Why proper redaction matters
Improper redaction is one of the most common data leaks in regulated industries. A 2017 study by the US Department of Justice found that 80% of "redacted" court documents they tested were still leaking the supposedly redacted text. The problem is that most people redact by:
- Drawing a black rectangle on top of the text (text is still there)
- Using the PDF "redact" tool but the underlying content survives (depends on tool and version)
- Covering the text with an image (text is still in the file as a separate text layer)
True redaction permanently removes the text from the file. It is not recoverable by any means short of recovering an earlier version from a backup. That is what we do.
What we redact
Common redaction jobs include:
- Personal data — names, addresses, phone numbers, email addresses, dates of birth, national ID numbers, passport numbers, driving licence numbers
- Financial data — account numbers, sort codes, IBANs, credit card numbers (first 12 digits, last 4 only), transaction details
- Medical data — patient names, addresses, conditions, treatments, dates
- Legal data — witness names, addresses, identifying details, third-party personal data, juvenile names
- Signatures — physical signature images, electronic signatures, dates next to signatures
- Custom regions — anything else: logos, watermarks, specific paragraphs, embedded images
Our redaction process
We follow a strict four-step process.
- Identify redaction targets — either you tell us what to redact, or we apply a rule set (e.g. "redact all phone numbers matching this pattern", "redact all names except the applicant's", "redact all amounts above £5,000").
- Mark the targets — in a working copy, we add a permanent redaction layer over each target. The layer is metadata that says "this area is now empty".
- Flatten and verify — the marked redactions are applied, the underlying text is deleted, and the file is re-saved. We then verify by attempting to copy the redacted areas — they should produce nothing.
- Audit and deliver — we generate a brief audit log showing every redaction applied (page, region, reason), and deliver the file plus the log.
GDPR and regulatory compliance
Our redaction meets:
- GDPR (EU and UK) — Article 4(5) pseudonymisation, Article 17 right to erasure
- HIPAA (US healthcare) — Safe Harbor de-identification, Expert Determination
- FOIA (US Freedom of Information) — b6 personal privacy exemption handling
- CJIS (US Criminal Justice) — security and sanitization requirements
- FOIP / PIPA (Canada) — personal information redaction
- DIFC (UAE) — Data Protection Law redaction
For industry-specific requirements, ask us. We have handled redaction for court bundles, FOI responses, GDPR subject-access requests, medical record releases, HR file disclosures, M&A due-diligence packs, and whistleblower documents.
Pricing
Redaction is priced per page, with the rate depending on the number of redactions per page.
- Light redaction (1-5 redactions per page) — £15 per page
- Standard redaction (5-15 redactions per page) — £25 per page
- Heavy redaction (15+ redactions per page, e.g. court bundles) — quoted per project
Audit trail and certification
For every redaction job we provide:
- The redacted PDF
- An audit log listing every redaction (page, area, reason category)
- Verification that the redacted text is unrecoverable (we attempt copy-paste and screenshot text extraction before delivery)
- On request, a signed letter confirming the redaction was performed to a specified standard
The audit log can be in PDF, CSV, or JSON format depending on your needs.