Subject access redaction is the removal of other people's data from an investigation file before disclosure. UK GDPR Art. 15 gives a person access to their own records, not to third-party details. Where the investigation concerns preventing or detecting crime, DPA 2018 Schedule 2 lets a controller withhold data to the extent that access would be likely to prejudice that purpose, and a separate exemption in the same Schedule covers material protected by legal professional privilege. anonym.plus clears third-party names on your device; it does not decide whether an exemption applies to material the requester wants to see.
When this applies
An employee files a subject access request (DSAR) for an investigation about them. The file also names witnesses and colleagues whom you must shield, and may hold material a lawyer or the crime/taxation exemption in Schedule 2 covers separately.
How anonym.plus handles it
- Open the file in anonym.plus on your device.
- The tool flags every named person in the text.
- Keep the requester's own details; flag the rest.
- Swap or black out third-party names and contacts.
- Save the disclosable copy on your device.
What you need to provide
- The investigation file (PDF, DOCX, or export).
- An allow-list for the requester's own identifiers.
- An operator (Redact for third-party items).
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | requester → kept (their right) |
| Names | PERSON | witness → [REDACTED] |
| Names | PERSON | named colleague → [REDACTED] |
| Contact | EMAIL_ADDRESS | witness email → [REDACTED] |
| Contact | PHONE_NUMBER | witness phone → [REDACTED] |
| Identifiers | UK_NINO | third-party ID → [REDACTED] |
Compliance achieved
- Supports the access duty under UK GDPR Art. 15.
- Shields third-party details the requester has no right to see.
- Leaves room for the crime-and-taxation and legal-privilege exemptions in DPA 2018 Schedule 2 to be applied separately, where they genuinely fit.
- On-device AES-256-GCM guards the working files.
Anonymise subject access files offline — see plans & start free →
Limitations & cautions
Art. 15 needs a balance between the requester's right and others' privacy, and a Schedule 2 exemption may remove some material from the response entirely — a legal judgment this tool does not make. A witness may still be obvious from context even with the name gone.
Frequently asked questions
Why keep the requester's own details?
UK GDPR Art. 15 gives a person the right to access their own file. You keep their identifiers and shield only the records of other people.
Can an investigation file ever be withheld entirely from a DSAR?
In part, sometimes. DPA 2018 Schedule 2 lets a controller withhold data where disclosure would be likely to prejudice the prevention or detection of crime, and a separate exemption covers material protected by legal professional privilege. Deciding whether either applies is a legal judgment, not something redaction settles.
Can I set the requester's own IDs as allowed?
Yes. An allow-list keeps the requester's identifiers in place while the tool removes everyone else's.