Redacting ID Copies: What You Can Black Out
The default when someone asks for an ID copy is to scan the whole card and send it — every field, full resolution, no thought given to what's actually being verified. That instinct hands over far more than most checks need. Redacting ID copies is the simplest, most underused lever you have: black out what the request doesn't require, and a leaked copy is worth a great deal less to whoever ends up with it.
The questions that matter are concrete. Which fields can you legally black out? What does the diagonal Sperrvermerk note actually do? And when is a full, unredacted copy genuinely required rather than just casually requested? Here's the practitioner's map.
What a copy reveals — and which parts a check needs
A German Personalausweis or passport is dense with data points, and most requests need only a couple of them. Before redacting, separate what verifies your identity from what's just sitting on the card.
| Field | Usually needed to verify identity? | Redact for casual requests? |
|---|---|---|
| Name, date of birth | Yes | No |
| Photo | Sometimes (visual match) | Often yes |
| Nationality, place of birth | Sometimes | Often yes |
| Document / serial number | Rarely for casual checks | Often yes |
| Access number (CAN) | Almost never for a copy | Yes |
| Machine-readable zone (MRZ) | Rarely for casual checks | Yes — high value to attackers |
| Signature | Rarely | Often yes |
The MRZ and document number deserve special attention. They're the parts an attacker most wants, because they feed identity-theft and account-takeover attempts. If a recipient only needs to confirm who you are, those lines are exactly what should disappear under a black bar. For more on how a leaked copy gets weaponised, see how ID theft happens from copies.
The legal basis for redacting
You don't need permission to redact. Two pillars support it:
- GDPR Art. 5(1)(c) data minimisation. A controller may only process data that is adequate, relevant, and limited to what's necessary. If a check doesn't need a field, there's a strong argument that field shouldn't be disclosed in the first place — redaction is you exercising minimisation on your own initiative.
- Personalausweisgesetz restrictions. German law treats the ID card and its data with particular care: §20 PAuswG limits what may be done with serial numbers and the card's data, and copying is constrained in purpose. The card is not meant to be freely duplicated and stored.
Put together: redacting non-required fields isn't a grey-area workaround. It's the data-minimisation-aligned default, and the burden sits with the recipient to justify needing more.
The Sperrvermerk: what the diagonal note does and doesn't do
The Sperrvermerk is the diagonal text you write across an ID copy — something like "Kopie nur zur [Zweck] bei [Empfänger], am [Datum]. Nicht gültig für andere Zwecke." It's a familiar sight on copies handed to landlords and registration offices.
Be clear-eyed about it. Technically, a Sperrvermerk prevents nothing — a determined misuser can ignore it or crop it out. What it does is document three things: the purpose you consented to, the recipient you intended, and the date. In a dispute, that turns a stolen copy from "a copy of your ID floating around" into "a copy you released for one narrow purpose, used outside it." It scopes the consent and creates a paper trail. That's real, even though it's not a technical control.
Two practical notes:
- Write it across the data, not in the margin, so it can't be cleanly cropped away without damaging the copy.
- Combine it with redaction. A Sperrvermerk on a fully unredacted MRZ is weaker than redaction plus a note — defence in depth, not either/or.
A Sperrvermerk is a manual, static cousin of a proper watermark. A purpose-and-recipient-bound watermark does the same scoping job and travels with the file; an invisible forensic layer adds traceability a handwritten note can't. The full comparison is in how to watermark ID documents the right way.
When a full unredacted copy is actually required
Redaction has limits. There are situations where a recipient has a legal basis to record specific fields, and blacking them out would stall a legitimate process:
- GwG identification. An obliged entity verifying you under anti-money-laundering duties may need to record particular data points and retain evidence of the identification. If the document number or MRZ is part of what they're required to capture, redacting it isn't appropriate.
- Notarial identification. A notary confirming identity for a deed needs to see the document properly.
- Specific regulated onboarding where the rulebook names the fields.
The move here is not to redact blindly but to ask what the specific check requires before deciding. "Which fields does your check need recorded?" is a fair question and a fast filter. Where the law genuinely requires a full copy, provide it — but still control how it's shared and whether they can keep a downloadable copy beyond the retention they're entitled to. Working out the required-field set per situation is its own discipline; see data minimisation: which fields to share.
A clean redaction workflow
Redaction done badly is worse than none — a "black box" laid over a PDF that's still selectable underneath has leaked plenty of real data. To do it properly:
- Flatten first. Export to an image or print-to-PDF so the redaction can't be peeled back to reveal the layer beneath.
- Cover, don't blur. A solid bar beats a blur; blurred MRZ and numbers have been reconstructed before.
- Redact the high-value fields the check doesn't need: MRZ, document number, CAN, and often the photo and signature.
- Add a scoped note — purpose, recipient, date — across the data.
- Share with control, not as a permanent attachment: a scoped link with expiry, downloads off where retention isn't required, and the ability to revoke.
That last step is where tooling pays off. Redacting and then emailing the result still produces an uncontrolled copy. Sharing field-scoped, watermarked data through a revocable link — the model behind ShareKYC — means the minimisation you did by redacting isn't immediately undone by the channel you used to send it. The broader framing of access control as a set of levers is in share your ID without losing control.
The takeaway
Redacting ID copies is the cheapest privacy win available to anyone who shares their identity regularly, and it's fully within your rights. Black out the fields a check doesn't need — MRZ, document number, CAN above all — flatten the file so the redaction holds, add a purpose-and-date Sperrvermerk across the data, and reserve full unredacted copies for the narrow cases where a real legal duty requires them.
The next time a form says "upload a copy of your ID," pause and ask what's actually being verified. Usually it's two fields, not twenty data points. Sharing exactly those — redacted, watermarked, and revocable — is what ShareKYC is designed to make routine.
Frequently asked questions
Can I black out my document number on an ID copy?
For most casual requests, yes — if the recipient only needs to confirm name and date of birth, the document number, machine-readable zone, and access number are often redactable. For some bank checks the number is needed, so ask what the specific check requires.
What is a Sperrvermerk and does it have legal force?
It is a diagonal note across the copy stating purpose and that the copy is invalid for other uses. It does not technically prevent misuse but documents your intent and the limited consent, which matters in a dispute.
When is a full unredacted ID copy actually required?
Mainly where the GwG or a comparable duty requires recording specific data and retaining evidence of identification. Outside those duties, a redacted copy or scoped verification is usually sufficient.
Is redacting an ID copy legal in Germany and Austria?
Yes. You are entitled to minimise what you disclose. The Personalausweisgesetz even restricts how ID copies may be used; redacting non-required fields aligns with data minimisation under GDPR Art. 5.