SAR exemptions can limit disclosure, but they should be applied to the relevant data and circumstances - not used as blanket labels.
The right of access is subject to exemptions and restrictions in the UK GDPR/DPA 2018 framework. Common issues include legal professional privilege, third-party information, crime/taxation functions, confidential references and management information, but the exact rule and test vary.
A controller should disclose what it can. An exemption applying to one passage or category does not automatically justify withholding an entire file.
Key points
- Ask which exemption or restriction is being relied upon.
- Some exemptions are conditional and require a necessity/prejudice test.
- Third-party data often requires balancing, redaction or extraction rather than automatic refusal.
- Legal professional privilege is specific; copying a lawyer into an email does not automatically make everything privileged.
Third-party information
A SAR can contain information about both you and another person. The controller must consider whether it can disclose without the other person’s consent, taking account of the circumstances. Redaction, summaries or extracting your personal data may be appropriate.
Legal professional privilege
Privileged legal advice and litigation communications can be exempt, but privilege has defined legal requirements. Ask the controller to identify the category/basis as far as possible without requiring disclosure of the privileged content itself.
Manifestly unfounded or excessive requests
This is not an ordinary exemption to any inconvenient request. The controller bears responsibility for demonstrating why a request is manifestly unfounded or excessive, taking account of context. The right can sometimes be refused or a reasonable fee charged where the legal threshold is met.
In practice
- Challenge the breadth of an exemption separately from whether the exemption exists at all.
- Ask whether partial disclosure/redaction was considered.
- Keep the refusal wording because it may be central to an ICO complaint.
What to do
A practical next-step plan
- Identify the withheld category.
- Ask for the legal exemption/restriction relied upon.
- Check its conditions.
- Ask whether partial disclosure is possible.
- Challenge overbroad application with focused reasons.
Common traps
Things that often confuse the issue
- Do not assume every withheld item must be described in detail if doing so would reveal exempt material.
- Do not treat “confidential” and “legally privileged” as synonyms.
- A controller’s internal policy is not itself a statutory exemption.
Evidence worth keeping
Build an exemption schedule if withholding is extensive.
| Record/category | Controller’s stated basis | Your challenge |
|---|---|---|
| Internal legal email | Legal professional privilege | Ask whether every withheld part is privileged and whether non-privileged personal data can be separated. |
| Staff/third-party names | Rights of others | Ask whether redaction would permit disclosure of your remaining personal data. |
| Management planning | DPA exemption | Ask which specific prejudice/conditions are said to apply to the particular information. |
Useful wording.
“Please identify the exemption or restriction applied to each material category withheld and explain its application so far as you can without undermining the exemption. Where only part of a record is protected, please disclose the remainder with appropriate redaction.”
Third-party information often requires balancing, not automatic deletion of the whole document.
A document can contain your personal data and another person’s information at the same time. The controller may need to consider consent, reasonableness and the other person’s rights. In some cases names or identifying details can be redacted while your personal data is disclosed. The fact that somebody else wrote an email about you does not mean the whole email necessarily falls outside your access right.
Ask what was withheld and why, without demanding information the exemption itself protects.
A useful challenge asks the controller to identify the exemption/restriction relied upon, the category of material affected and the reason it applies so far as it can lawfully explain that without defeating the exemption. If only part of a record is protected, ask whether the remainder can be disclosed with proportionate redaction.
An exemption is not a magic label that removes an entire SAR.
The DPA 2018 contains exemptions and restrictions that can limit access in defined circumstances. Their operation varies: some apply only to particular information, purposes or prejudice tests, and third-party information requires its own analysis. A controller should not treat “legal privilege”, “management information” or “third-party data” as a one-line reason to withhold everything around it.
Official sources
Check the rules behind this guide
These are official or primary sources for this topic. Rules, scheme terms and deadlines can change, so check the live source before relying on a formal time limit or procedure.