---
id: KB-DI-019
url: https://app.codecontract.io/help/documents-and-ai/documents-that-bring-more-personal-data-than-needed
idioma: en
categoria: documentos-ia
subcategoria: subir
audiencia: usuario
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-DI-010, KB-GL-013, KB-DI-014]
citadoPor: [KB-DI-008]
---

# Documents that bring more personal data than needed

_You ask for one thing and it arrives inside a document carrying five more details you never needed._

**Responde a:** they sent a document with excess personal data · can I ask for details to be redacted · do I need to keep the full ID number · hiding data before sharing a document

You ask for proof of good standing and a full employment history arrives. You ask for a technician's qualification and their entire file turns up. Nobody is acting in bad faith: whoever sends it grabs what they have. The problem is that from that moment you hold it.

## What to do in each case

| What arrived | What to do | Why |
| --- | --- | --- |
| The right document with excess data | Ask for the narrower document if one exists | What you do not hold needs no safeguarding |
| A document you did not ask for | Do not file it, and say so | Keeping it «just in case» makes you responsible for it |
| Third parties' data inside (relatives, patients, other clients) | Return it and ask for a version without | There you do not even hold the permission |
| Exactly what was needed | File it and move on | That is the aim |

> [!IMPORTANT]
> Before sharing a document with excess data outwards, there is a technical detail that surprises many people: **covering something with a black box in a PDF does not always delete it**. If the text is still underneath, anyone can copy it or see it in another program, and the document looks properly redacted. Hidden on screen is not the same as removed: if the document is leaving your organisation, make sure the data is gone, not merely invisible.

## How to ask so it does not happen

1. **Say what you need to prove, not which document you want** — «That they are in good standing» allows several papers, some leaner.
2. **Accept the narrowest one that works** — If a certificate suffices, do not ask for the full report.
3. **And if excess data arrives, say so at once** — Three weeks later nobody returns anything.

> [!WARNING]
> The reasoning to disarm is «since we have it, let us keep it»: **every stored item is one to safeguard, to justify if someone asks, and to delete some day**. A surplus document gives you nothing and adds obligations — and if there is ever an incident, its scope is measured by what you held, not by what you used.

## And if you already hold it

**En corto**

- Replace it with the narrower version once the issuer can send one.
- Withdraw what you should never have received, recording that it was withdrawn.
- And review who had access while it was there.

> [!NOTE]
> Which data you may request, how long to keep it and what to do when third parties' data arrives depend on the data protection framework that applies to you — the **GDPR** in Europe — and on your activity. **Your adviser settles that**; here it is the practical reflex: ask for exactly what is needed and do not keep the surplus.

**Can I redact the document they sent me?**

You can keep a narrowed version, but stay clear about which is the original.

**What if the supplier has no other version?**

Keep what there is, with restricted access, and note why it was needed.

**Does this apply to what we send out?**

Equally, and there you are the one sending someone else's surplus data.

## Ejemplos

**A company receives a technician's full file when all it asked for was one qualification.**

- Returns it, requests the specific certificate and records that the other was not filed

→ It keeps what it needed and none of the duty to safeguard the rest.

**A document arrives with more personal data than was requested.**

- Checks what it contains before filing it

→ You know what you are holding.

**The whole document is requested when part would do.**

- Requests only what needs checking

→ You hold less of what was never needed.

**The whole team can open that document.**

- Limits who sees anything containing personal data

→ Access stops being general.

**It is shared with a client without reviewing the contents.**

- Reviews the content before sharing

→ Third-party data is not forwarded unintentionally.

**It is kept indefinitely just in case.**

- Applies the retention period

→ What is kept has a reason and a period.
