Outcome Measure Dataset De-Identification with anonym.plus

Strip identity from score exports and keep the measures clean.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

De-identifying an outcome dataset is the removal of data that names a subject from a score export. UK GDPR Art. 89 covers scientific research safeguards. anonym.plus runs on your device, so the measures stay while subjects are hidden. A multi-site pooled dataset like this normally also falls under the Health Research Authority's UK Policy Framework for Health and Social Care Research, which sets the ethics and governance standard for the study alongside UK GDPR Art. 89.

When this applies

A multi-site NHS Talking Therapies research collaboration pools PHQ-9 and GAD-7 symptom scores across services. The export holds subject names, IDs, and dates, which must be stripped before analysis.

How anonym.plus handles it

  1. Open the export in anonym.plus on your device.
  2. Local OCR reads scanned score sheets too.
  3. It flags subject names, IDs, and dates.
  4. Review each flag and keep the score columns.
  5. Replace each value with a label, or remove it.
  6. Save the clean dataset. The source stays local.

What you need to provide

Patient data entity types detected

Categoryanonym.plus entity typeExample
SubjectPERSONYusuf Demir → [SUBJECT_1]
Subject codeIDSUBJ-0142 → [CODE]
Score dateDATE_TIMEScored 22/05/2026 → [DATE]
SiteORGANIZATIONSite Manchester → [SITE]
EmailEMAIL_ADDRESSy.demir@uni.ac.uk → [EMAIL]
NHS numberNHS_NUMBERNHS 904 117 1234 → [NHS_NO]

Compliance achieved

Anonymise outcome measure datasets offline — see plans & start free →

Limitations & cautions

A small cell of rare scores can re-identify a subject. The tool removes direct identifiers. You still apply statistical care so an unusual row does not single out one person.

Frequently asked questions

What safeguards does UK GDPR Art. 89 expect?

It calls for measures like data minimisation and pseudonymisation for research use, on top of the study's own ethics approval. Stripping direct identifiers from the pooled export is a core step toward meeting that standard alongside the ICO Anonymisation Code.

Can I keep a subject code?

Yes, if it is a random label rather than a real ID such as an NHS number. Keep the link table apart from the export so the pooled dataset alone cannot be reversed back to a named participant.

Does the HRA Policy Framework replace UK GDPR Art. 89?

No, they work together. The Policy Framework sets the ethics-approval and governance process a multi-site study must follow; UK GDPR Art. 89 sets the data-protection safeguards, including minimisation and pseudonymisation, that the same study's data handling must meet.