Redaction risk checklist
A 16-question DPO-conversation starter. Score your organisation’s disclosure-preparation posture across governance, process, tooling, audit, and people. Designed for UK schools, GP practices, housing associations, NHS suppliers, and small public bodies.
Inputs are processed in your browser. Nothing leaves your device unless you opt to email yourself the results.
1. Do you have a written subject access / disclosure-preparation procedure?
A short document — half a page is fine — that says who triggers it, who runs it, what the scope rules are, and how the disclosure ships. ICO guidance assumes you have one.
2. Is the SAR / FOI / disclosure process owned by a single named individual?
An SBM/SBL, bursar, IG officer, or DPO who is the accountable contact when the next request lands. “Whoever has time on Tuesday” is not a named owner.
3. Does your organisation have a DPO function (in-house, shared, or outsourced)?
Schools and small organisations frequently use a shared / outsourced DPO. The DPO function exists if a named individual or firm provides DPO advice on request, even if part-time.
4. Do you systematically record the request-received date and the statutory disclosure deadline?
UK GDPR Article 12(3) gives one calendar month to respond; extensions to three months are available for complex cases but must be communicated within the original month. The clock starts the day the request lands. Recording the date matters.
5. Do you author a structured scope before you start triaging records?
Subject, requester, date range, in-scope categories, out-of-scope categories. Authored once and revisited as triage proceeds. Avoids drift.
6. Do you have a written approach to third-party personal data inside disclosed records?
Other pupils’ names, parents’ details, staff details, third-party correspondents. The default position under DPA 2018 Schedule 2 Part 3 is third-party data is exempt from disclosure unless consent is given or the disclosure is reasonable. Your approach should be written, not improvised.
7. Do you have a written approach to safeguarding-sensitive content in disclosure?
Schools and care-providers routinely receive SARs that touch safeguarding records. The position on what is and isn’t disclosable, and to whom (the data subject vs a parent acting on their behalf), needs to be settled in advance.
8. Do you have a written approach to financial records in disclosure?
Pupil-specific finances (pupil premium allocation, fees, individual spend) are typically in scope; institutional finances (general bank statements, payroll, supplier ledgers) are typically out of scope. Line-level entries in institutional records that name the subject stay in scope. Worth writing down.
9. What tool do you use for the actual redaction step? Is it configured for forensic redaction?
Acrobat Pro can do forensic redaction if you remember to use Apply Redactions then Sanitize Document. Specialist tools like SureRedact are forensic by default. “Black box drawn on annotation layer in Acrobat Reader” is the famous-published-but-not-really-redacted failure mode — answer “no” here if that’s your current process.
10. Do you have a structured way to import records from your source systems?
Google Vault export, Microsoft 365 Purview eDiscovery export, exported MIS data, an organised filesystem. A structured import beats “screenshot the inbox and copy-paste the relevant emails into a Word document” for both speed and audit-trail.
11. Do you have a way of surfacing PII candidates beyond what you can think to search for?
Acrobat’s text-search redaction finds what you tell it to find. A specialist redaction tool surfaces candidates by pattern (signatures, phone numbers, email addresses, credentials, names, dates of birth) on every page. The difference matters when records are unfamiliar or when the operator is tired.
12. Do you maintain an append-only log of operator decisions during disclosure preparation?
Every include / exclude / review / redact decision recorded with timestamp, operator identity, and before / after state. “Append-only” means the log can’t be silently mutated. A spreadsheet with manual entries is partial; a tamper-evident system log is full.
13. Could you reconstruct, three months after disclosure, why a specific record was excluded?
The honest answer for many hand-redaction workflows is “sort of, from memory.” The robust answer is “yes, by reading the decisions log entry for that record.” This is the question the ICO will ask if you receive a complaint about the disclosure.
14. Does your disclosure pack include a manifest of what was redacted and why?
The disclosure pack should accompany the redacted PDF with a structured record of redaction count by category, redaction certificate, and audit-log excerpts. Typically a Professional feature in disclosure-prep tooling; not part of the hand-redaction workflow by default.
15. Is the person doing the redaction trained on your organisation’s specific disclosure rules?
Generic redaction-tool training doesn’t cover “what counts as third-party PII at this school” or “what’s the position on safeguarding records here.” The operator-specific knowledge is what makes consistent decisions possible.
16. Is there a second-pair-of-eyes review step before disclosure ships to the data subject?
A reviewer who isn’t the operator who did the redaction. Catches accidental over-disclosure (third-party PII not redacted) and under-disclosure (in-scope material accidentally excluded). Worth doing on every disclosure; mandatory on safeguarding-sensitive ones.
How to use this checklist
- Answer each question honestly — “partial” or “unknown” are real options. The score isn’t a grade; it’s a starting point.
- Email yourself the results (the button at the bottom opens your email client). Forward to your DPO.
- Use the conversation to identify the two or three highest-impact improvements your organisation could make in the next term.
The checklist is informational only. A “high” score means your posture is robust; it does not certify compliance with UK GDPR / DPA 2018, which depends on your specific processing activities and your DPO’s assessment.
What to do if you score low
A low score isn’t unusual — many UK schools and small organisations are in the hand-redaction-in-Acrobat starting state. The structured next steps are typically:
- Write the procedure first. Half a page covering who triggers, who runs, the scope rules, how disclosure ships. Most-effective single change.
- Name an owner. Even if the workload is shared, someone is accountable — usually the SBM/SBL, bursar, or IG officer.
- Add an audit trail. A structured decisions log gives you the “why was this excluded?” answer when the regulator asks.
- Tooling last, not first. A tool on an undefined procedure produces consistent-but-wrong results. Procedure → tooling → continuous improvement.
SureMatters helps with the tooling layer (SureRedact for the redaction step; SurePrepare for pre-redaction triage). The procedure / governance / people layers are your DPO’s.