Structured Data Production De-Identification with anonym.plus

Turn a database export into an anonymous file that sits outside UK GDPR scope.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Structured-data de-identification is the removal of personal details from a database export so it is no longer personal data under UK GDPR Recital 26. CPR 31.4's wide document definition means such an export is disclosable material in the first place, and UK GDPR Art. 4(5) keeps a pseudonymised version — one still holding a re-linking key — inside the regulation's scope. anonym.plus does this on a local device, keeping the column structure.

When this applies

Disclosure may include a database export with thousands of rows, itself a 'document' within CPR 31.4's broad definition. Once it is truly anonymous under the Recital 26 test, it falls outside UK GDPR for any second use; if you keep a reversible key instead, Art. 4(5) means it stays personal data and stays in scope.

How anonym.plus handles it

  1. Point anonym.plus at the export on your device.
  2. It maps ID fields and free-text values.
  3. The tool flags names, IDs, and contacts per field.
  4. Swap them with the reversible map turned off.
  5. Confirm no re-link key is left behind.
  6. Save the anonymous dataset on your device.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONname field → [PERSON_n]
IdentifiersUK_NINOnino field → [NINO]
ContactEMAIL_ADDRESSemail field → [EMAIL]
DatesDATE_TIMEdob field → [DOB]
LocationLOCATIONaddress field → [ADDRESS]
AccountUK_SORT_CODEsort_code field → [SORT_CODE]

Compliance achieved

Anonymise structured datasets offline — see plans & start free →

Limitations & cautions

True anonymity is a high bar. A unique row, like one rare value in a small group, can re-identify even after direct IDs go. If you keep a reversible key, the data is pseudonymous and stays in scope. Weigh the residual risk first.

Frequently asked questions

When is a structured export truly anonymous?

When no one can reasonably re-identify any row — no kept key, and low risk from rare value combinations. Only then does Recital 26 take it out of UK GDPR scope.

Anonymous or pseudonymous — what is the difference?

Pseudonymous output keeps a key that can re-link rows, so UK GDPR Art. 4(5) keeps it as personal data. Anonymous output drops that key for good, which is the higher bar Recital 26 actually asks for.

Does it read SQL dumps?

Yes. CSV, JSON, and SQL exports are supported, with a field map for known IDs, all treated as disclosable material under CPR 31.4 until the anonymisation pass is done.