Guide

DSAR Exemptions: What You Can Legally Refuse to Disclose

The right to access personal data isn't unlimited. Here's the narrow, specific set of exemptions that let you withhold or redact information in a DSAR response, and where the limits of those exemptions actually sit.

Published August 19, 2026·Last updated August 19, 2026

Businesses sometimes assume a DSAR requires handing over literally everything in a file. In practice, both GDPR and CCPA/CPRA carve out specific, narrower exemptions, but treating every exemption as broadly applicable is its own compliance risk, they’re meant to be exceptions, not defaults.

Third-party data

You generally can’t disclose another person’s personal data just because it appears in the same record as the requester’s. If a coworker’s complaint, a manager’s note about someone else, or a third party’s contact details show up in the file, redact the third party’s identifying information rather than withholding the entire document or disclosing it unredacted.

Documents genuinely prepared for the purpose of obtaining legal advice, or created in contemplation of litigation, can be exempt. This is narrower than it’s often assumed to be, copying a lawyer on an email doesn’t retroactively make the whole thread privileged, and routine business records don’t become exempt just because a dispute later arises around them.

Trade secrets and confidential business information

You’re not required to disclose your internal decision-making logic, proprietary algorithms, or confidential business processes just because a request references data that touched them. What you do owe is the personal data itself, an explanation of a scoring outcome doesn’t require handing over the underlying model.

Manifestly unfounded or excessive requests

Covered in more detail in our DSAR fee guide, but worth repeating here: this exemption is genuinely narrow. “Inconvenient to fulfill” is not the same as “manifestly unfounded or excessive,” and treating it as such is one of the more common overreach mistakes.

Data that would identify a confidential source

In specific contexts, whistleblower reports, some fraud-investigation records, disclosing the requester’s own data might indirectly reveal who reported them. Some frameworks allow withholding in these narrow cases, but this exemption is fact-specific and worth a legal review rather than a default assumption.

Our recommendation

Enzuzo

Knowing what to withhold matters less than knowing what you actually hold in the first place. Enzuzo's data subject request handling starts from the same data inventory as its consent management, so fulfillment isn't a separate, disconnected lookup.

Try Enzuzo

The general rule

Exemptions are meant to be applied narrowly and explained, not used as a default reason to limit a response. If you’re withholding or redacting something, document specifically which exemption applies and why, the same way you’d document a lawful basis for processing. “We felt uncomfortable sharing it” isn’t a recognized exemption under either framework.

The bottom line

Exemptions exist to protect third parties, genuine legal privilege, and confidential business information, not to give businesses broad discretion to limit what a DSAR response includes. When in doubt, disclose more rather than less, and reserve exemptions for the specific, narrow circumstances they were designed for.

This guide is educational and not legal advice. For your specific situation, consult a privacy attorney.