Bulk DSAR redactionFrankfurt, EUSheet 00 of 08
Keep the subject.
Redact redacted, everyone else
Nothing underneath.
An access request over a few hundred documents should not cost you a week. Declare who the request is about, drop in the files, and Veil redacts third-party personal data across all of them at once. What it cannot attribute to the subject, it redacts anyway and raises for you, so nothing is disclosed on a guess. It never edits your originals. It generates new documents with nothing underneath.
Residency
Your case data never leaves the EU
Originals
Originals are never modified
Verification
Every document independently checked before release
Commercials
Published pricing, no annual contract
Two files. One of them still contains the names.
Scroll to run the redaction pass. On the left, the file you hold, with rectangles drawn over the names. On the right, the document Veil generates from what it decided to release.
Five rectangles. Five names, still in the file, underneath them.
A new document, generated from the decision. The subject stays. Everyone else became a label.
Veil never edits your document. There is nothing underneath.
Drawing a black box over a name hides it from a reader. It does not remove it from the file. The text stays under the rectangle, a PDF keeps its earlier versions, a Word file keeps its tracked changes, a spreadsheet keeps its hidden columns, and an email carries a second copy of itself that your tool never showed you. These are not bugs. They are how the formats are specified to work.
A rectangle is a drawing. Ask the file what it says.
$ pdftotext redacted-in-place.pdf - [ press extract ] The file has five black rectangles drawn over five names. Nothing has been removed from the content stream.
$ pdftotext generated-by-veil.pdf - [ press extract ] A new document, generated from what Veil decided to release. The redacted names were never written into it.
GDPR Article 15(3) entitles the requester to a copy of their personal data, not to the original artifact. Supervisory authority guidance accepts extracts.
Eight places a covered name survives
- 01Text under the box
- 02Incremental update history
- 03Document metadata
- 04Embedded objects
- 05Tracked changes and comments
- 06Hidden sheets and columns
- 07Hidden slides
- 08Alternative MIME parts
Built for the difficult part of an access request.
Most DSAR software manages the request: intake, identity checks, the deadline clock, who is doing what. Veil does none of that and does not ask you to stop using whatever already does it. It does the part that eats the week, the disclosure review, where the requester's information sits in the same paragraph as their colleagues', their customers' and a witness's.
Stays where it already is
- Receiving the request and checking who is asking
- The one month clock, and any extension you rely on
- Assigning the work and chasing it
- The letter that goes back with the bundle
Veil's part
- Working out who each person in the case is, across every document at once rather than file by file
- Redacting third-party personal data, and redacting rather than disclosing whatever it cannot attribute
- Generating new documents instead of drawing over the ones you hold
- The bundle, the manifest and the quality report you actually release
Work out the deadline on the Desk
How a case runs
Three steps. Then close your laptop.
The work runs on European infrastructure whether your tab is open or not. A three hundred document case finishes while you do something else.
- 01
Declare the subject
Tell Veil who the request is about: name, email, the identifiers you hold. Everything that belongs to that person is kept.
- 02
Drop in the documents
Email with attachments, PDF, Word, Excel, PowerPoint, text and ZIP archives, several hundred at a time. Attachments are unpacked and treated as documents of their own.
- 03
Review, then release
Can withholdVeil presents one row per person it found, twenty to sixty rows for a large case. You confirm the ones it was not certain about. Every document is independently checked, then you release a bundle with a manifest and a quality report for your case file.
Drops in as it arrives
- EML
- MSG
- PDF, native text
- PDF, scanned via OCR
- DOCX
- XLSX
- PPTX
- TXT
- ZIP archives
- Nested attachments
The things a privacy team asks first.
What exactly does Veil redact?
Personal data belonging to anyone other than the data subject. Names, contact details, national identifiers, bank details, dates of birth and the identifying context around them. The data subject's own personal data is kept rather than removed, because that is what the access request entitles them to, and that turns on two things you do: marking the subject on the case, and declaring their identifiers in the form the documents actually write them. Anything we are not sure about is redacted and flagged for you rather than disclosed, so an identifier you have not declared comes back removed rather than kept.
What happens when the system is unsure?
It redacts and raises a flag. Uncertainty always resolves toward redaction, never toward disclosure, and that is enforced in the system rather than left to the interface. Turning a flagged entity into the data subject requires either a match against the anchors you declared, or an explicit attestation that is written to the audit log. This is why the product publishes no accuracy percentage: the part a percentage would describe as missed is not disclosed, it is covered and queued for a person.
Does the original document get modified?
No. Originals are read only from the moment they are uploaded. Veil produces new files alongside them and never writes back.
Where is the data processed and stored?
Entirely in the European Union. Database and object storage in Frankfurt, processing workers in Frankfurt, web functions pinned to Frankfurt, and model inference at a European provider, with no case, document or account identifier accompanying the content.
Which file formats are supported?
EML and MSG email with recursive attachment extraction, native and scanned PDF, DOCX, XLSX, PPTX, TXT, and ZIP archives. Scanned pages go through OCR. Every attachment inside an email becomes its own document in the case, with its parent recorded.
How is this different from a DSAR workflow platform?
Most DSAR tools manage the request: intake, deadline clocks, task routing. Almost none of them redact the documents themselves. Veil does that part, and only that part: it redacts third-party personal data across several hundred documents at once, and what it cannot attribute to the data subject it redacts anyway and raises for you. It sits alongside whatever you already use to track the request.
One decision. Every document.
The reason a large request takes a week is not that the decisions are hard. It is that the same manager appears in forty seven places across twelve documents, and each one is a separate decision made late in the afternoon. Veil resolves every mention of a person, across every file in the case, into a single row. You decide once. It applies everywhere that person appears, including the documents you have not opened.
- 212 · 38Kept, data subjectdeclared on the case
- 47 · 12
- 9 · 4
- 31 · 17Redacted everywherematched by rule
- 4 · 3Redacted everywherematched by rule
- 001·
- 002·
- 003·
- 004·
- 005·
- 006·
- 007·
- 008·
- 009·
- 010·
- 011·
- 012·
Spellings, initials, short forms and email addresses fold into the same person.
Confirming someone as the data subject keeps their data in place across the whole case. The same decision, in the other direction.
Every decision is recorded: what was decided, by whom, and when.
When Veil is not sure, it redacts.
No system reads every document perfectly, and we will not ask you to take an accuracy figure on faith. What protects you is which way the system errs when it is uncertain. Veil errs in one direction only.
- 01
Uncertainty redacts
Anyone who cannot be attributed to the data subject is redacted, then raised for a person to decide. Nothing goes from unknown to disclosed without a named person confirming it, and the confirmation is written to the audit log.
- 02
Identifiers are matched, not judged
National identifiers, bank details, contact details and dates of birth are recognised by rule. Nothing the automation infers afterwards can take one back out of the redaction set.
- 03
A separate check has the last word
Every generated document is re-read by a component built and run separately from the one that redacted it. Anything it cannot clear is withheld and the case stops, loudly, until a person looks.
What Veil will not guess at
Purely indirect identification, the colleague who broke his leg skiing. Badly degraded scans and handwriting. Original page imagery such as signatures. All of it is redacted first and raised for you second. None of it reaches a bundle because nobody looked.
Anyone who cannot be attributed to the data subject is redacted first, then raised for a person to decide.
European by construction, not by preference.
The parts of this product that touch personal data were designed on the assumption that they will one day be audited.
Residency
Every component that touches a document runs inside the European Union, pinned rather than defaulted.
Keys
Each case is encrypted under its own key. Purging a case destroys the key, so what was encrypted under it is unreadable everywhere, including in backups. The rest of the case is deleted, and survives only in a backup until that backup expires.
Retention
Cases purge on a schedule you set. Logs never contain personal data. Storage cannot be browsed.
Record
Every decision, download authorisation and settings change is written to an audit record that cannot be edited.
Priced on pages redacted. Nothing else.
No per-seat charge on a team that answers four requests a year, and no annual contract to sign before you can try it on a real case.
Every plan carries the full detection capability, independent verification on every document, and the bundle, manifest and quality report. There is no reduced tier.
Pay as you go
EUR0.50per page, no monthly fee
0.25 per page beyond 750 in one case, metered monthly
- Documents per case
- Up to 2,000
- Active cases
- 2
- Retention window
- Up to 30 days
- Seats
- 3
Team
Most casesEUR600per month, 2,300 pages included
0.26 per page beyond the included volume
- Documents per case
- Up to 2,000
- Active cases
- 10
- Retention window
- Up to 60 days
- Seats
- 10
Business
EUR1,800per month, 9,200 pages included
0.16 per page beyond the included volume
- Documents per case
- Unlimited
- Active cases
- Unlimited
- Retention window
- Up to 90 days
- Seats
- Unlimited
Worked example
Every document counts as at least two pages, so a 200 document access request is 400 billable pages at least, and costs 200 on pay as you go. On Team the same case is inside the included volume. In our own testing, a 1,000 upload case of 1,432 documents completed in 68 minutes.
Most recent run
68 minutes. A 1,000 upload mixed format case of 1,432 documents, completed in our own testing.
ReleaseManifest and quality report attached
Nothing
underneath.
Open a case, declare the subject, drop the documents in. Veil redacts, raises what it is not sure of, and shows you its working.
Reference
The Access Request Desk
The practitioner's reference for data subject access requests: what the law says in each jurisdiction, how a request is run, and what a redaction actually removes.
Guides
Long-form answers on redacting a data subject access request: what the law requires, whose data comes out and whose stays, and how to check what you release.
API documentation
The Pritect Veil API: bearer authentication and scopes, the error shape, cursor pagination, idempotency, every endpoint with examples, five webhook events.