Skip to main content
Category: Access and Security

Redaction

Also known as: Sanitization
Simply put

Redaction is the process of removing or obscuring sensitive information from a document so that the remaining content can be shared with a wider audience. It is commonly used when a record must be disclosed but certain details, such as personal data, must be withheld. The goal is to release information safely while protecting what should not be seen.

Formal definition

Redaction is the controlled removal or permanent obscuring of sensitive, confidential, or personal information from a document or other record prior to its distribution or disclosure to a broader audience. Also referred to as sanitization, it is applied to records in various formats, including word-processing files, PDFs, scanned documents, and image files. Effective redaction requires that the underlying data be genuinely removed rather than merely visually masked, since improperly redacted source files may retain hidden text or metadata that can expose the intended-to-be-withheld content. The specific information subject to redaction, and the obligations governing it, typically depend on jurisdiction, sector, and applicable disclosure or privacy requirements; determining what must be withheld falls outside the scope of this term and is governed by separate legal and policy frameworks.

Why it matters

Redaction sits at the intersection of two competing obligations that many organizations must reconcile: the duty to disclose records and the duty to protect sensitive information. When a record must be released, whether in response to a freedom of information request, a court process, a subject access request, or a proactive publication, the whole document may not be suitable for wider distribution. Redaction allows the releasable portions of a record to be shared while the material that should be withheld is removed, supporting disclosure without compromising confidentiality, privacy, or other protected interests.

The principal risk in redaction is that it may fail silently. Because redaction can be applied to word-processing files, PDFs, scanned documents, and image files, the technique used must genuinely remove the underlying data rather than merely place a visual mask over it. A black box drawn over text, or content hidden behind a graphic, can leave the original text and associated metadata intact within the source file, allowing the supposedly withheld information to be recovered. An improperly redacted release is difficult to retract once it has been distributed, and the failure typically becomes apparent only after the harm has occurred.

Because of these stakes, redaction should be treated as a controlled process rather than an incidental editing step. What information must be withheld, and the obligations that govern it, depend on jurisdiction, sector, and the applicable disclosure or privacy requirements; those determinations fall outside redaction itself and are governed by separate legal and policy frameworks. Redaction is the mechanism that gives effect to those decisions, and its reliability directly affects an organization's ability to disclose responsibly.

Who it's relevant to

Freedom of information and disclosure officers
Those responsible for responding to access requests frequently need to release records while withholding specific content. Redaction is the practical means by which they disclose the releasable portions of a record without exposing information that must be protected, though the determination of what to withhold is governed by separate legal frameworks that vary by jurisdiction.
Privacy and data protection professionals
Where records contain personal data that must not be shared with a wider audience, redaction supports safe disclosure. Practitioners in this area are typically concerned that redaction genuinely removes the underlying personal data rather than merely masking it, since improperly redacted files may retain recoverable content.
Legal and litigation support teams
In court processes and related disclosures, documents are often produced with sensitive content removed. These teams need reliable redaction across formats such as word-processing files and PDFs, and an awareness that hidden text or metadata in source files can undermine the intended protection.
Records managers and information governance leads
Those overseeing records prepared for disclosure benefit from treating redaction as a controlled process. Their interest lies in ensuring consistent methods are used across the formats an organization holds, and in preserving the distinction between the authoritative source record and the redacted version prepared for release.

Inside Redaction

Obscuring or removal of content
Redaction involves masking, deleting, or otherwise rendering unreadable specific portions of a record while typically preserving the remainder of the document for use or disclosure. The affected content may include personal data, sensitive information, or material subject to exemption.
Purpose and legal basis
Redaction is usually applied to satisfy a specific obligation or exemption, such as protecting privacy, safeguarding confidential or exempt information under freedom of information regimes, or complying with disclosure rules. The applicable grounds depend on jurisdiction, sector, and organizational policy.
Redacted copy versus source record
Redaction is often performed on a copy prepared for a particular disclosure or release, rather than on the authoritative source record. Maintaining the distinction between the unredacted authoritative record and the redacted derivative is important for preserving the integrity and usability of the original.
Irreversibility of the redaction
For redaction to be effective, the obscured content should not be recoverable from the released version. This is particularly relevant for electronic records, where underlying text, metadata, or layered content may persist beneath a visual mask if the redaction is applied only at the display level.
Metadata and hidden content considerations
Electronic documents may carry embedded information such as document properties, tracked changes, comments, or hidden layers. Effective redaction typically addresses these elements in addition to visible text, since they can reveal information the redaction was intended to withhold.
Audit trail and justification
Recordkeeping practice often calls for documenting what was redacted, on what basis, and by whom, so that the action can be explained, reviewed, or defended. The extent of such documentation depends on organizational policy and applicable requirements.

Common questions

Answers to the questions practitioners most commonly ask about Redaction.

Is redaction the same as simply hiding or covering text before sharing a document?
No. Visually obscuring content, for example, placing a black box over text, highlighting in an overlay, or changing font color to match the background, does not necessarily remove the underlying information. In many electronic formats the concealed text remains recoverable through copying, layer inspection, or metadata examination. Proper redaction typically requires that the exempted or sensitive content be genuinely removed or rendered irretrievable from the released copy, not merely masked from view. The distinction matters because an apparent redaction that leaves recoverable content can result in inadvertent disclosure.
Does redacting a record mean altering or destroying the original record?
Generally no. Redaction is normally applied to a copy prepared for a particular purpose, such as disclosure under a freedom of information request or release to a third party, while the authoritative original record is retained intact. Treating redaction as an edit to the source record would compromise the integrity and completeness that make it an authoritative record. Depending on organizational policy and applicable requirements, the redacted version is often managed as a distinct derivative, with the unredacted original preserved under its own retention and access controls.
How should a redacted copy be managed alongside the original record?
In many organizations the redacted version is captured and managed as a separate item linked to the source record, rather than replacing it. This typically allows the authoritative original to remain complete and available for authorized users, while the redacted copy serves its specific disclosure or distribution purpose. Organizations often document the relationship between the two, along with who produced the redacted copy and why, so that the basis for each release can later be understood. Specific practices depend on organizational policy and the systems in use.
What should be recorded about a redaction to support later accountability?
Depending on organizational policy and applicable requirements, it is often useful to document what was redacted, the reason or exemption relied upon, who performed and approved the redaction, and when it occurred. Some workflows also note the version of the source record from which the redacted copy was derived. Capturing this contextual information can help demonstrate that redactions were applied consistently and on a defensible basis, and can assist in responding to challenges, appeals, or review of a disclosure decision.
What formats or handling steps commonly create a risk of incomplete redaction?
Risks often arise where sensitive content persists beyond the visible page. Common examples include recoverable text beneath visual overlays, information held in metadata or document properties, tracked changes or comments, hidden rows or columns, embedded objects, and speaker or transcript layers in multimedia. Converting a document to another format, or flattening it, may reduce some of these risks but does not automatically address all of them. Because behavior varies by format and tool, organizations typically verify the released copy rather than assuming concealment equals removal.
Who should decide what content is redacted and on what basis?
Redaction decisions usually depend on the applicable legal, regulatory, and policy grounds for withholding information, which vary by jurisdiction and sector. For that reason, the basis for redaction is often determined by, or in consultation with, those responsible for the relevant disclosure regime, privacy obligations, or legal considerations, rather than left solely to the person performing the mechanical redaction. Clear roles and documented decision criteria can help ensure redactions are applied consistently and can be justified if questioned.

Common misconceptions

Redaction is the same as destruction or disposition of a record.
Redaction obscures selected content within a record or, more commonly, a copy prepared for release, while the underlying authoritative record typically remains intact. Destruction removes the record itself, and disposition is a broader lifecycle concept that may include transfer or permanent preservation. Redaction should not be treated as a form of disposition of the source record.
Placing a black box or highlight over text in an electronic document is sufficient redaction.
A visual overlay may leave the underlying text, metadata, or hidden content recoverable in the released file. For redaction to be reliable, the obscured content generally needs to be removed from the underlying data, not merely hidden at the display level.
Redaction requirements are uniform and universally defined.
The grounds for redaction, the categories of information affected, and the procedures expected vary by jurisdiction, sector, and organizational policy. What must or may be redacted under one regime, such as certain privacy or freedom of information exemptions, may differ elsewhere.

Best practices

Redact from a designated copy prepared for release rather than the authoritative source record, and keep the unredacted original intact and appropriately controlled.
For electronic records, use methods that remove the underlying content rather than only masking it visually, and check embedded metadata, tracked changes, comments, and hidden layers before release.
Record the basis for each redaction, including the exemption, privacy ground, or policy relied upon, and who performed and reviewed it, to the extent required by organizational policy.
Verify the redacted output before disclosure, for example by confirming that obscured content cannot be recovered from the released file.
Apply redaction consistently against documented criteria and, where practical, subject the result to independent review to reduce the risk of over- or under-redaction.
Confirm the applicable requirements for the relevant jurisdiction and sector, since the permissible and required grounds for redaction can differ.