DSAR Exemptions: When You Can Withhold or Refuse Data
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
DSAR exemptions are the limited circumstances in which you can withhold data, redact part of a response, or refuse a request entirely. The right of access is broad but not absolute: you must protect other people's personal data, you may withhold material that is legally privileged or covered by a specific exemption, and you can refuse or charge for a request only where it is manifestly unfounded or excessive. Every time you rely on an exemption, you should document the reason.
This is general information, not legal advice. Exemptions are fact-specific and vary by jurisdiction, so check the law that applies and take advice on borderline cases.
The two ways to limit a response
Exemptions work in two ways. Most of the time you still respond, but you redact or withhold certain material within it. Occasionally you may refuse the request as a whole. Refusal is the rare exception; partial withholding is the common case.
| Type | What it means | How common |
|---|---|---|
| Redact third-party data | Remove data about other people | Very common |
| Withhold exempt material | Hold back privileged or exempt content | Occasional |
| Refuse the request | Decline a manifestly unfounded or excessive request | Rare |
Third-party data: the most common exemption
An access request covers the requester's own personal data, not other people's. When a record about the requester also contains someone else's data, you generally redact the third party unless disclosure is reasonable, for example where they have consented or their identity is already known and disclosure causes no harm. This is the exemption you will apply most often, and it is covered in depth in the guide on how to redact a DSAR response. A dedicated redaction step keeps it consistent.
Legally privileged and exempt material
Some material can be withheld rather than redacted piecemeal. Common examples include:
- Legal professional privilege. Confidential legal advice is generally exempt from disclosure.
- Data under legal hold. Material preserved for litigation may be subject to separate rules; withholding it from a routine response can be appropriate, but coordinate with legal.
- Management and negotiation information. Certain internal planning or negotiation data may be exempt depending on the jurisdiction.
- Data that would prejudice specific functions. Some laws exempt data where disclosure would harm functions such as crime prevention or regulatory activity.
Because these depend on the specific legal framework, treat the list as a prompt to check, not a definitive rule. Flag candidates during manifest review rather than at the last minute, which is easier when discovery has produced a clear list to work from through personal data discovery.
Refusing a request: manifestly unfounded or excessive
You can refuse a request, or charge a reasonable fee, only where it is manifestly unfounded or excessive. This is a high bar, not a convenience.
Manifestly unfounded
A request might be manifestly unfounded where the person clearly has no genuine intention to exercise the access right, for example where the request is made purely to harass or is explicitly used as a bargaining chip. The volume of data or the effort involved does not, on its own, make a request unfounded.
Excessive
A request may be excessive where it repeats a request you have already satisfied within a short period, or is part of a pattern of clearly repetitive requests. Again, a large amount of data is not the same as an excessive request. If in doubt, respond rather than refuse.
Document every exemption you use
Whenever you redact, withhold, or refuse, keep a record of what you did and the basis for it, without exposing the withheld content itself. That record is your evidence that the response was handled properly if the requester challenges it or a regulator asks. Documenting exemptions is part of a disciplined DSAR process, and it protects you far more than an undocumented judgment call.
The safeguard: human judgment
Exemptions are judgment calls. Whether a third party's data can be disclosed, whether material is genuinely privileged, or whether a request crosses the line into excessive all depend on context that only a person can weigh. Automation can surface candidates and flag likely exemptions, but the decision should sit with a reviewer. A human review gate is what keeps you in control and prevents both over-withholding and accidental disclosure. The same discipline applies whether you are meeting GDPR or CCPA obligations.
Exemptions under the CCPA
The framing above leans on GDPR concepts, but similar limits exist under the CCPA. A business does not have to disclose certain information where doing so would create a security risk, and there are constraints around specific pieces of sensitive personal information such as government identifiers and financial account numbers. The CCPA also does not require a business to retain data it would not otherwise keep just to answer a request, or to re-identify data that is not linked to a particular consumer. As with the GDPR, these are limits applied case by case, not blanket reasons to disclose less, and the safe default remains disclosing the requester's own data while protecting others.
When in doubt, disclose
The default position under access rights is disclosure. Exemptions are genuine, but they are limits on a right, not loopholes to shrink your obligations. If you are unsure whether something is exempt, the safer course is usually to disclose the requester's own data and redact only what clearly belongs to others, while taking advice on anything genuinely uncertain.
Want exemptions flagged during review instead of missed under deadline pressure? Obtainer compiles a manifest, surfaces likely third-party and exempt material, and holds everything at an approval gate. DSAR automation keeps a person in control of every withholding decision before the response is disclosed.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.