Third-Party Data in DSAR Redaction with anonym.plus

Protect other people's data so a subject's reply harms nobody else.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Third-party redaction is the removal of other people's PII from a DSAR pack. UK GDPR Art. 15(4) says a copy must not adversely affect the rights of others. The Court of Appeal's approach in DB v General Medical Council [2018] EWCA Civ 1497 — decided under the 1998 Act's equivalent provision but still the leading authority on redacting third-party material from a case file before disclosure — is that a controller may withhold or redact identifying detail about others rather than refuse the whole request. anonym.plus marks that data on your device, so you balance access against their privacy.

When this applies

A subject asks for their file, but it names co-workers, witnesses, and other clients. Art. 15(4) means their PII cannot ride along unredacted in the disclosure, and the DB v GMC approach is to cut out the third party's detail rather than hold back the subject's own record.

How anonym.plus handles it

  1. Open the subject's file in anonym.plus on your device.
  2. The tool scans for every name, contact, and ID in the text.
  3. Tell it which identity is the subject's own.
  4. Mark all other people's PII for removal.
  5. Black out or swap each one, then check the balance.
  6. Save the clean copy on your machine.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONco-worker Laura Voss → [PERSON]
ContactEMAIL_ADDRESSl.voss@example.co.uk → [EMAIL]
ContactPHONE_NUMBER07700 900199 → [PHONE]
IdentifiersNATIONAL_IDstaff no. 44821 → [ID]
LocationLOCATIONhome address → [ADDRESS]
NamesPERSONwitness J. Marek → [PERSON]

Compliance achieved

Anonymise DSAR responses offline — see plans & start free →

Limitations & cautions

Art. 15(4) asks you to weigh access against others' rights. The tool flags candidate PII; the balance is yours to strike. A name alone may be fine to keep, or it may harm someone. DB v GMC endorses redacting over refusing, but it does not remove the judgment call on any one name. Judge each case, then redact.

Frequently asked questions

What does Art. 15(4) actually require?

A copy of the data must not adversely affect the rights and freedoms of others. In practice you redact third-party PII unless disclosure is fair and reasonable, rather than withholding the subject's own file to avoid the question.

What did DB v General Medical Council decide?

The Court of Appeal held that a controller holding a mixed file, naming both the requester and other people, should generally redact the third parties' identifying detail and disclose the rest, rather than refuse the whole request. It was decided under the 1998 Act's access provisions, but the reasoning is the one courts and the ICO still apply to Art. 15(4) today.

Can I keep a colleague's name if it is harmless?

Sometimes. The balance is a legal judgment that depends on context, expectation, and whether the colleague was acting in a work capacity. anonym.plus flags the name so a person can keep or remove it; the tool does not decide for you.

Will this catch indirect clues, not just names?

Yes. With 340+ entity types it flags emails, phones, IDs, and locations that point to a person even when no name appears, which matters because a job title plus a department can identify a colleague as surely as their name would.