How to Redact Personal Data Correctly for GDPR DSARs

A practical guide to redacting third-party personal data when responding to data subject access requests. For IT admins, office managers, clinics, schools, and small businesses.

Why Redaction Matters

🚨 Sending unredacted data is a data breach

When you respond to a DSAR, you must only provide the requester's personal data. If you accidentally include other people's personal data (third-party data), you've caused a data breach that may need to be reported to the regulator.

Many GDPR fines have been issued for exactly this mistake — organisations sending complete documents without removing references to other individuals.

What to Redact

Third-party personal data includes:

  • Names of other people Colleagues, customers, suppliers, family members mentioned in documents
  • Email addresses Any email address that isn't the requester's
  • Phone numbers Mobile, home, or work numbers of third parties
  • Addresses Physical addresses of other individuals
  • Identifiers Employee numbers, customer IDs, account numbers of others
  • Signatures Handwritten signatures of third parties on documents

What NOT to Redact

Keep the following visible:

  • The requester's own data All information about the data subject themselves
  • Company/business names Organisation names are not personal data
  • Job titles (usually) Generic job titles without names are typically fine
  • Public information Information that is genuinely publicly available

🔧 Redaction Methods

⚠ Common mistake: fake redaction

Black highlighting over text, white boxes, or changing text colour to white are NOT proper redaction. The text can often still be copied, searched, or revealed.

Correct Methods

  • Professional redaction software
  • Adobe Acrobat redaction tool
  • Print, manually redact, rescan
  • AI-powered redaction tools

Incorrect Methods

  • Black highlight in Word
  • White boxes over text
  • Changing text to white
  • Using opaque shapes in PDFs

🏢 Industry-Specific Examples

Healthcare / Clinics

Patient records may contain:

  • Referring doctor names
  • Staff who treated patient
  • Family member contacts
  • Other patient names (in shared appointment records)

Schools / Education

Student records may contain:

  • Teacher names and comments
  • Other students' names
  • Parent/guardian details
  • Social worker information

HR / Employment

Employee records may contain:

  • Manager names and feedback
  • Colleague references
  • Disciplinary witnesses
  • Emergency contacts

Customer Service

Support records may contain:

  • Agent names
  • Supervisor names
  • Other customers mentioned
  • Technical staff details

Need help with redaction?

SAR Portal's AI automatically detects and redacts third-party personal data from your documents. Human review, full audit trail.

Try SAR Portal Free

14-day free trial. No credit card required.

Handle DSARs the right way

SAR Portal guides you through every step of GDPR compliance — from request intake to final response.

Start Free Trial See How It Works