Production Metadata Scrub with anonym.plus

Clear PII from hidden property fields before a file leaves your firm.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Metadata scrubbing is the removal of personal data from the buried properties of files in the form produced under CPR PD 31B. CPR 31.10's disclosure statement also asks you to describe the extent of your search, including where electronic documents and their metadata are held. anonym.plus runs locally and clears author, editor, and path fields you cannot see.

When this applies

A clean-looking file can still carry the author name, edit history, and a path full of usernames in its properties, all of which sits inside the scope your CPR 31.10 disclosure statement is meant to describe honestly. That buried layer leaks when you hand the file over, even though the visible text looks fine.

How anonym.plus handles it

  1. Load the files into anonym.plus on your device.
  2. It reads document properties and buried fields.
  3. The tool flags author, editor, path, and comment data.
  4. Confirm the flags in the property layer.
  5. Strip or replace each confirmed field.
  6. Save the scrubbed files on your device.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONAuthor property → [NAME]
NamesPERSONLast edited by → [EDITOR]
LocationLOCATIONfile path C:\Users\jbrown → [PATH]
ContactEMAIL_ADDRESScompany email → [EMAIL]
DatesDATE_TIMEcreated date → [DATE]
IdentifiersPERSONusername token → [USER]

Compliance achieved

Anonymise file metadata offline — see plans & start free →

Limitations & cautions

Buried fields vary by file type and app. Some, like custom XMP tags, may need a specific profile to catch. Always open one scrubbed file and check its properties before a full run, so no field slips through.

Frequently asked questions

Why scrub buried file properties?

Files carry author, editor, and path data that leak names and usernames once produced. CPR PD 31B lets parties agree the form of the export, and a scrubbed static form is one accepted way to meet it.

What fields get cleared?

Author, last-edited-by, created and modified dates, file paths, comments, and custom properties, depending on your profile — the same buried layer your CPR 31.10 disclosure statement should account for.

Does it touch the visible content?

No. Scrubbing targets the buried metadata layer. The visible text and layout stay the same, so the document still reads as the one your disclosure statement describes.