Redacting a subject access request response without exposing third parties
A subject access request is the one disclosure where the reader will examine every line, has a statutory right to complain, and already suspects you of something. It also has a clock: normally one month.
Why the risk is concentrated here
A DSAR bundle is assembled quickly, from mailboxes and shared drives, by whoever is available. Third-party personal data has to come out, and the material that has to come out is scattered through email threads, attachments and spreadsheets rather than sitting in one tidy field.
What enforcement looks like
On 31 July 2025 the Information Commissioner's Office published guidance specifically on disclosing documents to the public securely, addressing personal information hidden inside files. Announcing it, the ICO pointed to serious breaches at the Police Service of Northern Ireland and the Ministry of Defence in which documents had been disclosed without proper checks for hidden personal information. The PSNI case cost £750,000: a hidden worksheet in a spreadsheet released under freedom of information exposed the surnames, initials, ranks and roles of all 9,483 officers and staff. In the MoD case, a spreadsheet believed to concern a small number of applicants in fact carried hidden data on more than 18,000 people. And in March 2026 the ICO fined Police Scotland £66,000 and issued a reprimand after the full unredacted contents of a crime victim's mobile phone were put into a misconduct disclosure bundle and shared with a third party who should not have received it — the ICO found that appropriate review, redaction and security procedures were not in place.
The four hiding places in a bundle
- Text that was covered rather than deleted — a black box, a highlight, a white-filled shape.
- Hidden rows, hidden columns and filtered ranges in spreadsheets exported to PDF.
- Metadata and tracked changes carried over from the original documents.
- Scanned annexes, where nothing can be searched and only a human can see what is on the page.
A workflow that fits the deadline
- Assemble the bundle first and freeze it; redact once, at the end, on the final PDF.
- Remove third-party names, contact details and identifiers by marking them directly.
- Strip metadata from the finished file.
- Re-extract the text of the finished file and search it for the names you removed.
- Read the scanned annexes with your own eyes; nothing else can.
- Keep the verification record with the response, so that if the requester complains you can show what you checked and when.
General information, not legal advice. TachadoPDF removes and verifies; deciding what a data subject is entitled to receive is a judgement it cannot make for you.
Check a DSAR bundle for hidden data — free Redact your PDF now — free, and without uploading it to any server