Death Certificate De-Identification with anonym.plus

Clear identifiers from the certificate while cause and broad demographics stay.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Death-certificate de-identification removes the deceased person's, the informant's, and the certifier's identifiers from a medical certificate of cause of death. The legal position is unusual: DPA 2018 s.3(2) limits personal data to information about a living individual, so UK GDPR does not protect the deceased — but the informant and the certifying doctor are alive, and the common-law duty of confidence survives death. anonym.plus runs locally and keeps the cause-of-death chain for mortality analysis.

When this applies

Mortality datasets underpin public-health research. The certificate is issued under Births and Deaths Registration Act 1953 s.22 and, since September 2024, is scrutinised by the statutory medical examiner system introduced by the Health and Care Act 2022. Every version of it names the informant and the doctor who signed it.

How anonym.plus handles it

  1. Load the certificate into anonym.plus on your device.
  2. It finds decedent, informant, and certifier identifiers.
  3. Exact dates and places get flagged; the cause text stays.
  4. Swap or black out the confirmed identifiers.
  5. Save the clean file on your device.

What you need to provide

Patient data entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONdeceased name → [NAME]
RelativesPERSONinformant (spouse) → [INFORMANT]
NamesPERSONcertifying doctor → [CERTIFIER]
DatesDATE_TIMEdate registered → [DATE]
LocationLOCATIONplace registered → [PLACE]
National InsuranceUK_NINOQQ 12 34 56 C → [ID]

Compliance achieved

Anonymise death certificates offline — see plans & start free →

Limitations & cautions

The deceased are outside UK GDPR by DPA 2018 s.3(2), but confidentiality and Access to Health Records Act 1990 duties continue, and the informant and certifier remain living data subjects. Place and exact date are powerful clues in mortality data, so broaden them. A rare cause in a small area can re-identify after every direct identifier is gone.

Frequently asked questions

Is a deceased person's data still protected?

Not by UK GDPR: DPA 2018 s.3(2) defines personal data as information about an identified or identifiable living individual. But the common-law duty of confidence survives death, which the Information Tribunal confirmed in Bluck v Information Commissioner in 2007, and FOIA 2000 s.41 reflects it. De-identification before reuse remains good practice.

Who can see the health records of someone who has died?

Access is governed by the Access to Health Records Act 1990 rather than by UK GDPR. Section 3(1)(f) gives a right of application to the deceased person's personal representative and to anyone who may have a claim arising out of the death, and the Act contains its own exemptions.

Are informant and certifier details removed too?

Yes, and they are the most clearly protected people in the document, because they are alive. The informant is usually a close relative, and the certifying doctor is an identifiable professional. Both are flagged alongside the deceased person's details.