How To Write a Redaction Log for a Redacted PDF
Every other guide on this site is about the file — whether the black box holds, whether the text underneath is gone. This one is about the second document that travels with it: the record of what you covered and why, written so it explains the redaction without undoing it.
A redacted PDF answers one question and raises another. It shows the recipient what you were willing to share. It does not show them what you took out, on what basis, or whether the person who drew the boxes was applying a rule or a mood. In any process where someone can push back — a records request, a litigation production, a regulator's file, an internal investigation, a grant or benefits submission — that second question arrives almost immediately, and a black rectangle is not an answer to it.
The redaction log is the answer. It is a separate document, usually a table, that lists each withholding and gives a reason for it. Writing one is a different skill from redacting, and the difficulty is not clerical. A log has to be specific enough to be reviewable and vague enough to stay safe, and those two requirements pull against each other on every line. Get it wrong in one direction and the log is useless boilerplate; get it wrong in the other and the log republishes the content you spent an afternoon covering. That failure mode is real: the description of a redaction can leak what the redaction hid, and unlike a bad black box, nobody thinks to check the log for leaks.
What a redaction log is — and what yours might be called
The same artefact appears under different names depending on the process, and the name matters because it usually carries a required format with it. In litigation, the log of material withheld on privilege grounds is generally called a privilege log, and it is typically counsel's document rather than the paralegal's. In public-records work, agencies commonly annotate each mark with an exemption code and maintain an index of withholdings; in some disputes a more detailed itemised justification is required. Internal investigations, audits, HR disclosures, academic ethics submissions, and journalism all use looser versions of the same thing, often just a spreadsheet.
Two consequences follow. First, do not invent a format if one has been specified for you — the rule, order, contract, or agency procedure that governs your matter controls the required columns, and a well-written log in the wrong shape still gets sent back. Second, if nothing has been specified, you are free to keep it simple, and a plain four-column table is enough for almost every informal case.
The central tension: describe it without disclosing it
Every entry sits somewhere on a line between two failures. At one end, "redacted — personal information" repeated ninety times, which tells a reviewer nothing and reads as if no decisions were made. At the other, "home address of the complainant, 14 Elm Row, Apt 2B", which is not a description of a redaction, it is the redaction, typed out again in a document you are about to hand over.
The workable middle is to describe the category and role of what you covered, never its value. "Third-party home address" identifies the kind of thing and why it mattered. "Bank account number belonging to a non-party" is reviewable — a reader can judge whether that class of data was properly withheld — without recovering a single digit. The habit to build is writing the noun, not the instance.
Two further checks are worth applying to a finished log. The first is the reconstruction test: read each entry next to the visible text that still surrounds the mark on the page. The document says "payment was made to the supplier named in paragraph 9"; your log says "supplier name, commercially confidential". Fine. But if the log for page 12 says "name of the sole company we purchased laminating film from in 2025", the entry has done the identifying for the reader. The second is the aggregation check: entries that are each harmless can combine. A log with eighteen entries reading "date of birth", "postcode", and "job title", against a document with one named individual left visible, can narrow a person down even though no single line gives anything away. Read the log as a document in its own right, not as a list of independent cells.
Anatomy of an entry
For an informal log, these are the fields that actually do work. Add columns if a process demands them; resist adding them for decoration.
- Locator. Where the mark is. Page number at minimum; a position or mark reference if the page has several. If the document is Bates-stamped or paragraph-numbered, use that instead of the PDF page count, because page numbering shifts when documents are assembled and the stamped reference does not.
- Extent. Whether you covered a value, a line, a paragraph, or the whole page. This is the column reviewers query most, and recording it forces you to notice when a mark grew larger than the thing it was covering.
- Category of content. The noun, not the instance: third-party identifier, account number, medical detail, security information, privileged legal advice, trade-secret pricing.
- Basis for withholding. The reason it is out: an exemption or rule reference where one applies, a contractual confidentiality obligation, a third party's privacy, a specific safety concern. If you cannot complete the sentence "if this is read, the harm is ___", you have found a mark to reconsider rather than an entry to write.
- Decision maker and date. Trivial to record, valuable months later, and essential when several people redact parts of one production and their standards need reconciling.
- Status. Optional but useful on anything contested: withheld in full, withheld in part, released on review, deferred pending a third party's consent.
Locating a mark once the pages are flattened
Reliable redaction destroys the addressing system you would otherwise use to describe it. HidePDF rebuilds every page of the document as an image on download and burns the boxes into those images, which is what makes the covered material unrecoverable — but it also means the exported file has no text to quote, no field names, and no labels on the rectangles. A log entry that says "the third redaction on page 6" is ambiguous the moment two marks sit side by side, and there is nothing in the exported file to disambiguate it.
The fix is to fix your reading order before you start and state it at the top of the log: marks are numbered top to bottom, then left to right, per page. Then describe position in human terms — "p.6, header block", "p.6, third row of the payments table", "p.12, signature block, left" — using structural landmarks that survive rasterisation because they are still visible on the page. A reviewer holding the redacted PDF can find every mark you mean, and no landmark you cite has told them what was under the box.
Write the log while you redact, not after
This is the single practical rule that matters most, and it is the one most often broken, because logging feels like paperwork and redacting feels like the job. Work page by page: read the page, draw the marks on it, write the entries for those marks, move on. Keep the source document open beside the log while you do it — after export, the covered content is genuinely gone from that file, and reconstructing a log from a flattened production means going back to your retained original and re-reading it against the black boxes, which takes longer than logging would have and introduces errors.
The status bar gives you a free consistency check while you work. It shows the number of boxes on the page you are looking at, so you can compare that count against the number of entries you have written for the page before moving on. A mismatch means either an undocumented mark or a stray box you drew and forgot, and both are worth catching before the export rather than after delivery. The same pass is also the natural moment to notice a mark you cannot justify — the entries you struggle to write are usually the redactions you made out of caution rather than need.
Where the log should live
Keep it as its own document unless you have been told otherwise. Appending it to the redacted PDF as extra pages binds the two together permanently: the log then travels everywhere the file does, cannot be corrected without reissuing the whole production, and gets read by people who were only ever meant to receive the document. Worse is putting reasons into the PDF's own furniture — comments, sticky notes, bookmark titles, attachment names. Those are structural parts of a PDF rather than marks on the page, a recipient can read them, and they are already a common hiding place for text that a redaction pass missed.
Treat the log itself as a disclosable document. In many processes it is one, and in most of the rest it can become one later, so write every line as if the other side will read it — because the version of the log you can safely hand over is the only version worth writing twice.
Common mistakes and misconceptions
Quoting the withheld text "for clarity". The most direct way to undo a redaction. If an entry needs a quotation to make sense, the entry is describing the wrong thing.
Writing the log from the redacted copy. You cannot see what you covered, so you end up guessing, and guesses in a log are worse than gaps. Log from the original, with the redacted version beside it.
One boilerplate reason for everything. Ninety identical rows reading "confidential" is a claim that you applied no judgement, and it invites a reviewer to test the whole set rather than a line of it.
Using PDF page numbers on a document that will be reassembled. Exhibits get inserted, cover sheets get added, and every locator in the log shifts by three. Stamped numbers, paragraph numbers, or document IDs are stable; the viewer's page counter is not.
Letting several redactors keep separate logs. Merge them into one document with one vocabulary before delivery. Two people describing the same category two ways is the easiest inconsistency for a reviewer to find and the hardest to explain.
Logging the marks but not the near-misses. When you decide not to withhold something contested, a one-line note on that decision is often more valuable later than any entry about what you did cover.
Assuming the log replaces verification. It documents intent, not outcome. A complete, well-written log describing eleven redactions is fully consistent with a file in which all eleven boxes are sitting on top of live, selectable text. The log and the technical check are separate jobs, and the log is the one that cannot catch the other's failures.
Treating the log as internal by default. Notes written in the belief that nobody else will read them — shorthand, speculation, frustration about the requester — read very differently when the log is produced. Write it for an audience from the first line.
Related guides
Explore more ways to redact PDFs privately, or use the redaction tool above:
- Redact PDF for Legal Discovery
- Redact a PDF for a FOIA Request
- Delegating PDF Redaction: How To Check Someone Else's Work
Frequently asked questions
Do I always need a redaction log?
No. If you are sharing a document voluntarily and nobody has a right to the material you covered, a log is optional and usually unnecessary. A log earns its keep whenever someone can challenge your scope: a records request, a litigation production, a regulatory filing, an audit, an internal investigation, or any process where a reviewer decides whether your withholding was proper. Formal processes often specify the format and sometimes the name — the governing rule, order, or agency procedure for your matter is the authority on that, not a general guide. Even where nothing is required, a short private log is worth keeping, because it is the only record of why a permanent redaction was made once the original has been filed away.
How specific should a log entry be before it gives away what I covered?
Describe the category and the role of the content, never its value. "Third-party bank account number" is a category. "Account ending 4417 at the claimant's credit union" is the content, and writing it in the log puts back exactly what the black box removed. The test is to read the entry as if you were the recipient trying to reconstruct the page: if the entry plus the visible text around the mark lets you work out the covered value, the entry is too specific. Two entries that are individually vague can also fail this test together, so read the finished log as a whole document rather than line by line.
Can I put the redaction log inside the redacted PDF itself?
Only if the process you are following asks for it that way. A log appended as extra pages becomes part of the file you are handing over, travels wherever that file travels, and cannot be corrected separately once sent. Putting reasons into PDF comments, sticky notes, or bookmark titles is worse: those are structural parts of the file that a recipient can read, and they are exactly the places sensitive text tends to survive a redaction pass. The safer default is a separate document, delivered alongside the PDF, with its own filename and version.
Does HidePDF generate a redaction log automatically?
No, and no tool that works this way can. You draw the boxes by hand on each page, and the tool's job is to burn them into the exported file permanently — it does not label the marks, number them, or export a list of what you covered. The one thing it gives you is a running count of boxes on the current page in the status bar, which is a useful cross-check: if page seven shows four boxes and your log has three entries for page seven, one mark is undocumented. Write the entries as you go, because once the file is exported and flattened, nothing in it tells you what a given black rectangle used to be.