A breach notification is the message you send affected people under UK GDPR Art. 34 when a breach is likely to result in a high risk to their rights. It runs alongside, not instead of, the separate duty in Art. 33 to tell the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Before you send the individual notice, you strip PII that belongs to other victims. anonym.plus marks that data on your own device.
When this applies
A breach hits many people, and you must tell each one. A shared incident log or victim list names everyone, but each person should see only their own row.
How anonym.plus handles it
- Open the incident log in anonym.plus on your device.
- The tool flags every name, contact, and ID in the list.
- Keep the one person's data for their own notice.
- Mark all other victims' PII for removal.
- Black out or swap each one, then verify the notice.
- Save the per-person message on your machine.
What you need to provide
- The incident log or victim list (CSV, XLSX, PDF, or DOCX).
- An operator: Redact to remove other victims' details.
- Optional per-recipient allow-list for their own data.
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | other victim → [PERSON] |
| Contact | EMAIL_ADDRESS | a.clarke@example.co.uk → [EMAIL] |
| Accounts | CREDIT_CARD | exposed card → [CARD] |
| Identifiers | NATIONAL_ID | customer no. → [ID] |
| Contact | PHONE_NUMBER | 07700 900188 → [PHONE] |
| Location | LOCATION | billing address → [ADDRESS] |
Compliance achieved
- Supports lawful victim notices under UK GDPR Art. 34.
- Keeps working files ready alongside the separate 72-hour UK GDPR Art. 33 notice duty to the ICO.
- Stops one notice from leaking another victim's PII.
- Offline work avoids a second exposure during the response.
- Reads CSV and spreadsheet logs as well as documents.
Anonymise breach notifications offline — see plans & start free →
Limitations & cautions
Art. 34 sets when and what to tell people, which is a legal judgment, and it is a different threshold and a different audience from the Art. 33 duty to tell the ICO. The tool flags PII so each notice stays specific; it does not decide if a breach is notifiable under either article. Confirm the threshold and content with your DPO, and report to the ICO where required.
Frequently asked questions
Why redact a breach notice at all?
A shared list names many victims. Sending it whole would itself disclose their PII to people it does not belong to. anonym.plus strips other rows so each person sees only their own notice.
How does Art. 34 differ from the 72-hour ICO rule?
Art. 33 requires telling the ICO without undue delay, and within 72 hours where feasible, for any breach with a risk to people's rights. Art. 34 is a higher bar: telling the affected people themselves, which only applies where the breach is likely to result in a high risk to them, and it has no fixed 72-hour clock.
Does it read a victim spreadsheet?
Yes. CSV and XLSX logs are scanned column by column, and a steady map keeps a person's rows together if you need them linked, which is common in a large incident export.
Could the tool cause a second breach?
No. It runs offline, so the log never leaves your device. That avoids the upload risk that a cloud service would add during an incident that is already under active response.