Handle an access request

Review and redact documents

Review the documents on a case and redact information that should not be disclosed in the response.

What this task achieves

Review is where a pile of collected material becomes a response you can defend. Once a document has been analysed, the Documents & Review tab turns into a three-panel workspace: the case's documents on the left, the document itself in the middle, and an AI Suggestions panel on the right. The suggestions are a starting point — every one of them is accepted or rejected by a person, and anything the analysis missed is redacted by hand. You finish when every document is marked as reviewed and the case review is finalised.

Before you begin

Before you begin

  • At least one document must have finished analysis and reached Pending Review. See Add and organise documents if documents are still processing.
  • Admins and Members can accept and reject suggestions, draw manual redactions, and mark documents as reviewed. Viewers can open the workspace and see the review checklist, but none of the actions are available to them.
  • Only an Admin can select Finalize Review to finish the case review.
  • Have your organisation's escalation route to hand. Decisions about other people's information and about exemptions are judgements for your data protection officer or legal adviser, not for the product.

Understand what the analysis does

AI analysis looks for patterns that usually indicate personal identifiers — names, email addresses, phone numbers, locations, dates of birth, National Insurance and NHS numbers, passport and driving licence numbers, bank and payment card numbers, and IP addresses — and proposes each match as a suggestion with a confidence score.

That is all it does. It does not know whose information it has found, whether a third party's identity is already known to the requester, whether an exemption applies, or whether releasing something would be unfair. It cannot see context you hold outside the document. Treat every suggestion as a prompt to look, and treat the absence of a suggestion as no assurance that a page is clear.

Important

AI analysis produces suggestions, not decisions. Nothing is redacted because the product proposed it — a redaction takes effect only after a person accepts or draws it, and the responsibility for what is released stays with your organisation. Read each page yourself rather than working from the suggestion list alone.

Review the suggestions

  1. Open the case, select the Documents & Review tab, and choose a document from the list on the left. Each document carries a badge — Pending Review, Reviewed, Processing, Quarantined, or Needs Attention.
  2. Work through the AI Suggestions panel. Suggestions are grouped by confidence into High Confidence, Medium Confidence (labelled for verification), and Possible PII, which starts collapsed. Open every group: low-confidence matches are the ones most likely to be missed.
  3. Select a suggestion to jump the viewer to it and see it highlighted in place. Each entry shows the detected type, a confidence percentage, the detected text, and whether it is Reviewed or Unreviewed.
  4. Suggestions start out accepted. Selecting one toggles it between accepted and rejected, so reject anything that should stay visible — for example the requester's own name and contact details, which are exactly what they are entitled to see.
  5. Use Accept all on a group only when you have already read that group's entries. It is a shortcut for confirming decisions you have made, not a substitute for making them.
  6. Watch the counters at the top of the panel: detected, accepted, rejected, touched, and manual. The touched count tells you how much of the document you have actually considered.

Your decisions save automatically as you go.

Add a manual redaction

Analysis will miss things — handwriting, a name inside an image, a comment that identifies someone without naming them. Redact those yourself:

  1. Select Draw Box in the viewer toolbar. It becomes available once analysis has produced a redaction job for the document and that job is ready for review.
  2. Drag a box over the material to remove.
  3. In Select PII type, choose Name, Email, Address, Phone, NI Number, or Other, add an optional note, and select Add.
  4. The redaction appears under Manual Redactions in the right-hand panel, listed by page. The Reason (optional) field on each entry saves when you click away from it.

The reason field is optional in the product, but fill it in. A redaction with a recorded reason is evidence of a considered decision; a black box with no reason is something you will have to reconstruct from memory if the requester challenges it or the ICO asks.

Decide about other people and exemptions

UK GDPR context

A response often contains information about other people as well as the requester. You are not automatically required to remove it, and you are not automatically entitled to. You must decide whether it is reasonable to disclose without the other person's consent, weighing any duty of confidentiality, any express refusal, and what the requester already knows. Separately, an exemption may apply to some of the material. Both are fact-specific judgements that depend on the circumstances, and this guidance cannot make them for you. Where the answer is not obvious — and particularly where the material concerns health, children, social work, legal advice, or an ongoing investigation — record the facts and your provisional view on the case and escalate to your data protection officer or legal adviser before finalising. Record the outcome and its reasons whichever way the decision goes. See Clarification, extensions, refusal, and specialist advice.

This is operational guidance for UK organisations, not legal advice.

Mark a document as reviewed

When you are satisfied with a document, select Mark as Reviewed. The document moves to Reviewed and the workspace selects the next document still awaiting review, so you can work straight through the case.

Only mark a document as reviewed once you have looked at every page. Marking is what counts the document towards finishing the case, and a document that was never really read looks identical to one that was.

Finish the case review

The left panel shows how many documents are reviewed and a Review Checklist naming each document and whether it is done. Until every document is ticked, the panel says that all documents must be reviewed before finalising.

When the checklist is complete, an Admin selects Finalize Review and confirms. The dialog reports how many documents were reviewed and warns that the case will be marked as completed. Finalising moves the case to Completed and starts preparation of the response package.

Adding a document reopens the review

Uploading another document to a case that already has reviewed documents returns the case to In Review, and the new document must be analysed and reviewed before the case can be finalised again. Add everything you intend to disclose before finalising.

Official sources

What happens next

What happens next

Finalising the review moves the case to Completed and the response package is prepared automatically. Continue to Prepare and securely deliver the response.

Last reviewed . UK regulatory context.

Previous
Add and organise documents