Home / Compliance

Redaction and Compliance Regulations

Redaction is a legal obligation before it is a software problem. This section covers what each regime requires, per media type, and what a defensible response looks like.

WHICH RULE REACHES WHICH MEDIA VIDEOAUDIODOCSIMAGES HIPAAPCI DSSUS FOIAGDPRCJISFERPA COVERAGE AGAINST THE FRAMEWORK 18/18 classes 12 frameworks ship with their own class sets

What Ships With the Product

12

Frameworks with their own detection class sets

51

Statutory exemption codes, US and UK

18

US state privacy acts in scope

4

Media types governed by one policy

Disclosure Regimes

Where the obligation is to release, with specific things withheld.

US FOIA

Exemptions 1 through 9, statutory deadlines, and the requirement that every withholding be justified under a named basis rather than asserted.

UK FOIA

Twenty working days, and for qualified exemptions a public interest test that has to be reasoned on the record, not just reached.

GDPR and DSAR

A 30-day clock, and the harder problem underneath it: releasing footage to a requester when other people appear in it.

UK GDPR

The same structure as the EU regime, diverging in places that matter for transfers and for public authority duties.

Sector Regimes

HIPAA

Eighteen enumerated identifiers, which hide in clinical narrative and burned into imaging as readily as in a patient field.

CJIS

Criminal justice information, where the agency holds the compliance obligation and a vendor's controls support it rather than discharge it.

FERPA

Student records, and campus footage that routinely contains minors who are not the subject of the request.

COPPA

Children's data, with consent requirements that reach content collected incidentally.

GLBA

Financial institutions and customer information, including what is spoken aloud on a recorded call.

PCI DSS

Cardholder data, most often a card number read out to an agent and captured in the recording.

Biometric and AI

BIPA

Illinois biometric information. A face in footage is a category of its own here, not merely personal data, which changes what consent and retention look like.

EU AI Act

Obligations attaching to AI systems that process personal data, including transparency about automated processing.

US State Privacy Acts

A patchwork that now spans most of the country, each act with its own definitions and its own deadline.

California (CCPA and CPRA) · Virginia (VCDPA) · Colorado (CPA) · Connecticut (CTDPA) · Florida (FDBR) · Texas (TDPSA) · Oregon · Montana · Delaware · Rhode Island (RIDPA) · Maryland (MODPA) · New Hampshire (NHDPA) · New Jersey · Nebraska (NDPA) · Iowa · Indiana (ICDPA) · Tennessee · Utah

Measuring a Release Against the Rule

Requirements are one thing; evidence is another

When a detection job runs against a framework, the dashboard reports how much of that framework's detection set was actually redacted, per job and across the portal.

Twelve frameworks ship with their own class sets

HIPAA, PCI DSS, GDPR, FERPA, CCPA and CPRA, GLBA, CJIS, SOX, COPPA, FRCP, US FOIA and UK FOIA. Custom sets are definable alongside them.

The exemption travels on the file

A statutory code is applied as the redaction is made and drawn onto the mask, so a requester sees the basis without being sent to a separate log.

A Note on How This Is Written

We are not your counsel. These pages describe what the regimes require and how the software supports it. They do not tell you which exemption applies to your record, because that judgement is yours.

FAQ

Redaction and the Law questions, answered

Which regulations does redaction support?

Disclosure regimes including US FOIA, UK FOIA and GDPR subject access requests; sector regimes including HIPAA, CJIS, FERPA, COPPA, GLBA and PCI DSS; biometric and AI rules including BIPA and the EU AI Act; and eighteen US state privacy acts.

Can we prove a release met a framework?

When a detection job runs against a framework, the dashboard reports what proportion of that framework's detection set was actually redacted. Twelve frameworks ship with their own class sets, and custom sets are definable alongside them.

Which frameworks ship with their own detection classes?

HIPAA, PCI DSS, GDPR, FERPA, CCPA and CPRA, GLBA, CJIS, SOX, COPPA, FRCP, US FOIA and UK FOIA.

Does the released file show which exemption was applied?

Yes. A statutory code is applied as the redaction is made and drawn onto the mask, so a requester sees the basis without being sent to a separate log.

Can you tell us which exemption applies to our record?

No. These pages describe what the regimes require and how the software supports it. Which exemption applies to a particular record is a legal judgement and it is yours to make.

Bring Us a Release You Have Already Made

Send us a file you released under one of these regimes and we will show you what the coverage report would have said.