PDF and GDPR: redact and anonymize personal data
2 min read·25 July 2026
For a GDPR access request you sometimes need to remove personal data of others from a document. Learn how to do this with PDF tools.
When you need to remove personal data
When someone submits an access request, you may not disclose information about third parties (other people) without their consent. If a report contains data about multiple persons, you must redact the personal data of others before sharing the document with the requester.
Redact with PDFrust
Use the Redact tool on PDFrust to black out specific text passages or personal data. Select the text you want to redact, choose the redaction color (black or other) and confirm. The text is then permanently removed from the document — metadata no longer contains the redacted text either. Download the redacted file.
Redact PDF
Try for free — no account needed
Anonymization vs. pseudonymization
Anonymization removes personal data completely — the person is no longer identifiable. Pseudonymization replaces names with codes (e.g. "Person A") — the person is still traceable via the code table. For GDPR access requests shared with the data subject, anonymization of third parties is the norm. Pseudonymization is more for internal use.
Check metadata after redacting
Some PDF editors retain the original text in metadata even after you "redact" it — only the display is black but the text is still readable by reading the metadata. Use the Info tool on PDFrust to verify the redacted text is also truly removed from metadata. PDFrust removes the text permanently.
Document the redaction process
Keep a log of which passages were redacted and on what grounds (e.g. "personal data of third party — consent absent"). This is important for evidence if the data subject or a supervisory authority (DPA) asks questions later. Note the date of the redaction process and who performed it.
Related tools