DSAR Denial and Exemptions: When You Can Say No
The legitimate grounds for declining or narrowing a data subject request, and how to document the decision so it holds up.
7 min read
Not every data subject request has to be fulfilled in full. Privacy laws build in exemptions, because the right to access or delete your own data can collide with other people's rights, legal obligations, or the integrity of a legal case. The key is to decline for a real reason and to write that reason down, rather than to say no by default or to ignore the request. This is a guide, not legal advice; check the specific law that applies.
Grounds to Decline or Narrow
- Manifestly unfounded or excessive requests. Most laws let you refuse or charge a fee for requests that are clearly abusive or repetitive. This is a narrow exception, not a catch-all, so use it sparingly.
- Other people's data. If fulfilling a request would disclose a third party's personal data, you can redact or withhold that portion. You do not hand over someone else's information to satisfy an access request.
- Legal privilege and ongoing claims. Data tied to legal advice or an active legal claim is often exempt, so you are not required to expose your own legal position.
- Regulatory and legal retention. Where another law requires you to keep data, a deletion request does not override that obligation. You retain what you must and delete the rest.
Partial Fulfillment Is Normal
Denial is rarely all or nothing. The common outcome is partial: you fulfill most of a request and withhold a specific piece with a stated reason. Redacting a third party's name from an otherwise complete access response is a fulfillment, not a refusal.
Document the Decision
Whatever you decline, record why, under which exemption, and who decided. Two reasons: most laws require you to tell the requester the basis for a refusal and their right to complain, and your written rationale is your defense if the decision is ever challenged. An undocumented denial looks the same as ignoring the request.
How Concord Fits
Concord Privacy keeps each request and its outcome in one tracked workflow, so a partial fulfillment or a documented refusal is recorded alongside the request rather than living in someone's inbox. The audit trail is the record you reach for if a decision is questioned later.