DSAR Exemptions: Regulatory, Parliamentary and Judiciary

SAR Exemptions 05 Regulation Parliament Judiciary Thumbnail

This guide explains what the DSAR regulatory and parliamentary exemption actually covers. It explains why it’s easy to over-apply. It also explains how ProvePrivacy’s DSAR Redaction Tool helps data protection teams apply it correctly.

What is the DSAR regulatory and parliamentary exemption?

Schedule 2, Part 1 of the Data Protection Act 2018 sets out a group of exemptions. These cover certain regulatory functions, Parliamentary privilege, and judicial or Crown functions. Several of these protections apply only “to the extent” that disclosure would be likely to prejudice the proper discharge of that function. This includes the regulatory functions exemption, the Bank of England’s functions, and named regulators. It is a prejudice test, not a blanket exclusion.

Does the DSAR regulatory and parliamentary exemption apply to regulators in general?

No. This is the most common misconception. The DSAR regulatory and parliamentary exemption does not apply to regulators in general. It applies to a defined, named list of functions and bodies set out in the Data Protection Act 2018. An organisation cannot rely on this exemption simply because it carries out some regulatory activity. The specific function has to fall within the scope Parliament actually legislated for.

How does the prejudice test work for the DSAR regulatory and parliamentary exemption?

Where the exemption is prejudice-based, the organisation must show that disclosure would be likely to prejudice the proper discharge of the relevant function. It is not enough to show that disclosure would merely be inconvenient or embarrassing. “Likely to prejudice” sets a real evidential bar.

  • Identify precisely which named function or protection is being relied on.
  • Establish a genuine, evidenced causal link between disclosure and prejudice to that function.
  • Apply the exemption only to the specific information that would cause that prejudice, not the whole file.

What about Parliamentary privilege and judicial functions?

Separate protections in the same part of Schedule 2 cover Parliamentary privilege. They also cover certain judicial and Crown functions, including judicial appointments and honours. These sit alongside the general right of access, rather than replacing it. They are narrow, function-specific carve-outs. They are not a general exemption for anything connected to Parliament or the courts.

What happens if the DSAR regulatory and parliamentary exemption is applied too broadly?

Over-applying a prejudice-based exemption is a common, costly mistake. Withholding an entire case file because one function within it might qualify is a common error. The correct approach isolates only the specific information that meets the prejudice test. Getting this wrong exposes an organisation to an ICO complaint. It also undermines the requester’s statutory right of access.

A practical example of the DSAR regulatory and parliamentary exemption

Consider a financial services firm handling a SAR from a former employee. The case file includes internal notes and correspondence with a named financial regulator about an ongoing supervisory review.

The firm cannot withhold the whole file simply because a regulator is mentioned. It must first check whether the regulator’s function is on the named list in Schedule 2, Part 1. It then has to show, with evidence, that disclosure of the specific correspondence would be likely to prejudice that regulator’s supervisory function.

General background notes that do not touch the supervisory review stay disclosable. Only the correspondence that would genuinely prejudice the regulator’s work can be withheld under the DSAR regulatory and parliamentary exemption. This document-by-document approach is what keeps the exemption defensible if challenged.

Frequently asked questions about the DSAR regulatory and parliamentary exemption

Which regulators can rely on the DSAR regulatory and parliamentary exemption? Only the specific, named regulators and functions listed in Schedule 2, Part 1 of the Data Protection Act 2018. A body cannot rely on it simply because it performs some regulatory activity.

Does the exemption cover an entire regulatory investigation file? No. It only covers the specific information whose disclosure would be likely to prejudice the named function. The rest of the file remains disclosable in the normal way.

Can Parliamentary privilege be used outside the named functions? No. Parliamentary privilege and judicial functions are narrow, function-specific protections. They cannot be stretched to cover general activity connected to Parliament or the courts.

What evidence should be kept when applying this exemption? Keep a documented rationale showing which named function was relied on, and the evidenced link between disclosure and prejudice to that function. This record is essential if the ICO later reviews the decision.

Key takeaways on the DSAR regulatory and parliamentary exemption

  • The exemption applies only to a defined, named list of regulators and functions, not to regulators in general.
  • Most protections in this exemption use a prejudice test, so genuine evidence of harm is required, not inconvenience.
  • Parliamentary privilege and judicial functions are separate, narrow carve-outs within the same part of Schedule 2.
  • Assess and redact document by document — withholding an entire file is a common and risky over-application.
  • Keep a documented rationale for every decision, in case the ICO later reviews the assessment.

Manual assessment vs a structured DSAR redaction tool

Factor Manual, ad hoc assessment ProvePrivacy DSAR Redaction Tool
Identifying the correct named exemption Relies on individual legal knowledge, case by case Structured exemption library keeps assessments consistent
Evidencing the prejudice test Rationale often undocumented Documented decision and rationale per redaction
Avoiding over-redaction of a whole file Risk of blanket withholding under time pressure Applies the exemption to the specific information only

How does ProvePrivacy help with the DSAR regulatory and parliamentary exemption?

ProvePrivacy is the affordable GDPR compliance software built for data protection teams in resource-constrained, mid-market organisations. It’s a genuine OneTrust alternative, with all modules included and unlimited users.

Its DSAR management software includes a built-in DSAR Redaction Tool, available as standard to every client. It helps teams apply narrow, function-specific exemptions like this one accurately, with a documented rationale for every decision.

Book a demo today to see how ProvePrivacy’s RoPA, risk, incident and DSAR modules work together in one governed platform.

Sources

Scroll to Top

Contact us

If you would like to ask more questions or to arrange training, complete the form below and we will respond shortly.

Prefer to schedule a 15 minute call? Schedule call today >>

See our Privacy Statement for more details.