Retention Record Deletion Confirmation with anonym.plus

Clear a subject's identifiers from an erasure confirmation before it is archived.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Deletion confirmation redaction is the removal of personal identifiers from the proof that an erasure ran. UK GDPR Art. 17(1) gives a person the right to have their data deleted, Art. 19 requires you to tell each recipient it happened, and Art. 5(2) requires you to be able to demonstrate all of it. anonym.plus marks the subject and references on your device, so the record of action survives while the named individual is hidden.

When this applies

The paradox is obvious once you see it: a confirmation that names the person, lists their request ID, and cites the systems purged is itself a fresh copy of the data you just erased. Art. 12(3) gave you one month to act, so the timestamp matters and the name does not. Where a record legitimately stayed — a PAYE file, right-to-work evidence — Art. 17(3)(b) is the reason, and that reason belongs in the log too.

How anonym.plus handles it

  1. Open the confirmation in anonym.plus on your device.
  2. The tool flags the subject, request ID, and contacts.
  3. Local OCR reads a scanned acknowledgement.
  4. Keep the action timestamps and system names.
  5. Swap or black out the confirmed items.
  6. Save the clean record locally.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONdata subject → [SUBJECT]
IdentifiersNATIONAL_IDrequest DSR-4412 → [REQUEST_ID]
ContactEMAIL_ADDRESSsubject@example.co.uk → [EMAIL]
DatesDATE_TIMEerased 01/06 → [DATE]
OrganisationORGANIZATIONsystem name → [SYSTEM]
LocationLOCATIONsubject city → [CITY]

Compliance achieved

Anonymise deletion confirmations offline — see plans & start free →

Limitations & cautions

A proof of erasure should show that work was done, not re-store the very data just deleted. The tool flags named items. Confirm no kept reference — a request ID, a ticket number — rebuilds the link to the subject through another system.

Frequently asked questions

Why redact a confirmation of deletion?

Keeping the subject's identifiers in it re-stores the data Art. 17 told you to erase. Redaction lets you keep the audit trail safely.

What should the record still show?

The timestamps and system names that prove the erasure ran, the Art. 19 notifications sent, and any Art. 17(3)(b) reason a record stayed. Allow-list those.

Is the log uploaded?

No. The app is fully offline, so the file stays on your device.