Performance Analytics Export De-Identification with anonym.plus

Strip the names from an analytics export before it reaches a BI tool.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

This task is the removal of identifiers from a people-data extract of appraisal metrics, so no one is named. Coding the name is not the end of it: UK GDPR Article 4(5) treats pseudonymised data as still personal while a key exists, and Recital 26 with the ICO's motivated-intruder test asks whether tenure, site and role together rebuild a person. anonym.plus marks each identifier on your device, so the numbers stay rich while the staff stay private.

When this applies

An analyst loads an HR extract into a BI dashboard that a hundred managers can open. You strip the identifiers first, so the feed clears Recital 26 before it leaves the HR system.

How anonym.plus handles it

  1. Open the data extract in anonym.plus on your device.
  2. Built-in OCR reads a scanned report page.
  3. The app marks names, emails, and IDs.
  4. Confirm the markings and keep the metric columns.
  5. Swap each identifier for a code.
  6. Save the cleaned feed locally.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONPavel Novak → ID_318
ContactEMAIL_ADDRESSp.novak@example.co.uk → [EMAIL]
OrgORGANIZATIONRetail Region 4 → [UNIT]
DatesDATE_TIMEhire 2017 → [TENURE]
LocationLOCATIONLiverpool store → [SITE]
DemographicNRPshift group B → [GROUP]

Compliance achieved

Anonymise performance analytics exports offline — see plans & start free →

Limitations & cautions

Quasi-identifiers can re-link a row. A rare mix of tenure, site, and role may match one person even with no name. Bucket such fields before you publish the dashboard.

Frequently asked questions

What is a quasi-identifier risk here?

A combination like tenure plus site plus role can match one person. Recital 26 and the motivated-intruder test treat that as non-anonymous, so bucket or coarsen those fields.

Is a coded staff ID enough to call the feed anonymous?

No. Article 4(5) defines pseudonymisation as processing that still allows attribution using separately held information. While anyone holds the key, the data stays personal and every duty follows it.

Does a research or statistics purpose relax the rules?

It adds safeguards rather than removing them. Article 89(1) expects technical and organisational measures, with data minimisation and anonymisation named as the route where the purpose can still be met.

Is the extract uploaded?

No. The tool works offline, so it stays on your device.