Redaction is usually treated as a document task. Open the file, black out the personal data, save a flattened copy, send it. The information is protected and the request is answered.
The problem appears months later. An applicant asks for an internal review, or the ICO asks the authority to explain a decision, and someone has to reconstruct why a particular passage was withheld. The redacted file itself is no help. It shows that information was removed, but nothing about the reasoning.
The record is the compliance value, not the black box
Withholding information under FOIA or the EIRs is a decision that has to be justified against a specific provision. A refusal notice under section 17 must state which exemption is relied on and why it applies. Where a qualified exemption is used, the public interest reasoning has to be explained too.
That means the useful artefact is not the redacted document. It is the record sitting behind it: which passage, which exemption, whose decision, and when.
- Which part of which page was withheld.
- The exemption or exception relied on, in the wording used at the time.
- The officer who applied it.
- The date it was applied.
- Any note explaining the specific application of that exemption.
- Whether it was identified by a person or proposed by a tool and then confirmed.
Why the wording needs snapshotting
Exemption libraries change. Teams rename entries, retire ones they no longer use, and adjust house wording as guidance develops. If a redaction record only points at a library entry, then editing that entry quietly rewrites history. The file now claims a basis that was not the one actually relied on.
Storing the section reference and the exemption wording as they stood at the moment of redaction avoids that. The record continues to say what the officer actually decided, regardless of what the library looks like today.
How Phanera helps
In Phanera every redaction is stored as its own record against the exemption it relies on, with the officer, the timestamp, and the exemption wording captured at the point it was applied. Suggestions can come from a pattern scan for personal data or from AI mapped to your own exemption library, but nothing is applied until an officer confirms it.
A schedule of redactions falls out of the record
Once each redaction carries its own basis, a schedule of redactions is no longer a document someone has to assemble by hand at the end of the case. It can be produced from what is already held, which makes it far more likely to be accurate and far more likely to exist at all.
The same records support a redaction indicator on a public disclosure log entry, so a reader can see that material was withheld and under which provision, without the authority publishing anything further.
Confirm before you apply
Automated detection is useful for finding candidates. Email addresses, phone numbers, national insurance numbers and similar patterns are easy to miss by eye across a long document. It is not a substitute for the decision itself.
Keeping a person in the loop for every redaction, and recording that they confirmed it, is what makes the resulting file defensible. It also means the record can distinguish between what a tool proposed and what an officer decided, which is a question worth being able to answer.
