Skip to main content

Free resource

FOI and DSAR redaction checklist

Seven steps to ship a disclosure pack without leftover personal data. Use it with any tool; Northdocs automates the painful parts.

Before you release an FOI or DSAR pack, confirm you found personal data, reviewed third parties, removed content (not only covered it), verified the export, and kept an audit trail. This checklist is the minimum bar for legal-grade disclosure hygiene.

  1. 1

    Define the disclosure scope

    List which files are in scope, who the requester is, and which third parties must remain protected.

  2. 2

    Collect the full file set

    Include email exports, Office docs, and scans. Convert to PDF when your process requires a single pack format.

  3. 3

    Detect structured and semantic PII

    Catch emails, phones, national IDs, and IBAN-like values, plus names, orgs, and addresses that regex alone misses.

  4. 4

    Review by identity, not only by page

    Accept or reject each person across the pack so variants of the same identity do not slip through.

  5. 5

    Apply permanent removal rules

    Redact or pseudonymize with content-stream removal. Do not rely on black boxes that leave extractable text.

  6. 6

    Verify before anyone downloads

    Re-extract text after apply. If sensitive strings survive, block the export and fix the misses.

  7. 7

    Pack, stamp, and retain audit evidence

    Assemble TOC/binders if needed, stamp exhibits, and keep an audit log of who approved the release.

Where teams still get stuck

A checklist helps. A fail-closed workspace finishes the job when volume rises.

  • Fast Track identity dossiers instead of page-by-page hunting
  • Automatic verify gate before download
  • EU-hosted cases with diligence pages for procurement

30-day free trial · no card required