Talent vendor data redaction is the removal of identifiers from people records before they reach a processor. UK GDPR Article 28(1) requires you to use only processors offering sufficient guarantees, and Article 28(3) sets out the written terms that must bind them. Article 32(1)(a) names pseudonymisation and encryption as security measures. anonym.plus marks each name on your device, so you share only what the task needs and nothing more.
When this applies
An HR team sends a file to an assessment partner, and the file still carries National Insurance numbers nobody needs. You strip the identifiers first, so the transfer honours the Article 28 duties and sends the partner only the fields the task requires.
How anonym.plus handles it
- Open the file in anonym.plus on your device.
- Built-in OCR reads any scanned source page.
- The app marks names, emails, and IDs.
- Confirm the markings and keep the fields the partner needs.
- Swap each identifier for a code.
- Save the minimised set locally, then transfer it.
What you need to provide
- The source file (CSV-as-TXT, XLSX-as-TXT, PDF).
- An operator (Replace keeps needed fields readable).
- Optional alias map, held by the controller only.
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | Lena Rowe → SUBJ_44 |
| Contact | EMAIL_ADDRESS | l.rowe@example.co.uk → [EMAIL] |
| Contact | PHONE_NUMBER | +44 161 496 0720 → [PHONE] |
| Org | ORGANIZATION | Finance Unit → [UNIT] |
| Identifiers | UK_NINO | QQ 12 34 56 C → [NINO] |
| Location | LOCATION | Coventry office → [SITE] |
Compliance achieved
- Supports the sufficient-guarantees duty in UK GDPR Art. 28(1) and the written terms required by Art. 28(3).
- Applies data minimisation under UK GDPR Art. 5(1)(c) — an assessment partner rarely needs a National Insurance number.
- Uses the pseudonymisation and encryption measures named in UK GDPR Art. 32(1)(a), while Art. 4(5) keeps coded rows in scope.
- Leaves Chapter V of the UK GDPR transfer rules to check if the supplier sits outside the UK. Offline, AES-256-GCM at rest.
Anonymise talent vendor data sets offline — see plans & start free →
Limitations & cautions
Article 28 still applies if a supplier can re-identify the people. A held alias map or rich quasi-identifiers may keep the set personal in the supplier's hands. Share the map only under contract, or leave it off.
Frequently asked questions
Does Article 28 require full anonymisation?
No. It requires a processor offering sufficient guarantees under Article 28(1) and a binding written contract under Article 28(3). If the supplier can still re-identify people, the set stays personal and every Article 28 duty applies.
Is a coded file exempt from the contract?
Not while a key exists. Article 4(5) treats pseudonymised data as personal data, so the processor terms and the Article 32(1)(a) security measures still stand.
What if the partner is based abroad?
Then Chapter V of the UK GDPR applies on top of Article 28, and you need a valid transfer mechanism before the file goes. Minimising the file first reduces what is at stake either way.
Is the source set uploaded?
No. The app is fully offline. You control when the minimised copy goes out.