Answering a GDPR Subject Access Request Without Exposing Everyone Else in the Thread

A Subject Access Request rarely arrives asking for one clean document. It usually means combing through email threads full of other people's names, then deciding what has to stay in and what has to come out — inside a one-month deadline.

Michael Carter Updated

The request is simple. The inbox behind it never is

A Subject Access Request under UK/EU GDPR sounds like a narrow ask: give this person their own personal data. In practice it usually means searching years of email for their name, then discovering that most of the relevant messages also mention colleagues, customers, or other third parties who never agreed to be part of anyone's SAR.

The ICO's guidance is specific about how to handle that overlap. Just because someone is copied on or is the recipient of an email doesn't make the whole message their personal data — only the parts that actually relate to them. The ICO's own worked example: if an employee's name and email address appear on 2,000 emails but nothing else in those messages relates to them, you can lawfully respond by telling them that and disclosing just the name and address found — you don't have to hand over 2,000 full emails. Where a message does contain content about the requester, you generally do have to provide it, redacted where a third party's information needs to come out first.

UK employers are also on a clock: a SAR must be answered without undue delay and within one month of receipt, extendable by up to two further months only for genuinely complex requests, and only if you tell the requester within the first month that you're doing so.

A concrete example

What this looks like for an HR or DPO team

A SAR arriving in the middle of an ongoing grievance or disciplinary process — one of the most common real-world triggers.

1

The situation

A current employee has submitted a SAR while a workplace investigation is ongoing. The relevant emails run to several hundred messages across HR, the employee's manager and two colleagues, and most of them mention other staff by name. Before the one-month deadline, someone has to work out which content belongs to the requester and strip out everyone else's personal details from what gets sent.

2

Source and destination you choose

Where it comes from

Exported mailbox or forwarded .eml/.msg files

The messages your search of the mailbox turned up as relevant to the requester

Why this one: You still need to identify which emails mention the requester first — Redact works on that shortlist, not on searching the mailbox for you.

Also works with

  • PST export from a specific mailbox
  • PDF copies of printed correspondence

Where the result goes

Redacted PDF or plain text pack

The same emails with third-party names, addresses, and other personal details blacked out

Why this one: This is the format you can actually send to the requester or their solicitor.

Or choose

  • Redacted CSV of extracted fields
  • Side-by-side review before download
3

How the review pass works

  1. 1

    Each email is scanned for personal identifiers

    Names, email addresses, phone numbers, physical addresses and similar details that could identify someone other than the requester.

  2. 2

    Suggested redactions are shown, not applied blindly

    You see a proposed list of what would be redacted before anything is blacked out, so it stays your decision.

  3. 3

    You adjust the list against the ICO's third-party test

    Add back anything the requester already knows or clearly consented to; remove anything genuinely irrelevant to their own data.

  4. 4

    The redacted set is exported

    As a downloadable pack you can send, with the originals kept separately for your own records.

This is a first-pass detection and redaction aid, not a compliance decision. The judgment call the ICO asks for — is it reasonable to disclose this third party's information without their consent? — still has to be made by a person who understands the specific request and relationship, and documented as such.

Getting the amount of disclosure right in both directions

The ICO's guidance to organisations on employment disputes and SARs flags a real risk on both sides: redact too much and the requester can complain to the ICO or start proceedings; disclose too much and you may hand over a colleague's personal data, commercially sensitive material, or something that later weakens your own position in a related dispute. Neither mistake is free, which is why most guidance recommends a documented, three-step approach for every piece of third-party content — does it identify someone else, do they consent, and if not, is disclosure reasonable anyway.

Questions that come up on real SARs

Do I have to redact my own organisation's name and business details?

No — a SAR is about the requester's personal data, not your organisation's. Business information only needs redacting where it also happens to identify a specific individual, such as a personal mobile number in a signature block.

What if the requester already knows what the redacted person said?

The ICO notes that if the requester was already party to the exchange and has seen the third-party content before, it may not be unfair to disclose it in full. That's a judgment call for the response, not something the tool decides automatically.

Can this handle a PST export of a whole mailbox?

Yes, PST is a supported input alongside .eml and .msg files, so you don't need to convert an exported mailbox before starting.

How do I get the emails out of Outlook in the first place?

Save individual messages as .msg (File → Save As → Outlook Message Format), or export a folder to a PST. Outlook itself has no redaction command — the native file is what you redact. There is a separate walkthrough for that export step.

Related guides

Get a SAR response pack ready well before the deadline