Free resource
FOI and DSAR redaction checklist
Seven steps to ship a disclosure pack without leftover personal data. Use it with any tool; Northdocs automates the painful parts.
Before you release an FOI or DSAR pack, confirm you found personal data, reviewed third parties, removed content (not only covered it), verified the export, and kept an audit trail. This checklist is the minimum bar for legal-grade disclosure hygiene.
- 1
Define the disclosure scope
List which files are in scope, who the requester is, and which third parties must remain protected.
- 2
Collect the full file set
Include email exports, Office docs, and scans. Convert to PDF when your process requires a single pack format.
- 3
Detect structured and semantic PII
Catch emails, phones, national IDs, and IBAN-like values, plus names, orgs, and addresses that regex alone misses.
- 4
Review by identity, not only by page
Accept or reject each person across the pack so variants of the same identity do not slip through.
- 5
Apply permanent removal rules
Redact or pseudonymize with content-stream removal. Do not rely on black boxes that leave extractable text.
- 6
Verify before anyone downloads
Re-extract text after apply. If sensitive strings survive, block the export and fix the misses.
- 7
Pack, stamp, and retain audit evidence
Assemble TOC/binders if needed, stamp exhibits, and keep an audit log of who approved the release.
Where teams still get stuck
A checklist helps. A fail-closed workspace finishes the job when volume rises.
- Fast Track identity dossiers instead of page-by-page hunting
- Automatic verify gate before download
- EU-hosted cases with diligence pages for procurement
30-day free trial · no card required