The DSAR third party exemption is the rule that a controller need not disclose information where doing so would identify another individual. It applies unless that person has consented. It also applies where disclosure without consent is reasonable in the circumstances. This is set out in UK GDPR Article 15(4). It is supported by the Data Protection Act 2018.
Case notes, email chains, meeting minutes and complaint files almost always contain personal data about people other than the requester. Because of this, the DSAR third party exemption comes up in nearly every subject access request an organisation handles, not just the complex ones.
Why isn’t deleting the third party’s name enough?
Deleting an obvious name is not enough on its own. A job title, a date, a department or another distinguishing detail can still let the requester work out exactly who the third party is.
The exemption exists because personal data rarely sits in isolation. It is defined by context, not by a single field on a page. Role, date, location and relationship can combine to identify someone just as clearly as a name would.
Identifiability has to be tested against what the requester already knows. It also has to be tested against what they could reasonably obtain elsewhere. It is not enough to consider only what is visible on the page in front of the redactor.
How do you decide whether to disclose third party data?
The Information Commissioner’s Office (ICO) sets out a three-step process for handling third party data in a SAR response:
- Identify whether the information is genuinely about someone other than the requester.
- Decide whether that third party has consented to disclosure.
- If they haven’t, weigh up all the circumstances to decide whether it is reasonable to disclose without consent.
Relevant circumstances include any duty of confidentiality owed to the third party. They also include steps already taken to seek their consent, whether they are capable of giving consent, and any express refusal they have given. None of these factors is decisive alone. The assessment has to weigh them together, case by case.
Is there a presumption of reasonableness for professionals?
Yes. Where the third party is a health, social work or education professional acting in that professional capacity, disclosure of their identity is generally presumed reasonable. Examples include a GP named in a care record, or a teacher named in a safeguarding file. This applies to information they provided in their professional role, unless there is a specific reason not to disclose it.
This presumption does not extend to third parties acting in a personal capacity. A family member, a witness, or a colleague mentioned incidentally still needs the full three-step reasonableness assessment, applied case by case.
What happens when a SAR response involves dozens of documents?
Large case files raise the stakes. A single missed indirect identifier, repeated across dozens of documents, becomes a pattern rather than a one-off mistake. Reviewers under time pressure, working towards the statutory one-month deadline, are more likely to apply the third party test inconsistently from document to document.
This is exactly where a structured, repeatable process for the DSAR third party exemption matters most. It matters less on easy, single-document requests. It matters most on high-volume, high-risk ones.
Frequently asked questions about the DSAR third party exemption
What counts as third party data in a SAR? Third party data is any information in a case file that identifies someone other than the requester. This includes names, job titles, email addresses and any detail that could reveal who a person is, even without naming them directly.
Can you always redact a third party’s name and move on? No. Removing a name is a good first step, but details like a role, date or department can still identify someone. Each case needs the full three-step assessment, not just a name search.
Do you always need consent to disclose third party data? Consent is the simplest route. If a third party consents, you can share their data. Without consent, you must weigh up the circumstances and decide if disclosure is reasonable.
What if the third party objects to disclosure? An objection is relevant, but it is not automatically decisive. Weigh the objection alongside other circumstances, such as any duty of confidentiality and whether the third party is capable of giving consent.
Key takeaways on the DSAR third party exemption
- Redacting a name alone is rarely enough — role, date, location and relationship can still identify someone.
- Follow the ICO’s three-step process for every third party: identify, check consent, then weigh reasonableness.
- Professionals acting in a professional capacity carry a presumption of reasonable disclosure; personal-capacity third parties do not.
- Large, high-volume case files carry the greatest risk of inconsistent, document-by-document mistakes.
- Keep a documented rationale for every redaction decision, in case the ICO later reviews the assessment.
Manual redaction vs a structured DSAR redaction tool
| Factor | Manual redaction (spreadsheets/PDF tools) | ProvePrivacy DSAR Redaction Tool |
|---|---|---|
| Consistency across a large case file | Relies on one reviewer’s judgement; easy to miss indirect identifiers | Structured workflow applies the same third-party test across every document |
| Audit trail | Often informal or absent | Documented decision and rationale for each redaction |
| Speed on high-volume requests | Slow, especially against the statutory one-month SAR deadline | Built for organisations managing DSARs at volume |
| Evidence for the ICO | Difficult to reconstruct after the fact | Clear, exportable record of how third party identifiability was assessed |
How does ProvePrivacy help with the DSAR third party exemption?
ProvePrivacy is the affordable GDPR compliance software built for data protection teams in resource-constrained, mid-market organisations. It’s a genuine OneTrust alternative, with all modules included and unlimited users.
Its DSAR management software includes a built-in DSAR Redaction Tool, available as standard to every client. It applies the DSAR third party exemption consistently across case files, and keeps a documented rationale for every decision. This reduces the risk of both over-disclosure and unnecessary redaction.
Book a demo today to see how ProvePrivacy’s RoPA, risk, incident and DSAR modules work together in one governed platform.



