Skip to main content
Should You Redact Employee Names in a DSAR?Data Subject Rights
5 min readFor DSAR Operators

Should You Redact Employee Names in a DSAR?

When an employee submits a data subject access request (DSAR) during a workplace dispute, you face a dilemma: do you disclose the names of colleagues who've commented on their performance, raised concerns, or participated in an investigation? Or do you redact those names to protect workplace relationships and confidentiality?

This isn't just a theoretical question. DSARs often arrive alongside grievances or before Employment Tribunal proceedings, and your decision impacts whether you're transparent with the requesting employee or protective of the wider team. Both positions have regulatory and practical foundations. Neither is risk-free.

The Case for Full Disclosure

Article 15 gives data subjects the right to obtain a copy of their personal data. When a manager writes "John raised concerns about Sarah's timekeeping in our one-to-one," that sentence contains Sarah's personal data. The manager's name and John's identity provide context that makes the data meaningful.

Practitioners who favor disclosure argue that redacting colleague names undermines the purpose of the DSAR. If you're investigating a bullying complaint and the employee receives documents with every name blacked out except their own, they can't properly understand what happened or prepare their case. The transparency obligations in Articles 13 and 14 require you to inform data subjects about the sources of their data where possible. Systematic redaction feels incompatible with that principle.

You also avoid accusations of selective disclosure. Deciding which names to reveal and which to hide involves judgment calls about whose privacy matters more. That's a position supervisory authorities scrutinize closely. If the requesting employee challenges your redactions and you can't articulate a clear, consistent policy, you've created an enforcement risk that didn't need to exist.

Some employment lawyers point out that tribunal proceedings will likely expose the same information anyway. If you're heading toward a hearing, the employee will eventually see witness statements, investigation notes, and email chains with full names attached. Redacting now just delays the inevitable and signals you're trying to hide something.

The Case for Targeted Redaction

Article 15(4) explicitly states that the right to obtain a copy "shall not adversely affect the rights and freedoms of others." When you disclose that "Michael told HR he's concerned about working with this employee," you're revealing Michael's personal data without his knowledge or consent. That matters under Article 6, where you need a lawful basis for every processing activity, including disclosure.

Practitioners who favor redaction argue that employees who provide information during investigations do so with an expectation of confidentiality. If you routinely disclose their identities in DSARs, people stop speaking honestly to HR. Your ability to investigate future concerns collapses. That's not a hypothetical risk; it's a documented pattern in organizations that adopted full-disclosure policies without considering the chilling effect.

You also need to consider the Article 5(1)(f) security principle. When an employee has made allegations of bullying or harassment, disclosing the names of witnesses can create a genuine risk of retaliation or workplace conflict. Your obligation to protect personal data extends to protecting people from harm that might result from disclosure.

Recital 63 acknowledges that the right of access shouldn't undermine confidentiality obligations, particularly in workplace investigations. Some supervisory authorities have issued guidance supporting limited redaction where disclosure would compromise ongoing investigations or put individuals at risk. You're not inventing an exemption; you're applying a recognized legitimate interests assessment.

Where Practitioners Actually Land

Most privacy teams develop a framework rather than a blanket rule. They disclose names in routine documents (meeting schedules, project updates, standard performance reviews) but redact selectively in sensitive contexts (investigation witness statements, third-party complaints, medical or HR case notes).

The test usually comes down to three questions: Is the third party's identity essential to the requesting employee's understanding of their own data? Did the third party provide information with a reasonable expectation of confidentiality? Would disclosure create a specific, articulable risk to that person?

If you're disclosing an email where a colleague casually mentioned the employee in a project update, you probably keep the name. If you're disclosing an investigation statement where a colleague reported serious misconduct, you probably redact unless there's a compelling reason not to.

The critical step is documentation. When you redact a name, you record why. Not "to protect confidentiality" but "witness expressed fear of retaliation; disclosure would breach Article 5(1)(f) security obligation and adversely affect rights under Article 15(4)." That specificity matters when you're explaining your decision to the employee or, later, to a supervisory authority.

Our Take

You should default to disclosure but build a defensible framework for exceptions. The GDPR's transparency principles are strong, and systematic redaction creates more problems than it solves. But Article 15(4) exists for a reason, and workplace investigations are exactly the context where it applies.

Your policy should establish clear criteria for when you'll redact: witness statements in disciplinary or grievance investigations, third-party complaints where the complainant requested confidentiality, and situations where you can document a specific risk of harm. Everything else gets disclosed with names intact.

Train your HR and legal teams to recognize these situations early. When someone provides information during an investigation, tell them whether their identity might be disclosed in a subsequent DSAR. That conversation protects you later and gives them a chance to understand the implications of their participation.

And when you do redact, explain it. Don't just black out names and hope the employee doesn't notice. Include a cover note: "We've redacted certain third-party names under Article 15(4) where disclosure would adversely affect their rights. If you believe any redaction prevents you from exercising your rights, contact us and we'll review that specific decision."

The employees making DSARs during disputes aren't usually satisfied with that answer. But it's legally sound, procedurally fair, and far better than the alternative: either blanket disclosure that destroys workplace confidentiality or blanket redaction that fails the transparency test.

You Might Also Like