This task is the removal of identifiers from a people-data extract of appraisal metrics, so no one is named. Coding the name is not the end of it: UK GDPR Article 4(5) treats pseudonymised data as still personal while a key exists, and Recital 26 with the ICO's motivated-intruder test asks whether tenure, site and role together rebuild a person. anonym.plus marks each identifier on your device, so the numbers stay rich while the staff stay private.
When this applies
An analyst loads an HR extract into a BI dashboard that a hundred managers can open. You strip the identifiers first, so the feed clears Recital 26 before it leaves the HR system.
How anonym.plus handles it
- Open the data extract in anonym.plus on your device.
- Built-in OCR reads a scanned report page.
- The app marks names, emails, and IDs.
- Confirm the markings and keep the metric columns.
- Swap each identifier for a code.
- Save the cleaned feed locally.
What you need to provide
- The data extract (CSV-as-TXT, XLSX-as-TXT, PDF).
- An operator (Replace keeps metrics readable).
- Optional alias map, OFF for true anonymity.
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | Pavel Novak → ID_318 |
| Contact | EMAIL_ADDRESS | p.novak@example.co.uk → [EMAIL] |
| Org | ORGANIZATION | Retail Region 4 → [UNIT] |
| Dates | DATE_TIME | hire 2017 → [TENURE] |
| Location | LOCATION | Liverpool store → [SITE] |
| Demographic | NRP | shift group B → [GROUP] |
Compliance achieved
- Marks the line UK GDPR Art. 4(5) draws: pseudonymised rows are still personal data while a key exists.
- Applies the UK GDPR Recital 26 bar and the ICO's motivated-intruder test to quasi-identifiers such as tenure plus site.
- Signals the DPIA trigger in UK GDPR Art. 35(3)(a) for systematic evaluation, alongside the ICO's monitoring-workers guidance.
- Supports the statistical-purpose safeguards in UK GDPR Art. 89(1). Batch up to 20 files for a multi-source feed, offline.
Anonymise performance analytics exports offline — see plans & start free →
Limitations & cautions
Quasi-identifiers can re-link a row. A rare mix of tenure, site, and role may match one person even with no name. Bucket such fields before you publish the dashboard.
Frequently asked questions
What is a quasi-identifier risk here?
A combination like tenure plus site plus role can match one person. Recital 26 and the motivated-intruder test treat that as non-anonymous, so bucket or coarsen those fields.
Is a coded staff ID enough to call the feed anonymous?
No. Article 4(5) defines pseudonymisation as processing that still allows attribution using separately held information. While anyone holds the key, the data stays personal and every duty follows it.
Does a research or statistics purpose relax the rules?
It adds safeguards rather than removing them. Article 89(1) expects technical and organisational measures, with data minimisation and anonymisation named as the route where the purpose can still be met.
Is the extract uploaded?
No. The tool works offline, so it stays on your device.