Talent Vendor Data Redaction with anonym.plus

Strip identifiers before talent records go to an outside processor.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Talent vendor data redaction is the removal of identifiers from people records before they reach a processor. UK GDPR Article 28(1) requires you to use only processors offering sufficient guarantees, and Article 28(3) sets out the written terms that must bind them. Article 32(1)(a) names pseudonymisation and encryption as security measures. anonym.plus marks each name on your device, so you share only what the task needs and nothing more.

When this applies

An HR team sends a file to an assessment partner, and the file still carries National Insurance numbers nobody needs. You strip the identifiers first, so the transfer honours the Article 28 duties and sends the partner only the fields the task requires.

How anonym.plus handles it

  1. Open the file in anonym.plus on your device.
  2. Built-in OCR reads any scanned source page.
  3. The app marks names, emails, and IDs.
  4. Confirm the markings and keep the fields the partner needs.
  5. Swap each identifier for a code.
  6. Save the minimised set locally, then transfer it.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONLena Rowe → SUBJ_44
ContactEMAIL_ADDRESSl.rowe@example.co.uk → [EMAIL]
ContactPHONE_NUMBER+44 161 496 0720 → [PHONE]
OrgORGANIZATIONFinance Unit → [UNIT]
IdentifiersUK_NINOQQ 12 34 56 C → [NINO]
LocationLOCATIONCoventry office → [SITE]

Compliance achieved

Anonymise talent vendor data sets offline — see plans & start free →

Limitations & cautions

Article 28 still applies if a supplier can re-identify the people. A held alias map or rich quasi-identifiers may keep the set personal in the supplier's hands. Share the map only under contract, or leave it off.

Frequently asked questions

Does Article 28 require full anonymisation?

No. It requires a processor offering sufficient guarantees under Article 28(1) and a binding written contract under Article 28(3). If the supplier can still re-identify people, the set stays personal and every Article 28 duty applies.

Is a coded file exempt from the contract?

Not while a key exists. Article 4(5) treats pseudonymised data as personal data, so the processor terms and the Article 32(1)(a) security measures still stand.

What if the partner is based abroad?

Then Chapter V of the UK GDPR applies on top of Article 28, and you need a valid transfer mechanism before the file goes. Minimising the file first reduces what is at stake either way.

Is the source set uploaded?

No. The app is fully offline. You control when the minimised copy goes out.