Almost every DSAR contains someone else’s personal data. The question is never whether to think about third parties, but how to justify what you did about them.
You can withhold third-party information in a DSAR where disclosing it would mean revealing information about another identifiable individual — unless that person has consented, or it is reasonable to disclose without their consent. In practice, redacting third parties is the default. This applies to any UK controller answering a request under Article 15 of the UK GDPR, and the exemption is set out in Schedule 2, Part 3, paragraph 16 of the Data Protection Act 2018.
What does the law actually say about third-party data?
Article 15(4) UK GDPR provides that the right to obtain a copy must not adversely affect the rights and freedoms of others. Paragraph 16 of Schedule 2 puts flesh on that: you are not obliged to disclose information that would identify another individual, unless the other individual has consented, or it is reasonable to comply without consent. The right of access is a right to the requester’s own personal data — it is not a route to information about other people.
What does “reasonable to disclose without consent” mean?
Paragraph 16 requires you to weigh all the relevant circumstances. That includes any duty of confidentiality owed to the third party, whether they can be identified from the information, any steps taken to seek their consent, whether they are capable of giving it, and any express refusal. A colleague named in a routine email in their professional capacity sits very differently from a member of the public who made a confidential complaint. The balancing is contextual, and it is yours to justify.
Is redaction always the answer?
Not automatically, but it is usually the safest route to disclosing the requester’s data while protecting others. Blanket withholding of whole documents because they mention someone else is a common error — it over-redacts, denies the requester data they are entitled to, and is hard to defend. The better approach is to disclose the requester’s personal data and redact only what genuinely identifies a third party, having done the balancing exercise. Over-redaction and under-redaction are both failures, as we explore in why most DSAR redaction processes fail under scrutiny.
How should you record the decision?
Per redaction, or per category of third party, note what was withheld and the basis for it — confidentiality, no consent, not reasonable to disclose. A third-party decision that cannot be explained later is exactly the kind of judgement that unravels under challenge, the point made in the silent risk of “non-relevant” documents. The contemporaneous record, not the redacted bundle, is what answers a complaint.
Frequently asked questions
Not necessarily. Under Schedule 2 paragraph 16 DPA 2018 you can disclose either where the third party has consented, or where it is reasonable to disclose without their consent. If neither applies, you withhold or redact that information. Seeking consent is one option, not a mandatory step.
No. The presence of third-party data is a reason to redact, not to refuse. You must still disclose the requester’s own personal data, removing or obscuring only what genuinely identifies another individual after carrying out the balancing exercise.
It is good practice to explain that some information has been withheld to protect the rights of others, without revealing the third-party data itself. Transparency about the fact of redaction, and its basis, helps demonstrate that the response was considered rather than evasive.
