SARIn-depth guide

SAR Exemptions: How to Apply Them

Exemptions to the standard principles and rights of data subjects are contained in Schedules 2 and 3 of the Data Protection Act 2018. Although there are a considerable number of exemptions, many only apply in specific circumstances or to specific types of personal data. This guidance sets out how to apply them, lists the most common exemptions you are likely to rely on, and explains your obligations as a data controller when applying an exemption to a subject access request.

Data Protection Act 2018 (Schedules 2 & 3)Updated 13 September 2025Data Protection Officers, Principals & Trust Leaders

Documentation

You should already be keeping a record of the SARs that you receive and respond to, as well as the correspondence and the data that you actually disclose. Whenever applying an exemption to a SAR, you should produce a rationale document that is stored with the disclosed data and correspondence, setting out why you applied the exemption and to what data. This will help you remember your thought process at the time and assist with any complaints, requests for reviews or regulator involvement. For larger organisations, these documents will also help your DPO to quality assure the process if necessary.

How to apply

When applying an exemption, you should first collate all of the data that falls in-scope of the request, including CCTV, emails and physical records (stored at any site and regardless of whether it has been archived). It is not advisable to pre-empt the application of exemptions to data. Should the ICO or any other regulatory authority query your process or use of exemptions, they will ask to see the data that you opted not to disclose. Consequently, it is beneficial to retain a copy of the original data collated, as well as a separate bundle for disclosure (with redactions applied) and any particular data which you did not disclose.

Once you have collated all of the data, there will be documents which can still be disclosed after redactions are applied, as well as potentially complete documents which you cannot disclose even if redacted. Work through the documents and note the data you believe an exemption will apply to, then take the necessary steps to apply those exemptions — whether that is through redaction or segregation of a document entirely from the disclosure bundle.

Common exemptions

The following exemptions are those you are most likely to rely upon. The list is supplied in a hierarchical order that we believe reflects how often each applies.

What is it?

This exemption to the right of access applies to the vast majority of responses you provide to pupils or parents, as well as elements of responses to staff requests. At its core, its purpose is to protect the personal data of other individuals who happen to be contained in the same document or data set as the data subject to whom the request relates.

How do I apply it?

Redact the personal data of all data subjects whose data is not being requested in the SAR.

Remember that even if the personal data of a third party is referenced in shorthand, such as “M. Lindsay” or “MRL”, this could still constitute a data breach. Ask yourself whether the receiving individual would still be able to identify the third-party subject using the shorthand only. If it’s likely, you should also redact that shorthand.

What to write in your SAR correspondence

The Trust has redacted the personal data of third party data subjects pursuant to paragraph 16(1), Schedule 2, Data Protection Act 2018.

Anything else to know?

Education data, health data and social care data are subject to an assumption of reasonableness for health workers, social workers and education workers, as detailed in Schedule 2, Part 3, paragraph 17 DPA 2018. This means you should not redact the personal data of current or former staff from your responses (subject to the serious harm test below). The same principle applies to the personal data of health professionals contributing to a health record in their capacity as a health professional involved in the diagnosis, care or treatment of the data subject.

What is it?

This exemption is designed to protect individuals from suffering serious harm due to their involvement in a pupil’s education. It allows an organisation to withhold the data in response to a request, and also puts the organisation under no obligation to confirm if it even holds the data.

How do I apply it?

The “serious harm test” is met with respect to education data if disclosure would be likely to cause serious harm to the physical or mental health of the data subject or another individual.

Organisations should not use this exemption in a blanket fashion. The “serious harm test” should be considered for each individual data subject that you are considering for redaction.

What to write in your SAR correspondence

The Trust does not process the data which you have requested, or the data that you have requested is subject to an exemption under Schedule 3, Data Protection Act 2018.

Anything else to know?

This is one exemption where extra care should be given to your rationale document, and you should document how you reached the decision. Simply having an argumentative parent is unlikely to suffice; you should consider:

  • The past and current relationship between the recipient of the SAR and the data subject to which you are applying the “serious harm test”.
  • Any threats or history of violence between the data subjects.
  • The effect of the disclosure on other data subjects, such as pupils and other family members.
  • Anything else that seems relevant to your organisation’s setting.

What is it?

This exemption allows you to withhold any personal data consisting of information as to whether the data subject is or has been the subject of, or may be at risk of, child abuse. It’s a common-sense exemption in place to protect the safeguarding of pupils. The legislation highlights that “child abuse” includes physical injury (other than accidental injury) to, and physical and emotional neglect, ill-treatment and sexual abuse of, an individual aged under 18.

How do I apply it?

This exemption only applies to a SAR received when:

  • the data subject is an individual aged under 18 and the person making the request has parental responsibility for the data subject; or
  • the data subject is incapable of managing his or her own affairs and the person making the request has been appointed by a court to manage those affairs.

If possible, segregate the child abuse data from any other documents that are eligible for disclosure. For data sets where this is not possible, apply redactions to the data. If you are unable to provide any data in response to the request, you should still respond as below.

What to write in your SAR correspondence

The Trust does not process the data which you have requested, or the data that you have requested is subject to an exemption under Schedule 3, Data Protection Act 2018.

Anything else to know?

This exemption is relatively common-sense to apply but can attract complaints from requesters. Be confident in your safeguarding processes and reach out to your DSL if necessary. Try to avoid getting into protracted arguments with requesters, and ensure they are directed to the ICO’s complaint process.

What is it?

There is an exemption from the right of access relating to information about the outcome of academic, professional or other examinations, but it only applies to the information recorded by candidates. This means candidates do not have the right to copies of their answers to the exam questions.

The information recorded by the person marking the exam is not exempt. However, if an individual makes a SAR for this information before the results are announced, special rules apply to how long you have to comply with the request.

How do I apply it?

When receiving a request for exam papers, you should redact the answers from the paper but leave the comments and markings unredacted. The disclosure should be provided within either:

  • five months of receiving the request; or
  • 40 days of announcing the exam results, if this is earlier.
Suggested acknowledgment to the requester

The Trust notes that you have requested personal data that is contained within exam scripts and/or exam marks. Pursuant to Schedule 2, Part 4, paragraph 25 of the Data Protection Act 2018, our deadline for responding to this request will be five months of receiving the request, or 40 days of announcing the exam results, if this is earlier. We calculate that the deadline for providing the response is therefore [INSERT DEADLINE DATE] and we will provide you with that element of your request on that date. Please note that this will not include the answers that were provided as part of the exam, but will include any other personal data as well as the examiner’s comments and markings.

Anything else to know?

It’s essential that you confirm with your exams lead when the exam results will be announced. You can then calculate whether the 40-day window after that date falls sooner than the 5-month anniversary of the request being made. Once you have confirmed your timescale for replying, note it in a calendar so that it’s not missed.

If the request includes other forms of personal data, you should still disclose these within the one-month timeframe. Use the same reference number for both disclosures — even though you have had to delay the disclosure of the exam data, both disclosures are in response to the same request.

What is it?

Personal data held in confidential references (both made and received) are exempt from disclosure. This applies when the references relate to:

  • education, training or employment of an individual;
  • placement of an individual as a volunteer;
  • appointment of an individual to office; or
  • provision of any service by an individual.

How do I apply it?

During the collation process, your organisation should segregate all references made or received in respect of the data subject making the request.

What to write in your SAR correspondence

The Trust is unable to provide confidential references that may have been made or received pursuant to paragraph 24, Schedule 2, Data Protection Act 2018.

Anything else to know?

It is important to note that this exemption only applies to references given in confidence. You should make it clear to individuals, and to those providing references, whether you will treat references confidentially or adopt a policy of openness. Do this through the privacy information you provide, such as your policy and privacy notices.

What is it?

Personal data that is a record of your intentions in negotiations with an individual is exempt from the right of access. This only applies to the extent that providing the data would be likely to prejudice the negotiations. It is likely to apply to some staff data.

How do I apply it?

Assess whether the document or data set includes anything that would harm your position in negotiations with the requester. This could include pay reviews or settlement discussions.

What to write in your SAR correspondence

The Trust is unable to provide [INSERT NAME OF DOCUMENT] as the data consists of records of the intentions of the controller in relation to potential negotiations pursuant to paragraph 23, Schedule 2, Data Protection Act 2018.

Anything else to know?

It’s relatively rare for staff members or other individuals to be entering into negotiations with your organisation, but the situation may still arise. When applying this exemption, focus not on the reason for the negotiation but on the potential effect of the disclosure. The exemption does not set out any limits regarding the timing of negotiations, nor does it say you can only withhold information where negotiations are still ongoing. You may therefore be able to apply the exemption after negotiations have ended, but only if you can justify why disclosure would be likely to prejudice negotiations — most relevant where you can demonstrate that disclosure would prejudice your position in future negotiations.

What is it?

An exemption applies to personal data that you process for management forecasting or management planning about a business or other activity. Disclosure of this data is exempt from the right of access if responding to the SAR would be likely to prejudice the conduct of the business or activity.

How do I apply it?

During the collation process, you may notice that the requester is referred to within data sets and documents setting out management planning or forecasting decisions which have not yet been shared with the wider workforce — for example, due to a restructure, merger or other similar process. The requester’s personal data within these sources is exempt from disclosure. Whilst redaction may be the most suitable way forward, there could be other information in the data set that allows the requester to identify when they or other staff are being referred to. In this situation, the appropriate action would be to remove the documents from the disclosure bundle entirely.

What to write in your SAR correspondence

The Trust is unable to provide [INSERT NAME OF DOCUMENT] as the data consists of management forecasting or management planning in relation to a business or other activity pursuant to paragraph 22, Schedule 2, Data Protection Act 2018.

Anything else to know?

This exemption is most likely to apply to data you hold regarding staff roles during a reshuffle, merger or redundancy process. Your organisation may have produced this data in anticipation of these activities but not yet announced them to the workforce. If you receive a SAR for staff members’ personal data included in these documents, you do not need to disclose it if doing so would prejudice the conduct of the business or activity, such as by causing staff unrest before the plans are announced.

Redact with confidence

Eclipse surfaces likely personal data across your documents and keeps you in control of every redaction — so nothing gets missed.

Try Eclipse