Many fraud alerts are generated by an automated risk-scoring model, which brings UK GDPR Art. 22's rules on automated decision-making into play alongside the case file itself. Where a customer disputes the transaction as unauthorised, the Payment Services Regulations 2017 put the burden on the payment service provider to show the transaction was properly authenticated — the case file is exactly where that evidence sits. If the alert points to genuine fraud proceeds, it can also feed a suspicious activity report to the NCA under POCA 2002. PCI DSS v4.0 still limits how the card number itself is kept. anonym.plus marks each value on your device, so the case stays actionable while customer data is shielded.
When this applies
A case file bundles the flagged card, the customer, and device clues. You strip those identifiers under the standard before it is escalated.
How anonym.plus handles it
- Open the file in anonym.plus on your device.
- Local OCR reads a scanned attachment.
- The tool flags card digits, names, and contacts.
- Keep the case ID and risk score you must cite.
- Swap or black out the confirmed items.
- Save the clean file locally.
What you need to provide
- The alert file (PDF, CSV, JSON, scan).
- An operator (Replace keeps the record readable).
- Optional allow-list for case and rule IDs.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Account | CREDIT_CARD | flagged card → [CARD] |
| Names | PERSON | customer Hale → [BUYER] |
| Contact | EMAIL_ADDRESS | hale@example.co.uk → [EMAIL] |
| Location | LOCATION | IP geolocation → [LOCATION] |
| Amount | MONEY | £899.00 → [AMOUNT] |
| Dates | DATE_TIME | alert time → [TIME] |
Compliance achieved
- Limits stored card data per PCI DSS v4.0.
- Keeps the case ID and risk score readable, relevant where UK GDPR Art. 22 governs a solely automated fraud-scoring decision.
- Keeps the transaction reference intact to support the authentication evidence a Payment Services Regulations 2017 dispute may require.
- Keeps the case usable for a POCA 2002 suspicious activity report where genuine fraud proceeds are suspected.
- Offline handling keeps the file off any server.
Anonymise fraud alerts offline — see plans & start free →
Limitations & cautions
An analyst note may describe behaviour that points to a customer indirectly. The tool flags named fields, so read those notes before you escalate.
Frequently asked questions
Does an automated fraud score trigger any special rule?
It can. Where a fraud alert results from a solely automated decision with a legal or similarly significant effect on the customer, UK GDPR Art. 22 gives that customer rights around the decision, including the right to request human review.
Who has to prove the transaction was authenticated?
Under the Payment Services Regulations 2017, the payment service provider generally carries that burden once a customer disputes a transaction as unauthorised. Keeping the case ID and risk score legible is what makes that evidence usable later.
Is the alert uploaded?
No. The app runs locally, so the data stays on your device.