For the complete documentation index, see llms.txt. This page is also available as Markdown.

Redaction (data masking)

Automatically redact and mask PII in KYC document verification to protect sensitive data, support GDPR compliance, and strengthen privacy controls.

Overview

ComplyCube automatically applies field-level redaction (also known as field masking or data masking) on sensitive personally identifiable information (PII) fields to ensure compliance with global privacy regulations.

Examples of redacted fields include:

  • Dutch BSN (Burgerservicenummer or Dutch Citizen Service Number)

  • Singapore NRIC (National Registration Identity Card Number)

  • Korean RRN (Resident Registration Number)

To meet strict compliance requirements, sensitive fields are automatically redacted from document images stored in the customer record and the results of Document Checks. Where applicable, redaction is applied to both the front and back of the document.

Users on our Growth or Enterprise plans can customize and add additional fields to their redaction policies. Please contact your Account Manager to update your policy.

Scope

Redaction is applied immediately on document capture, before the document image is stored. All instances of sensitive fields are masked, including those encoded within QR codes, the Visual Inspection Zone (VIZ), the Machine Readable Zone (MRZ), and barcodes.

ComplyCube does not store or process these sensitive fields, ensuring strong privacy protection and full regulatory compliance.

During Document Check processing, all redacted text fields return as fixed-length asterisk (*) strings. This format is consistent across the API, Web Portal, and reports.

Where redaction is applied

Redaction applies anywhere ComplyCube displays or returns document images or extracted fields, including:

  • Stored document images in the customer record (Portal and exports).

  • Document Check results returned via API and visible in the Portal.

  • Generated reports that include document images or extracted fields.

Configuring redaction policies

Redaction is enabled by default for supported sensitive fields.

If you need to modify or add masking rules, your redaction configuration can be updated by contacting your Account Manager.

Sample illustrations of field redaction

Example of personally identifiable information (PII) redaction (data masking) of a Dutch BSN on a passport
Redacted BSN on a Dutch passport
Example of personally identifiable information (PII) redaction (data masking) of a Korean RRN on a passport
Redacted RRN on a Korean passport

Frequently asked questions

What does redaction do in ComplyCube?

Redaction masks supported sensitive fields before document images are stored or returned.

This helps reduce privacy risk and supports compliance with data minimization requirements.

Why is redaction important for jurisdiction-specific compliance?

Some jurisdictions restrict the processing or storage of certain document fields, such as national ID numbers or other regulated identifiers.

Redaction helps meet these requirements by masking supported fields before they are stored or returned in results.

Where is redaction applied?

Redaction applies to stored document images, Document Check results, and generated reports.

It also covers sensitive data found in the VIZ, MRZ, barcodes, and supported QR codes.

Can I customize which fields are redacted?

Yes.

You can request changes to your redaction policy, including additional fields, if this is available under your plan.