Guide
How to redact a PDF properly: why a black bar often deletes nothing
You want to share a PDF, but first you need to hide names, salaries or bank details. The quick fix is a black rectangle over the passage. The result looks secure. In many cases it is not: the text is still stored in the file and can be made visible again with a few clicks.
This guide explains why that happens, which second leak many people overlook and what real redaction means. At the end you will find a checklist for sharing files and a short look at the EU General Data Protection Regulation (GDPR), known in Germany as the Datenschutz-Grundverordnung or DSGVO.
The classic mistake: a bar on top, the text stays in
A PDF stores content in separate objects. The text is one object, a drawn rectangle is another. If you place a black bar over a passage with a comment or shape tool, the bar only sits on top visually. The text underneath remains fully stored in the file.
Any recipient can then extract it. Selecting the area with the mouse and copying it is enough. The search function also finds the hidden text. Programs that read PDFs aloud or process them automatically will output it as well.
Mishaps like this happen again and again, even to experienced organizations. There have been public cases in which redacted passages from court documents, investigation reports and contracts could simply be copied out. The mistake is almost never caused by an outside attack, but by the wrong tool for the job.
The same trap exists in word processors. If you highlight a passage in black in Word or set the font color to black on a black background, you only cover the text. Even after exporting to PDF, it remains selectable, copyable and searchable.
The second leak: metadata and hidden content
Even if the visible text has been removed cleanly, the file can reveal more than you would like. PDFs contain metadata, that is, information about the document itself: author, company name, title, editing program and creation date. One example: you redact an employee's name in the text, but it still appears in the author field.
On top of that, there is content that does not stand out in normal reading mode and is therefore easily forgotten:
- Comments and annotations, such as internal notes from the review process
- Hidden layers containing older versions or additional information
- Attached or embedded files, for example the original Word file
- Bookmarks and links that point to internal names or storage paths
- The file name itself, for instance when it contains a person's name
What real redaction means
Real redaction means the content is removed from the file, not just covered. After the process, the text at that spot simply no longer exists. No copying, no search and no specialist tool can restore it, because there is nothing left.
There are two proven ways to achieve this. First: a redaction feature, that is, a dedicated blackout function, deletes the selected text objects from the file and puts an empty area in their place. Second: the page is rasterized. Rasterizing means the page is converted into a pixel image and rebuilt into the PDF as an image. The removed content is no longer contained in those pixels.
Both approaches have an honest price. A rasterized page no longer contains selectable text. You cannot select or search anything on that page, and the file may become somewhat larger. For confidential documents, this drawback is usually easy to accept.
One more important point: even after real redaction, the metadata remains a separate issue. Clean up both, the page content and the document properties.
Checklist: what to check before sharing
Take five minutes before you send the file. This check is far quicker than cleaning up after a data mishap. Only when every item passes is the file ready to be shared.
- Copy test: select the entire content, copy it and paste it into an empty text editor. The redacted content must not appear there.
- Search test: use the search function to look specifically for a redacted term. No hits is the goal.
- Metadata: open the document properties and check or clean author, title, subject and keywords.
- Display comments, annotations, layers and attached files, and remove them.
- Check the file name: no names and no confidential details in the file name.
- Always create a new file. The unredacted original stays stored separately and protected.
- For sensitive cases, have a second person double-check, following the four-eyes principle.
What the GDPR has to do with it
As soon as a document contains names, addresses, salaries, health details or bank data, you are dealing with personal data. Under Art. 4 No. 1 GDPR, that means all information relating to an identified or identifiable person. Anyone who passes such data on even though the recipient does not need it quickly runs into conflict with the principle of data minimization under Art. 5 (1) GDPR.
If a poorly redacted PDF reaches unauthorized recipients, this usually constitutes a personal data breach, colloquially a data mishap. Art. 33 GDPR then applies: you must inform the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. If you do business in Germany, that is the state data protection authority of the German federal state (Bundesland) where you are based. The notification is only waived if the breach is unlikely to result in a risk for the individuals concerned.
If a high risk is likely, you must additionally notify the affected individuals themselves under Art. 34 GDPR. Regardless of that, document every breach internally, including those you do not have to report. Violations of these duties can lead to fines.
The good news: with a clean redaction process, you never end up in this situation in the first place. Define once who redacts, who checks and with which tool. Even in a small team, this is settled in half an hour and saves a great deal of effort if things ever go wrong.
Questions and answers
Is it enough to print the document, black it out with a marker and scan it again?
That works, because the digital text from the original does not end up in the scan. Make sure the marker really covers the text and that nothing shows through when scanning. The approach is laborious, though, quality suffers, and the scanner writes its own metadata into the new file. Check that before sending.
Is redacting directly in Word safe?
No. Black highlighting or black font color only covers the text, even after exporting to PDF. Actually delete the passage in Word or replace it with placeholders such as XXX. Also check the document properties, because Word often carries the author and company over into the PDF.
How do I recognize whether a tool really redacts?
The vendor should state clearly that content is removed, for example with terms such as redact, rasterize or remove permanently. Do not rely on the description alone, though: run the copy test and the search test after redacting. If the text can still be selected or found, it is still there.
Do I have to report a data breach if a poorly redacted PDF was sent out?
That depends on the risk for the individuals concerned. If there is a risk, the notification to the competent data protection authority applies, without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33 GDPR). In the case of high risk, you also inform the affected individuals (Art. 34 GDPR). In any case, document the incident internally and seek professional advice if in doubt.
Redaction with Nimovis PDF
Nimovis PDF redacts by rasterizing: when you download or save, the marked passages are removed and the page is rebuilt as an image. The metadata cleanup clears the author, title and other document properties. You select text with character precision, or draw a box over an area for scans without a text layer. An honest limitation: a redacted page becomes an image page afterwards, so its content can no longer be selected or searched there. And the check before sharing, for example with the checklist above, remains your job.
Start for free- Art. 4 GDPR, definitions (personal data)
- Art. 33 GDPR, notification of a personal data breach to the supervisory authority (72-hour deadline)
- Art. 34 GDPR, communication of a personal data breach to the data subject
- Data Protection Commissioner of Lower Saxony: guidance on redacting documents
- Saxon Commissioner for Data Protection and Transparency: privacy-compliant redaction
This guide provides general information and does not replace legal or tax advice.