ESI Export De-Identification with anonym.plus

Clean a bulk data export — fields and free text — without leaving your network.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Export de-identification is the removal of personal data from electronically stored data before disclosure. Rule 31.4 defines a 'document' broadly enough to reach a database export, and Practice Direction 31B sets how a party searches and exchanges that material electronically. anonym.plus does the clearing pass on your own device, so nothing is uploaded before the parties even agree a search protocol.

When this applies

Before this exercise you scope a bulk export of thousands of records, often as part of an Extended Disclosure discussion in the Business and Property Courts. Sending that raw export to a cloud vendor before the parties settle on a search protocol is itself a privilege and confidentiality risk, and it pre-empts the proportionality assessment the rules ask the parties to make.

How anonym.plus handles it

  1. Point anonym.plus at the export folder on your server.
  2. It scans both ID columns and free-text fields.
  3. Steady labels keep links across joined rows intact.
  4. Review the summary and tune the column rules.
  5. Replace or mask the confirmed PII.
  6. Save the clean dataset on your device for review.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONcustodian field → [PERSON_n]
IdentifiersUK_NINOnino column → [NINO]
DatesDATE_TIMEsent_date → [DATE]
ContactEMAIL_ADDRESSfrom_email → [EMAIL]
LocationLOCATIONaddress fields → [ADDRESS]
Free textPERSON / LOCATIONinline names → labels

Compliance achieved

Anonymise data exports offline — see plans & start free →

Limitations & cautions

Bulk data mixes tidy columns with messy free text. Column rules handle the first well. Free-text fields need the same review as any note. Test a sample before a full run, and confirm joins still hold after the swap.

Frequently asked questions

What counts as electronically stored data here?

It means email, files, chat, and database records that fall within the wide definition of a 'document' — anything in which information is recorded, not only paper. A separate rule then sets how that electronic material is searched and exchanged.

Why de-identify before the conference?

Scoping needs counts and field coverage, not identities. A cleared export lets you share volume figures with the other side, or discuss an Extended Disclosure model, without exposing anyone's personal data first.

Can records stay linkable after the swap?

Yes. A steady label map swaps each ID the same way, so rows for one custodian still join while no real identity is left, which keeps the proportionality assessment meaningful.

Does it handle both CSV and document exports?

Yes. Tidy CSV or JSON columns and bundled files are both supported, whichever form the export takes as part of the disclosable material.