GDPR redaction guide

GDPR image redaction tool

GDPR's data-minimisation principle says you should only share or store the personal data you actually need. Redacted helps you strip personal data out of screenshots and document images before they enter chat, tickets, knowledge bases, or shared drives.

What "personal data" looks like in an image

How Redacted helps

How to do a GDPR pass on an image

  1. Drop or paste the image into Redacted.
  2. Click Detect text for an automatic first pass.
  3. Manually mask anything the auto-detector missed — internal IDs, badges, chat avatars, freeform text.
  4. Use the black-box mask for anything you intend to be unrecoverable.
  5. Download the redacted image and share that copy.

Where this fits in your process

Redacted is a tool, not a compliance product. It helps with:

For full DSAR workflows, audit logging, or processor-level redaction, you'll need a dedicated platform. Redacted is for the operator at the keyboard.

Privacy

The OCR model and the personal-data detector run in-browser. No image and no extracted text are sent over the network. There's nothing to delete — the data was never anywhere else.

FAQ

Is Redacted a GDPR processor?

No — there's no data flow to process. Everything runs in your browser. There's no controller / processor relationship to declare.

Will it strip image metadata?

Yes. The exported image does not retain EXIF data such as location or camera info.

Can I use it inside an internal-only network?

Yes. Redacted is a static web app and works offline once loaded.

Redact for GDPR

Related Redacted pages

Browse all guides