Batch redaction is the removal of personal data from a whole folder of client records in a single local run. A book of business is where consistency matters most: FCA SYSC 9.1 requires orderly records — five years for MiFID business — and COBS 9.5 layers different retention on suitability files depending on the product. UK GDPR Art. 5(1)(e) limits how long identifiable data is kept, Art. 32(1)(a) names pseudonymisation and encryption as security measures, and Art. 24 makes the firm accountable for demonstrating all of it. anonym.plus processes up to 20 files at a time on your device, with a shared map so one person maps to one alias everywhere.
When this applies
A book of business holds statements, suitability files, agreements and correspondence that all name the same clients. File-by-file work drifts, and drift is what breaks a review. A batch run applies one policy evenly across the set and leaves a summary you can show.
How anonym.plus handles it
- Point anonym.plus at the folder on your machine.
- It scans each file for names, numbers, addresses and contacts.
- Local OCR reads any scanned pages inside the set.
- A shared alias map keeps repeat clients steady across every file.
- Review the run summary and fix low-confidence flags by hand.
- Save the clean set locally.
What you need to provide
- A folder of records (PDF, DOCX, CSV, mixed).
- The shared alias map turned on for steady labels across files.
- An operator (Replace works well across a whole book).
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | client across files → [CLIENT_1] |
| Identifiers | UK_NINO | NINOs → [NINO] |
| Financial | UK_BANK_NUMBER | accounts → [ACCOUNT] |
| Money | MONEY | balances → [VALUE] |
| Contact | EMAIL_ADDRESS | emails → [EMAIL] |
| Location | LOCATION | addresses → [ADDRESS] |
Compliance achieved
- FCA SYSC 9.1 requires records orderly enough for the FCA to monitor the firm, held for five years for MiFID business; a batch run applies one policy across the book instead of twenty inconsistent ones.
- COBS 9.5 sets different retention for suitability files — indefinitely for pension transfers and opt-outs, five years for life policies and pension contracts, three years otherwise — so a folder rarely has a single expiry date.
- UK GDPR Art. 5(1)(e) limits how long identifiable data is kept, and Art. 32(1)(a) names pseudonymisation and encryption as security measures; working copies are protected with AES-256-GCM at rest.
- UK GDPR Art. 24 makes the firm accountable for demonstrating its measures — the run summary is evidence that one policy was applied to every file, with 340+ PII types covered and nothing uploaded.
Anonymise wealth client datasets offline — see plans & start free →
Limitations & cautions
A mixed folder of scans and structured exports leans on OCR for the images, so low-confidence flags need a human pass. The shared alias map can re-link the whole set if it is kept, which means the output is pseudonymised rather than anonymous — turn it off when true anonymity is the goal.
Frequently asked questions
How does batch mode keep one client steady across files?
A shared alias map logs each person once, so the same client maps to the same label in every file in the folder. That consistency is what makes a redacted book usable for a review rather than a pile of unrelated documents.
How many files can one run handle?
Up to 20 files per batch, all processed locally, with OCR for any scanned pages. Run the folder in slices if it is larger, keeping the same alias map.
Does batch work upload anything?
No. The whole run is offline, so the records stay on your machine — which also keeps the retention clocks in SYSC 9.1 and COBS 9.5 running against files you still control.