Email Production Redaction with anonym.plus

Clear PII from email headers and threads before you disclose them.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Email-disclosure redaction is the removal of personal data from messages you disclose under CPR PD 31B. CPR 31.4's wide definition of a document reaches an email and its metadata equally. anonym.plus scans headers, bodies, and quoted threads on your device, so the message still reads in context.

When this applies

Email is the bulk of most disclosure exercises conducted under CPR PD 31B. Headers, signatures, and quoted replies repeat names and contacts, and under CPR 31.9 you need not separately disclose a copy that is identical in every material way to one already produced — so a clean, de-duplicated set is worth doing properly the first time.

How anonym.plus handles it

  1. Load the messages into anonym.plus on your device.
  2. It scans To, From, Cc, body, and quoted threads.
  3. The tool flags names, emails, phones, and signatures.
  4. Confirm the flags across the full thread.
  5. Replace or mask each confirmed value.
  6. Save the clean messages on your device.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONFrom: K. Bell → [SENDER]
ContactEMAIL_ADDRESSk.bell@corp.co.uk → [EMAIL]
ContactPHONE_NUMBERsig +44 20 7946 0199 → [PHONE]
DatesDATE_TIMESent 03/02 → [DATE]
LocationLOCATIONoffice address → [ADDRESS]
IdentifiersUK_NINONINO in body → [NINO]

Compliance achieved

Anonymise email disclosure offline — see plans & start free →

Limitations & cautions

Long threads repeat the same names many times. The tool catches each one, but check signature blocks and image footers, where OCR may miss faint text. A missed quoted reply can leak a name you meant to clear.

Frequently asked questions

Does it redact the whole thread, not just the top message?

Yes. It scans quoted replies and forwards too, so a name buried deep in a thread is flagged the same as one in the header — important given how CPR 31.4 treats an email and every quoted layer as part of the same document.

Can it read PST and MSG files?

Yes. Common mail formats are supported, plus PDF and DOCX exports of messages, whatever form the parties agreed for CPR PD 31B exchange.

Will the message still make sense after redaction?

Yes. Replace puts a steady label in place of each value, so the exchange still reads in context, and CPR 31.9 means you are not obliged to hand over an identical copy again once one clean version exists.