H
HidePDF
Redact PDFs in your browser. Nothing leaves your device.
100% local · fully local

How Long Should You Keep the Unredacted Original?

Deleting the original feels like the private, tidy, obviously-correct thing to do. Sometimes it is the one thing you must not do — and the date you delete it is a decision, not an afterthought.

PDF
Drop a PDF here, or click to choose
Your file never leaves your device.
Burning in redactions…
Preparing pages…

Almost every piece of redaction advice, on this site included, is about the moment of redaction: what the black actually removes, whether anything survives underneath it, which of the two near-identical files you then attach to the email. All of that is about the next few hours. This page is about the next few years.

Once you have a clean redacted copy, you are holding two documents, and one of them is the unredacted original. Sooner or later you have to decide what happens to it. The instinct is almost universal and almost always the same: get rid of it. It is the dangerous one, it is the file that could leak, it has served its purpose. Deleting it feels like finishing the job properly.

That instinct is right often enough to be a bad habit, because the cases where it is wrong are the expensive ones. The original is not just a privacy liability, it is also the record — the only authoritative statement of what the document said before you intervened, and the only way to prove your redactions were what you say they were. Destroying it can be a breach of a legal duty, a records schedule, an audit requirement or a contract, and unlike a bad redaction it cannot be corrected afterwards. So the question is not whether to delete the original. It is when, decided on purpose, with a reason you could state out loud.

Two pressures pulling in opposite directions

Retention decisions are genuinely hard because two legitimate principles point the other way from each other, and neither one is wrong.

Minimisation says you should not hold personal data longer than you need it. This is not just good hygiene, it is written into data-protection law. The GDPR's storage-limitation principle, in Article 5(1)(e), requires that personal data be "kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed," with narrow carve-outs for archiving in the public interest and scientific, historical or statistical research. Every month you keep an unredacted file is a month it can be stolen, mis-sent, backed up somewhere you forgot about, or swept up in a subject access request. The risk is not static; it accumulates.

Preservation says that some records must survive, and that losing them has consequences of its own. The sharpest version of this in US practice is Rule 37(e) of the Federal Rules of Civil Procedure, which deals with electronically stored information "that should have been preserved in the anticipation or conduct of litigation" and is lost because a party "failed to take reasonable steps to preserve it." Where that loss prejudices another party, a court may order measures to cure the prejudice; where the court finds the party "acted with the intent to deprive another party of the information's use in the litigation," it may go considerably further, including presuming the lost information was unfavourable to that party. The words anticipation of matter: the duty can bite before a case is filed, from the point you reasonably expect one.

You cannot satisfy both principles by splitting the difference. What you can do is work out which one actually governs this particular file, and for how long.

What sets the clock

Before you pick a date, check each of these. Any one of them can override your preference, and they are listed roughly in order of how often they turn out to apply.

  1. A live or foreseeable dispute. If there is a lawsuit, a grievance, a claim, an insurance matter or a regulatory complaint — or you can see one coming — stop. Preservation wins, and the decision is not yours to make alone. The redacted copy is a derivative; the original is the thing anyone would want to examine.
  2. A records-retention schedule. Employers, public bodies, healthcare providers, schools, charities and regulated firms typically have one, and it usually specifies classes of record and periods in years. If your organisation has a schedule, the file's class in that schedule is the answer, and your judgement is not required.
  3. A specific statutory or regulatory period. These exist, and they are narrower than people assume. For example, the HIPAA Security Rule at 45 CFR 164.316(b) requires covered entities to maintain their policies and procedures in written form and to keep a written record of any action, activity or assessment that the subpart requires to be documented — and then to retain that documentation for six years from creation or from the date it was last in effect, whichever is later. Note carefully what that covers: the compliance documentation, not patient records in general. Retention periods for clinical records themselves come from state law and vary, so the applicable period for a given file depends on what the file is and where you are.
  4. A contract or a grant condition. Audit clauses, funder requirements and supplier agreements frequently impose a retention period and sometimes a destruction obligation at the end of it. Both halves are binding.
  5. Your own need to answer questions about the redaction. In the absence of anything above, this is the floor. Until the recipient has accepted the document and nobody has queried it, you want to be able to look at what was underneath. A reviewer asking "why is this figure blacked out?" is answerable in thirty seconds with the original and awkward without it.

Making the decision once, and writing it down

The failure mode here is not choosing badly. It is never choosing at all — the original sits in a folder indefinitely because no decision was ever made, and nobody now remembers whether it is being kept for a reason or just left there. A lightweight routine fixes that.

  1. Work out the period before you redact, not after. It takes a minute and it is far easier while the context is fresh.
  2. Record one line somewhere durable. What the file is, when you produced the redacted version, the retention basis, and the review date. A line in a case file or a spreadsheet is enough. If you already keep a note of what you redacted and why, this belongs in the same place.
  3. Name the storage so the status is unmistakable. The original and the redacted copy should not be filed as siblings with near-identical names, because the whole category of accidental disclosure lives in that gap.
  4. Set a calendar reminder for the review date. Not a deletion date — a review date. When it fires you re-check whether anything has changed, and only then delete.
  5. Count the copies you did not make deliberately. The original mail attachment, the scanner output folder, a chat thread, a cloud sync folder, your backups. These are the copies that survive your careful deletion and the ones nobody inventories.

Destruction at the end of the period

When the clock does run out, deleting the one file you can see is not the same as destroying the record. Backups are the usual survivor: if your backup system keeps versioned snapshots, the original persists there until those snapshots age out, and that lag is sometimes months. On a shared or managed system, a deleted file may be recoverable from a trash or retention bin for a defined window by design. Neither of those is a scandal — they are ordinary infrastructure — but they mean "deleted" has a date attached to it rather than being instantaneous, and it is worth knowing roughly what that date is for your own setup.

Where the content is sensitive enough that this matters, the cleaner pattern is to have kept the original somewhere with a known lifecycle from the start — an encrypted container, a dedicated folder excluded from general backup, or a system with an actual retention policy applied — rather than trying to chase copies afterwards. Deletion is much easier to do properly when you planned the storage for it.

Common mistakes and misconceptions

"The redacted copy replaces the original." It does not. The redacted file is lossy by design: the covered content is gone and so, in a rasterised export, is the selectable text everywhere else. It is a publication of the document, not a copy of it. Anything you need to do later that requires the real content requires the original.

"Deleting it is always the privacy-respecting choice." Minimisation is a real principle, but it is not the only one, and in a matter where somebody else has a right to see the underlying document, destroying it is the opposite of respecting their interests.

"There is no duty because nothing has been filed." This is the specific trap Rule 37(e) sets, with its reference to information that should have been preserved in the anticipation of litigation. The point at which you reasonably foresee a dispute is earlier than the point at which it becomes official.

Assuming a single retention period covers everything. Different categories of document carry different periods, and a mixed bundle inherits the longest one that applies to anything in it. Do not retrofit a tidy number across a folder of unlike files.

Treating "keep the original" as "keep it where I work." Retention and accessibility are different requirements. The original should be findable when needed and awkward to touch the rest of the time.

Expecting the tool to handle this. Browser-based redaction leaves the input file exactly where it was; the download is a separate new file. Nothing is archived on your behalf because there is no archive. Retention is a question about your storage, not about the tool.

Deleting the original to fix a bad redaction. If you have already sent a file that was not redacted properly, destroying your copy of the original does nothing about the copy you sent, and it removes your ability to work out exactly what was exposed — which is the first thing you will be asked.

Related guides

See also, or use the redaction tool above:

Frequently asked questions

Should I delete the unredacted original as soon as I have the redacted copy?

Usually not immediately, and occasionally not for years. Deleting it is the instinctively private choice, but it is irreversible and it removes your only proof of what the document said before you touched it. In the short term you will almost certainly need the original again: to re-check a box you are unsure about, to produce a slightly different version for a different recipient, or to answer a question about a figure that is now under black. A reasonable default is to keep the original at least until the matter it belongs to is closed and nobody has queried your redactions. The exception runs the other way: if the file is subject to a preservation duty, a records-retention schedule, an audit requirement or a contractual obligation, the decision is not yours to make on convenience grounds at all, and you keep it for the period that applies. Delete on a date you chose deliberately, not on the afternoon you happened to finish the job.

If I am in a dispute or a lawsuit, can I delete the unredacted version?

Treat the answer as no until somebody qualified tells you otherwise. In United States federal practice, Rule 37(e) of the Federal Rules of Civil Procedure addresses electronically stored information that should have been preserved in the anticipation or conduct of litigation and is lost because a party failed to take reasonable steps to preserve it. Where the loss prejudices another party a court may order measures to cure that prejudice, and where it finds a party acted with the intent to deprive another party of the information's use it may go further, including presuming the lost information was unfavourable. Note the phrase anticipation of litigation: the duty can attach before anything is filed. Other jurisdictions have their own rules and the details differ, so this is a question for a lawyer rather than a checklist. The practical point is that the unredacted original is the evidence and the redacted copy is a derivative of it, so destroying the original while a matter is live is the version of this decision that can actually hurt you.

Does HidePDF keep the original for me, so I do not have to?

No, and that is deliberate. The redaction work happens in the page in front of you; the file you pick is read into the browser tab, and the download is a newly built PDF. There is no account, no archive and no restore-from-anywhere feature, because there is nowhere for a copy to be kept. That cuts both ways and it is worth being honest about it: no remote copy means no remote copy to be breached, subpoenaed or mis-shared, and equally no remote copy to rescue you if you delete your own original and then need it. Retention is therefore entirely a question about your own storage — your disk, your backups, your document management system, your mail archive. If you need the original to survive a dead laptop, that is a job for your own encrypted backup, not for a redaction tool.

Where should the unredacted original live while I wait out the retention period?

Somewhere you will not reach for it by accident. The two failure modes are different and both are real: losing the original when you needed it, and attaching the original when you meant to attach the redacted copy. Separating them structurally beats relying on care in the moment. Put the original in a folder whose name makes its status unmistakable, keep it out of the directory you drag attachments from, and keep it out of any folder that syncs to a space other people can browse. Where the content is genuinely sensitive, an encrypted container or a drive that is not mounted day to day adds a useful speed bump. Also think about the copies you did not create on purpose — the mail attachment you were originally sent, the chat message, the scanner output folder, the browser Downloads list. Those count as retained copies for the purpose of a breach and usually not for the purpose of satisfying anyone's records obligation, which is the worst of both worlds.