Dataset anonymisation is the removal of personal detail from a mobile-health study collection. UK GDPR Art. 89(1) allows processing for scientific research subject to safeguards, and names anonymisation as the goal wherever the purpose can be met that way. DPA 2018 Schedule 1, Part 1, paragraph 4 is the matching condition for special category research data, and section 19 sets the safeguards that come with it. anonym.plus applies the strongest measure on your device, so the study fields stay usable.
When this applies
A mobile study gathers app events, sensor readings, and survey answers from enrolled participants. Sharing the collection with partner sites is a new disclosure. Dense sensor traces make that riskier than a tabular study, so identity has to go before the transfer.
How anonym.plus handles it
- Open the study set in anonym.plus on a local device.
- It scans identifier columns and free-text fields alike.
- Sensor readings and survey scores stay in place.
- Swap the personal parts with the map turned off.
- Save the anonymous collection for sharing.
What you need to provide
- The collection (CSV, JSON, or a record bundle).
- Replace with the re-link map off for anonymity.
- Optional column map for participant fields.
Patient data entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | participant name → [SUBJECT_n] |
| Contact | EMAIL_ADDRESS | enrolment email → [EMAIL] |
| Identifiers | ID | device handle → [DEVICE] |
| Network | IP_ADDRESS | sync IP → [IP] |
| Dates | DATE_TIME | enrolment date → shifted [TIME] |
| Free text | LOCATION | diary city → [PLACE] |
Compliance achieved
- Supports scientific reuse under the safeguards in UK GDPR Art. 89(1).
- Uses the research condition for special category data in DPA 2018 Schedule 1, Part 1, paragraph 4.
- Applies the further research safeguards in DPA 2018 section 19.
- Anonymisation is the strongest safeguard — a genuinely anonymous set falls outside scope by UK GDPR Recital 26.
- Sits within study governance under the UK Policy Framework for Health and Social Care Research (2017), including HRA approval where required.
- Residual risk is judged with the ICO motivated-intruder test before any transfer.
Anonymise mHealth research datasets offline — see plans & start free →
Limitations & cautions
Rich mobile data raises re-identification risk, because dense sensor traces can fingerprint a subject. Coarsen the timestamps and the location, keep no re-link key, and review rare diary entries before you share the collection.
Frequently asked questions
What does UK GDPR Art. 89(1) actually require?
It requires safeguards for processing carried out for scientific research, and it points to technical and organisational measures that respect data minimisation. It names pseudonymisation as an example, and says that where the research purpose can be met without identifying anyone, it should be. Full anonymisation is the strongest version of that.
Which condition covers special category research data?
DPA 2018 Schedule 1, Part 1, paragraph 4 is the research condition that sits under Art. 9(2)(j), and section 19 attaches safeguards to it. Those safeguards rule out using the data for measures or decisions about a particular participant, which anonymisation supports directly.
Can subjects stay linkable across visits?
Yes. A steady code map gives each subject one alias so visits still join. Keeping that map makes the set pseudonymous rather than anonymous, so hold it separately under its own controls.