The most common redaction mistakes teams encounter can expose UK businesses to significant regulatory penalties, reputational damage, and legal challenges. When organisations fail to properly redact third-party data from subject access request responses, they risk breaching GDPR regulations and compromising confidential information. Understanding these critical errors is the first step toward building a compliant and effective SAR process.
Subject access requests continue to increase across UK organisations, particularly in sectors handling sensitive personal data. As the volume rises, so does the potential for costly errors during the redaction phase. Many businesses underestimate the complexity of identifying what must be redacted, leading to either excessive redaction that frustrates requesters or insufficient redaction that violates privacy rights.
1. Failing to Identify All Third-Party Personal Data
One of the most prevalent redaction mistakes SAR processors make is overlooking personal data belonging to individuals other than the requester. This frequently occurs in email chains, meeting notes, and collaborative documents where multiple people contribute information.
Third-party data can appear in unexpected places, including email signatures, CC fields, witness statements, and internal communications about the requester. Many organisations focus solely on redacting obvious identifiers like names and contact details, missing indirect identifiers such as job titles, project assignments, or contextual information that could identify colleagues or clients.
How to Avoid This Mistake
Implement a systematic review process that examines every document through the lens of data protection. Train your team to recognise all forms of personal data, not just direct identifiers. Create checklists that prompt reviewers to consider:
- Email metadata and distribution lists
- Names, roles, and contact information of third parties
- Opinions and assessments about individuals other than the requester
- Indirect identifiers that could expose someone's identity when combined with other information
2. Over-Redacting Information the Requester Is Entitled to Receive
While caution is important, excessive redaction represents another significant category of redaction mistakes teams must avoid. Some organisations adopt a defensive approach, redacting any information they consider sensitive or potentially problematic, even when the requester has a legal right to access it.
Over-redaction often stems from misunderstanding exemptions or applying them too broadly. For instance, organisations may redact their own opinions about the requester, believing this constitutes sensitive business information, when in fact the requester is entitled to see assessments made about them.
When in doubt about whether to redact, ask yourself: "Does this information relate to the requester or to someone else?" If it relates to the requester, they generally have a right to see it unless a specific exemption applies. Understanding what can be redacted from a SAR helps you strike the right balance between transparency and data protection.
Finding the Right Balance
Proper redaction requires understanding the legal framework. The GDPR grants individuals the right to access their personal data, including assessments, opinions, and decisions made about them. You should only withhold information when a specific exemption genuinely applies, and you must be prepared to justify your decision if challenged.
3. Inconsistent Redaction Approaches Across Documents
When multiple team members handle different aspects of a SAR response, inconsistent redaction standards frequently emerge. One person might redact colleague names throughout their documents, while another leaves them visible, creating confusion and potential compliance gaps.
This inconsistency becomes particularly problematic in large or complex requests involving hundreds of pages. Without clear guidelines and quality assurance processes, the same type of information may be treated differently depending on who reviews it, leading to both over-redaction and under-redaction within the same response.
Establishing Consistency
Develop comprehensive written redaction guidelines specific to your organisation. These should address common scenarios your team encounters and provide clear examples of when to redact and when not to. Implement a quality assurance layer where a senior reviewer checks samples of redacted documents to ensure consistency across the entire response.
4. Technical Redaction Mistakes That Leave Data Recoverable
Among the most serious redaction mistakes teams can make are technical failures that allow redacted information to be recovered. Simply highlighting text in black, using text boxes to cover information, or applying cosmetic redaction in PDF readers may appear to hide data on screen, but the underlying information remains accessible.
Recipients can often recover improperly redacted information by copying and pasting content, removing layers in PDF software, or accessing document metadata. This technical vulnerability can turn a well-intentioned redaction effort into a significant data breach.
Technical Best Practices
Use proper redaction tools that permanently remove information rather than simply obscuring it visually. Adobe Acrobat Pro, for example, offers a specific redaction function that permanently deletes underlying data. After applying redactions, always test documents by attempting to copy text from redacted areas and checking document properties for hidden metadata.
For organisations handling frequent or complex SARs, investing in professional redaction software provides robust security and efficiency benefits. These tools often include search functions to identify all instances of specific names or data points, reducing the risk of missing occurrences.
5. Inadequate Documentation of Redaction Decisions
The final category of redaction mistakes SAR organisations make involves failing to properly document why information was withheld. Under GDPR, when you refuse to provide information, you must inform the requester about which exemptions you relied upon and why they apply.
Many organisations redact information without maintaining clear records of their reasoning, making it impossible to provide a coherent explanation if challenged. This documentation gap weakens your position if the requester complains to the Information Commissioner's Office or pursues legal action.
Building a Defensible Audit Trail
Create a redaction log for each SAR that records what was redacted, which exemption justified the redaction, and the specific reasoning. This log serves multiple purposes: it helps ensure consistency, facilitates quality review, and provides essential documentation if you need to defend your decisions.
Your documentation should be specific enough that someone unfamiliar with the case could understand your reasoning. Rather than noting "third party data," specify "redacted John Smith's email address and comments as they constitute his personal data and disclosure is not necessary to respond to the SAR."
The consequences of poor redaction extend beyond regulatory penalties. The cost of getting a SAR wrong includes reputational damage, loss of trust, and potential civil claims from individuals whose data was improperly disclosed.
Building a Robust Redaction Framework to Prevent Common Redaction Mistakes SAR Teams Face
Avoiding these redaction mistakes SAR processors commonly make requires investment in training, technology, and processes. Start by developing clear written procedures that address the specific challenges your organisation faces based on the types of data you hold and the nature of requests you receive.
Regular training ensures everyone involved in SAR processing understands both the legal requirements and your organisation's specific standards. Training should cover real examples from your organisation, discussing challenging redaction decisions and how they were resolved.
Quality assurance mechanisms provide essential safeguards. Even experienced processors make mistakes, particularly when working under time pressure or handling complex requests. A systematic review process catches errors before responses are sent, protecting both the requester's rights and your organisation's compliance position.
Finally, consider seeking specialist support for complex or high-risk requests. Professional SAR services bring expertise and resources that can prevent costly mistakes while ensuring requests are handled efficiently and compliantly.
Moving Forward with Confidence
Understanding common redaction mistakes is essential, but preventing them requires ongoing commitment to best practices. By implementing robust processes, investing in appropriate technology, and maintaining clear documentation, your organisation can handle subject access requests with confidence.
The regulatory environment continues to evolve, and expectations for SAR compliance are rising. Organisations that proactively address redaction challenges position themselves not only to avoid penalties but to build trust with employees, customers, and stakeholders who value responsible data handling.
Need expert SAR redaction support?
Our specialist team delivers defensible redaction with a full audit trail. Fixed fee, on your case within 24 hours, from £495 per case.
Get Your Free SAR Assessment →Frequently Asked Questions
What is the most common SAR redaction mistake?
Failing to identify all third-party personal data is the most frequent error. Third-party information is often embedded in email threads, meeting notes, CC lines and attachments where it is easily overlooked during review — particularly under deadline pressure.
Is over-redaction as serious as under-redaction?
Yes. Over-redaction withholds information the requester is legally entitled to receive and is a breach of Article 15 in its own right. The ICO treats both over-redaction and under-redaction as compliance failures, and over-redaction is one of the most common grounds for SAR complaints.
How do I prove my redaction decisions were correct?
Maintain a redaction schedule documenting every redaction, the legal basis relied upon, the specific prejudice that would result from disclosure, and who made and reviewed the decision. Contemporaneous documentation is the only reliable defence if a decision is later challenged.