EAP referral record redaction is the removal of special category identifiers from an employee assistance programme intake. The presenting issue is data concerning health under UK GDPR Art. 9(1), and counselling material also attracts the common-law duty of confidence. Where the provider acts on your instructions it is a processor, so the written terms in Art. 28(3) apply. anonym.plus marks each identifier on your device.
When this applies
Such an intake names the worker, a presenting issue, an NI number, and contact lines. You strip those identifiers before any aggregate report on programme use goes to the board.
How anonym.plus handles it
- Open the file in anonym.plus on your device.
- Local OCR reads a scanned intake page if needed.
- The tool flags names, the issue note, and contacts.
- Keep the de-identified category a report needs.
- Swap or black out the confirmed items.
- Save the de-identified copy locally.
What you need to provide
- The intake file (PDF, DOCX, or scan).
- An operator (Replace keeps the category readable).
- Optional batch for a programme-wide set.
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | employee A. Marsh → [EMPLOYEE] |
| Health | MEDICAL_CONDITION | presenting issue → [CONDITION] |
| NI number | UK_NINO | QQ 20 19 77 C → [NINO] |
| Dates | DATE_TIME | intake 04/2026 → [DATE] |
| Contact | PHONE_NUMBER | +44 20 7946 1180 → [PHONE] |
| Contact | EMAIL_ADDRESS | a.marsh@example.co.uk → [EMAIL] |
Compliance achieved
- Treats the presenting issue as special category data under UK GDPR Art. 9(1), with Art. 9(2)(h) covering an occupational health purpose; counselling notes also attract the common-law duty of confidence.
- Where an EAP provider acts on your instructions it is a processor, so the written terms in UK GDPR Art. 28(3) and the security duty in Art. 32 apply to what you send it.
- Keeps a de-identified category so aggregate reporting still works without naming anyone — minimisation under Art. 5(1)(c).
- Where a report on a worker is sought from a doctor responsible for their care, the Access to Medical Reports Act 1988 gives that worker consent and access rights that redaction does not replace.
Anonymise EAP referral records offline — see plans & start free →
Limitations & cautions
The tool removes direct identifiers, yet a rare issue plus a small team can still hint at a person. Review such notes before sharing, and apply the ICO motivated-intruder test for high-risk cases.
Frequently asked questions
Should an employer see EAP intake detail at all?
Usually not. The presenting issue is Art. 9 health data held in confidence by the provider; the employer normally needs counts and categories. De-identifying the copy you hold makes that boundary real.
What contract does an EAP provider need?
If it processes on your documented instructions, UK GDPR Art. 28(3) requires written terms covering purpose, duration, security, and deletion. Some providers act as controllers for the clinical record instead — confirm which before you send anything.
Is the file uploaded?
No. The app runs offline, so the intake stays on your device.