What is DSAR redaction?
DSAR redaction is the practice of separating data (including personal data) that is legally exempt from disclosure from the rest of a subject access request response, so the exempt part is withheld and everything else is released. It is the practical mechanism that turns a legal exemption into a defensible, disclosable response. DSAR and SAR both refer to the same right, the data subject access request, and the terms are used interchangeably across UK data protection practice.
A subject access request rarely produces a simple answer. Most case files mix information the requester is entitled to with information that is genuinely exempt, often in the same email, the same case note, or the same paragraph. The question a data protection team has to answer is almost never disclose everything or refuse everything. It is which specific parts, and on what legal basis. Get the underlying exemption wrong, and a well executed redaction will not save the response. Get the redaction wrong, applying it too broadly or too narrowly, and even a correctly identified exemption will not either.
This guide sets out the legal principle behind every SAR exemption in the Data Protection Act 2018, then works through all eight exemption categories covered in our SAR Exemptions guide series, from health and social work data through to the general rule protecting other people’s identities. Each guide in the series goes into far more depth on its own category. Treat this article as the map, and the guides as the terrain.
What is a SAR exemption under the Data Protection Act 2018?
A SAR exemption is a specific provision in Schedule 2 or Schedule 3 of the Data Protection Act 2018 that allows a controller to restrict some or all of a data subject’s right of access under Article 15 UK GDPR, where a defined legal test is met. Common tests include serious harm, prejudice, and impairment of a specific purpose.
Each exemption is narrow by design. It applies to a defined category of information, such as health data or crime related data, and only where a stated outcome, such as serious harm or prejudice to an investigation, would actually result from disclosure. According to the ICO’s official guidance on subject access exemptions, controllers must assess each exemption against its own test rather than treating any single exemption as a general licence to withhold.
Can you withhold a whole document because part of it is exempt?
No. Nearly every SAR exemption in Schedule 2 and Schedule 3 is qualified by the phrase to the extent, meaning the exemption applies only to the specific information that meets the legal test, not to the whole document, case file, or record it appears in.
The crime and taxation exemption applies to the extent disclosure would prejudice the prevention or detection of crime. The health data exemption applies to the extent disclosure would be likely to cause serious harm. The negotiations exemption applies to the extent disclosure would prejudice the organisation’s negotiating position. In every case, the exemption is a property of specific information, not a property of the document that contains it.
Withholding an entire document because part of it qualifies is over withholding, and it denies a requester information they were legally entitled to. Disclosing an entire document because most of it does not qualify is under protection, and it risks exactly the harm the exemption exists to prevent. DSAR redaction is the discipline that resolves this correctly: assess each piece of information against the relevant test, then separate what is exempt from what is not, rather than making one decision for the whole record.
What are the 8 SAR exemption categories in the Data Protection Act 2018?
The Data Protection Act 2018 groups the exemptions relevant to subject access requests into eight practical categories, each covering a distinct legal test and a distinct set of protected interests.
| Category | Core legal test | Statutory basis |
|---|---|---|
| Health, social work, education and child abuse data | Serious harm, or best interests of the child | Data Protection Act 2018, Schedule 3 |
| Crime, law and public protection | Prejudice to crime, tax, immigration or legal proceedings | Data Protection Act 2018, Schedule 2, Part 1 |
| Finance, management and negotiations | Prejudice to a specific commercial activity | Data Protection Act 2018, Schedule 2, Part 1 |
| References and exams | Confidentiality, and statutory disclosure deadlines | Data Protection Act 2018, Schedule 2 |
| Regulation, Parliament and the judiciary | Prejudice to a named regulator, Parliament or the courts | Data Protection Act 2018, Schedule 2, Part 2 |
| Journalism, research and archiving | Prevention or serious impairment of the purpose | Data Protection Act 2018, Schedule 2, Part 5 |
| Legal professional privilege and self incrimination | Common law and criminal law doctrine | Data Protection Act 2018, Schedule 2, Part 4 |
| Protecting third party identities | Reasonableness of disclosure without consent | Data Protection Act 2018, general provision |
Each category is covered in full depth in its own guide, referenced in the sections below.
How does the health, social work, education and child abuse data exemption work?
This exemption restricts subject access to the extent disclosure would be likely to cause serious harm to the physical or mental health of the data subject or another individual, with a related best interests of the child test for child abuse data specifically.
This is the highest stakes category in the whole series, because it protects the data subject and other individuals, not the organisation holding the data. Three of the four Schedule 3 data types share the serious harm test, and it is a high bar, not met by information that is simply upsetting or embarrassing. For health data, the assessment cannot normally come from your own organisation alone. Getting the category right, and holding a properly reasoned, documented assessment for each piece of information, is what separates a defensible redaction from a guess. Read the full detail in our guide, SAR Exemptions: Health, Social Work, Education and Child Abuse Data.
How does the crime, law and public protection exemption work?
This exemption restricts subject access to the extent disclosure would prejudice the prevention or detection of crime, the assessment or collection of tax, effective immigration control, or a legal proceeding.
The to the extent wording means a document by document, or even paragraph by paragraph, assessment of where disclosure would actually cause prejudice, not a blanket withhold across an entire investigation file. Over claiming this exemption, by withholding a whole case file because it touches a live matter somewhere within it, is a common and costly error. The immigration limb has attracted direct legal challenge: litigation brought by the Open Rights Group and the3million revealed that the Home Office was applying the immigration exemption to around 60 percent of immigration related data requests, and a subsequent Court of Appeal judgment led Parliament to amend the exemption itself. Read the full detail in our guide, SAR Exemptions: Crime, Law and Public Protection.
How does the finance, management and negotiations exemption work?
This exemption restricts subject access to the extent disclosure would prejudice a specific commercial activity: the price of a listed financial instrument, a live and sensitive business forecast, or an organisation’s own negotiating position.
Each of the three exemptions protects something narrower than it sounds. Corporate finance protects price sensitive information connected to a listed instrument, not every document connected to a transaction. Management forecasts protect a genuinely live business plan, not historical figures once the sensitivity has passed. Negotiations protect the record of an organisation’s own negotiating position specifically, not an employee’s entire personnel file simply because they happen to be negotiating with their employer. Read the full detail in our guide, SAR Exemptions: Finance, Management and Negotiations.
How does the references and exams exemption work?
This exemption protects confidential references given for education, training, employment or office purposes, and separately governs when exam scripts and exam marks must be disclosed and on what timescale.
A confidential reference exemption travels with the reference to whichever organisation holds it, provided it was given in confidence for a listed purpose, protecting the recipient as much as the person who wrote it. Exam scripts are exempt from disclosure outright, with no proportionality test applied. Exam marks are not withheld outright, only delayed, until the earlier of five months from the request or forty days from the results being announced. Applying the correct deadline, rather than defaulting to the standard subject access timescale, matters here. Read the full detail in our guide, SAR Exemptions: References and Exams.
How does the regulation, Parliament and judiciary exemption work?
This group of six exemptions restricts subject access where disclosure would prejudice the functions of specific named institutions, including the Bank of England, Parliament, the courts, and defined regulatory bodies.
The six exemptions fall into two structures. Parliamentary privilege and judicial functions are close to absolute, requiring little further balancing once engaged. Audit and regulatory functions are narrower, and the regulatory functions exemption specifically applies only to a defined list of named bodies set out in the schedule, not to any organisation that simply considers itself a regulator. Assuming the exemption applies because a function feels regulatory, without checking the named list, is one of the most common errors in this group. Read the full detail in our guide, SAR Exemptions: Regulation, Parliament and the Judiciary.
How does the journalism, research and archiving exemption work?
This exemption restricts subject access only to the extent disclosure would prevent or seriously impair journalism, scientific or historical research, statistics, or public interest archiving.
The standard across all three activities is an impairment test, not an inconvenience test. Access can be restricted only where disclosure would genuinely prevent or seriously impair the purpose, not simply make it less convenient. The research and statistics exemption also carries specific statutory safeguards, including pseudonymisation so far as compatible with the research purpose, and a prohibition on using the data to make decisions about particular individuals outside approved medical research. Labelling routine internal record keeping as archiving does not meet the bar; the exemption is aimed at genuine, long term public archives. Read the full detail in our guide, SAR Exemptions: Journalism, Research and Archiving.
How does the legal professional privilege and self incrimination exemption work?
This exemption protects confidential communications between a client and their lawyer under legal advice privilege and litigation privilege, and separately prevents a subject access request being used to force self incriminating disclosure, subject to specific statutory limits.
These two exemptions sit apart from the rest of Schedule 2 because neither uses the familiar prejudice test. Instead, they import established common law and criminal law doctrine directly, so applying them correctly means applying the same test a court would apply. Litigation privilege requires litigation to be in reasonable contemplation, an objective test assessed at the time the document was created, not with hindsight once litigation actually follows. The Court of Appeal addressed this directly in Serious Fraud Office v Eurasian Natural Resources Corporation Ltd, finding that documents created before litigation could reasonably have been contemplated will not attract litigation privilege simply because proceedings followed later. The self incrimination exemption does not extend to offences under the Data Protection Act 2018 itself or to certain false statement offences. Read the full detail in our guide, SAR Exemptions: Legal Professional Privilege and Self-Incrimination.
How does the third party identities exemption work?
This is a general rule, sometimes called the rights of others exemption, that restricts disclosure of information identifying another individual unless that person has consented, or it is reasonable to disclose without their consent.
Unlike the other seven categories, this rule is not a single named exemption. It applies to almost every subject access response, regardless of which other exemptions were or were not relevant. The ICO’s guidance sets out a three step process: first, consider whether the request can be answered at all without identifying the third party; second, check whether that person has consented; third, if not, assess whether it is reasonable to disclose without consent. Removing a name is rarely sufficient on its own. A job title, a department and a date are often enough for a requester who knows a small team to work out who is being described, even once the name itself has gone. Read the full detail in our guide, SAR Exemptions: Protecting Third Party Identities.
Does DSAR redaction apply to rights other than subject access?
Yes. Many Schedule 2 and Schedule 3 exemptions disapply more than the right of access, extending to related rights such as rectification, erasure, restriction or objection where the same underlying concern applies, so the same DSAR redaction discipline is relevant beyond Article 15 requests specifically.
This series, and most of this article, focuses on the right of access under Article 15, because that is where exemption and redaction decisions come up most often. Never assume an exemption applied to an access request automatically extends to a different right without checking which specific provisions it disapplies. Apply the same to the extent discipline whichever right is in front of you, including data subject rights cases handled through a Freedom of Information channel where a public authority is involved.
How do you apply DSAR redaction correctly? A 5 step process
DSAR redaction is applied correctly by working through five steps for every response: identify the exemption category, apply its specific legal test to each piece of information, check whether the information identifies a third party, redact only what meets the test, and document the reasoning behind every decision.
- Identify which exemption category may apply. Match the information in front of you to one of the eight categories above, rather than assuming a category based on the type of document.
- Apply the specific legal test to each piece of information. Assess serious harm, prejudice or impairment at the level of the sentence or paragraph, not the whole file.
- Check whether the information identifies a third party. Run the three step reasonableness process, and remember that surrounding detail can identify someone even after their name is removed.
- Redact only what meets the test. Separate the exempt content from the rest of the record, using a consistent, repeatable method rather than an ad hoc judgement call.
- Document the assessment. Record the test applied, the reasoning, and who was consulted, so the decision can be defended later rather than reconstructed after the fact.
Manual redaction vs the ProvePrivacy DSAR Redaction Tool
| Manual redaction | ProvePrivacy DSAR Redaction Tool | |
|---|---|---|
| Assessment method | Ad hoc, reviewer dependent judgement | Structured exemption assessment applied directly against the case |
| Consistency across a team | Varies by reviewer and case load | Consistent process applied every time |
| Audit trail | Often informal or missing | Evidenced and attached to the case record |
| Third party identifiability checks | Manual, easy to miss surrounding detail | Built into the redaction workflow |
| Ease of use | Complex search for redaction candidates | Simple process with candidates highlighted |
How does ProvePrivacy help with DSAR redaction and SAR exemptions?
The DSAR Redaction Tool is included as standard within the ProvePrivacy platform, available to every client, so data protection teams applying these exemptions work from an evidenced, auditable process rather than a manual, document by document judgement call made under deadline pressure. It applies and evidences exemptions like the ones covered in this guide directly against the case, alongside ProvePrivacy’s wider data subject rights case management, records of processing, risk and incident modules. If your team is handling subject access requests, other data subject rights cases or Freedom of Information requests without that kind of structure in place, ask your account manager for a walkthrough.
Further reading: the full SAR Exemptions guide series
The full SAR Exemptions guide series covers each of the eight categories above in complete detail, including the specific statutory tests, the deadlines that apply, and worked examples of where each exemption is commonly misapplied.
- SAR Exemptions: Health, Social Work, Education and Child Abuse Data
- SAR Exemptions: Crime, Law and Public Protection
- SAR Exemptions: Finance, Management and Negotiations
- SAR Exemptions: References and Exams
- SAR Exemptions: Regulation, Parliament and the Judiciary
- SAR Exemptions: Journalism, Research and Archiving
- SAR Exemptions: Legal Professional Privilege and Self-Incrimination
- SAR Exemptions: Protecting Third Party Identities
Frequently asked questions
What is DSAR redaction? DSAR redaction is the practice of separating personal data that is legally exempt from disclosure from the rest of a subject access request response, so only the exempt part is withheld and everything else is released.
What is a SAR exemption? A SAR exemption is a specific provision in Schedule 2 or Schedule 3 of the Data Protection Act 2018 that restricts some or all of a data subject’s right of access, where a defined legal test such as serious harm or prejudice is met.
Does removing a name count as effective redaction under UK GDPR? Not on its own. Surrounding detail, such as a job title, department or date, can still make a person identifiable to a requester who has other knowledge, even after their name has been removed.
Do SAR exemptions apply to rights other than subject access? Many of them do. Several Schedule 2 and Schedule 3 exemptions disapply more than the right of access, extending to rights such as rectification, erasure, restriction or objection, so the same assessment discipline applies across those rights too.
What is the serious harm test? The serious harm test is the legal threshold in Schedule 3 of the Data Protection Act 2018 that exempts health, social work and education data from disclosure only to the extent doing so would be likely to cause serious harm to the physical or mental health of the data subject or another person.
Who can access the ProvePrivacy DSAR Redaction Tool? The DSAR Redaction Tool is included as standard within the ProvePrivacy platform and is available to every client, with an included allowance as part of the subscription.
External Sources:
- ICO: What exemptions are relevant for SARs?
- ICO: A guide to the data protection exemptions
- ICO: When can an exemption apply to information about other people in a SAR?
- Data Protection Act 2018, Schedule 2, Part 1 — legislation.gov.uk
- The Data Protection Act 2018 (Amendment of Schedule 2 Exemptions) Regulations 2024 — legislation.gov.uk
- Serious Fraud Office v Eurasian Natural Resources Corporation Ltd [2018] EWCA Civ 2006 — Find Case Law, The National Archives
- Open Rights Group: Immigration exemption campaign page






