AI Redaction Tools for SARs: Where They Help and What They Miss
Where AI can speed up SAR review, the redaction mistakes to watch for and the human checks needed before disclosure.
Written by Data Protection People
AI redaction tools can save time on subject access requests (SARs). They scan large sets of documents, find personal information and suggest what to hide before a response goes out. What they cannot do is take responsibility for the result. They can miss information about other people or hide information the requester is entitled to. A trained person still needs to check the output before anything is sent.
What is an AI redaction tool?
An AI redaction tool is software that finds personal information in documents and removes it or flags it for review. Tools commonly look for patterns such as names, email addresses, phone numbers and account numbers. Some also try to read context, for example spotting that “my manager” refers to a specific person. Capabilities vary, so test the actual product against representative documents.
In a SAR, redaction can protect information that should not be disclosed while allowing the requester to receive their own personal data. Third-party information is not automatically withheld: consider whether that person consents or disclosure without consent is reasonable. Other exemptions may also apply, and each decision needs a reason.
Where AI redaction saves time on SARs
The slowest part of a large SAR is often the volume. An employee request can pull in thousands of emails, chat messages and attachments. Reading every page by hand can take weeks.
AI tools can help with repetitive work:
- First-pass detection. Marking likely names, contact details and identifiers gives reviewers a starting point.
- Consistency. Finding repeated identifiers helps reviewers apply decisions consistently, while checking whether the context changes the decision.
- Duplicates and noise. Some tools group near-identical emails and threads to reduce repeated review.
- Speed against the deadline. You usually have one month to respond. Cutting the manual workload can make that deadline easier to meet.
Used this way, the tool does the first pass and a person makes the decisions.
The mistakes automated redaction can miss
Automated systems work from patterns. Real documents do not always follow them. Common gaps include:
- Indirect identifiers. A job title, team name or “the only person on nights that week” can identify someone without naming them.
- Images and scans. Screenshots, scanned letters, handwriting and photos may not be read accurately, or at all.
- Embedded content. Spreadsheets, tracked changes, comments and metadata can hold personal information the visible page does not show.
- Context. Whether a third party’s information should be disclosed requires judgement, not just a pattern match.
- Ineffective redactions. A black box over text may leave the underlying text searchable or copyable. Check the exported file, not just the preview.
These limitations do not mean AI tools cannot be used safely. They mean their output needs checking.
Over-redaction and under-redaction: why both matter
Under-redaction means information that should have been withheld goes out by mistake. That can be a personal data breach and may put someone at risk, for example in an employment dispute or safeguarding case.
Over-redaction means hiding information the requester is entitled to. Blacking out whole pages “to be safe” can leave the response incomplete and lead to complaints.
The ICO explains the balancing exercise in its guidance on information about other people in a SAR. A tool can flag information, but a person has to assess whether disclosure is appropriate.
Questions to ask before adopting a tool
- What does it detect, and what does it miss? Ask about scanned documents, images, handwriting and the file types you use. Test it on representative material before relying on it.
- Where is data processed? Check storage locations, access, retention, deletion, international transfers and whether documents are used to train models.
- What is the provider’s role? If it processes personal data on your behalf, put the required Article 28 terms in a binding contract or other applicable legal act. Check sub-processors too.
- Is a DPIA required? Assess whether the proposed processing is likely to result in high risks to people. Consider scale, sensitivity, new technology and the wider context; using AI alone does not settle the answer.
- Are redactions permanent? The final output must remove the information being withheld rather than simply cover it.
- Can you show your working? Keep reasons for withholding information so you can explain decisions to the requester or regulator.
How to keep human oversight
The controller answering the SAR stays responsible for the response, whatever tool it uses.
- Name an owner. A trained person signs off the response before it goes out.
- Review suggested redactions. Accept, reject or change suggestions based on the disclosure decision. Do not assume every flagged identifier must be removed.
- Check unflagged content. Pay particular attention to scans, attachments and indirect identifiers. Sampling alone does not establish that a disclosure pack is safe.
- Keep a record. Log what was withheld and why, including any exemption relied on.
- Train reviewers. They need to understand the third-party balancing test and SAR exemptions, as well as the software.
A practical check before sending
Open an exported copy as the recipient would. Try searching for redacted names and copying text near redactions. Inspect comments, tracked changes, hidden spreadsheet content and document properties. Confirm the correct recipient and attachments have been selected. These checks complement the substantive review; a clean-looking PDF is not proof that every disclosure decision is right.
Frequently asked questions
Can we use AI to redact a subject access request?
Yes. AI tools can support SAR redaction, but the organisation remains responsible. A trained person should review suggestions and the final documents before they are sent.
Does an AI tool give us more time to respond?
No. The time limit is the same whatever tools you use. It is usually one month, with an extension only where the legal conditions are met. See our step-by-step SAR response guide.
What if the tool misses information that should have been withheld?
Sending personal data to the wrong person can be a personal data breach. Assess and document the incident promptly. A controller must notify the regulator without undue delay and, where feasible, within 72 hours of awareness unless the breach is unlikely to risk people’s rights and freedoms. A processor must notify its controller without undue delay. A high risk may also require notification to affected people.
Is it safer to redact everything we are unsure about?
No. Over-redaction can withhold information the requester is entitled to. Make and document a reasoned decision rather than applying a blanket rule.
Get support with a complex SAR
Listen to S2 Ep35 of Data Protection Made Easy for the discussion behind this article. If a large or difficult SAR is landing on your desk, our SAR support team can help with review and redaction. You can also read our guide to SAR redaction services.
Content reviewed: 2 October 2026.