ER case export de-identification is the removal of personal data from a case-management extract, guided by UK GDPR Recital 26. Anything short of that bar is pseudonymisation as Art. 4(5) defines it, and pseudonymised data is still personal data. anonym.plus marks names and contacts on your device, so the dataset stays useful for counting while people are shielded.
When this applies
An export lists matters with names, dates, and outcomes for analytics. You strip those identifiers under Recital 26 before the dataset is shared.
How anonym.plus handles it
- Open the export in anonym.plus on your device.
- The app marks names, emails, and IDs in each row.
- Built-in OCR reads any scanned attachment.
- Turn the alias map OFF for true anonymity.
- Swap or black out the confirmed identifiers.
- Save the clean dataset locally.
What you need to provide
- The case export (CSV, XLSX, or TXT).
- An operator (Redact for an analytics dataset).
- Alias map turned OFF for true anonymisation.
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | case subject → [SUBJECT] |
| Contact | EMAIL_ADDRESS | user@example.co.uk → [EMAIL] |
| Dates | DATE_TIME | opened 2025 → [DATE] |
| Identifiers | UK_NINO | QQ 12 34 56 C → [NINO] |
| Location | LOCATION | Edinburgh office → [LOCATION] |
| Organization | ORGANIZATION | Acme Ltd → [EMPLOYER] |
Compliance achieved
- Targets the anonymity bar in UK GDPR Recital 26; anything short of it is pseudonymisation as Art. 4(5) defines it, and still personal data.
- Applies data minimisation under UK GDPR Art. 5(1)(c) to a dataset built for counting, not for casework.
- Supports the safeguards UK GDPR Art. 89(1) expects where the extract is used for statistical purposes.
- Adds the security measure Art. 32(1)(a) names before the extract leaves the case system.
- Deliberately re-identifying the export is an offence under DPA 2018 s.171; the whole run stays offline.
Anonymise ER case exports offline — see plans & start free →
Limitations & cautions
Recital 26 treats data as anonymous only if no one can be singled out under the motivated-intruder test. A rare combination of date, site, role and outcome can still point to one person, and small-cell rows are the usual failure. Aggregate small groups, keep the alias map off, and remember that a held key makes the file pseudonymised, not anonymous.
Frequently asked questions
How do I anonymise an export under Recital 26?
Turn the reversible map OFF and use Redact across the rows. Then check that no rare combination of fields singles out a person, and aggregate any small cells.
Can I keep a pseudonym for trend analysis?
Yes, with the alias map on. UK GDPR Art. 4(5) still treats that as personal data, so the dataset stays in scope of the rules.
Is the export uploaded?
No. The app runs locally, so the dataset never reaches a cloud server.