SafeRedact
UK GDPR 2026 · 7 min read

ICO DSAR Redaction Guidance Explained

The UK Information Commissioner's Office publishes the most practical guidance available on redacting third-party data in DSAR responses. Whether you operate under UK GDPR or EU GDPR, the ICO's framework provides a clear, defensible methodology for the redaction decisions that make DSARs so challenging.

This page walks through the ICO's guidance in detail, analyzes the key case law that shapes its application, and provides worked examples for common scenarios. For the broader DSAR redaction process, see our definitive DSAR redaction guide.

The statutory foundation

The right to third-party redaction comes from two sources. Article 15(4) of the UK GDPR states that the right to obtain a copy of personal data "shall not adversely affect the rights and freedoms of others." Section 45 of the Data Protection Act 2018 then provides that a controller is not obliged to disclose personal data to the extent that doing so would involve disclosing information relating to another identifiable individual: unless that individual has consented or it is reasonable to comply without consent.

The ICO's guidance translates these legal provisions into a practical three-step test that controllers should apply to every piece of third-party data in a DSAR response.

The three-part balancing test

Question 1: Can you comply without disclosing?

This is the starting point. Before considering anything else, ask whether the third-party information can be separated from the requester's data without making the response unintelligible. In many cases, redacting names, email addresses, and contact details allows you to disclose the substance of a document while protecting the third party.

Example: an email thread discussing the employee's performance review. You can redact the HR business partner's name and email address while preserving the content of the discussion that relates to the requester. The employee gets their personal data; the third party's identity is protected.

However, the ICO acknowledges that simple name redaction doesn't always work. If the requester had a single line manager, redacting the manager's name from a performance review is futile: the requester will obviously know who wrote it. In these situations, you move to Question 2.

Question 2: Has the third party consented?

If redaction alone doesn't solve the problem, consider whether you can obtain the third party's consent to disclosure. This is straightforward in some situations, a colleague might readily agree to their name appearing in a routine meeting note, and completely inappropriate in others.

The ICO emphasizes that you are not obliged to seek consent. There are many legitimate reasons not to: it may be impractical (the third party is a former employee with no current contact details), it may be inappropriate (seeking consent would reveal that a DSAR has been submitted, which may be sensitive in a disciplinary context), or it may simply not be feasible within the response timeline.

Question 3: Is it reasonable to disclose without consent?

This is where the balancing exercise happens. The ICO identifies several factors to weigh:

The type of information involved. Routine business communications carry less sensitivity than health data, financial details, or confidential opinions about the requester.

Any duty of confidentiality owed to the third party. Information provided during a grievance investigation with an explicit promise of confidentiality carries more weight than a casual email between colleagues.

Whether the third party would expect disclosure. A manager conducting a formal appraisal might reasonably expect the employee to see the review. A colleague who provided anonymous feedback would not.

Whether the individual can be identified from the information. If the third party remains anonymous even after disclosure (e.g., "feedback from a peer" with no identifying details), disclosure may not engage the exemption at all.

Any steps taken to seek consent. If you attempted to obtain consent and failed, that weighs in favor of withholding. If seeking consent was impractical, document why.

Harrison v Cameron [2024]: The leading case

The High Court case of Harrison v Cameron and Anor [2024] EWHC 1377 (KB) is the most significant recent case on third-party data in DSAR responses. The facts are instructive for any organization handling employee or business-relationship DSARs.

A property developer (Harrison) and a landscaping company director (Cameron) had a business relationship that deteriorated. Cameron recorded heated phone conversations and shared them with employees, family members, and business contacts. Harrison submitted a DSAR seeking the identity of everyone who received the recordings: information that was clearly personal data about the recipients.

The court confirmed three key principles. First, the controller (Cameron's company) was the "primary decision maker" when applying the third-party exemption and had a "wide margin of discretion." Courts will not second-guess reasonable decisions. Second, the absence of third-party consent was not determinative: the reasonableness test under Question 3 was the deciding factor. Third, the court found it was reasonable to withhold the recipients' identities because there was evidence that disclosure could expose them to threatening behavior.

The practical takeaway: document your reasoning thoroughly. If you exercise the discretion reasonably, with reference to the ICO's factors, your decision is likely to withstand challenge.

Worked examples

Scenario 1: Performance review with named colleagues

A performance review for Employee A mentions three colleagues by name: "A worked closely with Sarah on the Q3 project, and feedback from James and Priya was positive." Employee A submits a DSAR.

Analysis: The feedback about Employee A is their personal data and must be disclosed. The colleagues' names are third-party data. Apply Question 1: can you redact the names without making the document unintelligible? Yes: replace with "[Colleague 1]", "[Colleague 2]", "[Colleague 3]." The substance of the review remains intact.

Scenario 2: Grievance investigation witness statement

Employee B filed a grievance. Employee C provided a witness statement with an expectation of confidentiality. Employee B submits a DSAR.

Analysis: Employee B is entitled to know what was said about them (their personal data), but the witness's identity was provided in confidence. Question 1: can you redact the witness's identity? Possibly, anonymize the statement. Question 3: would disclosure of the witness's identity be reasonable? Given the explicit confidentiality, likely not. Disclose the substance of the statement with the witness anonymized, and document that the confidential reference/information exemption was applied.

Scenario 3: Email thread about redundancy planning

An internal email between three managers discusses which roles to make redundant. Employee D, who was later made redundant, submits a DSAR.

Analysis: The discussion about Employee D's role is their personal data. However, the management forecasting exemption (DPA 2018, Schedule 2, Part 3, Para 22) may apply to strategic planning elements. Redact other employees' names and roles. If the redundancy process is concluded, the time-limited management forecasting exemption may no longer apply: disclose the portions relating to Employee D's selection, with third-party identifiers redacted.

Consistent, documented redaction is the foundation of defensible DSAR responses. SafeRedact's AI detects every piece of PII across your DSAR documents, and the review interface lets you make per-item keep/redact decisions that map directly to the ICO's balancing test. Try it free →

Practical tips for applying the ICO guidance

Default to redaction. When the balancing test is unclear, redact. A regulator is far more likely to criticize accidental disclosure of third-party data than over-redaction. You can always re-disclose if challenged; you cannot un-disclose.

Use consistent anonymization. If you redact a name, use the same placeholder consistently across all documents ("[Person 1]" everywhere, not "the manager" in some places and "[REDACTED]" in others). Inconsistency makes your response harder to read and suggests a disorganised process.

Explain your redactions. The covering letter should state that third-party personal data has been redacted in accordance with Article 15(4) and Section 45 of the DPA 2018, and that specific exemptions have been applied where indicated. You don't need to justify each individual redaction in the letter, but your internal records should contain the detail.

Seek legal advice for complex cases. Employment-related DSARs with litigation potential, DSARs involving whistleblowing or safeguarding, and requests where the balancing test yields genuinely ambiguous results should be reviewed by someone with data protection law expertise.

Frequently asked questions

What is the ICO's balancing test for DSAR redaction?

A three-step sequential test: (1) can you comply without disclosing the third party's data? (2) has the third party consented? (3) is it reasonable to disclose without consent? Controllers should work through these questions for each piece of third-party data.

Is the ICO guidance legally binding?

No, but it carries significant persuasive weight. Courts and tribunals regularly reference ICO guidance, and departing from it without good reason weakens your position in any regulatory challenge.

What did Harrison v Cameron decide?

The High Court confirmed that the controller is the "primary decision maker" with a "wide margin of discretion" when applying the third-party exemption. The court upheld the decision to withhold identities where disclosure would create a risk of harm to the third parties.

Should staff names be redacted in a DSAR response?

Not automatically. ICO guidance treats information about employees acting in a professional capacity as generally more reasonable to disclose than information about private individuals. Weigh the person's seniority and role, their reasonable expectations, any duty of confidentiality, and any express refusal of consent. A decision made by a senior manager in their official role will usually be disclosable; a junior employee's identity may deserve more protection.

Do I have to disclose every email that mentions the requester?

No. The right of access covers information that is about the person, not every document that contains their name or email address. An email that merely copies the requester, or mentions them in passing, may contain little or none of their personal data. Disclose the personal data within a document, and redact the material that is not their personal data or that engages an exemption.

Can opinions be withheld because they are not facts?

No. Personal data includes opinions about an individual, so an opinion expressed about the requester is their personal data and is disclosable unless an exemption applies. What may need protection is the identity of the person who gave the opinion, which is assessed under the third-party balancing test, particularly for witness statements and HR records.

What is third-party redaction?

Third-party redaction is the removal of other people's personal data from documents before they are disclosed in a DSAR response. Article 15(4) provides that the right to a copy must not adversely affect the rights and freedoms of others, so names, contact details, opinions, and identifying context belonging to other individuals are redacted unless consent or the balancing test supports disclosure.

What can be withheld beyond third-party data?

Schedule 2 of the Data Protection Act 2018 contains further exemptions, including legal professional privilege, confidential references, management forecasting, and records of negotiations. Each applies item by item, never as a blanket, and the remainder of a document must still be disclosed. Our guide to witness statements and HR files covers the exemptions most often encountered in employee DSARs.

Does a DSAR give a right to whole documents?

No. The right of access is a right to personal data, not to documents. Supplying copies of documents is usually the practical way to comply, with the material that is not the requester's personal data, or that is exempt, redacted. That is why a long email thread can properly be disclosed with entire sections removed where they say nothing about the requester.

How SafeRedact Fits

SafeRedact is browser-based redaction software for data subject access requests. Files never leave your browser: documents are processed client-side, only extracted text is sent for AI detection, and no documents are stored on servers. Detection text is never used for training and is deleted within 30 days. You name the data subject whose information should be preserved, and other individuals' personal information is flagged for redaction across every file in the case, including ZIP and Purview PST exports. Every detection is reviewed by a human before anything is exported, and the export package includes the redacted files, a processing summary, an audit trail and a review decision log. Supported formats: PST, PDF, DOCX, XLSX, EML, MSG, HTML, TXT, CSV, JSON, ZIP. A Data Processing Agreement is available and enterprise cases are priced per case, with the price set with you and shown before you download.

Make Every Redaction Decision Once

AI detection flags every identifier in the case. You decide whose it is, with the requester's data preserved and every decision recorded in the exported audit trail. Cases are priced per case, with a Data Processing Agreement available.

Start Your Evaluation

This page is informational, not legal advice. The legislation, regulator guidance, and your counsel govern how the rules apply to your organization.