Third-party redaction is the removal of other people's PII from a DSAR pack. UK GDPR Art. 15(4) says a copy must not adversely affect the rights of others. The Court of Appeal's approach in DB v General Medical Council [2018] EWCA Civ 1497 — decided under the 1998 Act's equivalent provision but still the leading authority on redacting third-party material from a case file before disclosure — is that a controller may withhold or redact identifying detail about others rather than refuse the whole request. anonym.plus marks that data on your device, so you balance access against their privacy.
When this applies
A subject asks for their file, but it names co-workers, witnesses, and other clients. Art. 15(4) means their PII cannot ride along unredacted in the disclosure, and the DB v GMC approach is to cut out the third party's detail rather than hold back the subject's own record.
How anonym.plus handles it
- Open the subject's file in anonym.plus on your device.
- The tool scans for every name, contact, and ID in the text.
- Tell it which identity is the subject's own.
- Mark all other people's PII for removal.
- Black out or swap each one, then check the balance.
- Save the clean copy on your machine.
What you need to provide
- The subject's file (PDF, DOCX, TXT, email export, or scan).
- An operator: Redact for full removal of others' details.
- An allow-list holding the subject's own identifiers.
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | co-worker Laura Voss → [PERSON] |
| Contact | EMAIL_ADDRESS | l.voss@example.co.uk → [EMAIL] |
| Contact | PHONE_NUMBER | 07700 900199 → [PHONE] |
| Identifiers | NATIONAL_ID | staff no. 44821 → [ID] |
| Location | LOCATION | home address → [ADDRESS] |
| Names | PERSON | witness J. Marek → [PERSON] |
Compliance achieved
- Meets the rights-of-others test in UK GDPR Art. 15(4).
- Follows the redact-rather-than-refuse approach set out in DB v General Medical Council [2018] EWCA Civ 1497.
- Keeps the subject's data while hiding everyone else's PII.
- Offline work means no third party sees the file at any step.
- 340+ PII entity types catch indirect clues, not just names.
Anonymise DSAR responses offline — see plans & start free →
Limitations & cautions
Art. 15(4) asks you to weigh access against others' rights. The tool flags candidate PII; the balance is yours to strike. A name alone may be fine to keep, or it may harm someone. DB v GMC endorses redacting over refusing, but it does not remove the judgment call on any one name. Judge each case, then redact.
Frequently asked questions
What does Art. 15(4) actually require?
A copy of the data must not adversely affect the rights and freedoms of others. In practice you redact third-party PII unless disclosure is fair and reasonable, rather than withholding the subject's own file to avoid the question.
What did DB v General Medical Council decide?
The Court of Appeal held that a controller holding a mixed file, naming both the requester and other people, should generally redact the third parties' identifying detail and disclose the rest, rather than refuse the whole request. It was decided under the 1998 Act's access provisions, but the reasoning is the one courts and the ICO still apply to Art. 15(4) today.
Can I keep a colleague's name if it is harmless?
Sometimes. The balance is a legal judgment that depends on context, expectation, and whether the colleague was acting in a work capacity. anonym.plus flags the name so a person can keep or remove it; the tool does not decide for you.
Will this catch indirect clues, not just names?
Yes. With 340+ entity types it flags emails, phones, IDs, and locations that point to a person even when no name appears, which matters because a job title plus a department can identify a colleague as surely as their name would.