An FOI response can fail long after it has been sent. A name missed in an attachment, a black box that can be removed, or a decision that was never recorded can expose personal data, damage confidence and make a complaint difficult to defend. Knowing how to redact an FOI response therefore means more than obscuring text. It means making lawful, necessary and reviewable disclosure decisions within statutory timescales.
For UK public authorities, redaction is usually the final operational step in a wider assessment of what information is held, what falls within scope and whether an exemption applies. The redacted copy must be safe to disclose. The underlying reasoning must also be sufficiently clear to withstand internal review, an Information Commissioner’s Office complaint or later scrutiny.
Start with the information, not the black box
Before opening a PDF editor, establish the exact request, the relevant time period and the information sources likely to contain responsive records. Preserve the original material and work from controlled copies. This protects the integrity of the source record and prevents well-intentioned reviewers from overwriting evidence of what was originally held.
FOI requests often involve more than the document first identified. Emails may contain attachments, spreadsheets can hold hidden columns or comments, and scans may include handwritten notes. If CCTV, images, audio or video are in scope, identifying information may appear in frames, backgrounds or accompanying metadata rather than in a searchable text field.
At this stage, distinguish between information that is out of scope, information that is not held and information that is held but may be exempt. These are different conclusions and should not be treated as interchangeable. A redaction should not be used to conceal information merely because it is awkward, sensitive or likely to attract criticism.
How to redact an FOI response using a defensible workflow
A controlled workflow separates legal decision-making from the technical act of applying a redaction. That separation reduces the risk that a reviewer makes inconsistent disclosure choices while working quickly through a large bundle.
Identify the applicable exemption and test it properly
Review the responsive information in context. Common redaction grounds can include personal information under section 40, information provided in confidence under section 41, and commercial interests under section 43 of the Freedom of Information Act 2000. The appropriate exemption depends on the facts, the information itself and the consequences of disclosure.
Personal data requires particular care. The question is not simply whether a person is named. A combination of job title, incident details, location and dates can identify an individual, especially in a small team or a high-profile matter. Consider whether disclosure would be lawful, fair and transparent under data protection law, including UK GDPR and the Data (Use and Access) Act 2025 where relevant.
Some exemptions are qualified. Where they are engaged, record the public interest factors for and against disclosure and the conclusion reached at the time. A brief but specific explanation is stronger than a formulaic statement. It should show why the anticipated harm is credible and why disclosure is, or is not, in the public interest.
Environmental information may need separate consideration under the Environmental Information Regulations 2004. Do not assume that an FOI request label determines the legal regime. Where the boundary is uncertain or the material is particularly sensitive, obtain appropriate information governance or legal advice before release.
Create a redaction schedule as you review
For every proposed redaction, capture the page or item reference, the precise information withheld, the exemption or exception relied upon, and a concise rationale. Record the reviewer, decision date and any approval or escalation. This schedule creates a reliable bridge between the decision and the released document.
A structured schedule is far safer than relying on memory, email comments or a disconnected spreadsheet with no link to the final output. It also enables another reviewer to understand why a name, paragraph, figure or image area has been withheld without repeating the entire review.
Consistency matters across related records. If an individual’s identity is withheld in one email, check whether the same identity appears in a meeting note, attachment, filename or document properties. Equally, do not apply an exemption mechanically across a whole document if meaningful information can be disclosed with limited redaction. The duty is to disclose what can properly be released, not simply to release or withhold documents as a whole.
Apply irreversible redactions to every relevant format
A visual cover-up is not a redaction. Highlighting text in black, drawing a shape over it, changing the text colour or flattening a document without checking its underlying layers can leave the original content recoverable. The risk is not theoretical: copied text, search results, document layers, annotations and metadata can all reveal information that appears hidden on screen.
Use a secure redaction process that permanently removes the selected content and sanitises hidden information before producing the disclosure copy. The process should support the formats in the request, including PDFs, office documents, images and, where needed, video or CCTV. Video redaction requires frame-level treatment, because a person, vehicle registration or screen display may appear only briefly.
Redact only the minimum necessary. For example, removing a third party’s direct telephone number may be sufficient where the remainder of the sentence can be disclosed. In other cases, contextual detail will make partial disclosure unsafe. The decision should follow the evidence, not a fixed preference for either heavy or light redaction.
Check the document as a recipient would receive it
Quality assurance is a distinct control, not a final glance before sending. A second reviewer should compare the redacted output against the schedule and source material, confirming that every approved redaction has been applied and no unapproved information has been removed.
The check should include more than visible page text. Search the output, inspect comments and annotations, test copied text where appropriate, review document properties and confirm that filenames, bookmarks, headers, footers and embedded objects do not disclose withheld information. For spreadsheets, inspect hidden worksheets, rows, columns, formulae and cell comments. For image and video files, check metadata and every relevant frame.
Before release, confirm that the response letter explains the outcome clearly. Where information is withheld, identify the exemption relied upon and provide the required explanation, including public interest reasoning for qualified exemptions. The wording must be accurate without revealing the very information that has been withheld.
Avoid the process failures that create disclosure risk
The greatest redaction failures are often operational. Teams under pressure may divide a request across several reviewers, use multiple editing tools and exchange working files by email. That can lead to duplicate versions, unclear ownership and no reliable account of which copy was approved for disclosure.
A defensible process should maintain controlled access to source material, a clear version history, recorded decisions and formal approval before release. It should also preserve the original documents and the final disclosed copy. If a requester seeks an internal review, the organisation needs to reconstruct what was considered and why – quickly and accurately.
Generic PDF tools are particularly risky where they do not permanently remove underlying content or retain an audit trail. They may be adequate for routine document annotation, but redaction for statutory disclosure is a different task. The relevant test is whether the organisation can demonstrate that withheld information was securely removed and that each decision was authorised, consistent and reviewable.
For high-volume or complex requests, a platform such as Redaktr can bring the decision record, secure redaction and audit trail into one controlled workflow. This is valuable where multiple reviewers must work against the same evidence base, particularly for records containing personal data, commercial material, investigation information or video.
A release-ready FOI redaction check
Before issuing the response, confirm that the team can answer all of the following questions:
- Is every document and attachment within scope accounted for, including hidden or embedded content?
- Does each redaction have a recorded legal basis and case-specific rationale?
- Has the public interest test been documented where a qualified exemption is used?
- Are the redactions irreversible, with metadata, comments and other hidden data removed?
- Has an independent reviewer checked the final disclosure copy against the approved schedule?
- Does the response explain exemptions accurately and preserve the required review rights?
A clean-looking document is not proof of safe disclosure. The stronger standard is whether your organisation can evidence the path from request, to review, to exemption decision, to irreversible redaction, to approved release. Build that record while the work is being done, and the response will be safer to issue and far easier to defend.

