Internal Investigation Report Redaction with anonym.plus

Pull names and contacts from the file while the findings stay readable.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Internal investigation report redaction is the removal of personal data so the file is anonymous under UK GDPR Recital 26. Many such reports are prepared once a company anticipates a criminal investigation or a dismissal, and the Court of Appeal in Serious Fraud Office v Eurasian Natural Resources Corp Ltd [2018] EWCA Civ 2006 confirmed that material created for the dominant purpose of resisting or avoiding anticipated adversarial proceedings can attract litigation privilege even at the internal fact-finding stage. anonym.plus works on your own device; the findings stay readable, but the document no longer names the people involved.

When this applies

You must share the report with the board, outside solicitors, or a body such as the SFO or the FCA. Each reader needs the personal data stripped of names, emails, and IDs first — whether the report itself is privileged is a separate legal question the redaction does not answer.

How anonym.plus handles it

  1. Open the file (PDF, DOCX, or scan) in anonym.plus on your device.
  2. Local OCR reads scanned exhibits, so it catches printed text too.
  3. The tool flags names, emails, phone numbers, and account IDs.
  4. Check each flag and fix any term caught by mistake.
  5. Swap each ID for a steady label, or black it out.
  6. Save the clean copy. The original never leaves your machine.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONEmily Hartley → [EMPLOYEE_1]
ContactEMAIL_ADDRESSe.hartley@corp.co.uk → [EMAIL]
DatesDATE_TIMEinterviewed 03/11/2026 → [DATE]
ContactPHONE_NUMBER+44 7700 900147 → [PHONE]
IdentifiersUK_NINOQQ 12 34 56 C → [ID]
FinancialUK_BANK_NUMBER20-00-00 12345678 → [ACCOUNT]

Compliance achieved

Anonymise investigation reports offline — see plans & start free →

Limitations & cautions

Direct IDs go, but a unique role plus a date can still hint at one person. Review free-text quotes by hand. The tool catches named items, yet it cannot judge when an indirect clue re-identifies someone, and it does not decide whether the document is privileged.

Frequently asked questions

Redaction and privilege are separate questions. The file stays on your own device, so no outside party sees it during processing — that alone cannot waive a privilege claim. Whether the report attracts litigation privilege at all turns on the dominant-purpose test from SFO v Eurasian Natural Resources Corp Ltd [2018] EWCA Civ 2006, which is a question for your legal advisers, not this tool.

When is the report truly anonymous under UK GDPR?

When no one can reasonably re-identify it. That means no kept re-link key and low risk from the rest of the text. Only then does Recital 26 take it out of scope.

Does removing names undermine a fair disciplinary process?

No. The ACAS Code of Practice on Disciplinary and Grievance Procedures, which employment tribunals weigh under TULRCA 1992 s.207, judges the fairness of the process that produced the report — not whether a later, de-identified copy still names every participant.