Requirement 3.3.2 allows sensitive authentication data to exist only in the window before authorisation, and only in encrypted form. A point-of-sale receipt is generated after authorisation, so by the time it prints, that window has already closed — nothing from that category belongs on the slip at all. UK GDPR Art. 5(1)(c) reinforces the same limit from the privacy side: a kept field must be adequate and relevant, not just convenient to leave on the printout. anonym.plus marks each value on your device, so the receipt stays readable while the data is shielded.
When this applies
A terminal print shows the customer name, masked digits, and an approval code. You strip the sensitive parts under Requirement 3.3 before it is filed.
How anonym.plus handles it
- Open the receipt in anonym.plus on your device.
- Local OCR reads a thermal or photographed print.
- The tool flags account digits, names, and codes.
- Confirm each flag on a faint image.
- Black out or swap the confirmed items.
- Save the clean copy locally.
What you need to provide
- The terminal slip (image scan, PDF).
- An operator (Redact suits a printed receipt).
- Optional batch of up to 20 files per run.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Account | CREDIT_CARD | ************1111 → [CARD] |
| Names | PERSON | cardholder name → [BUYER] |
| Amount | MONEY | £12.40 → [AMOUNT] |
| Org | ORGANIZATION | store name → [MERCHANT] |
| Dates | DATE_TIME | 12/06/2026 → [DATE] |
| Location | LOCATION | store address → [ADDRESS] |
Compliance achieved
- Recognises that any post-authorisation slip falls outside the encrypted pre-authorisation window PCI DSS v4.0 Req. 3.3.2 allows.
- Follows the adequate-and-relevant test in UK GDPR Art. 5(1)(c) for what a printout may keep.
- Local OCR reads thermal terminal prints.
- Offline handling keeps the receipt on your machine — no upload.
Anonymise point-of-sale slips offline — see plans & start free →
Limitations & cautions
Thermal ink fades, so OCR may struggle on an old print. Check the flags on weak images. The tool marks named fields but cannot recover smudged digits.
Frequently asked questions
Why can a printed receipt never carry sensitive authentication data?
Req. 3.3.2 allows such data to exist only before authorisation and only encrypted. A terminal receipt prints after authorisation has already happened, so that window has closed by the time the paper comes out — nothing from that category should ever reach it.
Can the tool read a faded thermal print?
Local OCR tries, but very faint images may need a clearer scan. Verify the flags on weak ones before you treat a receipt as fully cleaned.
Is the receipt uploaded?
No. The app is fully offline, so it stays on your device throughout.