Data Breach Notification Redaction with anonym.plus

Tell each affected person about a breach without exposing other victims' data.

A breach notification is the message you send affected people under GDPR Art. 34 when a breach is likely to risk their rights. Before you send it, you strip PII that belongs to other victims. anonym.plus marks that data on your own device.

When this applies

A breach hits many people, and you must tell each one. A shared incident log or victim list names everyone, but each person should see only their own row.

How anonym.plus handles it

  1. Open the incident log in anonym.plus on your device.
  2. The tool flags every name, contact, and ID in the list.
  3. Keep the one person's data for their own notice.
  4. Mark all other victims' PII for removal.
  5. Black out or swap each one, then verify the notice.
  6. Save the per-person message on your machine.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONother victim → [PERSON]
ContactEMAIL_ADDRESSa.krause@example.com → [EMAIL]
AccountsCREDIT_CARDexposed card → [CARD]
IdentifiersNATIONAL_IDcustomer no. → [ID]
ContactPHONE_NUMBER0170-555-0188 → [PHONE]
LocationLOCATIONbilling address → [ADDRESS]

Compliance achieved

Anonymize breach notifications offline — see plans & start free →

Limitations & cautions

Art. 34 sets when and what to tell people, which is a legal judgment. The tool flags PII so each notice stays specific; it does not decide if a breach is notifiable. Confirm the threshold and content with your DPO first.

Frequently asked questions

Why redact a breach notice at all?

A shared list names many victims. Sending it whole would itself disclose their PII. anonym.plus strips other rows so each person sees only their own.

Does it read a victim spreadsheet?

Yes. CSV and XLSX logs are scanned column by column, and a steady map keeps a person's rows together if you need them linked.

Could the tool cause a second breach?

No. It runs offline, so the log never leaves your device. That avoids the upload risk that a cloud service would add during an incident.