H
HidePDF
Redact PDFs in your browser. Nothing leaves your device.
100% local · fully local

Someone Asked You To Remove Their Information From a PDF You Published

An email arrives from a person named in a document your organisation put online — minutes, a roster, a budget pack, a complaint log — and they want their details taken out. You are not the one trying to protect your own data here. You are the one holding the file, deciding what a stranger is entitled to ask of you, and answering them afterwards. That is a different job from redaction, and the editing is the last and easiest part of it.

PDF
Drop a PDF here, or click to choose
Your file never leaves your device.
Burning in redactions…
Preparing pages…

Almost every guide on this site is written for the person who controls a document and wants to release less of it. You choose what is sensitive, you cover it, you send the file. This page is written for the other side of that transaction: the volunteer treasurer, the school office, the HOA secretary, the small charity, the parish council clerk, the club administrator who put a PDF on a website months ago and has now received a message from someone in it asking for their address, phone number, salary, case reference or signature to come out.

Three things make this genuinely different from ordinary redaction. First, you did not choose the timing or the scope — someone else did, and their idea of what is sensitive may be wider or narrower than yours. Second, the document is already public, which means there is a population of copies out there and your edit cannot reach them. Third, there is a person at the end of it who will read your reply, and how you answer determines whether this ends here or escalates. Get the workflow right and the actual black boxes take five minutes.

Before you open the file: four things to establish

Who is asking, and are they who they say they are. This sounds paranoid for a neighbourhood newsletter and it is not. An email saying "please remove my home address from the January minutes" is easy to honour. An email saying "please remove my name from the safeguarding log and confirm what else you hold about me" deserves a moment's thought about whether the sender is the person named, because the reply itself can leak. Verify proportionately: if the request only asks you to take something away, and honouring it reveals nothing, identity matters less. If the request asks you to confirm, describe or send anything back, verify first.

What they actually want removed. People describe this loosely. "Take my details off" might mean a phone number, or it might mean every trace that they were involved. Ask them to point at the specific document and the specific information, and ask whether it appears anywhere else you publish. It is much cheaper to answer that question once than to get three follow-up emails as they find more.

Whether you are obliged, and whether you want to. These are separate. Depending on your jurisdiction, the type of organisation you are, and why the document was published, a legal right to have personal data deleted may or may not apply to you, and such rights generally come with exemptions — records you are required to keep, publication that serves a recognised public interest, and so on. Whether any of that binds you is a question for a lawyer or your data-protection regulator, not for a web page. But notice that you often do not need the answer: if there is no reason to keep a home phone number in published minutes, remove it because it is reasonable, not because you were compelled. Reserve the legal analysis for the cases where you want to say no.

Whether the document is one you are allowed to alter. Some published records are published under a rule, and a rule may also govern how they are amended — a filed set of minutes, a statutory register, a tendering record. Quietly replacing the file may be the wrong move even when removing the information is the right one. Find out who signs off on a change before you make it.

The workflow

  1. Acknowledge fast, act at your own pace. A same-day reply saying you have received the request and are looking at it defuses most of the urgency. Silence is what turns a request into a complaint.
  2. Find every copy you control. Not just the one they linked. The same PDF is often attached to a newsletter page, sitting in a documents archive, duplicated under an old URL, and embedded in a page that renders it inline. Search your own site for the filename and for the person's name before you start editing.
  3. Check your other publications for the same person. If their address is in the January minutes it is plausibly in the March ones too. Handling all of them in one pass is the difference between one email and six. Our guide on redacting the same name or number consistently across multiple PDFs covers how to keep that pass systematic rather than from memory.
  4. Keep the original. Store the unedited file somewhere private before you replace anything. You may need it to answer a later question about what was published and when, and once the redacted version is the only copy, that record is gone.
  5. Redact and verify. Cover the regions, export, then open the export and try to select and copy text from where the information used to be. Verification is not optional on a file that is going back out in public.
  6. Replace, do not just re-upload alongside. Overwrite the file at the same URL where you can, so existing links keep working and resolve to the corrected version. A new file at a new address leaves the old one live.
  7. Deal with the copies you do not control. Search engines, archive services and any site that mirrored the document each need their own request. Replacing the file does not remove it from a search index by itself, and that gap is the single most common misunderstanding in this whole process.
  8. Close the loop in writing. Tell them what you removed, from which documents, where the corrected versions are, what you have asked third parties to do, and — honestly — what you cannot reach.

Scoping: what comes out and what stays

The temptation is to do exactly what was asked and no more. Usually you should do slightly more, because the person asking has looked at the document as themselves, not as a stranger trying to identify them. If you remove a home address but leave a phone number two lines down, you have not solved their problem. Read the passage as a whole and ask what it now supports.

The opposite failure is worth naming too. Removing so much that the document no longer makes sense — a set of minutes where the proposer and seconder of every motion is a black box — damages a record other people depend on, and it makes the redaction conspicuous in a way that invites speculation about who was covered. Where the shape of the remaining text still points at one obvious person, covering the name achieves very little; that is the moment to consider whether the right answer is removing a section, or the document, rather than editing it.

Be careful with the fact of the request itself. If someone asks to be removed from a list of four people, republishing with three names and a black rectangle tells every reader which of the four complained. Sometimes the discreet option is to restructure the passage, or to handle all four the same way, rather than to leave a single hole.

Common mistakes and misconceptions

Treating a takedown request as an accusation. Most of these are ordinary and reasonable, and a defensive first reply escalates something that would otherwise have ended in two emails. Answer the request, not the tone.

Editing the live file and leaving the old one reachable. Uploading a corrected PDF under a new name while the original stays at its old URL is the most common technical failure here. Both files are then public and the old one is the one that is already linked to.

Assuming a fixed website file means fixed everywhere. It does not. Indexes, archives, forwarded attachments and mirrors are separate problems with separate processes, and some are not solvable. Saying so is better than implying otherwise.

Drawing a rectangle in a PDF viewer's annotation tool and calling it done. An annotation sits on top of the text and can be moved or deleted by the recipient. Republishing that publicly is worse than not editing at all, because you have now advertised exactly where to look.

Deleting the original as a tidiness measure. If the request later becomes a formal complaint, you will be asked what was published. Keep the original privately and restrict who can reach it.

Handling only the document they named. The person can search your site as well as you can. Doing one pass across everything you publish is less work than the alternative.

Where HidePDF fits in this

HidePDF does one part of the job: turning the file you host into a file that no longer contains the information. It accepts a PDF, lets you draw black boxes by hand over the regions you choose, and on export rebuilds every page as an image with the boxes burned in, so there is no selectable text layer left underneath anywhere in the document. There is no text search, no pattern matching and no automatic detection of names or numbers — deciding what to cover and finding every instance of it is yours to do. It works on one file at a time, and it covers regions rather than deleting pages. Everything runs locally in the browser tab, with no upload required, which is useful here for a plain practical reason: the file you are fixing is one that someone has already objected to being public, and handling it does not require sending it anywhere new.

What it cannot do is the rest of the process — find your duplicate copies, reach a search index, or write the reply. Those are the parts that determine whether the request is actually resolved.

Related guides

Explore more ways to redact PDFs privately, or use the redaction tool above:

Frequently asked questions

Do I have to remove someone's information just because they asked?

Sometimes yes, sometimes no, and this page cannot tell you which — it depends on where you and the requester are, what kind of organisation you are, and why the document was published. Several data-protection regimes create a right to have personal data deleted, but each has its own scope, its own definition of who is covered, and its own exemptions, including situations where a record must be kept or where publication serves a recognised public interest. Other documents are published because a rule requires them to be, and quietly editing those can create a separate problem. The practical approach is to separate the two questions: whether you are obliged, which is a question for a lawyer or your regulator, and whether you want to, which is often an easy yes regardless of obligation. Do not answer the first question by guessing.

They want the whole document taken down. Is redacting it instead good enough?

Often it is the better outcome for both sides, but say so rather than deciding it silently. Removing the document entirely can break links, delete a record other people rely on, and in some contexts remove something you were supposed to keep available. Replacing it with a version that has their details covered usually resolves the actual harm while leaving the document intact. Where this fails is when the person's involvement is the sensitive fact, not just their contact details — if the document is a complaint they filed, covering the name leaves a complaint that a reader can still attribute from context. Explain which of the two you are doing and why, and let them come back if it does not solve their problem.

The PDF has already been downloaded and shared elsewhere. Is there any point redacting it now?

Yes, but be honest about what it achieves. Replacing the hosted file stops new copies of the old version being made from your site, which matters because that is where most copies come from. It does not reach copies that already exist — search-engine indexes, archive services, forwarded email attachments, other sites that mirrored it. Those need their own separate requests, and some of them you cannot reach at all. Tell the requester plainly that you have fixed the source and which other places you have asked, rather than implying the information is now gone everywhere.

Does HidePDF find and remove every mention of their name automatically?

No. HidePDF has no text search, no pattern matching and no automatic detection of names, numbers or dates. You open one PDF at a time, draw black boxes by hand over the regions you want covered, and the export rebuilds every page as an image so nothing selectable survives underneath. That means finding all the occurrences is your job, and on a long document it is the part most likely to go wrong — read every page rather than the ones you expect. It also accepts PDF files only, and it covers regions rather than deleting pages, so removing a whole page is a separate job for different software. Everything runs locally in the browser tab with no upload required.