Actuarial Dataset Anonymisation with anonym.plus

Strip direct identifiers from an actuarial table before analysts model it.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Actuarial anonymisation is the removal of direct identifiers from a modelling table. UK GDPR Recital 26 puts truly anonymous data outside the rules, and the ICO applies a motivated-intruder test to decide whether that bar is met. Where the table is still personal data but used for statistical purposes, Art. 89(1) requires safeguards and names pseudonymisation as one. The FRC's Technical Actuarial Standards — TAS 100 for principles, TAS 200 for insurance — expect the data behind a model to be fit for its purpose.

When this applies

A modelling table mixes premiums and losses with the names behind each row. The model needs the figures, not the people. You strip the identifiers before the data feeds an analyst, and you note what was removed so the actuary can judge whether the table is still fit for the exercise.

How anonym.plus handles it

  1. Open the table in anonym.plus on your device.
  2. The tool flags names, IDs, and contacts in each field.
  3. Local OCR reads any scanned source sheet.
  4. Turn the alias map OFF for true anonymity.
  5. Swap or black out the confirmed identifiers.
  6. Save the clean table locally.

What you need to provide

PII & financial identifiers detected

Categoryanonym.plus entity typeExample
NamesPERSONpolicyholder name → [SUBJECT]
IdentifiersUK_NINOnational insurance no → [NINO]
FinancialMONEYclaim sum £41,200 → [AMOUNT]
ContactEMAIL_ADDRESSholder@example.co.uk → [EMAIL]
DatesDATE_TIMEDOB 1984 → [DOB]
LocationLOCATIONpostcode SW1A → [REGION]

Compliance achieved

Anonymise actuarial datasets offline — see plans & start free →

Limitations & cautions

Recital 26 treats data as anonymous only if no one can re-identify a person. Rare combinations of age, region, and loss can still single someone out under the motivated-intruder test. The tool removes fields; it cannot measure residual risk across the whole table.

Frequently asked questions

When is a dataset truly anonymous under UK GDPR?

Recital 26 sets the bar at no reasonable means of re-identification, and the ICO tests it with the motivated-intruder question. Remove direct identifiers, turn the alias map off, then look for rare row combinations.

What if the table must stay personal data?

Then Art. 89(1) applies: statistical use needs safeguards, and pseudonymisation is the one the article names. Keep the alias map under control, restrict access, and record the decision.

Does stripping identifiers break the actuarial work?

It should not. TAS 100 and TAS 200 are about data being appropriate and complete for the purpose, and the exposure, premium, and loss columns are untouched. Record what was removed so the actuary can judge it.