How to Redact Personal Data Correctly for GDPR DSARs
A practical guide to redacting third-party personal data when responding to data subject access requests. For IT admins, office managers, clinics, schools, and small businesses.
⚠ Why Redaction Matters
🚨 Sending unredacted data is a data breach
When you respond to a DSAR, you must only provide the requester's personal data. If you accidentally include other people's personal data (third-party data), you've caused a data breach that may need to be reported to the regulator.
Many GDPR fines have been issued for exactly this mistake — organisations sending complete documents without removing references to other individuals.
✏ What to Redact
Third-party personal data includes:
-
Names of other people Colleagues, customers, suppliers, family members mentioned in documents
-
Email addresses Any email address that isn't the requester's
-
Phone numbers Mobile, home, or work numbers of third parties
-
Addresses Physical addresses of other individuals
-
Identifiers Employee numbers, customer IDs, account numbers of others
-
Signatures Handwritten signatures of third parties on documents
✓ What NOT to Redact
Keep the following visible:
-
The requester's own data All information about the data subject themselves
-
Company/business names Organisation names are not personal data
-
Job titles (usually) Generic job titles without names are typically fine
-
Public information Information that is genuinely publicly available
🔧 Redaction Methods
⚠ Common mistake: fake redaction
Black highlighting over text, white boxes, or changing text colour to white are NOT proper redaction. The text can often still be copied, searched, or revealed.
Correct Methods
- Professional redaction software
- Adobe Acrobat redaction tool
- Print, manually redact, rescan
- AI-powered redaction tools
Incorrect Methods
- Black highlight in Word
- White boxes over text
- Changing text to white
- Using opaque shapes in PDFs
🏢 Industry-Specific Examples
Healthcare / Clinics
Patient records may contain:
- Referring doctor names
- Staff who treated patient
- Family member contacts
- Other patient names (in shared appointment records)
Schools / Education
Student records may contain:
- Teacher names and comments
- Other students' names
- Parent/guardian details
- Social worker information
HR / Employment
Employee records may contain:
- Manager names and feedback
- Colleague references
- Disciplinary witnesses
- Emergency contacts
Customer Service
Support records may contain:
- Agent names
- Supervisor names
- Other customers mentioned
- Technical staff details
Need help with redaction?
SAR Portal's AI automatically detects and redacts third-party personal data from your documents. Human review, full audit trail.
Try SAR Portal Free14-day free trial. No credit card required.
Handle DSARs the right way
SAR Portal guides you through every step of GDPR compliance — from request intake to final response.