Skip to content

Guide

What do I redact in a DSAR, and what stays?

The data subject's own data stays, even inside somebody else's sentence. Other people's identifying details come out. Article 15(4) protects their rights and is not a ground to withhold the document.

By Magdalena Góralczyk, Partner, Head of Data Protection. Last updated

Short answer

The requester's own personal data stays, including where it sits inside a colleague's sentence about them. Other people's identifying details come out. Article 15(4) protects those people's rights, but it is not permission to withhold the document, so the work is redaction rather than refusal.

The rule is narrower than people expect

Almost everyone answering a first large access request reaches for the same instinct: this file mentions four other employees, so the file is a problem. The provision that instinct points at is one sentence long, and it says less than it is usually asked to say. The right to obtain a copy shall not adversely affect the rights and freedoms of others. That is the whole of it.

The recital that explains it closes the door the sentence appears to open, in the same paragraph. Having named some of the rights involved, it says the result of those considerations should not be a refusal to provide all information to the data subject. Read together the two put the work on the material rather than on the answer: the right of access under the GDPR, article by article sets both out in full, and neither of them is a category exemption for anything a third party appears in.

So a document that contains another person is not a document you may withhold. It is a document you have to work on. That is a worse answer administratively and a much better one legally, and it is the whole reason a large request is expensive.

It is also the mistake regulators actually find. A Danish law firm declined a copy outright on the view that disclosure could hinder an investigation, and was met with serious criticism and an order: an exemption is assessed item by item, so the parts it does not reach are still disclosed. Refusing the whole because part of it is difficult is the one approach with a decision against it.

What stays in

The requester's personal data stays, and the category is wider than a list of their own contact details. It includes what other people wrote about them, because an opinion about a person is that person's personal data as much as their date of birth is. The awkward appraisal, the email complaining about their work, the note recording a decision about their shift: all of it is theirs to see.

It also includes data about operations carried out on their record rather than the record itself. The Court of Justice has held that information about consultation operations on a person's data, with the dates and purposes, is information they have the right to obtain, while the identity of the employees who carried out those consultations usually is not. That judgment is worth reading once even if nothing in your case looks like an access log, because it is the clearest statement there is of the shape of the answer: the event is disclosed, and the other person inside the event is not.

  • Their own identifiers, contact details and account records.
  • What colleagues, customers and managers said about them, in the words they used.
  • Decisions taken about them, and the material those decisions were taken on.
  • The fact that something happened to their record, with its date and purpose.

None of that becomes withholdable because it arrived in an email with four people on the thread.

What comes out

Everything that identifies somebody else. Names, of course, but a name is the easy half. A direct dial, a private address, a staff number, a national identifier, a bank detail, an account reference: each of those identifies a person on its own, and none of them stops doing so because the name beside it has gone.

The harder half is identification without an identifier. A sentence naming nobody can still name somebody to a reader who works there, and that reader is the requester, who knows the team. The colleague described by the injury he came back from, the one manager who was on secondment that quarter, the single person in the role the paragraph refers to: those are identifiable, and removing the name does not make them less so.

This is the part no rule catches reliably, and it is the reason a system's behaviour when it is uncertain matters more than its behaviour when it is confident. How Veil handles a person it cannot attribute, and what it will not guess at is the honest version of that: uncertainty is redacted and raised for a person to decide, and there is no path from unknown to disclosed.

How to decide it once per person

The reason a large request eats a week is not that the decisions are hard. Most of them are obvious in a second. It is that the same decision arrives again in the next document, and the next, and by the fortieth appearance of the same line manager nobody remembers what was decided about him on Tuesday. Work by person rather than by document and the volume collapses.

  1. Declare who the request is about, precisely

    Name, the email addresses they used, the identifiers you hold. Everything that belongs to that person is kept, and you cannot keep it consistently until you have written down what counts as them.

  2. Build the list of people, not the list of redactions

    Read for who appears in the case at all, across every document at once. A large case has tens of people in it and thousands of mentions of them. The list you want is the short one.

  3. Decide each person once, and write down why

    Third party, or the data subject, or not a person at all. Record the reason with the decision: a decision without a reason cannot be defended six months later and cannot be applied consistently by the next person.

  4. Apply the decision everywhere that person appears

    Including in documents nobody has opened. This is the step that has to be mechanical, because it is the step where a human reviewer's consistency runs out and where a missed mention becomes a disclosed third party.

  5. Check the output rather than the intention

    Search the released files for the surnames you decided to remove, and for the identifiers. A release that was correctly decided and incorrectly applied looks exactly like a correct one until somebody searches it.

That last step is its own subject, because a file can look redacted and not be. What survives a box drawn over a name in a PDF covers the eight places text stays behind after an in-place edit, and how to check a disclosure you have already sent.

Why the per document approach gives way

Every method above works on twenty documents. The trouble starts at several hundred, and it starts as inconsistency rather than as effort. The same person is redacted in one file and left in another, because two reviewers read the two files, or because one reviewer read them three days apart. An inconsistent redaction is worse than a missing one: the requester can often read the redacted name straight out of the version that kept it.

That failure has a worst case, and it is an employment file: the requester knows every person in the documents, the material is correspondence rather than records, and the same twenty colleagues recur across hundreds of files. Why an employee access request is the hard instance, and how to scope one is the same rule applied to that case, including the scoping mistake regulators actually find.

Pritect Veil is built for that specific failure. You declare the data subject, the case is resolved into one row per person found anywhere in it, and your decision on a row applies to every mention of that person across every document, including the ones you never opened. The originals are read only and are never modified; what you release is generated, with redacted people replaced by stable placeholders so the narrative still reads.

Each source document produces its own output, so a single file can be held back without costing you the rest of the bundle, and the bundle arrives with a manifest and a quality report rather than as a folder you have to vouch for from memory. What bulk DSAR redaction costs, priced per page redacted is the commercial side of it, and there is no per seat charge on a team that answers four requests a year.

Questions

Can I withhold a document because it mentions other people?

Not as a rule. Article 15(4) says the copy must not adversely affect the rights and freedoms of others, and Recital 63 says the result of that consideration should not be a refusal to provide all information to the data subject. The assessment is item by item, which is what the Danish decision on a copy refused in full turned on.

Does another employee's opinion about the requester belong to the requester?

Yes, as a rule. An opinion expressed about a person is personal data of that person, so it is disclosable to them, while the identity of the colleague who expressed it is that colleague's personal data and is normally redacted. The comment stays and the author comes out.

What about somebody who is identifiable without being named?

Treat them as identifiable. The test is whether the person can be singled out by a reader, and the reader here is the requester, who knows the organisation. A description that identifies one person to a colleague is not anonymous simply because the name is absent, which is why indirect identification is the class Veil redacts first and raises for a human decision rather than resolving on its own.

Do I have to give the original file or can I give an extract?

Article 15(3) entitles the requester to a copy of their personal data rather than to the original artifact, and supervisory authority guidance accepts extracts. That is why generating a new document containing only what you decided to release is a legitimate answer and not a workaround, and it is also the safer one.

Who decides whether something is privileged or out of scope?

You do. Veil is a redaction tool and it models no exemption vocabulary: it decides whether text identifies somebody other than the data subject, not whether a document is legally withholdable. The legal call stays with the controller and their advisers, and the tool's job is to make the disclosure you decided on come out consistently.

The rule is that other people come out and the requester stays, and the difficulty is doing it the same way across four hundred files. See how a case runs from upload to released bundle, or open a case and try it on a real disclosure.