DSAR Document Redaction: One Platform, One Record
By Privacy360
Last updated:
See how DSAR document redaction works inside Privacy360. Keep every request, document and audit trail in one record, from intake to release.
Topics: DSAR, document redaction, subject access requests, UK GDPR, EU GDPR, privacy operations

Putting this into practice? See how Privacy360's DSAR document redaction handles it. Redact PDF and Word documents inside the DSAR workflow, with suggestions a person approves.
A subject access request rarely goes wrong at intake. It goes wrong in the middle. Documents are exported, redacted in another tool and uploaded again. As a result, the request, the files and the decisions end up in different places.
This article explains how in-platform redaction fixes that. It also shows how Privacy360 Document Redaction keeps the DSAR process together, from request to released file.
What is DSAR document redaction?
DSAR document redaction removes or obscures information before disclosure to a data subject. Typically, this covers personal data about other people and exempt information. The aim is simple. The requester receives their own data, and nothing they are not entitled to see.
Article 15 of the UK GDPR and EU GDPR gives individuals a right of access. Organisations must normally respond within one month. That period can be extended by up to two further months for complex or numerous requests.
However, disclosure must not adversely affect the rights of others. Therefore, third-party data often needs redaction. In the UK, the Data Protection Act 2018 also sets out exemptions that may apply. For authoritative detail, read the ICO guidance on subject access requests.
Why bolt-on redaction tools weaken DSAR control
Many teams still redact in a separate tool. In practice, this splits one request across several systems. Consequently, control, evidence and accountability become harder to show.
Several problems follow:
- Documents leave the platform. Files must be exported first, so sensitive records travel outside your controlled environment.
- Extra processors and DPAs. A separate service is often another processor. Therefore, it may need its own contract and due diligence.
- International transfer questions. Some services process files in other regions. As a result, a transfer assessment may be needed.
- Version confusion. Copies multiply across systems. In contrast, reviewers need one clear version of each document.
- A broken audit trail. Redaction history sits apart from the request. Consequently, the record no longer tells the whole story.
- Manual re-uploading. Redacted files must be returned by hand. Because steps are manual, errors and delays increase.
- The wrong version disclosed. With several copies in circulation, the unredacted file can be sent by mistake.
The solution: one platform, one record
The answer is to keep redaction inside the DSAR lifecycle, not after it. Privacy360 does exactly that. Therefore, every step from intake to closure shares one record.
The lifecycle has eight stages:
- Intake
- Identity verification
- Data collection
- Review
- Redaction
- Exemptions log
- Disclosure
- Closure
Redaction is stage five. It happens inside Privacy360, between review and disclosure. Nothing is exported to a bolt-on or cloud tool. Equally, nothing needs to be re-imported.
How the DSAR process stays together, request to redaction
Here is how a request moves through the platform in practice.
1. Open a redaction job and link it to the request
You can start a job on its own. However, you can also link it to a DSAR request. When linked, the requester joins the keep-visible list automatically. The deadline then stays visible on the request itself.
2. Upload the collected documents
Add the PDF and Word (.docx) files gathered for the request. A single job can hold several files, up to 50 MB each. Scanned pages without selectable text are redacted by hand.
3. Review the suggestions
The module suggests names, contact details, addresses, ID and account numbers, bank details, dates of birth and health details. However, nothing is redacted automatically. A person accepts or rejects each suggestion.
Reviewers have practical controls. They can approve suggestions in bulk. They can also draw their own boxes. Alternatively, they can search a third party's name and mark every instance.
4. Tag a reason for every redaction
Each redaction carries a reason: third party, commercially sensitive, legal privilege, out of scope or other. These reasons feed the exemptions stage of the DSAR. As a result, decisions stay consistent and traceable.
5. Approve and release
Only a client admin, partner admin or platform admin can approve redactions or release a file. This is enforced in the database, not only on screen. Therefore, control stays with the people accountable for the response.
6. Check the export and keep the evidence
The exported PDF is rebuilt with redacted areas flattened and metadata removed. The export is then checked. If redacted content survives, release is blocked. You receive the redacted file and its redaction schedule.
What stays in the record
A defensible DSAR needs evidence. In Privacy360, the activity log records every detection, approval, rejection and export. A fingerprint of the released file is also kept.
The record therefore holds:
- the unredacted original, stored privately in the client's own region
- each redaction and the reason behind it
- who approved what, and when
- the redaction schedule produced with the released file
- the fingerprint of the file that was actually disclosed
Consequently, you can explain any decision later. This matters if a requester challenges the response or a regulator asks questions.
In-platform versus bolt-on redaction
| Criterion | Privacy360 in-platform | Bolt-on or cloud tool |
|---|---|---|
| Data leaves the platform | No | Usually |
| Additional processor | No new processor for redaction | Depends on the tool and its hosting |
| Audit trail | Detection, approvals and export logged | Often held apart from the request |
| Version control | Original kept privately; one released copy | Copies in several places |
| Link to DSAR record | Optional link to the request | Manual cross-referencing |
| Exemption logging | Reason per redaction, compiled into a schedule | Varies by tool |
| Access control | Approval and release limited to admins | Separate user management |
Other products vary, so check each one against your own requirements.
Human approval still matters
AI-assisted detection speeds up review. However, it should never replace judgement. In Privacy360, a person approves every redaction. Your data is processed for the request only and is not used to train AI models.
Because suggestions are only suggestions, accountability stays with your team. In contrast, fully automatic redaction can hide too much or too little.
Who benefits most?
- In-house DPOs keep each request, its documents and its disclosure decisions in one defensible record.
- Legal and compliance teams apply consistent reasons, so privilege and third-party decisions stay traceable.
- Outsourced DPOs and consultancies work across clients with partner admin access. Each client's originals stay private and in their region.
Keep the whole DSAR in one place
Redaction should not be the point where your DSAR process fragments. Instead, it should be a controlled stage inside a single record, from request to release.
To see how it works, explore the Document Redaction module or the wider DSAR management software. You can also use the DSAR toolkit, review pricing or read about regional hosting. Alternatively, book a demo and walk through a redaction job from upload to release.
Frequently asked questions
What is DSAR document redaction?
DSAR document redaction removes or obscures information before disclosure to a data subject. Typically, this covers personal data about other people and exempt information. The aim is to give requesters their own data without revealing what they are not entitled to see. Each decision should be recorded, so the organisation can explain it later.
Why redact inside the DSAR platform rather than in a bolt-on tool?
Redacting in the same system as the request keeps one record and one audit trail. Sensitive documents are not exported to a third-party tool. Therefore, there are fewer copies, fewer hand-offs and less risk of sending the wrong version. In Privacy360, a redaction job can link directly to its DSAR request.
Does Privacy360 redact documents automatically?
No. The module suggests personal data for removal, such as names, contact details, addresses, ID and account numbers, bank details, dates of birth and health details. However, a person approves every redaction. Only authorised admins can approve redactions or release a file, and this is enforced in the database.
Is the redaction permanent?
Yes. The exported PDF is rebuilt with redacted areas flattened, so no text layer survives underneath. Document metadata is removed. The export is then checked before release. If any redacted content remains, the export is blocked. The unredacted original is kept separately in private storage.
Which file types does the module support?
You can upload PDF and Word (.docx) files, with several files in one job and up to 50 MB each. The released copy is a PDF. Scanned pages have no selectable text, so no suggestions are generated for them. However, a reviewer can still draw redaction boxes by hand.
Can I record the reason for each redaction?
Yes. Each redaction carries a reason: third party, commercially sensitive, legal privilege, out of scope or other. These reasons are compiled into a redaction schedule produced alongside the released file. The activity log also records who approved or rejected each item and who exported the file.
How does in-platform redaction help meet the DSAR deadline?
It removes hand-offs between systems, which are a common source of delay. Because a redaction job can link to its DSAR request, the deadline stays visible on that request. Reviewers can approve suggestions in bulk or mark every instance of a term. Final approval still rests with an authorised person.
Where are the original documents stored, and is my data used to train AI?
The unredacted original is kept separately in private storage, in the client's own region. Only people authorised for that client can see it. Your data is processed for the request only. It is not used to train AI models.
What is the time limit for responding to a DSAR?
Organisations must normally respond within one month of receipt under the UK GDPR and EU GDPR. However, that period can be extended by up to two further months for complex or numerous requests. Therefore, redaction should be planned early, not left until the end of the process.