Direct-debit mandate redaction is the removal of personal data from a payment authorisation. PSD2 (Dir. 2015/2366) governs how a payment service handles such data in the EU. anonym.plus marks each field on your device, so the form structure stays intact while the customer data is shielded.
When this applies
A SEPA authorisation names the account holder, the IBAN, and the creditor reference. You must mask those before the form goes to a processor or auditor.
How anonym.plus handles it
- Open the form in anonym.plus on your device.
- Local OCR reads a scanned, signed page.
- The tool flags the holder, IBAN, and BIC.
- Confirm the flags and keep the creditor identifier.
- Swap or black out the confirmed fields.
- Save the clean file locally.
What you need to provide
- The authorisation (PDF, DOCX, or scan).
- An operator (Replace keeps the form readable).
- Optional allow-list for the creditor identifier.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | payer S. Devos → [PAYER] |
| Financial | IBAN_CODE | DE89 3704 0044 ... → [IBAN] |
| Contact | EMAIL_ADDRESS | devos@example.com → [EMAIL] |
| Location | LOCATION | home address → [ADDRESS] |
| Identifiers | NATIONAL_ID | national ID → [ID] |
| Dates | DATE_TIME | signed 02/2026 → [DATE] |
Compliance achieved
- Handles the customer data within the scope of PSD2 (Dir. 2015/2366).
- Reads a scanned, signed page via local OCR.
- Offline work keeps the IBAN and holder data off any server.
Anonymize direct-debit mandates offline — see plans & start free →
Limitations & cautions
PSD2 sits alongside GDPR for personal data, so check both when you reuse a form. A masked IBAN that keeps the country and bank prefix can still narrow the payer; remove the whole value for true anonymity.
Frequently asked questions
Does the tool detect an IBAN?
Yes. The IBAN entity type matches the full account number, and you can mask or remove it in one pass.
Can I keep the creditor identifier?
Yes. Allow-list it so the creditor reference stays while the holder data is removed.
Is the file uploaded?
No. The desktop app runs locally, so the authorisation stays on your device.