Behavioural Risk Assessment Anonymisation with anonym.plus

Remove identity from the safety assessment and keep the clinical findings.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Anonymising a safety assessment means removing identifying detail from the file under UK GDPR Art. 9 and DPA 2018. anonym.plus does it on your device. The findings stay readable; the person is not named. UK courts have long recognised, in cases such as W v Egdell, that a clinician's duty of confidence is not absolute where there is a real risk of serious harm to someone else — which is exactly why a de-identified copy used for protocol review must still remove any named third party at risk, not only the client.

When this applies

A trust's clinical governance team studies patterns across risk assessments, following a Safeguarding Adults Board (SAB) case review, to improve protocols. The records name clients, dates, and a named third party, all of which must come out first.

How anonym.plus handles it

  1. Open the file in anonym.plus on your machine.
  2. Local OCR reads any scanned page.
  3. It flags names, dates, and any third party.
  4. Review each flag and keep the safety findings.
  5. Replace each identifier with a label, or black it out.
  6. Save the clean copy. The source stays local.

What you need to provide

Patient data entity types detected

Categoryanonym.plus entity typeExample
ClientPERSONRosa Mejia → [CLIENT_1]
Assessed dateDATE_TIMEAssessed 09/04/2026 → [DATE]
Third partyPERSONex-partner Vic → [PARTY_1]
NHS numberNHS_NUMBERNHS 388 120 2230 → [NHS_NO]
PhonePHONE_NUMBER+44 7700 900152 → [PHONE]
Record IDMEDICAL_RECORD_NUMBERMRN 38812 → [MRN]

Compliance achieved

Anonymise behavioural risk assessments offline — see plans & start free →

Limitations & cautions

A safety assessment often names a third party at the heart of the concern. The tool flags those names too. You still confirm no rare detail can re-identify either the client or that party.

Frequently asked questions

Are named third parties removed?

Yes. A safety assessment may name an ex-partner, family member, or other person the concern relates to. Each is an identifier, and the tool flags them so neither that person nor the client is exposed in a protocol-review copy.

Can I study patterns safely?

Yes. Once the forms are de-identified under UK GDPR Art. 9, they may support protocol review by a clinical governance team without further authorisation from the people named in them.

Does the Egdell principle mean I should disclose risk information instead of anonymising it?

No — that is a separate clinical and legal judgment for the professionals involved, not something this tool decides. Egdell is relevant here only because it shows why a named third party's identity in a risk record is legally significant and needs the same careful removal as the client's own name when the record is used for protocol review rather than an active safeguarding response.