Registry de-identification is the removal of patient identifiers under UK GDPR Art. 9 & DPA 2018 from the export. anonym.plus does this on your own device. The outcome fields stay, but no patient is named.
When this applies
A registry shares a cohort with a research partner. The export still holds patient names, full dates, and a record number per row.
How anonym.plus handles it
- Open the export (CSV, XLSX, or PDF) in anonym.plus on your device.
- The tool scans every row for names, dates, and record numbers.
- Local OCR reads a scanned intake page if you add one.
- Confirm the flagged identifiers across the columns.
- Swap names for codes, or black out whole columns.
- Save the clean export locally with no upload.
What you need to provide
- The export (CSV, XLSX, PDF, or scan).
- An operator: Replace for codes, Redact for whole fields.
- Optional: a code map if you re-link rows later.
Patient data entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | Daniel Morgan → [PATIENT_6] |
| Dates | DATE_TIME | enrolled 15/01/2026 → [DATE] |
| NHS number | MEDICAL_RECORD_NUMBER | NHS 943 476 5919 → [NHS_NO] |
| Address | LOCATION | Bristol BS1 → [ADDRESS] |
| Local ID | ID | REG 90431 → [REG_ID] |
| Contact | EMAIL_ADDRESS | d.morgan@example.co.uk → [EMAIL] |
Compliance achieved
- A registry built from care records carries the common law duty of confidentiality as well as UK GDPR Art. 9(1).
- Collection without individual consent generally rests on s.251 of the NHS Act 2006 with the Health Service (Control of Patient Information) Regulations 2002 (SI 2002/1438), on Confidentiality Advisory Group advice.
- The National Data Opt-Out applies to confidential information reused for research and planning; genuinely anonymised outputs fall outside it.
- Sharing a cohort onward needs UK GDPR Art. 9(2)(j), the Art. 89(1) safeguards and the conditions in DPA 2018 s.19.
- Runs offline — no cloud upload, no data-processor contract; the working export stays under AES-256-GCM.
Anonymise patient registries offline — see plans & start free →
Limitations & cautions
The ICO motivated-intruder test requires you to consider all means reasonably likely to re-identify a patient. The tool removes direct identifiers. A rare diagnosis in a small area can still narrow the field; apply the test before sharing.
Frequently asked questions
What is a patient registry?
It is an organised collection of data on people with a shared condition or treatment, tracked over time. Most UK registries collect confidential health records without individual consent under s.251 of the NHS Act 2006 and SI 2002/1438, which makes the National Data Opt-Out and the Caldicott Principles live constraints on any onward share.
Is a data-processor contract needed?
No. anonym.plus runs on your own device with no cloud step. No outside party sees the rows, so no processor agreement is triggered.
Can the outcomes still be analysed?
Yes. Diagnoses, treatments, and outcome fields stay. Only direct identifiers are swapped or removed.