What Can Be Withheld in a SAR? UK Exemptions

What Can Be Withheld in a SAR? UK Exemptions

A SAR response can fail in two opposite ways: it can disclose someone else’s confidential information, or it can withhold material without a lawful, recorded reason. The question of what can be withheld in a SAR is therefore not a document-editing question. It is a case-by-case assessment of scope, rights, exemptions and risk.

For UK organisations, the starting point is disclosure. A data subject is generally entitled to confirmation that their personal data is being processed, a copy of that data and prescribed supplementary information. The fact that a record is sensitive, awkward or commercially valuable does not, by itself, permit it to be withheld.

The defensible approach is to identify the requester’s personal data, assess whether an exemption applies, redact only what is necessary and preserve a clear record of every decision.

What can be withheld in a SAR?

Information may be withheld from a subject access request where it is outside the scope of the request, where an applicable exemption under the UK GDPR and Data Protection Act 2018 applies, or where disclosure would adversely affect another person’s rights and freedoms. The organisation must be able to explain which basis applies and why.

A SAR does not give an individual an unrestricted right to every document in which their name appears. Nor does it allow an organisation to remove inconvenient evidence. The right is to the requester’s personal data, not necessarily to original documents in their unredacted form.

That distinction matters in practice. An investigation report, email chain or CCTV recording may contain the requester’s personal data alongside information about colleagues, witnesses, customers, legal advice or a live regulatory matter. The correct outcome may be partial disclosure, with targeted and irreversible redactions, rather than full disclosure or blanket refusal.

Third-party personal data

Third-party information is one of the most common reasons for redaction in SAR responses. This can include names, contact details, opinions attributable to identifiable colleagues, witness accounts, health information, HR data, customer information and material that could identify another individual indirectly.

The UK GDPR requires controllers to consider the rights and freedoms of others. Where disclosure would reveal another person’s personal data, the organisation should consider whether that person has consented, whether it is reasonable to disclose without consent and the likely impact of disclosure.

There is no automatic rule that every third-party name must be removed. A senior manager acting in an official capacity, for example, may be treated differently from a private individual providing a confidential witness statement. Context, reasonable expectations and potential harm are central to the assessment.

Where disclosure is not justified, redact only the third-party material needed to protect the individual. Removing an entire email or report where a name, identifying detail or short passage would suffice is difficult to defend.

Legally privileged material

Communications protected by legal professional privilege may be exempt from disclosure. This commonly includes confidential communications between the organisation and its legal advisers made for the purpose of giving or receiving legal advice. It may also cover material created for the dominant purpose of actual or contemplated litigation, where the conditions for litigation privilege are met.

Privilege should not be claimed simply because lawyers were copied into an email or because a document concerns a dispute. Teams should establish the purpose of the communication, who created and received it, and whether confidentiality has been preserved.

A privilege assessment should be recorded with particular care. If challenged, an organisation may need to demonstrate that it identified the correct legal basis rather than using privilege as a broad label for sensitive material.

Crime, taxation and regulatory functions

Some personal data can be withheld where disclosure would be likely to prejudice the prevention or detection of crime, the apprehension or prosecution of offenders, the assessment or collection of a tax or duty, or certain regulatory functions.

These exemptions are fact-specific. A live internal fraud investigation, safeguarding enquiry or regulatory investigation may contain information that should not be disclosed if doing so would alert a suspect, compromise evidence, expose a source or undermine the investigation.

The test is not whether the information is connected to an investigation. The organisation should be able to identify the likely prejudice arising from disclosure and explain why a narrower redaction or delayed disclosure would not adequately address it.

Management information, negotiations and confidential references

The Data Protection Act 2018 contains further exemptions that may be relevant in particular circumstances. These include certain data processed for management forecasting or management planning, where disclosure would be likely to prejudice the conduct of the business or other activity. Information relating to negotiations with the requester may also be protected where disclosure would be likely to prejudice those negotiations.

Confidential references given or received for education, training or employment may be exempt in defined circumstances. This is particularly relevant to HR teams handling recruitment, appraisal and workplace investigation records, but it does not make all employment-related information exempt.

Other exemptions may arise in journalism, academia, examination marking, public functions, social work, health and professional regulation. Their availability depends on the precise statutory wording and the facts. Sensitive information requires a more disciplined assessment, not a more creative reading of the exemptions.

What cannot be withheld simply because it is difficult?

Some recurring reasons for withholding are not, on their own, lawful grounds for refusing disclosure. Commercial sensitivity is not a standalone SAR exemption. Neither are reputational concern, embarrassment, internal disagreement, workload or the fact that the requester may use the information in a grievance or claim.

Likewise, information should not be withheld merely because it appears in an internal report, a senior-level email or a system that is inconvenient to search. If it is the requester’s personal data and no exemption applies, it must be disclosed in an intelligible form.

A controller can provide the personal data in a form other than a full original document where this protects the rights of others or is otherwise appropriate. But the alternative must still communicate the relevant personal data faithfully. A heavily obscured document that leaves the individual unable to understand the data held about them may not meet the obligation.

Scope, exemptions and refusal are different decisions

A controlled SAR process separates three questions that are often incorrectly merged.

First, is the information personal data relating to the requester? If not, it may be outside scope. Secondly, if it is in scope, does a specific exemption apply? Thirdly, if disclosure is required, can third-party or exempt information be removed while still disclosing the requester’s data?

There are also circumstances in which a request may be refused or a reasonable fee charged because it is manifestly unfounded or manifestly excessive. This is a high threshold. A request is not excessive merely because it is broad, contentious or time-consuming. Before relying on this position, organisations should consider whether they can ask the individual to clarify the request or narrow searches in a proportionate way.

These distinctions should be reflected in correspondence and in the internal decision log. Saying that information is “confidential” or “not disclosable” is not enough. The record should identify the relevant data, the decision, the legal basis, the reviewer and the rationale.

A defensible redaction workflow for SARs

Statutory timescales leave little room for improvised review. Organisations normally have one month to respond, although the period can be extended by up to two further months for complex or numerous requests if the individual is informed within the initial month.

A reliable workflow begins with identity verification where genuinely necessary, followed by a documented search plan. Relevant systems, custodians, date ranges and search terms should be agreed early. Reviewers then need a consistent way to classify information as disclose, redact or withhold, with a reason assigned to every redaction.

For high-volume SARs, the following controls are particularly valuable:

  • a structured exemption and redaction-reason taxonomy;
  • clear allocation of review, quality assurance and legal escalation responsibilities;
  • secure handling of source files, including images, scans and CCTV;
  • irreversible redaction that removes underlying text, image data and metadata; and
  • an audit trail showing what was changed, by whom, when and on what basis.

The technical control is as significant as the legal analysis. A black box placed over text is not a redaction if the text remains selectable, searchable or recoverable from the file. The same risk applies to hidden comments, tracked changes, layers, embedded attachments and video frames. Disclosure should be generated from a secure process with no reversible redactions.

A platform such as Redaktr can support this discipline by recording redaction reasons and reviewer activity alongside the redacted output. That creates an auditable decision record rather than a collection of altered files and disconnected spreadsheets.

Record the reasoning, not just the result

SAR disputes are often decided by the quality of the organisation’s reasoning. A regulator, tribunal or complainant may ask why a witness name was removed, why privilege was claimed or why an entire category of records was excluded. The answer should not depend on a reviewer’s memory months later.

For each withheld passage or document, retain sufficient detail to evidence the assessment: the source record, the relevant exemption or third-party rights issue, the anticipated prejudice where required, the decision-maker and any legal review. This record should itself be access-controlled, particularly where it refers to investigations or privileged advice.

The objective is not to disclose the maximum possible volume or to redact defensively at every point. It is to disclose the requester’s personal data accurately while protecting information the law permits or requires the organisation to protect. When each decision is necessary, proportionate, securely applied and recorded, the SAR response is far better placed to withstand scrutiny.