Redaction, UK GDPR and subject access requests
General information, not legal advice — see the note at the end.
Most redaction in the UK happens for one of three reasons: someone has made a subject access request and the file contains other people's data; a document is being disclosed in litigation or under FOI; or material is being shared internally with people who have no business seeing all of it.
Subject access requests and other people's data
A subject access request gives a person the right to a copy of their own personal data. It does not give them a right to everyone else's. HR files, complaint records, email threads and investigation notes almost always contain third-party personal data — colleagues, complainants, witnesses — mixed into the same documents.
The Data Protection Act 2018 allows you to withhold third-party information where disclosing it would identify another individual, unless that person consents or it is reasonable to disclose without consent. In practice this usually means going through the documents and removing names and identifying detail rather than refusing the request or handing over everything.
The subtlety people miss: a name is not the only identifier. A job title in a small team, a shift pattern, a distinctive turn of phrase in a quoted email, or the sole person who attended a particular meeting can all identify someone just as reliably. Redaction has to be judged on whether a person is identifiable, not on whether their name appears. No automatic tool can make that call for you.
Data minimisation as a habit, not just a legal test
UK GDPR requires personal data to be adequate, relevant and limited to what is necessary. Applied to disclosure, the practical question is simple: does the recipient need this particular detail to do the thing they are receiving the document for? If not, it should come out. That standard is usually stricter than instinct, and it is the one a regulator will apply after something has gone wrong.
Why a black rectangle can be a reportable breach
This is the part that turns a formatting mistake into a legal one. If you cover a name with a drawn box and send the file, the name is still in the document and still recoverable by anyone who copies and pastes it. That is how the redaction failure always works, and it has caught out government agencies and law firms.
From a data-protection standpoint you have disclosed the personal data. That it was invisible on screen is not a defence — the data was transmitted to someone not entitled to receive it. Depending on the circumstances that can be a personal data breach requiring notification to the ICO within 72 hours, and to the affected individuals where the risk to them is high.
The failure mode is especially unkind because the person who made the mistake has no way of knowing. The file looks correct. It stays looking correct right up until a recipient highlights a passage out of curiosity.
A workable process
- Keep the original. Redact a copy, always. You may need to justify the redactions later, and you cannot un-redact a flattened file.
- Do a structured pass first. Automatic detection reliably finds emails, phone numbers, NHS and National Insurance numbers, card and bank numbers, postcodes and dates of birth.
- Then a names pass. List the people involved and remove every form of each name at once, including surname-only and initialled references.
- Then read it. This is the step that catches identification by context, and nothing can do it for you.
- Verify mechanically. Copy-paste the redacted regions, search for a removed name, and check the document properties for author and file path.
- Record what you did. If challenged, you want to show what was removed and on what basis.
Keeping a record without creating a second leak
A redaction log is good practice, and it is also a trap: a log that quotes the values it removed is a plaintext copy of exactly the data you just destroyed, usually filed somewhere less carefully than the document itself.
BLACKOUT can produce a summary alongside an export that records counts by type and page, the terms searched, and the Bates range — and never the removed content. It is a record of the pass that ran, not a certificate that everything was found, and it says so on the document.
A note on what this page is
This is general information about a common task, written by the people who make a redaction tool. It is not legal advice and it is not a compliance opinion. Whether a particular disclosure is lawful, whether an exemption applies, and whether an incident is reportable all depend on facts this page cannot know. For anything consequential, take advice from a data protection professional, and check current ICO guidance, which is the authoritative source in the UK.