Skip to content

HomeBlog › Privacy

Privacy

The line you forgot to remove is the one that costs you

By Sourav Mahapatra · 26 July 2026 · 7 min read

Sensitive lines being masked out of a document

You export a spreadsheet to send to a vendor. You forward an invoice to your accountant. You share a screenshot with a support agent so they can see the error.

Each of those is routine. Each of them, done carelessly, hands someone else a PAN number, a home address, a full salary line, or a customer list you had no right to pass on.

This stopped being merely embarrassing

India's Digital Personal Data Protection Rules were notified in November 2025, and they run on a phased timeline: the consent manager framework becomes operational in November 2026, with full substantive compliance due by 13 May 2027. That covers notice, consent, security safeguards, breach reporting and the rights of the people whose data you hold.

Two details matter more than the rest for a small business:

You cannot leak data you never sent.

Redaction is the cheapest safeguard available. It costs a minute and it removes the thing that would have been the breach.

What to strip, in order of regret

Work down this list before anything leaves your hands:

The mistake that undoes the whole exercise

Drawing a black box over text in a PDF editor often does not delete the text. It draws a rectangle on top of it. The characters are still in the file, selectable, copyable, and recoverable by anyone who opens it in a different reader. Several well-publicised leaks have been exactly this.

Real redaction removes the underlying characters, or flattens the page to an image so there is nothing left underneath. If you can still select the text after redacting, you have not redacted it.

Strip the sensitive lines, keep the document

Paste in text or a document and mask the identifiers before you send it. It runs entirely in your browser, so the unredacted original never reaches a server.

Open the PII redactor

Free, no sign-up, nothing uploaded.

Why the redaction tool itself must be local

There is an obvious trap here. If you upload an unredacted document to a cloud service in order to redact it, you have already done the thing you were trying to avoid. The most sensitive version of the file, the one with everything still in it, is the version you handed over.

Redaction only makes sense client-side. Same for reading text out of a scan in the first place, which is why our image to text tool also runs in the browser, and why that piece makes the same argument.

A two-minute habit

Before you attach anything, ask one question: if this file were forwarded to someone I have never met, what in it would I regret? Remove that. Then send. Over a year it costs you a few hours and removes an entire class of incident from your business. Start with the redactor, and see the plain-English DPDP explainer for what else the rules expect.

Questions people actually ask

What counts as personal data under the DPDP Act?
Broadly, any data about an identifiable individual. In practice that includes names tied to other details, government identifiers, contact details, financial account information and employment data such as salary. If it can be traced back to a person, treat it as personal data.
How long do I have to report a data breach in India?
Under the DPDP rules a personal data breach must be notified to the Data Protection Board within 72 hours, and to CERT-In within 6 hours. There is no minimum severity threshold, so all breaches are reportable.
Is drawing a black rectangle over text enough?
No. In most PDF editors that draws a shape on top of the text while leaving the characters in the file, where they can still be selected and copied. Proper redaction removes the underlying text or flattens the page so nothing remains beneath.
Do these rules apply to a one-person business?
The obligations attach to anyone determining how personal data is processed, not only large companies. Smaller entities have lighter reporting burdens in places, but the core duties of security safeguards and breach notification still apply.
What is the maximum penalty for a data breach?
The highest penalty in the schedule is Rs 250 crore, applied where a failure to implement reasonable security safeguards leads to a personal data breach. Failing to notify a breach carries penalties up to Rs 200 crore.

Written by Sourav Mahapatra, who builds BeginThings: free browser tools and BeginRooms, a 3D workspace you can walk through. Take the 30-second tour or start a free 15-day trial, no card needed.