
This guide explains what the DSAR crime and law enforcement exemption actually covers. It also explains how ProvePrivacy’s DSAR Redaction Tool helps teams apply it defensibly.
What is the DSAR crime and law enforcement exemption?
The Data Protection Act 2018 allows an organisation to withhold personal data where disclosure would be likely to prejudice one of five things. These are the prevention or detection of crime, the apprehension or prosecution of offenders, the assessment or collection of a tax or duty, the maintenance of immigration control, or a small number of related public protection functions. There are five separate legal bases behind this exemption, each with its own scope and its own prejudice test.
Why is the DSAR crime and law enforcement exemption deliberately narrow?
The exemption only applies to the extent that genuine prejudice would occur. It is not a blanket reason to refuse an entire case file. An organisation involved in a police investigation cannot withhold every piece of personal data connected to that investigation. Only the specific information whose disclosure would genuinely prejudice the investigation qualifies.
How do you apply the five bases of the DSAR crime and law enforcement exemption correctly?
- Crime prevention and detection — disclosure would be likely to prejudice an active or reasonably anticipated investigation.
- Apprehension and prosecution of offenders — disclosure would be likely to prejudice identifying or prosecuting a suspect.
- Tax assessment and collection — disclosure would be likely to prejudice HMRC or a similar body’s tax functions.
- Immigration control — disclosure would be likely to prejudice the maintenance of effective immigration control.
- Other public protection functions — a smaller set of related functions protecting the public from harm.
Each basis has to be assessed and evidenced on its own terms. Treating them as one generic “law enforcement” exemption is a common and risky shortcut.
What goes wrong when the DSAR crime and law enforcement exemption is misapplied?
The two most common errors are withholding an entire file rather than the specific prejudicial information. The other is applying the exemption reflexively whenever a police or HMRC request is involved, without a documented prejudice assessment for that specific disclosure.
A practical example of the DSAR crime and law enforcement exemption
Consider a retailer that receives a SAR from a customer who was previously investigated for suspected fraud. The case file includes CCTV logs, loss-prevention notes, and a reference to an ongoing police enquiry.
The retailer cannot withhold the whole file just because police are involved. It must assess, document by document, whether disclosure would genuinely prejudice the crime prevention and detection basis, or the apprehension and prosecution basis.
Routine loss-prevention notes unrelated to the live enquiry stay disclosable. Only the specific material that would genuinely prejudice the ongoing investigation can be withheld under the DSAR crime and law enforcement exemption. This document-by-document approach is what keeps the exemption defensible if challenged.
Frequently asked questions about the DSAR crime and law enforcement exemption
Does a police request automatically qualify for the DSAR crime and law enforcement exemption? No. Every request needs its own documented prejudice assessment. A police connection alone does not automatically justify withholding data.
Can you withhold a whole case file under this exemption? No. Only the specific information whose disclosure would genuinely prejudice the relevant function is exempt. The rest of the file stays disclosable.
Are all five legal bases assessed the same way? No. Each of the five bases has its own scope and its own prejudice test. Crime prevention, prosecution, tax, immigration and other public protection functions must each be evidenced separately.
What happens if an HMRC tax enquiry overlaps with a criminal investigation? Each basis still needs its own separate assessment. Overlapping investigations do not let an organisation apply one generic test across both.
Key takeaways on the DSAR crime and law enforcement exemption
- There are five separate legal bases, each with its own scope and its own prejudice test.
- The exemption only covers specific information causing genuine prejudice, not an entire case file.
- A police or HMRC connection alone does not automatically justify withholding data.
- Overlapping investigations, such as tax and crime, still need separate assessments for each basis.
- Keep a documented, evidenced rationale for every basis relied on, in case the ICO reviews the decision.
Why getting the DSAR crime and law enforcement exemption right matters
Requests connected to a live investigation are high-stakes on both sides. Under-redacting can compromise an ongoing enquiry, tip off a suspect, or prejudice a prosecution. Over-redacting risks a valid ICO complaint and denies the requester their statutory right.
A structured, evidenced process protects the organisation either way. It ensures every redaction is tied to one of the five legal bases, with a clear rationale that would stand up if the ICO ever asks for it.
Manual assessment vs a structured DSAR redaction tool
| Factor | Manual, ad hoc assessment | ProvePrivacy DSAR Redaction Tool |
|---|---|---|
| Selecting the correct one of five bases | Often generalised into one “law enforcement” exemption | Structured exemption library keeps each basis separate |
| Evidencing the prejudice test | Rationale often undocumented | Documented decision and rationale per redaction |
| Avoiding whole-file withholding | Risk of blanket refusal under time pressure | Applies the exemption to the specific information only |
How does ProvePrivacy help with the DSAR crime and law enforcement exemption?
ProvePrivacy is the affordable GDPR compliance software built for data protection teams in resource-constrained, mid-market organisations, and a genuine OneTrust alternative with all modules included and unlimited users.
Its DSAR management software includes a built-in DSAR Redaction Tool, available as standard to every client. It keeps each of the five legal bases separate and evidenced, with a documented rationale for every decision.
Book a demo today to see how ProvePrivacy’s RoPA, risk, incident and DSAR modules work together in one governed platform.


