A phone number, address, bank account number, or confidential passage needs to disappear from a PDF. So you place a black rectangle over it, save the document, and send it.
At first glance, the information appears to be gone. Technically, however, it may still be present in the document.
That is the difference between covering up content and properly redacting a PDF. A secure redaction needs to ensure that sensitive information is not merely hidden visually, but can no longer be easily recovered, selected, copied, or searched in the resulting document.
In this guide, we look at seven common PDF redaction mistakes and what you should check before sharing a document that contains sensitive information.
1. Simply placing a black box over the text
The most well-known redaction mistake is also one of the most important: placing a black rectangle over text does not automatically redact it.
Many PDF applications allow you to draw a shape, rectangle, or highlight over existing text. Visually, the information may no longer be visible.
But the original text can still remain underneath.
Depending on how the PDF is structured, it may still be possible to select, copy, search, or reveal that text with another application.
The key rule is: A black box is only a secure redaction if the tool actually removes the underlying content or otherwise makes it reliably inaccessible.
If you regularly work with confidential documents, use a dedicated PDF redaction tool rather than simply drawing a black rectangle over sensitive information.
2. Not testing whether the redacted text can still be copied
One of the simplest checks is also one of the easiest to forget: test the finished document.
Save the PDF, close it, open the saved version again, and try to select or copy text from the redacted area.
If the supposedly removed information can still be selected and pasted into a text editor, it was not reliably removed.
This test does not replace a complete technical review, but it can immediately reveal basic redaction mistakes.
Make sure you test the saved output file, not just the document that is still open inside the editor.
3. Checking only what is visible on the page
A PDF does not necessarily consist only of what you can see on the screen.
Depending on the document, it may contain text objects, images, forms, comments, attachments, OCR text, and other embedded information.
That means the same sensitive information may exist in more than one place.
A common example is a scanned document with optical character recognition. The page may visually consist of an image while an invisible text layer is also present in the background for search and copy-and-paste functionality.
When redacting a PDF, the important question is therefore not only:
“Can I still see the information?”
But also:
“Is the information still technically part of the file?”
4. Confusing page redaction with metadata removal
Removing information from a visible PDF page does not automatically remove every piece of information associated with the document.
PDF files can contain metadata. Depending on the file, this may include the document title, author, creation or modification information, and other document properties.
If a document needs to be anonymized before publication or sharing, it is useful to distinguish between:
- content on the PDF pages,
- document metadata,
- comments and form data,
- embedded files or attachments.
A tool that redacts visible page content is not automatically a tool that removes every piece of information stored inside a PDF.
5. Forgetting embedded attachments and additional content
PDF files can contain more than a sequence of pages.
Some documents include embedded files or other additional content. If sensitive information appears both on a visible page and inside an embedded document, redacting the page alone is not enough.
This is especially relevant when a PDF comes from a more complex document workflow or has been edited by several people before being shared.
Before sending the document, check whether it contains other components that may also include confidential information.
6. Accidentally sharing the original, unredacted file
This mistake has nothing to do with complex PDF technology, yet it can defeat every other protection you put in place.
After editing a document, it is common to end up with several versions:
Contract.pdfContract_new.pdfContract_final.pdfContract_final_new2.pdf
If the original file is then accidentally emailed, uploaded, or copied into a shared folder, a technically perfect redaction of another version does not help.
Use a clear filename instead, for example:
Contract_redacted.pdf
Then open that exact file separately and review it before sharing it.
7. Not reviewing the finished document
Redaction should not end when you click “Save.”
Especially with more complex PDFs, a final visual and functional review is worthwhile.
Check at least the following:
- Have all sensitive passages been redacted?
- Can text still be selected in a redacted area?
- Can a redacted term still be found using PDF search?
- Are you looking at the correct version of the file?
- Are all pages displayed completely and correctly?
- Does the document contain attachments or other information that also needs to be reviewed?
For particularly sensitive documents, a second review by another person can also be useful. Someone who performed the redaction themselves may be more likely to overlook the same passage again during the final check.
PDF redaction checklist before sharing
Before you send or publish a redacted PDF, use this checklist:
- Use a real redaction tool instead of simply drawing a black shape.
- Save the completed PDF and open the saved version again.
- Try to select and copy text from the redacted area.
- Search the document for a term that was supposed to be removed.
- Review every page visually.
- Check document metadata separately if anonymization is required.
- Review comments, forms, and embedded attachments where relevant.
- Make sure you are sharing the redacted version rather than the original.
How Priviot PDF handles redaction
Priviot PDF includes a dedicated feature for redacting selected PDF content.
It does not simply place a black rectangle over the original information. Selected content is removed from supported document structures.
If reliable removal is not possible within the existing PDF structure, complex pages can be rasterized after explicit confirmation. If a redaction cannot be performed reliably, the operation is intended to stop rather than silently produce an unsafe result.
A redaction feature still has defined limits. Redacting page content does not automatically remove document metadata, embedded attachments, or an older unredacted version of the file stored elsewhere.
For that reason, you should still review the saved document before sharing it.
You can learn more about the feature on the Priviot PDF redaction page.
Why local processing can matter when redacting PDFs
PDF redaction is often performed specifically because a document contains confidential information.
When an online PDF service is used, the original unredacted document usually has to be transferred to that service's infrastructure before it can be processed.
That is not automatically unsafe. It does, however, introduce an additional service into the processing chain.
If the required operation can be performed locally, that additional transfer can be avoided.
Priviot therefore takes a local approach to its core document features. Which functions operate locally, when online services are used, and which technical limitations apply are documented in our technical transparency documentation.
Frequently asked questions about PDF redaction
Is placing a black box over text enough to redact a PDF?
Not necessarily. If a black shape is simply placed over the text, the original information may still remain inside the PDF. Proper redaction requires the underlying information to be reliably removed or made permanently inaccessible.
How can I check whether a PDF was properly redacted?
Open the saved file again and try to select, copy, or search for the redacted text. Review all pages and, for particularly sensitive documents, also check metadata, attachments, and other document components separately.
Does redacting a PDF automatically remove its metadata?
That depends on the tool. A feature designed to redact page content does not automatically remove document metadata. The two tasks should be treated separately.
Can scanned PDFs be securely redacted?
Scanned documents can also be redacted, but the exact process depends on how the PDF is structured. A scanned page may contain image data as well as an OCR text layer, so the resulting document should be reviewed carefully.
Should I delete the original PDF after redacting it?
Not necessarily. Whether the original file should be retained depends on its purpose and any legal or organizational retention requirements. The important point is to make sure the unredacted original is not accidentally shared with people who should only receive the redacted version.
Conclusion: Hidden visually does not mean securely removed
If you want to redact a PDF properly, do not rely solely on what appears on the screen.
Secure redaction needs to account for the underlying content. Metadata, attachments, other document components, and the correct file version may also need to be checked before the document is shared.
The most important rule is simple:
Redact, save, reopen, and verify the result.
If you want to redact and edit PDF content locally, you can find the corresponding feature in Priviot PDF.