery method. Password-protected files shared through a separately communicated password, secure portals and controlled access arrangements may be appropriate depending on sensitivity. Emailing sensitive disclosures without considering recipient verification and encryption creates a new data protection risk at the final stage.
Treat redaction as an accountable decision
The most reliable DSAR teams do not measure success by how quickly they can place black boxes on a page. They measure it by whether the final disclosure is accurate, secure and explainable. That requires a process that connects search, review, legal assessment, irreversible redaction and release control.
For organisations dealing with high volumes or sensitive case material, a platform such as Redaktr can provide the structured workflow, no reversible redactions and decision record needed to make that process auditable. The useful test is simple: if a regulator, tribunal or senior reviewer asked why a particular line was withheld, your team should be able to show the decision, the rationale and the exact version released without hesitation.

