An acquirer bringing on a new merchant runs customer due diligence under the Money Laundering Regulations 2017 (MLR 2017), regs 27-28 — a know-your-business check on the merchant's principals, similar in substance to a bank's own KYC. Where the merchant is a company, some of that ownership picture is already public: Companies Act 2006 Part 21A puts a person-with-significant-control filing on the Companies House register. The onboarding form's own copy of a principal's National Insurance number, home address, and bank details usually goes further than the public record does. anonym.plus marks each value on your device, so the record stays on file while the principal's data is shielded.
When this applies
An onboarding packet gathers the principal's NI number, the settlement bank, and contacts. You strip those identifiers under the standard before it is archived.
How anonym.plus handles it
- Open the onboarding packet in anonym.plus on your device.
- Local OCR reads a scanned, signed application.
- The tool flags the principal ID, bank, and contact fields.
- Keep the merchant ID and MCC code you must retain.
- Swap or black out the confirmed items.
- Save the clean copy locally.
What you need to provide
- The onboarding form (PDF, DOCX, scan).
- An operator (Replace keeps it readable).
- Optional allow-list for merchant and MCC codes.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | owner Pearce → [OWNER] |
| Bank | UK_BANK_NUMBER | settlement a/c → [ACCOUNT] |
| Identifiers | UK_NINO | QQ 12 34 56 C → [NINO] |
| Contact | EMAIL_ADDRESS | principal email → [EMAIL] |
| Location | LOCATION | business address → [ADDRESS] |
| Org | ORGANIZATION | legal entity → [ENTITY] |
Compliance achieved
- Limits stored account data per PCI DSS v4.0.
- Supports the customer due diligence an acquirer runs under MLR 2017 regs 27-28 without over-retaining the raw personal fields collected to satisfy it.
- Clears principal data that usually goes further than the public filing under Companies Act 2006 Part 21A's PSC register.
- Offline handling keeps the form off any server.
Anonymise onboarding forms offline — see plans & start free →
Limitations & cautions
A signed application may carry handwriting OCR reads poorly. Verify flags on scanned pages. The tool removes named fields, not every detail a principal wrote in.
Frequently asked questions
Why does an onboarding form collect so much personal data?
Because MLR 2017 regs 27-28 require an acquirer to run customer due diligence on a new merchant's principals before opening the relationship, much like a bank's KYC process for a new customer.
Isn't a company's ownership already public?
Partly. Companies Act 2006 Part 21A puts a person-with-significant-control filing on the Companies House register, but it does not carry a principal's National Insurance number, full home address, or settlement bank details — those stay in the onboarding file itself.
Is the packet uploaded?
No. The app is fully offline, so the principal data stays on your device.