Overview
EN ISO/IEC 27038:2016 (ISO/IEC 27038:2014) is an international standard that specifies techniques and requirements for digital redaction of electronic documents. It defines how to permanently remove sensitive information (including metadata and embedded content) so that redacted content cannot be recovered. The standard clarifies redaction principles, software tool characteristics, testing methods to verify secure redaction, and record-keeping practices. Note: redaction of information stored in databases is explicitly excluded.
Keywords: ISO/IEC 27038, digital redaction, redaction standard, information security, document anonymization, PDF redaction
Key Topics
- Scope and purpose: Procedures for permanently removing text, images or metadata from digital documents prior to disclosure.
- Redaction principles: Redaction must be irreversible; redaction is performed on copies; reviewers must specify precisely what to remove.
- Levels of redaction:
- BASIC - context not considered.
- ENHANCED - takes contextual cues into account to prevent inference of redacted data.
- Anonymization: Guidance on removing personally identifiable information (PII) and preventing re-identification through remaining context.
- Redaction processes: Handling of paper intermediaries, digital images, simple vs. complex redaction, OCR considerations, and managing contextual information that could reveal redacted content.
- Software tool requirements: Characteristics expected of redaction tools (secure removal, metadata handling, auditability).
- Testing and verification: Methods to confirm redaction is complete and irreversible.
- Record keeping: Logging of redaction actions, reviewer instructions, and lifecycle management of redacted copies.
- Annex on PDF: Informative guidance specific to redacting PDF documents.
Keywords: software redaction tools, redaction testing, metadata removal, PII protection, OCR, PDF
Applications
- Preparing documents for public release (legal, FOI requests, press releases)
- Law enforcement and court document handling
- Government and regulatory disclosures
- Privacy compliance and data protection (anonymization for GDPR/PII concerns)
- Secure publication of reports that include sensitive images or signatures
- Vendor development of secure redaction software and PDF-processing tools
Keywords: document redaction, secure redaction, public records, privacy compliance
Who should use this standard
- Information security and privacy officers
- Records managers and legal teams
- Forensic analysts and e‑discovery practitioners
- Software vendors building redaction or PDF tools
- Government agencies and publishers that release redacted documents
Related Standards
- ISO/IEC 29100:2011 (privacy framework and definition sources referenced within the standard)
- ISO/IEC 27000 family (context: information security management - consult organizational security requirements)
This standard is a practical reference for organizations and vendors that need to ensure digital redaction is performed securely, verifiably, and in a way that prevents recovery or inference of sensitive content.