Blackline Guides Open the tool

Document redaction checklist for GDPR, HIPAA and disclosure

Written for the person who has to hand a document to a regulator, a requester, an opposing party or a client, and be able to say afterwards exactly what was removed and how they know. This is operational guidance, not legal advice.

1. Decide what must go, before you open the file

Redacting by eye, page by page, is how things get missed on page 41. Write the list first, then apply it uniformly.

2. Redact so the content is removed, not covered

3. Handle what is not on the page

4. Verify, with a test you could show someone

pdftotext released.pdf - | grep -Ei "name|@|[0-9]{3}-[0-9]{2}-[0-9]{4}"
exiftool released.pdf | grep -Ei "author|title|creator|producer|date"

Then open the file and select the whole page in a reader, because copy-paste is exactly how a journalist or an opposing party will find it. Verification is not optional — it is the only step that converts "we redacted it" into "we know it is gone".

5. Record what you did

6. Mind the chain of custody of the tool

A document being redacted is, at that moment, at its most sensitive — it is the version that still contains everything. Uploading it to a third-party web service to be redacted puts an unredacted copy on someone else's disk, which is a disclosure in its own right and one you will have to declare. Prefer a tool that processes the file locally, and be able to state that it did.

Blackline runs entirely in the browser with no upload of any kind — you can verify that by disconnecting from the network and watching it keep working. The Agency tier exists for exactly this requirement: it grants the right to self-host the tool on your own domain, inside your own network, and to use it on client work, so the tool itself becomes part of your controlled environment rather than an external dependency. The Team tier covers ten seats for an internal compliance or legal team.

See Team and Agency licensing   or try it free