Home / Compliance
Redaction and Compliance Regulations
Redaction is a legal obligation before it is a software problem. This section covers what each regime requires, per media type, and what a defensible response looks like.
Disclosure Regimes
Where the obligation is to release, with specific things withheld.
- US FOIA — exemptions 1 through 9, statutory deadlines, and the requirement that a withholding be justified
- UK FOIA — the UK regime, its exemptions and the public interest test
- GDPR and DSAR — the 30-day clock, and the problem of releasing footage that contains people other than the requester
- UK GDPR — where it diverges from the EU regime
Sector Regimes
- HIPAA — the enumerated identifiers, and where they hide in clinical narrative and imaging
- CJIS — criminal justice information, and why the agency holds the obligation
- FERPA — student records, and campus footage containing minors
- COPPA — children's data
- GLBA — financial institutions and customer information
- PCI DSS — cardholder data in recorded calls
Biometric and AI
- BIPA — Illinois biometric information, and why faces in footage are a category of their own
- EU AI Act — obligations attaching to AI systems that process personal data
US State Privacy Acts
A patchwork that now spans most of the country, each with its own definitions and its own deadline.
California (CCPA/CPRA) · Virginia (VCDPA) · Colorado (CPA) · Connecticut (CTDPA) · Florida (FDBR) · Texas (TDPSA) · Oregon · Montana · Delaware · Rhode Island (RIDPA) · Maryland (MODPA) · New Hampshire (NHDPA) · New Jersey · Nebraska (NDPA) · Iowa · Indiana (ICDPA) · Tennessee · Utah
Measuring a Release Against the Rule
Requirements are one thing; evidence that you met them is another.
When a detection job runs against a framework, the dashboard reports how much of that framework's detection set was actually redacted. Twelve frameworks ship with their own class sets: HIPAA, PCI DSS, GDPR, FERPA, CCPA and CPRA, GLBA, CJIS, SOX, COPPA, FRCP, US FOIA and UK FOIA. Custom sets are definable.