Skip to content

Person resolution: why one name is rarely one person

What goes wrong when SAR review is organised by document, and how organising by person fixes it.

6 min read, for Information governance leads, CIOs, anyone evaluating SAR tooling.

Ask a team to find everything an organisation holds about a person and the first thing they do is search for the name. That is where the problems start. The requester is Daniel to HR, Dan to colleagues, D. Okafor on the payroll file, an email address on 8,000 messages and an employee number on the access control log. Another D. Okafor, unrelated, appears in the supplier invoices. A search for the surname returns both. A search for the full name misses most of the material.

Person resolution is the process of linking every mention of a person, across every document, into one record, with evidence for each link and a decision recorded where the evidence is ambiguous.

What document-level tools cannot tell you

Tools that highlight names, dates and email addresses in a document are useful for a single file. For a case they answer the wrong question. They tell you that a string appears on page 12. They cannot tell you whether it refers to the requester, whether the same person appears under a different name on page 40, or whether a sentence is about the requester, a colleague or both. Those are the questions that decide disclosure.

How resolution works

  • Every mention is extracted with its context: the name form, nearby identifiers, the sender and recipients, the document and date.
  • Mentions are compared across the case. Strong evidence, such as a shared email address or employee number, links confidently. Weaker evidence, such as a surname alone, is scored.
  • Confident links are made automatically and the evidence is attached. Ambiguous links are queued for a person to decide, with the evidence for and against on screen.
  • Roles are inferred from context: line manager, clinician, family member, supplier. Third parties are grouped by role so the review can treat like cases alike.
  • Merges and splits are recorded. If a reviewer decides two records are one person, or one record is two, the decision and its basis are part of the case record.

Why it matters for the review

Once people are resolved, the review can be organised by person: everything about the requester in one place, and everything about each third party in theirs. Decisions are made once per finding and applied consistently wherever that person appears. The reviewer is answering "what do we hold about this person and what should we disclose?" rather than "what is on this page?".

It also catches the errors that lead to complaints: two people treated as one, or one person under four names treated as four. Both are common in manual processes, and both are difficult to explain afterwards.

This guide is general information about SAR practice under UK GDPR and the Data Protection Act 2018. It is not legal advice.

Make SARs manageable.

Try Redactics yourself or talk to us about your current process.