Redaction is the process of removing or obscuring information from documents before disclosure. When responding to a Subject Access Request, organisations walk a careful legal tightrope: provide the data subject with all information to which they are entitled, while simultaneously protecting information that falls outside the scope of the request or that would harm others if disclosed.

Part of our pillar guide SAR Redaction Service: The Complete UK Business Guide →

The Legal Framework for SAR Redaction

The legal basis for redaction stems from multiple provisions within UK data protection legislation. The UK GDPR and Data Protection Act 2018 contain several exemptions and qualifications that permit — or in some cases mandate — the redaction of certain information.

First and foremost, a SAR only entitles the requester to access their own personal data. Any information that does not constitute the requester's personal data falls outside the scope of the request entirely and should be redacted. This is not technically an exemption — it simply reflects the proper interpretation of what a SAR covers.

Beyond this fundamental principle, the Data Protection Act 2018 provides specific exemptions that permit redaction in defined circumstances, even where information does constitute the requester's personal data.

Third-Party Personal Data

One of the most common reasons for redaction involves protecting the personal data of third parties. When a document contains information about individuals other than the requester, that information must generally be redacted unless disclosure would be reasonable in all the circumstances.

The reasonableness test considers: the type of information, any duty of confidentiality owed to the third party, steps taken to seek consent, whether the third party can give consent, and any express refusal of consent. Handling SARs from former employees often raises complex third-party considerations, particularly where the requester's data is intertwined with information about colleagues.

Categories of Information That Can Be Redacted

Confidential References

Employment references given in confidence are exempt from disclosure under Schedule 2, Part 2, paragraph 1 of the Data Protection Act 2018. This exemption applies only to references given by the data controller — it does not extend to references received about the data subject.

If an organisation holds a reference it gave about the requester to another employer, that reference can be withheld in full. However, references received about the data subject from previous employers generally must be disclosed, though redaction of the referee's identity may still be appropriate.

Management Planning Information

Information revealing management plans or proposals that relate to the data subject may be redacted if disclosure would prejudice the effective conduct of those plans. This exemption (Schedule 2, Part 2, paragraph 12) commonly applies to restructuring plans, redundancy proposals or succession planning documents.

The exemption only applies where disclosure would be likely to prejudice the planning process. Once a plan has been implemented or abandoned, the rationale for withholding ceases to apply.

Legal Professional Privilege and Legal Advice

Legal professional privilege is a well-established principle that protects confidential communications between a client and their legal adviser. Schedule 2, Part 3, paragraph 18 of the Data Protection Act 2018 exempts data from disclosure where a claim to legal professional privilege could be maintained in legal proceedings.

This covers both legal advice privilege (communications between lawyer and client for the purpose of giving or receiving legal advice) and litigation privilege (communications made for the dominant purpose of actual or contemplated litigation).

Privilege belongs to the client, not the lawyer. In-house legal advice is privileged; advice from non-lawyer employees or external consultants generally is not. The cost of getting a SAR wrong can be substantial, particularly if privileged material is inadvertently disclosed.

Crime Prevention and Detection Exemptions

Where disclosure of information would be likely to prejudice the prevention or detection of crime, the apprehension or prosecution of offenders, or the assessment or collection of tax, organisations may rely on exemptions under Schedule 2, Part 1, paragraphs 2 and 4.

This exemption requires a genuine and present risk of prejudice — mere speculation is insufficient. It commonly applies to information about ongoing investigations, fraud prevention measures or security arrangements, and is applied on a case-by-case basis only to the extent necessary to protect the relevant interest.

Key Tip

Document your redaction decisions thoroughly. For each redaction, record the legal basis, the specific prejudice that would result from disclosure, and why redaction is proportionate. This contemporaneous reasoning will be invaluable if your decision is later challenged by the ICO or in court.

Practical Application: Implementing Redaction Policies

Determining what can be redacted requires careful judgement and consistent application of legal principles. Organisations should develop clear internal policies that guide staff through the redaction process.

Begin by identifying all personal data that falls within the scope of the request — this is information about the data subject that must be disclosed unless an exemption applies. Then systematically review documents for third-party data, privileged material and other exempt categories.

Apply the proportionality test: even where an exemption technically applies, consider whether full or partial redaction is actually necessary. The exemptions are permissive, not mandatory. Where possible, disclose information with minimal redaction to respect the data subject's right of access. Responding to employee SARs effectively often means finding solutions to disclose the maximum amount of information lawfully possible.

Technical Redaction Methods

Physical redaction must be permanent and irreversible. Simply covering text with a black box in a PDF editor is often insufficient — the underlying text may remain recoverable from metadata or layers.

Use dedicated redaction tools that permanently remove underlying data. For paper documents being scanned, apply redaction before scanning. Never rely on digital redaction methods that leave the original text technically recoverable.

Common Mistakes and How to Avoid Them

One frequent error is over-redaction — withholding information that does not genuinely fall within an exemption. This often stems from a defensive mindset or insufficient understanding of what constitutes the requester's personal data. Information about the requester, even if it reflects badly on them or relates to disciplinary matters, generally must be disclosed.

Another common mistake is inconsistent application across documents. If you redact the name of a colleague in one email but not in another, the redaction becomes pointless. Systematic document review and clear redaction protocols maintain consistency. Understanding SAR deadlines is crucial — rushed redaction decisions under time pressure frequently lead to errors.

Finally, failing to explain redactions to the data subject causes unnecessary friction. A brief covering letter explaining that certain information has been redacted to protect third-party rights or under applicable exemptions helps manage expectations and reduces the likelihood of complaints or ICO referrals.

Need expert help with SAR redaction?

Our specialist team provides defensible redaction with a full audit trail. Fixed fee, on your case within 24 hours, from £495 per case.

Get Your Free SAR Assessment →