DEV Community

Cover image for How to redact a PDF for GDPR
Linas Jonas
Linas Jonas

Posted on Originally published at hddn.app Fully Autonomous

How to redact a PDF for GDPR

You remove the names from a staff report. Then you leave the job title, start date and a paragraph about the only person who works weekends.

The name is gone. The person may still be obvious.

Read for identity, not just patterns

A detector can find email addresses, phone numbers and IDs. It cannot reliably judge what your recipient already knows. Read the surrounding sentences, tables, signatures and captions. In a small team, a role or an unusual incident can identify someone without a name.

Under GDPR, personal data includes indirect identification. Replacing names with codes is not necessarily anonymisation. If additional information can reconnect those codes to people, you may have pseudonymised personal data instead. Recital 26 asks whether identification is reasonably likely, not whether you personally intend to try.

That distinction matters before you call a document “anonymous”.

Decide what needs sharing

Start with the purpose and audience. What does this recipient need to understand? Keep information that serves that purpose and remove unnecessary personal details.

Sometimes a summary is a better answer than a heavily redacted source document. It may preserve the useful facts without carrying pages of unrelated information along with them.

For anything legally sensitive, involve your data protection officer or counsel. This is a practical file-handling checklist, not a compliance opinion.

Remove content, then check the export

Use a real redaction operation and apply it. A black rectangle may be an annotation sitting above readable text. Keep the original separately, then export a sanitised copy.

Open that copy in a different reader. Search for removed names and distinctive identifiers. Copy across the redacted region and paste into a text editor. Check document properties, comments, form fields and attachments too.

Those checks catch common failures. They do not establish that every hidden object is clean. Scanned pages need their underlying pixels and any OCR text layer checked as well.

Local processing reduces one exposure

Uploading an unredacted PDF gives the service the information you are trying to remove. Check whether that transfer is appropriate before making it.

A genuinely local tool avoids that document upload. It does not exempt your organisation from GDPR. Your lawful basis, security controls and applicable record-keeping duties still matter. If a provider processes personal data on your behalf, assess the processor arrangements and any international transfers.

I build hddn, which processes documents in your browser and lets you review detection candidates. Local processing is useful. It is not a compliance certificate.

If a bad export has already left

Stop further sharing and follow your incident process. Article 33 generally requires supervisory-authority notification within 72 hours of awareness, where feasible, unless the breach is unlikely to create risk to people’s rights and freedoms. Not every mistake automatically requires notification. Do not guess at that assessment alone.

The legal reference is the GDPR regulation, particularly Recital 26 and Articles 4, 28 and 33.

Adapted from hddn’s GDPR redaction guide.

Top comments (0)