Personal data covers information relating to an identified or identifiable person, including correspondence, notes, and recorded interactions. Legal analysis is different because it reflects the organisation’s assessment and application of the law, not the individual’s personal data itself. In practice, the factual material considered for that analysis may be disclosed, while the analysis and conclusions can be exempt.
What belongs in a DSAR, and what does not
A DSAR turns on whether the material is personal data, not whether it is useful to the requester. If a record identifies or relates to an individual, it may be in scope even when it sits inside emails, meeting notes, case files, or call records. The key test is substance: the underlying facts are potentially disclosable, while purely evaluative legal reasoning is treated differently.
That distinction matters because DSAR review is often a mixed document exercise. The same file can contain both factual material about a person and an organisation’s legal assessment of rights, obligations, or risk. In practice, reviewers need to separate the person-facing facts from the legal analysis, rather than assuming the whole document is either disclosable or exempt.
Why legal analysis is usually treated differently
Legal analysis is not personal data just because it was prepared about a person. It is the organisation’s interpretation of law, policy, or litigation risk, and that character does not change when the analysis references an individual. What often remains disclosable is the factual substrate used to reach that view, such as dates, events, correspondence, or the individual’s own statements.
This is where GDPR becomes the practical reference point: the regime protects access to personal data, not a right to see every internal thought process about that data. A good DSAR response therefore distinguishes between information about the person and internal analysis applied to that information.
Documents that mix facts and analysis usually need line-by-line review. A note can contain disclosable personal data in one sentence and withheld legal reasoning in the next. That is why redaction, extraction, and careful contextual review matter more than document-level assumptions.
How to separate factual material from exempt analysis
The cleanest way to review a DSAR is to ask three questions: does the passage describe the individual, does it record facts about what happened, or does it explain the organisation’s legal judgment? The first two are more likely to be within scope; the third is more likely to be withheld. The answer may differ within the same paragraph.
Identity Data Privacy and Consent Guide is useful here because it reinforces the practical habit of treating privacy review as a data classification exercise, not a document-labeling exercise. The same approach helps teams preserve disclosable personal data while separating out analysis, advice, and conclusions that are not themselves the individual’s data.
Where legal analysis quotes or summarises personal data, the quoted facts may still need disclosure even if the surrounding reasoning does not. The operative question is whether the requester is entitled to the facts about them, not whether the organisation would prefer to keep the internal commentary together with those facts.
Risk and Threat Considerations
DSAR handling creates exposure when teams over-disclose internal legal analysis or over-withhold factual material. The first can reveal litigation strategy, risk assessments, or internal control gaps; the second can create an incomplete response that undermines trust and increases regulatory risk.
Failure mechanism: Mixed documents are reviewed at the document level instead of the sentence or clause level, so factual personal data and legal reasoning are treated as one block. That leads either to unnecessary disclosure of internal analysis or to over-redaction of material personal data.
Impact: Poor separation can trigger complaints, challenge the defensibility of the DSAR process, and create inconsistent responses across similar cases. In higher-risk matters, it can also expose legal privilege or sensitive internal assessments that were never meant to be released.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
GDPR and ISO/IEC 27001:2022 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art.15 — Right of access by the data subject | DSAR access turns on personal data scope and access rights. |
| Art.5 — Principles relating to processing of personal data | Data minimisation and purpose limits shape what is returned in a DSAR. | |
| Art.15(4) — Right of access and rights and freedoms of others | This supports withholding material where disclosure would affect others' rights or interests. | |
| Recommendation — Apply Art.15 to separate disclosable personal data from exempt internal analysis. Use Art.5 principles to disclose only personal data that is necessary and relevant. Redact material that would infringe other persons' rights or protected interests. | ||
| ISO/IEC 27001:2022 | A.5.12 — Classification of information | DSAR review depends on identifying personal data, legal analysis, and other sensitive material. |
| A.5.34 — Privacy and protection of PII | The topic concerns handling personal data and privacy-sensitive records during disclosure. | |
| Recommendation — Classify DSAR content so personal data and exempt analysis are handled separately. Apply privacy controls to disclose personal data safely and lawfully. | ||
Practitioner Guidance
What to verify: Before withholding any passage, confirm whether the withheld content is actually analysis, advice, or legal conclusion rather than factual personal data. If the passage contains both, redact only the analytic portion and retain the disclosable facts where possible.
Decision rule: If the sentence would still make sense as a factual account without the organisation’s judgment, treat the factual part as a likely DSAR disclosure candidate. If removing the analysis would leave only a statement of facts, those facts usually deserve separate consideration.
Common mistake: Teams often mark an entire email chain or legal memo as exempt because it was written by counsel or used in a legal review. That shortcut is too broad for DSAR work, because authorship does not automatically convert factual personal data into exempt analysis.
Practitioner takeaway: The objective is not to disclose everything in a file or nothing at all, but to isolate the person-related facts and withhold only the organisation’s own legal reasoning where the law permits it.
Related resources from NHI Mgmt Group
- What is the difference between attack surface management and NHI governance?
- What is the difference between reviewing human access and reviewing NHIs?
- What is the difference between role-based access and API key governance for NHI security?
- What is the difference between human IAM controls and NHI governance?