Redact at disclosure, not at capture
Capture the full decision record and redact only when you disclose it — because a fact you refuse to record to protect privacy is a fact you have also destroyed for accountability, and you almost never needed to choose.
There are two moments in the life of a sensitive fact, and you must not let your system confuse them. There is the moment you capture it — write it into the decision record as one of the inputs the decision actually rested on. And there is the later moment you disclose it — hand some version of the record to a person, an auditor, a court, the public. These are different acts, separated in time, governed by different concerns, and answerable to different people. Yet in most systems they are collapsed into one. A team reaches for privacy, decides a field is too sensitive to keep, and does not log it at all. They have made a disclosure decision at capture time — and in doing so they have not protected the fact from the wrong eyes. They have removed it from every eye, including their own, including the eye of the person it might one day have protected.
The directive is to hold these two moments apart. Capture completely and protect strongly. Disclose selectively and redact per recipient. Do not let a concern that belongs to disclosure reach back up the pipeline and delete the record at its source.
The privacy that destroys the evidence
Watch how the conflation happens, because it is almost never a decision anyone announces. Someone is building the logging path. A field arrives that is plainly sensitive — a medical note, an immigration status, a protected characteristic, a raw document behind a score. The reflex, and it is a good-faith reflex trained by a decade of data-minimization guidance, is: we shouldn't be keeping this. So the field is dropped. Not disclosed narrowly — dropped. The system records that a decision was made and records the output, but the sensitive input that drove it is simply absent. Everyone feels responsible. The privacy review passes.
Then, a year later, the decision is questioned. The affected person says the system used a fact it should not have, or used a fact that was wrong, or reached a conclusion the inputs do not support. And now you go to the record to reconstruct what actually happened — and the very fact at the center of the dispute is the one you refused to write down. You cannot show the decision was sound, because you cannot show what it rested on. You cannot show the sensitive fact was not used, because you kept no account of what was. Privacy was cited as the reason for the gap; accountability is what the gap actually cost. The person the omission was supposed to protect is precisely the person who now cannot get an answer. You did not minimize the data. You minimized the defense.
A fact you refused to record to protect privacy is a fact you also destroyed for the person it might have exonerated.
Separate capture from disclosure in time
The way out is not to abandon privacy for accountability. It is to stop treating them as a single dial with a single setting, and to notice that they live at different points in time. At capture, the governing question is what did this decision actually rest on — and the honest answer includes the sensitive inputs, because they are part of what happened. At disclosure, the governing question is what is this particular recipient entitled to see — and the honest answer is almost never "everything." These two questions have different right answers, and a system that asks only one of them will get the other one wrong.
So capture the whole record — faithful, complete, including the sensitive fields — and put it under strong protection: encryption, tight access control, a defined retention limit, an audit trail on the record itself. Then make disclosure a separate operation layered on top. The affected party is shown their own data, in full, because it is theirs. The auditor is shown what their mandate entitles them to and no more. A court is shown what is discoverable under its order. The public, if the matter becomes public, is shown an anonymized form that carries the shape of the decision without the identity of the person. And underneath all of these views, the raw record stays sealed and complete — one faithful account, disclosed at different resolutions to different audiences, never reconstructed differently for each.
This is what it means to separate the concerns in time rather than opposing them in principle. Privacy is real and non-negotiable, and it is satisfied at disclosure, where it belongs — by controlling who sees what. Accountability is real and non-negotiable, and it is satisfied at capture, where it belongs — by preserving what happened. The record that serves the affected party, the auditor, and the public is the same record, viewed at three resolutions. You do not need three records, and you must not settle for zero.
Redaction as a disclosure-time transform
The concrete instruction, then, is this: build redaction as a transform applied to a complete, access-controlled record at the moment of disclosure — a view over the record, computed per recipient — and never as a gap punched in the record at capture. Redaction is a function from a full record and an audience to a permitted view. It presupposes the full record. The moment you implement redaction by not-capturing, you have not built a redaction system; you have built a system that forgets, and calls the forgetting privacy. Treat "we didn't log it for privacy" as what it usually is: a false economy that trades a durable accountability asset for a convenience, and forfeits your ability to defend the decision the day it is challenged.
Handle the genuine exceptions honestly, because they exist and the discipline is worthless if it pretends they don't. Some data legally must not be retained at all — a statute or a court order or a contractual bar forecloses keeping it, full stop. That is a real constraint, and where it binds, you record the fact that an input existed and was governed under that constraint, rather than the input itself. But name these as the exceptions they are, not the default. The default is capture-and-protect; the legal bar is the carve-out you can point to, not the reflex you reach for. And be honest about the cost of the default, too: capturing completely means you now hold a concentrated, sensitive record, and the price of holding it is real protection — encryption, least-privilege access, retention discipline, an audit trail. That protection is not optional overhead. It is the thing that earns you the right to capture completely. Pay it, and you get to keep both the privacy and the evidence. Skip it, and you have merely moved the risk without buying the accountability. The choice you were told you had to make — privacy or defensibility — was almost always false. Separate the two moments, and you can have both.
— Dispatches · Summit Cognitive
Continue from here
Turn the argument into a practice.
Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.