Compliance

Redact PDFs for GDPR and Subject Access Requests

A practical workflow for protecting third-party data and preparing privacy-safe SAR responses.

Published by RedactorFlow

Responding to a subject access request means going through every document you hold on someone and removing anyone else's personal data before it goes out. Third-party names, other people's contact details, internal notes that reference colleagues by name. In a school, that often means CPOMS exports, attendance records, and pastoral or safeguarding notes, all of which tend to mention other pupils, staff, or family members by name throughout. Under UK GDPR, getting this wrong creates a real compliance issue. Send a document with someone else's personal data still visible and you've made a second data breach while trying to fix the first one.

The scale is usually the hard part. A SAR response might run to hundreds of pages pulled from email threads, case notes, safeguarding logs, and internal systems, and you're expected to check every one of them for third-party information before anything goes out the door.

Where RedactorFlow started

RedactorFlow began as something closer to an educational tool than a commercial product. It was built to help data protection officers who were handling SARs and redaction largely on their own, often without a dedicated team, a budget for enterprise software, or much formal training in the mechanics of what proper redaction actually requires. School DPOs are a good example: often a single member of staff covering data protection alongside another role, working through CPOMS exports and attendance records that mention dozens of other pupils and staff by name, with a statutory deadline attached.

That's still the core of what the tool is for. The automatic scan and the colour coded preview aren't just there to save time. They also show you what's actually been identified as personal data and why, so you can learn to spot it yourself over time instead of treating the software as a black box.

Why manual redaction struggles with SARs

Drawing boxes over text page by page works fine for a five-page document. It falls apart at volume. Miss one mention of a colleague's name buried in an email thread on page 140 and that's a live compliance issue, not a typo.

There's also the upload question. A lot of redaction tools process your file on their own servers. For a SAR bundle, that means sending a document full of personal data, potentially including special category data, to a third party before you've even started removing the parts that shouldn't be shared. That's difficult to square with data minimisation principles on its own.

How RedactorFlow handles this

RedactorFlow runs entirely offline, so the document never leaves your machine during processing. That matters for any SAR bundle, and it matters more once special category data (health information, for instance) is involved.

Once a document is open, RedactorFlow scans it automatically and flags likely candidates for redaction: names, dates, and other personal identifiers. Each flagged item shows up colour coded by type in a preview, so you can see what's been picked up as a name versus a reference number at a glance, and accept or remove each one. The preview is an exact match for the final document, so there's no guessing what the output will actually look like.

For anything the automatic scan doesn't catch, there's a built-in assistant. Type in a specific name or phrase, such as a colleague mentioned informally in an email thread, and tell it to redact or ignore, and that instruction gets applied everywhere the term appears in the document. That's the difference between checking 200 pages by eye for one recurring name and applying one instruction once.

A practical SAR workflow

  1. Gather the documents that fall within scope of the request. This step happens outside RedactorFlow, but it determines everything that follows.
  2. Open each document and let the automatic scan run. It flags likely personal data for you to review, so you are not starting from a blank page.
  3. Work through the colour coded preview. Confirm what should be redacted, remove anything flagged incorrectly.
  4. Use the assistant for names and terms specific to this request. Third parties mentioned by name, internal references, anything the automatic scan wouldn't know to flag on its own.
  5. Use the draw tool for anything that isn't text. A signature, a handwritten annotation, a scanned stamp. Highlighting it manually applies the same permanent deletion as an automatically flagged item.
  6. Apply the redaction and check the metadata. Author fields and document properties can carry the same personal data you just removed from the page.
  7. Review the finished document before it goes out. Particularly for anything involving special category data, a second pass is worth the time.

Where RedactorFlow fits into GDPR compliance

Redaction software doesn't make you compliant on its own. Data minimisation, lawful basis, and your organisation's own SAR procedures still sit with you. RedactorFlow helps reduce two of the practical failure points: content that gets missed during manual review, and personal data sent to a third-party server before you've finished redacting it.

If SARs come across your desk regularly, the time saved by an automatic scan and a built-in assistant, compared with manually marking every instance of every name, adds up quickly. Because it runs offline, you're not weighing that convenience against sending unredacted personal data outside your organisation to get it.

This matters most if you're the only person in your organisation doing this work. RedactorFlow was built with exactly that DPO in mind: no large team behind them, no enterprise budget, but still expected to get SARs out the door correctly.

Try it on a real SAR bundle

The first 50 pages are free, so you can test RedactorFlow against an actual request instead of a sample file.

Download on the App StoreGet it from Microsoft

macOS 12+ and Windows 10+ supported. Free trial available; subscription required for continued use.