Drug Safety Narrative De-Identification with anonym.plus

Clear IDs from the narrative while the event timeline stays.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Safety-narrative de-identification is the removal of patient and reporter IDs from the free-text event story. ICH E2B(R3) carries that narrative alongside the coded fields, and it is where identifiers survive coding. anonym.plus runs locally and keeps the suspected product and the dose-to-onset timeline.

When this applies

An event story is dense free text naming the subject, the reporter, and places. Causality assessment depends on the interval between dose and onset, so the dates must keep their spacing even after the real ones go.

How anonym.plus handles it

  1. Open the narrative in anonym.plus on your device.
  2. It reads the free text for the named people.
  3. Dates, ages, and places get flagged across the story.
  4. Confirm the flags; the suspected product stays as non-personal data.
  5. Swap the IDs and shift the dates to keep the gaps.
  6. Save the clean file; the source stays on your machine.

What you need to provide

Patient data entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONNiamh Walsh → [PATIENT]
NamesPERSONreporting GP → [REPORTER]
DatesDATE_TIMEdose 09 Feb → shifted [DATE]
AgeAGEage 81 → [AGE_BAND]
LocationLOCATIONBristol site → [SITE]
IdentifiersIDnarrative ref 5521 → [ID]

Compliance achieved

Anonymise safety narratives offline — see plans & start free →

Limitations & cautions

The story is free text with mixed clues. The suspected product must stay, as it is the signal. Pseudonymised output is still personal data under UK GDPR Art. 4(5) if you hold the key, so destroy the map when you want true anonymity. A rare event on a known date at a small site can still narrow identity, so band the age and shift dates for unusual cases.

Frequently asked questions

Is the suspected product removed?

No. The product name is not patient data and carries the safety signal, so it stays. Only the patient and reporter IDs are taken out.

How is the timeline kept useful?

Date-shift moves all dates by one steady offset, so the gap between dose and event stays while the real dates are hidden. That gap is what causality assessment reads.

Does a label map count as anonymisation?

No. While you hold the map the output is pseudonymised, which UK GDPR Art. 4(5) still treats as personal data. Drop the map and the copy can be assessed as anonymous.