Breach Investigation File Redaction with anonym.plus

Clear affected-patient and staff detail from a breach case file.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Breach-investigation redaction is the removal of personal data from an incident case built after a suspected exposure. UK GDPR Art. 33 requires notification to the ICO within 72 hours, and Art. 34 separately requires telling the affected patients themselves where the breach is likely to result in a high risk to their rights. anonym.plus runs on your device, so impacted individuals are cleared from working copies while the timeline stays.

When this applies

An investigation lists impacted patients, the staff involved, and the access log, feeding both the 72-hour Art. 33 notification and, if the risk is high enough, the Art. 34 letters to those affected. To brief leadership or prepare a working summary, that personal detail comes out first.

How anonym.plus handles it

  1. Open the case in anonym.plus on your device.
  2. Local OCR reads scanned notices and forms.
  3. It flags impacted names, staff, IPs, and timestamps.
  4. Confirm the flags and keep the root-cause notes.
  5. Swap each item for a label, or black it out.
  6. Save the cleaned case. The source stays local.

What you need to provide

Patient data entity types detected

Categoryanonym.plus entity typeExample
PatientPERSONimpacted: 412 people → [PATIENT_n]
StaffPERSONinvolved RN Soto → [STAFF]
Staff IDIDuser msoto → [USERNAME]
NetworkIP_ADDRESS203.0.113.7 → [IP]
DatesDATE_TIMEexposed 05/2026 → shifted [DATE]
Record IDsMEDICAL_RECORD_NUMBERNHS Nos. leaked → [NHS_NUMBER_n]

Compliance achieved

Anonymise breach investigation files offline — see plans & start free →

Limitations & cautions

An investigation file is highly sensitive and must stay defensible. Never remove facts the ICO needs for its 72-hour notification. Clear the personal detail, keep a log of what changed, and confirm the redaction scope with your Data Protection Officer.

Frequently asked questions

What does an investigation file contain?

It lists the people exposed, the staff involved, the access records, and the cause. The personal detail can be cleared for briefings while the root cause is kept.

What does UK GDPR Art. 33 require, and how does Art. 34 differ?

Art. 33 requires notification to the ICO within 72 hours of becoming aware of an incident. Where the breach is likely to result in a high risk to the people affected, Art. 34 separately requires telling them directly, not just the regulator. Redacting personal detail for internal summaries lowers further exposure while both notifications are prepared.

Are usernames and IPs cleared?

Yes. Access usernames, IPs, and timestamps are flagged with patient and staff names.