DSAR Redaction: Mask Third-Party and Exempt Data Before You Disclose
A DSAR response often contains data about people other than the requester, and material you are entitled to withhold. Obtainer gives you a redaction desk where a human masks third-party and exempt data and approves the response, so you stay in control of exactly what is disclosed.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
DSAR redaction is the step of masking information you should not disclose in a data subject access response, most often data about third parties and material covered by an exemption, before the response goes to the requester. Obtainer is DSAR redaction software built around a human review gate: the compiled manifest arrives at a redaction desk where your team masks third-party and exempt data, and nothing is disclosed until a human approves it. This keeps you in control of what is disclosed, because the decision to release or withhold each item is made by a person, not by the tool. Obtainer helps you comply. It is not legal advice, so the judgment of what counts as an exemption or third-party data stays with your team. Redaction sits inside the same DSAR workflow as discovery and drafting, self-serve from a planned $49/mo, rather than a bolt-on inside a six-figure governance suite.
Last updated August 2026
What you get
Redaction, built for privacy, legal, and ops teams
Mask before you disclose
The response passes through a redaction desk where third-party and exempt data is masked, so it never reaches the requester unreviewed.
A human makes the call
Redaction and approval are done by a person, not automated, so you stay in control of exactly what is disclosed.
In the same workflow
Redaction sits right after discovery and drafting, so you move from manifest to masked response without switching tools.
A clear record of decisions
The review gate makes what was masked and approved visible, so your team can stand behind the response it sent.
How it works
From an intake request to a ready-to-review response in four steps
Open the compiled manifest
The reviewable manifest and draft response arrive at the redaction desk, gathered from your systems.
Mask what stays back
A reviewer masks third-party data and anything covered by an exemption your team identifies.
Check the redaction
A second look confirms the masked response contains only what the requester is entitled to see.
Approve the disclosure
A human approves before it ships. You stay in control of what is disclosed. Obtainer helps you comply. It is not legal advice.
Frequently asked
Questions teams ask about redaction
What can you redact from a DSAR response?
You can mask information that would reveal personal data about someone other than the requester, and material covered by an exemption your team applies, such as legally privileged content or data that would prejudice an ongoing investigation. The goal is to give the requester their own data while protecting third parties and exempt material. The judgment of what qualifies stays with your team.
Do you have to include third-party data in a DSAR response?
No. A DSAR entitles a person to their own personal data, not to data about other people. Where records mix the two, you redact or withhold the third-party information unless those individuals consent or it is reasonable to disclose without consent. This is one of the most common redaction decisions in a subject access response.
What are the exemptions to a data subject access request?
Common exemptions cover legal privilege, data that would tip off someone under investigation, confidential references, negotiation records, and information whose disclosure would harm another person. Exemptions are narrow and fact-specific, so apply them item by item rather than to a whole response. Obtainer helps you comply and is not legal advice, so the exemption call stays with your team.
Can you refuse or redact part of a DSAR?
Yes. You can withhold or redact specific items that are exempt or that contain third-party data while still disclosing the rest. A partial disclosure with explained redactions is often the correct response, not an all-or-nothing choice. Record what you masked and why, so the decision is defensible if the requester challenges it.
When I respond to a DSAR, should I redact third party info?
Yes, where the third party is identifiable in what you send and disclosing them would not be reasonable. Redact rather than withhold wherever possible, because the requester is entitled to the rest of the record. Staff acting in a professional capacity are usually disclosable; private individuals who are not the requester usually are not. An opinion somebody else wrote about the requester is still the requester's personal data, so the content goes in even where the author may not. The worked examples sit in the guide to redacting third-party data in a DSAR response.
Do third party company names get redacted?
Usually not. A company is not a person, so a company name is not personal data and the default is to leave it in. The exceptions are narrow: a sole trader whose business name identifies them, a company named after the individual, and cases where naming the organization makes an otherwise unidentifiable person identifiable. Blanket-redacting every company name removes the part of a response that is often most useful to the requester, which is who else holds their data.
What gets missed most often when redacting a DSAR response?
Metadata. Teams remove a name from the body of a document and leave it in the file properties, the exported file name, the participant list on a ticket, or the headers of a forwarded email. The second most common miss is redaction that only covers the text visually rather than removing it, so the original is recoverable by anyone who opens the file in the right tool. Flatten the file and check the container, not just the content, before anything is disclosed.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.