Obtainer
REDACT - YOU APPROVE

DSAR Redaction: Mask Third-Party and Exempt Data Before You Disclose

A DSAR response often contains data about people other than the requester, and material you are entitled to withhold. Obtainer gives you a redaction desk where a human masks third-party and exempt data and approves the response, so you stay in control of exactly what is disclosed.

See pricing
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

DSAR redaction is the step of masking information you should not disclose in a data subject access response, most often data about third parties and material covered by an exemption, before the response goes to the requester. Obtainer is DSAR redaction software built around a human review gate: the compiled manifest arrives at a redaction desk where your team masks third-party and exempt data, and nothing is disclosed until a human approves it. This keeps you in control of what is disclosed, because the decision to release or withhold each item is made by a person, not by the tool. Obtainer helps you comply. It is not legal advice, so the judgment of what counts as an exemption or third-party data stays with your team. Redaction sits inside the same DSAR workflow as discovery and drafting, self-serve from $49/mo, rather than a bolt-on inside a six-figure governance suite.

Last updated July 2026

// CAPABILITY

What you get

Redaction, built for privacy, legal, and ops teams

Mask before you disclose

The response passes through a redaction desk where third-party and exempt data is masked, so it never reaches the requester unreviewed.

A human makes the call

Redaction and approval are done by a person, not automated, so you stay in control of exactly what is disclosed.

In the same workflow

Redaction sits right after discovery and drafting, so you move from manifest to masked response without switching tools.

A clear record of decisions

The review gate makes what was masked and approved visible, so your team can stand behind the response it sent.

// 4 STEPS

How it works

From an intake request to a ready-to-review response in four steps

01

Open the compiled manifest

The reviewable manifest and draft response arrive at the redaction desk, gathered from your systems.

02

Mask what stays back

A reviewer masks third-party data and anything covered by an exemption your team identifies.

03

Check the redaction

A second look confirms the masked response contains only what the requester is entitled to see.

04

Approve the disclosure

A human approves before it ships. You stay in control of what is disclosed. Obtainer helps you comply. It is not legal advice.

// FAQ

Frequently asked

Questions teams ask about redaction

What can you redact from a DSAR response?

You can mask information that would reveal personal data about someone other than the requester, and material covered by an exemption your team applies, such as legally privileged content or data that would prejudice an ongoing investigation. The goal is to give the requester their own data while protecting third parties and exempt material. The judgment of what qualifies stays with your team.

Do you have to include third-party data in a DSAR response?

No. A DSAR entitles a person to their own personal data, not to data about other people. Where records mix the two, you redact or withhold the third-party information unless those individuals consent or it is reasonable to disclose without consent. This is one of the most common redaction decisions in a subject access response.

What are the exemptions to a data subject access request?

Common exemptions cover legal privilege, data that would tip off someone under investigation, confidential references, negotiation records, and information whose disclosure would harm another person. Exemptions are narrow and fact-specific, so apply them item by item rather than to a whole response. Obtainer helps you comply and is not legal advice, so the exemption call stays with your team.

Can you refuse or redact part of a DSAR?

Yes. You can withhold or redact specific items that are exempt or that contain third-party data while still disclosing the rest. A partial disclosure with explained redactions is often the correct response, not an all-or-nothing choice. Record what you masked and why, so the decision is defensible if the requester challenges it.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.