This task removes personal data from a Disclosure and Barring Service certificate. The Police Act 1997 established the criminal-record disclosure regime the DBS now runs, and the DBS Code of Practice issued under that Act tells registered bodies to handle and store a certificate securely and to dispose of it once the recruitment decision no longer needs it. Because the certificate is criminal-offence data, UK GDPR Art. 10 and DPA 2018 Sch. 1 Part 3 also require a lawful condition for keeping it at all. anonym.plus marks identifiers on your device, so the outcome stays useful while protected fields are shielded.
When this applies
The certificate lists a National Insurance number, addresses, and dates drawn from several sources, alongside the disclosure outcome the DBS Code of Practice says you may keep only as long as the recruitment decision needs it. You trim those identifiers before it reaches anyone without a need to know, and before it outlives the Code's own retention steer.
How anonym.plus handles it
- Open the certificate in anonym.plus on your device.
- Built-in OCR reads a scanned or posted disclosure.
- The app marks NINO, addresses, and birth dates.
- Confirm each marking and keep the clear or flagged result.
- Swap or black out the confirmed identifiers.
- Save the cleaned copy locally.
What you need to provide
- The vetting certificate (PDF, DOCX, or scan).
- An operator (Redact suits a sensitive file).
- Optional batch for many certificates at once.
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Identifiers | UK_NINO | QQ 12 34 56 C → [NINO] |
| Names | PERSON | subject of certificate → [SUBJECT] |
| Dates | DATE_TIME | DOB 1985 → [DOB] |
| Location | LOCATION | prior address → [ADDRESS] |
| Reference | NATIONAL_ID | certificate no. → [VETTING_REF] |
| Identifiers | UK_PASSPORT | passport 123456789 → [PASSPORT] |
Compliance achieved
- Handles disclosure data under the framework the Police Act 1997 established and the DBS Code of Practice governs for secure storage and disposal.
- Meets the criminal-offence-data condition in UK GDPR Art. 10 and DPA 2018 Sch. 1 Part 3.
- Keeps the disclosure outcome while hiding source identifiers.
- Offline work keeps personal data off the cloud.
Anonymise DBS check reports offline — see plans & start free →
Limitations & cautions
The Code of Practice also sets storage, access, and disposal duties this app does not handle, including its steer to destroy most certificates once the recruitment decision is made. It removes identifiers only. Follow the retention rules and the ICO's guidance separately.
Frequently asked questions
Who may see an unredacted DBS certificate?
The DBS Code of Practice and DPA 2018 Sch. 1 Part 3 limit access to those handling the specific recruitment decision. anonym.plus trims identifiers before the certificate circulates any wider inside the organisation.
How long should I keep the certificate?
The DBS Code of Practice recommends destroying most certificates as soon as a recruitment decision is made, save for a brief record of the fact and date of the check. The app does not set that timer; it prepares the file for the retention step you choose.
Can I clean several certificates together?
Yes. Batch mode handles up to 20 documents per run, all processed locally with OCR for scanned pages.