Redaction-log de-identification is the removal of personal data from the record that lists each cut and its basis. CPR 31.19(3) is the closest formal analogue — a written statement of grounds — and courts increasingly expect the same discipline for content redactions, not only privilege claims. anonym.plus runs locally and keeps the reason given for every entry.
When this applies
This record lists each cut and why you made it, in the same spirit as the CPR 31.19(3) grounds statement for a withheld document. The description fields can themselves name people, including the reviewer, so the file needs cleaning before it is shared, without the log becoming so vague that a CPR 31.19(6)-style inspection would be needed just to understand your own record.
How anonym.plus handles it
- Load the log into anonym.plus on your device.
- It scans the description and basis columns.
- The tool flags names and contacts in each entry.
- Confirm the flags; keep the stated basis for each cut.
- Replace or mask the confirmed PII.
- Save the clean record on your device.
What you need to provide
- The log (XLSX, CSV, DOCX, or PDF).
- An operator; Mask for partial names in entries.
- Optional steady labels so one person maps to one alias.
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | redacted-party name → [NAME] |
| Document IDs | PERSON | page ref ABC-0099 → [DOC_ID] |
| Dates | DATE_TIME | entry date → [DATE] |
| Contact | EMAIL_ADDRESS | entry email → [EMAIL] |
| Identifiers | UK_NINO | NINO in basis → [NINO] |
| Names | PERSON | reviewer name → [REVIEWER] |
Compliance achieved
- Follows the same written-grounds discipline as CPR 31.19(3), even though this log tracks content cuts rather than a privilege claim.
- Keeps the basis for each cut so the file stays useful if a court ever needs to test it, the same way CPR 31.19(6) lets a court inspect a withheld document.
- Clears the reviewer's own name from the record, not only the redacted parties'.
- Offline work keeps the record inside your firm.
Anonymise redaction logs offline — see plans & start free →
Limitations & cautions
Each entry must still justify its cut. Mask names in the rows, but keep the stated basis, or the file loses its purpose. Confirm that masking does not make two different cuts look identical.
Frequently asked questions
Why de-identify the log itself?
Its description fields can name the very people you redacted, plus the reviewer. Cleaning the record keeps that PII from leaking when it is shared, while the grounds you stated — in the spirit of CPR 31.19(3) — stay intact.
Will it still justify each cut?
Yes. The stated basis for each entry stays. Only PII inside the rows is masked or replaced, so the record would still support a CPR 31.19(6)-style inspection if it were ever challenged.
Does it read spreadsheet versions?
Yes. XLSX and CSV files are supported, plus DOCX and PDF versions of the log.