Investigation Subject Access Redaction with anonym.plus

Reveal the requester's own details while you shield other named people.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Subject access redaction is the removal of other people's data from an investigation file before disclosure. UK GDPR Art. 15 gives a person access to their own records, not to third-party details. Where the investigation concerns preventing or detecting crime, DPA 2018 Schedule 2 lets a controller withhold data to the extent that access would be likely to prejudice that purpose, and a separate exemption in the same Schedule covers material protected by legal professional privilege. anonym.plus clears third-party names on your device; it does not decide whether an exemption applies to material the requester wants to see.

When this applies

An employee files a subject access request (DSAR) for an investigation about them. The file also names witnesses and colleagues whom you must shield, and may hold material a lawyer or the crime/taxation exemption in Schedule 2 covers separately.

How anonym.plus handles it

  1. Open the file in anonym.plus on your device.
  2. The tool flags every named person in the text.
  3. Keep the requester's own details; flag the rest.
  4. Swap or black out third-party names and contacts.
  5. Save the disclosable copy on your device.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONrequester → kept (their right)
NamesPERSONwitness → [REDACTED]
NamesPERSONnamed colleague → [REDACTED]
ContactEMAIL_ADDRESSwitness email → [REDACTED]
ContactPHONE_NUMBERwitness phone → [REDACTED]
IdentifiersUK_NINOthird-party ID → [REDACTED]

Compliance achieved

Anonymise subject access files offline — see plans & start free →

Limitations & cautions

Art. 15 needs a balance between the requester's right and others' privacy, and a Schedule 2 exemption may remove some material from the response entirely — a legal judgment this tool does not make. A witness may still be obvious from context even with the name gone.

Frequently asked questions

Why keep the requester's own details?

UK GDPR Art. 15 gives a person the right to access their own file. You keep their identifiers and shield only the records of other people.

Can an investigation file ever be withheld entirely from a DSAR?

In part, sometimes. DPA 2018 Schedule 2 lets a controller withhold data where disclosure would be likely to prejudice the prevention or detection of crime, and a separate exemption covers material protected by legal professional privilege. Deciding whether either applies is a legal judgment, not something redaction settles.

Can I set the requester's own IDs as allowed?

Yes. An allow-list keeps the requester's identifiers in place while the tool removes everyone else's.