Supplier Contract Patient Data Removal with anonym.plus

Strip embedded health samples and signatory names from agreements before sharing.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Supplier-contract personal information removal strips identifying records from supplier agreements and their exhibits. Where a supplier processes patient data on the hospital's behalf, UK GDPR Art. 28(3) fixes the eight terms the contract must contain, and DPA 2018 governs the personal data that sometimes ends up embedded in a sample exhibit or schedule. anonym.plus runs on your device, so embedded samples and signatory names go while the Art. 28 terms stay.

When this applies

An agreement’s exhibits sometimes include sample records or a schema with real values, plus the names of those who signed. Before circulating a template drawn from a live processor contract, that identifying detail is cleared while the mandatory Art. 28(3) clauses stay untouched.

How anonym.plus handles it

  1. Open the agreement in anonym.plus on your device.
  2. Local OCR reads scanned signature pages.
  3. It flags signatory names, health sample records, and contacts.
  4. Confirm the flags and keep the contract terms.
  5. Swap each item for a label, or black it out.
  6. Save the clean template. The source stays local.

What you need to provide

Patient data entity types detected

Categoryanonym.plus entity typeExample
SignatoryPERSONsigned: V. Marek → [SIGNATORY]
OrganisationORGANIZATIONDataCare Ltd → [SUPPLIER]
IndividualPERSONexhibit sample: R. Day → [SUBJECT]
Record IDsMEDICAL_RECORD_NUMBERsample NHS No. → [NHS_NUMBER]
ContactEMAIL_ADDRESSv.marek@example.com → [EMAIL]
DatesDATE_TIMEsigned 02/2026 → [DATE]

Compliance achieved

Anonymise supplier contracts offline — see plans & start free →

Limitations & cautions

Identifying material hides in exhibits, schedules, and schema samples, not the main clauses. Check every appendix, not just the body. A signatory’s name is personal information and is cleared when you circulate a reusable template.

Frequently asked questions

What must a processor contract for patient data contain?

UK GDPR Art. 28(3) lists eight mandatory terms, covering things like acting only on the controller's documented instructions, confidentiality, and deletion or return of the data at the end of the contract. A precedent missing any of them isn't fit to reuse, so redaction here only touches the exhibits and signatures, never those clauses.

Do the terms survive the swap?

Yes. Clauses and terms stay. Only the identifying detail in signatures and exhibits changes.

Are signatory names removed?

Yes, for a circulated template. Those who signed are personal and their names are swapped along with the sample identifying material.