Credit Decision Dataset De-Identification with anonym.plus

De-identify a decision dataset for fair-lending analysis while signals stay usable.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Credit decision dataset de-identification is the removal of applicant fields from a decision table. Equality Act 2010 s.19 bars indirect discrimination, which is the real risk in a scored dataset where a proxy variable stands in for a protected characteristic, and UK GDPR Art. 22 gives an applicant scored by a solely automated process a right to meaningful review. anonym.plus marks each item on your device, so the analytic signals stay usable while direct identifiers go.

When this applies

A decision table ties applicants to scores, outcomes, and protected-characteristic proxies that an s.19 indirect-discrimination review would test. You strip direct fields before the data trains a model or feeds that review, keeping the score and outcome columns the analysis needs.

How anonym.plus handles it

  1. Open the decision table in anonym.plus on your device.
  2. The tool flags names, NI numbers, and contact fields.
  3. Local OCR reads any scanned supporting pages.
  4. Keep the score and outcome columns you must analyse.
  5. Swap or black out the confirmed direct fields.
  6. Save the clean dataset locally.

What you need to provide

PII & financial identifiers detected

Categoryanonym.plus entity typeExample
NamesPERSONapplicant id → [APPLICANT]
IdentifiersUK_NINOJK 45 21 77 C → [NINO]
Tax referenceNATIONAL_IDUTR row → [TAXID]
MoneyMONEYincome field → [AMOUNT]
DatesDATE_TIMEdecision date → [DATE]
ContactEMAIL_ADDRESScontact email → [EMAIL]

Compliance achieved

Anonymise credit decision datasets offline — see plans & start free →

Limitations & cautions

Direct identifiers are not the only risk. Score, income, and date combine into quasi-identifiers that can re-link a person under the ICO motivated-intruder test. Generalise those for true de-identification, and keep the alias map turned off; the tool flags fields, it does not itself run the s.19 statistical test for indirect discrimination.

Frequently asked questions

Is removing the applicant id enough for anonymity?

No. Score, income, and date can re-link a person when combined. Generalise or suppress those quasi-identifiers for stronger de-identification.

How does Equality Act 2010 s.19 apply to a scoring model?

Indirect discrimination under s.19 catches a facially neutral rule or score that disadvantages a protected group in practice, even without intent. Keeping the outcome and proxy columns, with direct identifiers removed, is what lets that statistical review happen at all.

Is the dataset uploaded for processing?

No. The app runs locally. For real anonymity, keep the reversible alias map turned off; that has no bearing on whether Art. 22 or s.19 apply to the underlying decision process itself.