Data Room Document Anonymisation with anonym.plus

Clear personal data from deal files so the output sits outside UK GDPR scope.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Data room anonymisation is the removal of personal data from files shared with bidders. UK GDPR Recital 26 puts truly anonymous data outside the regulation, and DPA 2018 s.3(2) sets the matching test for what still counts as personal data. Art. 5(1)(c) asks you to share no more than the purpose needs. anonym.plus applies both tests on your own device, so the deal file stays inside the firm.

When this applies

You open a virtual data room for a sale and let bidders review the target. The room provider is your processor, so Art. 28(3) terms bind it, yet the cleanest answer is to upload less. Each file loses names and IDs before a rival or its advisers read it.

How anonym.plus handles it

  1. Open the file (PDF, DOCX, or scan) in anonym.plus on your device.
  2. Local OCR reads scanned exhibits, so printed text is caught too.
  3. The tool flags names, emails, IDs, and account numbers.
  4. Check each flag and keep the deal terms that bidders need.
  5. Swap each value for a steady label, or black it out.
  6. Save the clean copy. The source never leaves your machine.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONEleanor Whitfield → [PERSON_1]
ContactEMAIL_ADDRESSe.whitfield@target.co.uk → [EMAIL]
IdentifiersUK_NINO / NATIONAL_IDQQ123456C → [ID]
FinanceIBAN_CODEGB29 NWBK 6016 → [ACCOUNT]
LocationLOCATION14 King's Road, Bristol → [ADDRESS]
DatesDATE_TIMEborn 03/11/1980 → [DATE]

Compliance achieved

Anonymise data room files offline — see plans & start free →

Limitations & cautions

True anonymity is a high bar. A rare mix of facts — a niche role plus a small site — can still re-identify after IDs go. Art. 28(3) terms govern your provider, not the residual risk in the text. Review that risk, and keep no re-link map before you treat the result as anonymous.

Frequently asked questions

When does a data room file fall outside UK GDPR?

When no one can reasonably re-identify the person. That means no kept key and low residual risk from the rest of the text. Only then does Recital 26 take it out of scope, and only then does DPA 2018 s.3(2) stop treating it as information about a living individual.

Does an Art. 28 contract with the room provider make anonymising pointless?

No. Art. 28(3) terms bind the provider, but they do not stop bidders and their advisers reading what you upload. Minimising what you upload first, as Art. 5(1)(c) asks, cuts the exposure that no contract can undo.

Can it read scanned exhibits?

Yes. Local OCR pulls text from scanned pages, so IDs in image files are caught.