Wearable Data Export De-Identification with anonym.plus

Strip account and device identifiers from tracker exports that hold vitals.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Export de-identification is the removal of personal detail from a fitness tracker download. Heart-rate and sleep series can reveal a physical state, which brings them inside UK GDPR Art. 9(1). The device itself is a different question: a general wellness tracker normally sits outside the Medical Devices Regulations 2002 unless the maker claims a medical purpose. Regulation 6 of PECR still applies to anything the companion app stored on the handset. anonym.plus works on your own device and keeps the series whole.

When this applies

A tracker download bundles steps and sleep with the account email and a hardware identifier. Before research reuse, those handles have to go. GPS traces need a second look, because a daily route is close to unique.

How anonym.plus handles it

  1. Open the download in anonym.plus on a local device.
  2. It finds the account email, name, and hardware identifier.
  3. The step, sleep, and pulse series stay untouched.
  4. Swap the personal parts with the map turned off.
  5. Save the anonymous file on your machine.

What you need to provide

Patient data entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONaccount holder → [USER]
ContactEMAIL_ADDRESSlogin email → [EMAIL]
IdentifiersIDhardware ID → [DEVICE]
NetworkIP_ADDRESSsync IP → [IP]
DatesDATE_TIMEdaily timestamp → [TIME]
LocationLOCATIONGPS city → [PLACE]

Compliance achieved

Anonymise wearable data exports offline — see plans & start free →

Limitations & cautions

GPS traces and timestamps can re-identify with no name attached, because a daily route is close to unique. Coarsen the location and shift the times. Keep no re-link key if the result has to stay anonymous under the motivated-intruder test.

Frequently asked questions

Why are heart-rate and sleep entries health information?

They reveal a person's physical state, and UK GDPR Art. 9 covers data concerning health however it was captured. A consumer device does not change that. What matters is whether the values, alone or with other fields, say something about the individual's health.

Is my tracker regulated by the MHRA?

Usually not. The Medical Devices Regulations 2002 turn on the purpose the manufacturer claims, so a step-and-sleep tracker sold for general wellness is normally out of scope. Add a claim about detecting or monitoring a condition and the same hardware can fall in. That call belongs to the manufacturer, not to you as a data analyst.

Are GPS points removed?

They are flagged as location data. A precise route is a strong clue on its own, so swap or coarsen it before you treat the export as anonymous.