DSAR Redaction: Mask Third-Party and Exempt Data Before You Disclose
A DSAR response often contains data about people other than the requester, and material you are entitled to withhold. Obtainer gives you a redaction desk where a human masks third-party and exempt data and approves the response, so you stay in control of exactly what is disclosed.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
DSAR redaction is the step of masking information you should not disclose in a data subject access response, most often data about third parties and material covered by an exemption, before the response goes to the requester. Obtainer is DSAR redaction software built around a human review gate: the compiled manifest arrives at a redaction desk where your team masks third-party and exempt data, and nothing is disclosed until a human approves it. This keeps you in control of what is disclosed, because the decision to release or withhold each item is made by a person, not by the tool. Obtainer helps you comply. It is not legal advice, so the judgment of what counts as an exemption or third-party data stays with your team. Redaction sits inside the same DSAR workflow as discovery and drafting, self-serve from $49/mo, rather than a bolt-on inside a six-figure governance suite.
Last updated July 2026
What you get
Redaction, built for privacy, legal, and ops teams
Mask before you disclose
The response passes through a redaction desk where third-party and exempt data is masked, so it never reaches the requester unreviewed.
A human makes the call
Redaction and approval are done by a person, not automated, so you stay in control of exactly what is disclosed.
In the same workflow
Redaction sits right after discovery and drafting, so you move from manifest to masked response without switching tools.
A clear record of decisions
The review gate makes what was masked and approved visible, so your team can stand behind the response it sent.
How it works
From an intake request to a ready-to-review response in four steps
Open the compiled manifest
The reviewable manifest and draft response arrive at the redaction desk, gathered from your systems.
Mask what stays back
A reviewer masks third-party data and anything covered by an exemption your team identifies.
Check the redaction
A second look confirms the masked response contains only what the requester is entitled to see.
Approve the disclosure
A human approves before it ships. You stay in control of what is disclosed. Obtainer helps you comply. It is not legal advice.
Frequently asked
Questions teams ask about redaction
What can you redact from a DSAR response?
You can mask information that would reveal personal data about someone other than the requester, and material covered by an exemption your team applies, such as legally privileged content or data that would prejudice an ongoing investigation. The goal is to give the requester their own data while protecting third parties and exempt material. The judgment of what qualifies stays with your team.
Do you have to include third-party data in a DSAR response?
No. A DSAR entitles a person to their own personal data, not to data about other people. Where records mix the two, you redact or withhold the third-party information unless those individuals consent or it is reasonable to disclose without consent. This is one of the most common redaction decisions in a subject access response.
What are the exemptions to a data subject access request?
Common exemptions cover legal privilege, data that would tip off someone under investigation, confidential references, negotiation records, and information whose disclosure would harm another person. Exemptions are narrow and fact-specific, so apply them item by item rather than to a whole response. Obtainer helps you comply and is not legal advice, so the exemption call stays with your team.
Can you refuse or redact part of a DSAR?
Yes. You can withhold or redact specific items that are exempt or that contain third-party data while still disclosing the rest. A partial disclosure with explained redactions is often the correct response, not an all-or-nothing choice. Record what you masked and why, so the decision is defensible if the requester challenges it.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.