Multicentre Study Data Sharing De-Identification with anonym.plus

Pool centre files into a shareable set that names no patient, fully on-device.

Multicentre sharing de-identification is the removal of patient identifiers under UK GDPR Art. 9 & DPA 2018 before centres pool their files. anonym.plus does this on your own device, so each contribution arrives without a named patient.

When this applies

Several teams combine files for a joint analysis. Each contribution still holds patient names, dates, and a local record number.

How anonym.plus handles it

  1. Open one team’s file (CSV, XLSX, or PDF) in anonym.plus.
  2. The tool scans for names, dates, and local record numbers.
  3. Local OCR reads any scanned source page you add.
  4. Confirm the flags and align the codes across centres.
  5. Swap each identifier for a shared, steady token.
  6. Save each cleaned file locally before you pool them.

What you need to provide

Patient data entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONMei Chen → [SUBJECT_C12]
DatesDATE_TIMEvisit 28/04/2026 → [DATE]
NHS numberMEDICAL_RECORD_NUMBERNHS 512 345 6789 → [NHS_NO]
CentreLOCATIONCentre B, Manchester → [CENTRE_B]
InvestigatorPERSONDr. Hussain → [INVESTIGATOR]
ContactPHONE_NUMBER+44 161 496 0162 → [PHONE]

Compliance achieved

Anonymise multicentre study files offline — see plans & start free →

Limitations & cautions

Pooling raises the re-identification risk, because one centre’s rare value can become unique in the combined set. The tool strips direct identifiers per file. The lead must still check the pooled result for rare combinations before any wider release.

Frequently asked questions

Why is multicentre sharing higher risk?

When centres pool files, a value that is common at one place can be unique across the whole set. So a record safe alone can become identifying once combined. The lead checks the merged data, not just each file.

How do tokens stay consistent across centres?

Each centre applies the same token scheme to the same person. A cross-centre map, held only by the lead, lets the records align without exposing names.

Does this need a data-processor contract between centres?

No. Each centre cleans its own file on its own device before sharing. No named data moves, so no processor agreement is triggered.