Obtainer
Blog / Guides 10 min read

DSAR Exemptions: When You Can Withhold or Refuse Data

Last updated July 2026 · Obtainer

Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

DSAR exemptions are the limited circumstances in which you can withhold data, redact part of a response, or refuse a request entirely. The right of access is broad but not absolute: you must protect other people's personal data, you may withhold material that is legally privileged or covered by a specific exemption, and you can refuse or charge for a request only where it is manifestly unfounded or excessive. Every time you rely on an exemption, you should document the reason.

This is general information, not legal advice. Exemptions are fact-specific and vary by jurisdiction, so check the law that applies and take advice on borderline cases.

The two ways to limit a response

Exemptions work in two ways. Most of the time you still respond, but you redact or withhold certain material within it. Occasionally you may refuse the request as a whole. Refusal is the rare exception; partial withholding is the common case.

TypeWhat it meansHow common
Redact third-party dataRemove data about other peopleVery common
Withhold exempt materialHold back privileged or exempt contentOccasional
Refuse the requestDecline a manifestly unfounded or excessive requestRare

Third-party data: the most common exemption

An access request covers the requester's own personal data, not other people's. When a record about the requester also contains someone else's data, you generally redact the third party unless disclosure is reasonable, for example where they have consented or their identity is already known and disclosure causes no harm. This is the exemption you will apply most often, and it is covered in depth in the guide on how to redact a DSAR response. A dedicated redaction step keeps it consistent.

Legally privileged and exempt material

Some material can be withheld rather than redacted piecemeal. Common examples include:

  • Legal professional privilege. Confidential legal advice is generally exempt from disclosure.
  • Data under legal hold. Material preserved for litigation may be subject to separate rules; withholding it from a routine response can be appropriate, but coordinate with legal.
  • Management and negotiation information. Certain internal planning or negotiation data may be exempt depending on the jurisdiction.
  • Data that would prejudice specific functions. Some laws exempt data where disclosure would harm functions such as crime prevention or regulatory activity.

Because these depend on the specific legal framework, treat the list as a prompt to check, not a definitive rule. Flag candidates during manifest review rather than at the last minute, which is easier when discovery has produced a clear list to work from through personal data discovery.

Refusing a request: manifestly unfounded or excessive

You can refuse a request, or charge a reasonable fee, only where it is manifestly unfounded or excessive. This is a high bar, not a convenience.

Manifestly unfounded

A request might be manifestly unfounded where the person clearly has no genuine intention to exercise the access right, for example where the request is made purely to harass or is explicitly used as a bargaining chip. The volume of data or the effort involved does not, on its own, make a request unfounded.

Excessive

A request may be excessive where it repeats a request you have already satisfied within a short period, or is part of a pattern of clearly repetitive requests. Again, a large amount of data is not the same as an excessive request. If in doubt, respond rather than refuse.

Document every exemption you use

Whenever you redact, withhold, or refuse, keep a record of what you did and the basis for it, without exposing the withheld content itself. That record is your evidence that the response was handled properly if the requester challenges it or a regulator asks. Documenting exemptions is part of a disciplined DSAR process, and it protects you far more than an undocumented judgment call.

The safeguard: human judgment

Exemptions are judgment calls. Whether a third party's data can be disclosed, whether material is genuinely privileged, or whether a request crosses the line into excessive all depend on context that only a person can weigh. Automation can surface candidates and flag likely exemptions, but the decision should sit with a reviewer. A human review gate is what keeps you in control and prevents both over-withholding and accidental disclosure. The same discipline applies whether you are meeting GDPR or CCPA obligations.

Exemptions under the CCPA

The framing above leans on GDPR concepts, but similar limits exist under the CCPA. A business does not have to disclose certain information where doing so would create a security risk, and there are constraints around specific pieces of sensitive personal information such as government identifiers and financial account numbers. The CCPA also does not require a business to retain data it would not otherwise keep just to answer a request, or to re-identify data that is not linked to a particular consumer. As with the GDPR, these are limits applied case by case, not blanket reasons to disclose less, and the safe default remains disclosing the requester's own data while protecting others.

When in doubt, disclose

The default position under access rights is disclosure. Exemptions are genuine, but they are limits on a right, not loopholes to shrink your obligations. If you are unsure whether something is exempt, the safer course is usually to disclose the requester's own data and redact only what clearly belongs to others, while taking advice on anything genuinely uncertain.

Want exemptions flagged during review instead of missed under deadline pressure? Obtainer compiles a manifest, surfaces likely third-party and exempt material, and holds everything at an approval gate. DSAR automation keeps a person in control of every withholding decision before the response is disclosed.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.