Multicentre sharing de-identification is the removal of patient identifiers under UK GDPR Art. 9 & DPA 2018 before centres pool their files. anonym.plus does this on your own device, so each contribution arrives without a named patient.
When this applies
Several teams combine files for a joint analysis. Each contribution still holds patient names, dates, and a local record number.
How anonym.plus handles it
- Open one team’s file (CSV, XLSX, or PDF) in anonym.plus.
- The tool scans for names, dates, and local record numbers.
- Local OCR reads any scanned source page you add.
- Confirm the flags and align the codes across centres.
- Swap each identifier for a shared, steady token.
- Save each cleaned file locally before you pool them.
What you need to provide
- Each centre file (CSV, XLSX, PDF, or scan).
- An operator: Replace with a shared token scheme.
- Optional: a cross-centre token map held by the lead only.
Patient data entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | Mei Chen → [SUBJECT_C12] |
| Dates | DATE_TIME | visit 28/04/2026 → [DATE] |
| NHS number | MEDICAL_RECORD_NUMBER | NHS 512 345 6789 → [NHS_NO] |
| Centre | LOCATION | Centre B, Manchester → [CENTRE_B] |
| Investigator | PERSON | Dr. Hussain → [INVESTIGATOR] |
| Contact | PHONE_NUMBER | +44 161 496 0162 → [PHONE] |
Compliance achieved
- A study across NHS sites runs on a single HRA and HCRW Approval alongside the research ethics committee opinion, so one standard applies to every centre's file.
- Sponsor and site responsibilities are set by the UK Policy Framework for Health and Social Care Research.
- Where centres decide jointly on purposes and means, UK GDPR Art. 26 requires a joint-controller arrangement recording who does what.
- Each contribution still needs the UK GDPR Art. 89(1) safeguards and the DPA 2018 s.19 conditions before it is pooled.
- Apply the ICO's motivated-intruder test to the pooled set, not to each file — rarity is a property of the combined data.
- Runs offline — each centre cleans its own file, so no data-processor contract is triggered; AES-256-GCM at rest.
Anonymise multicentre study files offline — see plans & start free →
Limitations & cautions
Pooling raises the re-identification risk, because one centre’s rare value can become unique in the combined set. The tool strips direct identifiers per file. The lead must still check the pooled result for rare combinations before any wider release.
Frequently asked questions
Why is multicentre sharing higher risk?
When centres pool files, a value that is common at one site can be unique across the whole set, so a record that was safe alone becomes identifying once combined. The ICO’s motivated-intruder test therefore has to be applied to the merged data, not to each contribution, and UK GDPR Art. 26 requires the centres to record who carries that responsibility.
How do tokens stay consistent across centres?
Each centre applies the same token scheme to the same person. A cross-centre map, held only by the lead, lets the records align without exposing names.
Does this need a data-processor contract between centres?
No. Each centre cleans its own file on its own device before sharing. No named data moves, so no processor agreement is triggered.