Short answer
No, not on its own. A box drawn over a name is a graphic. The characters stay in the content stream underneath it and copy straight out. Six other parts of the same file keep text too. The only reliable fix is to generate a new document.
Why the box does not remove anything
Drawing a rectangle over a name adds an object to the page. It does not take one away. The reader renders the rectangle on top, which is why the name disappears from the screen, and the characters remain exactly where they were in the file. Select across the area, copy, and paste: the name is in your clipboard.
This is not a defect in any particular tool. It is how the formats are specified to work. A PDF appends revisions rather than rewriting the file, a DOCX keeps deleted text as a revision, an XLSX hides a sheet by setting an attribute, and an email carries the same message twice in two different parts. Every one of those behaviours is useful, and every one of them keeps text that somebody believed they had removed.
So the question worth asking is not whether a redaction tool draws the box neatly. It is whether anything is left underneath it.
Seven ways a file keeps what you removed
These are the seven places text survives an in-place edit. They are not edge cases. Each one is the format doing what it was designed to do.
Text under the box
A drawn rectangle is a graphic. The characters underneath stay in the content stream and copy straight out.
Incremental update history
PDF appends revisions rather than rewriting. Earlier states of the page remain in the file.
Document metadata
Author, title, subject and custom properties survive an edit to the visible body.
Embedded objects
Charts, linked spreadsheets and attached files carry their own source data with them.
Tracked changes and comments
A DOCX keeps deleted text as a revision and keeps every comment thread.
Hidden sheets and columns
An XLSX hides a sheet by setting an attribute. The cells are still in the workbook.
Alternative MIME parts
An email carries plain text and HTML. Redacting the part you can see leaves the part you cannot.
A release that addresses one of these and not the other six is not a redacted release. It is the same file with one fewer way to read it.
How to check a file you have already sent
Every step below is something you can do with the software you already have, on a copy of the file, in a few minutes. Work down the list. A single hit means the disclosure carried personal data you meant to remove.
Select across the mark and paste it somewhere plain
Drag-select the area the box covers, copy, and paste into a plain text editor. Anything that appears was never removed from the file.
Search the document for a name you redacted
Use the reader's own find. A search hit that lands on a blacked-out area is the same finding as the paste above, and it is faster over a long document.
Read the document properties
Author, title, subject and any custom properties survive an edit to the visible body. Open the properties panel and read what is actually in them.
Look for earlier revisions of the page
A PDF that has been edited and saved holds the state it was in before the edit. If the file grew rather than shrank when you redacted it, that is what grew.
Open everything the file carries with it
Attachments, embedded charts and linked spreadsheets carry their own source data. Extract them and check each one the same way as the parent.
For DOCX and XLSX, check revisions, comments and hidden sheets
Turn on all markup and read the tracked changes and the comment threads. In a workbook, unhide every sheet, row and column before you decide it is clean.
For an email, read the part you were not looking at
A message carries plain text and HTML. Open the source and read both. Redacting the rendered version leaves the other one intact.
If any step produced a hit, treat the disclosure as having released personal data belonging to someone other than the requester, and follow your own breach assessment process. The file you sent is the file they hold.
What to do instead
The approach that removes the risk rather than reducing it is to stop editing the original at all. Produce a new document containing only what you decided to release, and release that. The entire list above stops applying, by construction rather than by care: there is nothing underneath the output, because the output was never the input.
This is what Pritect Veil does. Your originals are read only from the moment they are uploaded and are never modified. What you release is generated, with redacted people replaced by stable typed placeholders so the narrative still reads, and each source document producing its own output so a single file can be withheld without losing the rest of the bundle.
It also matters that the check clearing a document is not the thing that redacted it. Every generated document is verified by a component built and run separately from the redaction, and anything that check cannot clear is withheld rather than shipped with a warning attached. The same page sets out how Veil stores, encrypts and purges the documents you upload, which is the other half of the question a disclosure raises.
- Originals are read only and stay untouched in private storage.
- There is nothing underneath the output. What is not on the page is not in the file.
- Redacted people become stable typed placeholders, so the narrative still reads.
- Every page carries the case reference, document id, page number and generation time.
- Each source document produces its own output, so a single file can be withheld without losing the rest.
GDPR Article 15(3) entitles the requester to a copy of their personal data, not to the original artifact. Supervisory authority guidance accepts extracts.
Extracts are also the practical answer. Handing over a generated copy of the requester's own personal data is a smaller, faster and far more defensible artifact than a lightly edited version of everything you hold.
Questions
Is a black rectangle ever enough on its own?
No. A drawn rectangle is a graphic, and the characters underneath it stay in the content stream and copy straight out. It changes what the page looks like, not what the file contains.
Is this only a PDF problem?
No. A DOCX keeps deleted text as a revision and keeps every comment thread. An XLSX hides a sheet by setting an attribute, so the cells are still in the workbook. An email carries plain text and HTML, so redacting the part you can see leaves the part you cannot.
What does an access request actually entitle the requester to?
GDPR Article 15(3) entitles the requester to a copy of their personal data, not to the original artifact. Supervisory authority guidance accepts extracts, which is why generating a new document is a legitimate answer rather than a workaround.
Does Veil modify the document I upload?
No. Originals are read only from the moment they are uploaded. Veil produces new files alongside them and never writes back.
What happens with a scan that is hard to read?
Where optical character recognition confidence collapses, the pages are flagged and the case is held rather than passed through quietly. Output is generated from extracted text, so original page imagery is not reproduced in the output, and the bundle says so on the page.
Veil never edits your document. See what bulk DSAR redaction costs per document, or open a case and run it on a real disclosure.