Data room anonymisation is the removal of personal data from a deal repository before bidder access widens. Truly anonymous files fall outside the UK GDPR altogether on the Recital 26 test, which is worth far more than another access control: a virtual data room provider is a processor under Art. 28, and everything uploaded to it is your responsibility under Art. 32. anonym.plus processes up to 20 files per run on your machine, before anything reaches the room.
When this applies
A deal room holds HR files, contracts and emails across hundreds of documents, and in a Code deal a competing offeror can ask for the same information. You anonymise in batches before more bidders are admitted.
How anonym.plus handles it
- Point anonym.plus at the data-room folder on your machine.
- Local OCR reads any scanned pages in the set.
- The tool flags names, IDs, and contacts in each file.
- Keep the shared map OFF for true anonymity.
- Review the summary and fix low-confidence flags.
- Save the clean set locally.
What you need to provide
- A folder of deal files (PDF, DOCX, scan, mixed).
- An operator (Redact suits true anonymisation).
- The shared map turned off for unlinkable output.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | employee A. Okafor → [PERSON] |
| Identifiers | UK_NINO | National Insurance no. → [NINO] |
| Contact | EMAIL_ADDRESS | staff@example.co.uk → [EMAIL] |
| Money | MONEY | salary £80k → [AMOUNT] |
| Location | LOCATION | branch town → [CITY] |
| Dates | DATE_TIME | DOB 1990 → [DOB] |
Compliance achieved
- Anonymising to the UK GDPR Recital 26 standard takes the folder out of scope before it is ever uploaded.
- A virtual data room provider is a processor: UK GDPR Art. 28 terms and Art. 32 security apply to whatever you put in the room.
- In a Code deal, information given to one offeror must be given to a competing offeror on request — Rule 20.2 of the Takeover Code, administered under CA 2006 Part 28, so plan for wider disclosure from the start.
- Bidder access to staff records triggers UK GDPR Art. 14 notice duties; anonymised files avoid them.
- Up to 20 files per offline run, with local OCR for any scans.
Anonymise transaction data rooms offline — see plans & start free →
Limitations & cautions
A mixed folder of scans and native files leans on OCR for the images, so review low-confidence flags. A rare role plus a site can still single someone out, and Takeover Code Rule 20.1 equality-of-information duties mean today's narrow disclosure may become tomorrow's wide one.
Frequently asked questions
How many files can one run anonymise?
Up to 20 files per batch, all processed locally with OCR for any scanned pages.
Why anonymise before upload rather than restrict access?
Because the room provider is a processor under UK GDPR Art. 28 and Art. 32 security duties follow the data. Files that are anonymous under Recital 26 are out of scope entirely.
Does the room leave my machine?
No. The whole run is offline, so the repository stays on your device.