Privacy
The line you forgot to remove is the one that costs you
You export a spreadsheet to send to a vendor. You forward an invoice to your accountant. You share a screenshot with a support agent so they can see the error.
Each of those is routine. Each of them, done carelessly, hands someone else a PAN number, a home address, a full salary line, or a customer list you had no right to pass on.
This stopped being merely embarrassing
India's Digital Personal Data Protection Rules were notified in November 2025, and they run on a phased timeline: the consent manager framework becomes operational in November 2026, with full substantive compliance due by 13 May 2027. That covers notice, consent, security safeguards, breach reporting and the rights of the people whose data you hold.
Two details matter more than the rest for a small business:
- The breach clock is brutally short. A personal data breach must reach the Data Protection Board within 72 hours, and CERT-In within 6. There is no materiality threshold, so "it was only a small leak" is not a category that exists.
- The penalties are not symbolic. Failure to put reasonable security safeguards in place, where that failure leads to a breach, carries a maximum penalty of Rs 250 crore.
You cannot leak data you never sent.
Redaction is the cheapest safeguard available. It costs a minute and it removes the thing that would have been the breach.
What to strip, in order of regret
Work down this list before anything leaves your hands:
- Government identifiers. PAN, Aadhaar, passport, voter ID, driving licence. These are the keys to identity theft and they are almost never needed by the person you are emailing.
- Financial account details. Bank account numbers, IFSC, card numbers, UPI IDs tied to an individual.
- Contact and location data. Personal phone numbers, personal email, home addresses. Work contact details are usually fine; residential ones rarely are.
- Compensation. Salary, CTC, commission rates. A payroll sheet shared to prove one number exposes everyone else on it.
- Third-party names. Your other clients, in a document going to this client. Obvious in hindsight, missed constantly.
The mistake that undoes the whole exercise
Drawing a black box over text in a PDF editor often does not delete the text. It draws a rectangle on top of it. The characters are still in the file, selectable, copyable, and recoverable by anyone who opens it in a different reader. Several well-publicised leaks have been exactly this.
Real redaction removes the underlying characters, or flattens the page to an image so there is nothing left underneath. If you can still select the text after redacting, you have not redacted it.
Strip the sensitive lines, keep the document
Paste in text or a document and mask the identifiers before you send it. It runs entirely in your browser, so the unredacted original never reaches a server.
Open the PII redactorFree, no sign-up, nothing uploaded.
Why the redaction tool itself must be local
There is an obvious trap here. If you upload an unredacted document to a cloud service in order to redact it, you have already done the thing you were trying to avoid. The most sensitive version of the file, the one with everything still in it, is the version you handed over.
Redaction only makes sense client-side. Same for reading text out of a scan in the first place, which is why our image to text tool also runs in the browser, and why that piece makes the same argument.
A two-minute habit
Before you attach anything, ask one question: if this file were forwarded to someone I have never met, what in it would I regret? Remove that. Then send. Over a year it costs you a few hours and removes an entire class of incident from your business. Start with the redactor, and see the plain-English DPDP explainer for what else the rules expect.
Questions people actually ask
- What counts as personal data under the DPDP Act?
- Broadly, any data about an identifiable individual. In practice that includes names tied to other details, government identifiers, contact details, financial account information and employment data such as salary. If it can be traced back to a person, treat it as personal data.
- How long do I have to report a data breach in India?
- Under the DPDP rules a personal data breach must be notified to the Data Protection Board within 72 hours, and to CERT-In within 6 hours. There is no minimum severity threshold, so all breaches are reportable.
- Is drawing a black rectangle over text enough?
- No. In most PDF editors that draws a shape on top of the text while leaving the characters in the file, where they can still be selected and copied. Proper redaction removes the underlying text or flattens the page so nothing remains beneath.
- Do these rules apply to a one-person business?
- The obligations attach to anyone determining how personal data is processed, not only large companies. Smaller entities have lighter reporting burdens in places, but the core duties of security safeguards and breach notification still apply.
- What is the maximum penalty for a data breach?
- The highest penalty in the schedule is Rs 250 crore, applied where a failure to implement reasonable security safeguards leads to a personal data breach. Failing to notify a breach carries penalties up to Rs 200 crore.
Written by Sourav Mahapatra, who builds BeginThings: free browser tools and BeginRooms, a 3D workspace you can walk through. Take the 30-second tour or start a free 15-day trial, no card needed.