Data Breach Notification Redaction with anonym.plus

Tell each affected person about a breach without exposing other victims' data.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

A breach notification is the message you send affected people under UK GDPR Art. 34 when a breach is likely to result in a high risk to their rights. It runs alongside, not instead of, the separate duty in Art. 33 to tell the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Before you send the individual notice, you strip PII that belongs to other victims. anonym.plus marks that data on your own device.

When this applies

A breach hits many people, and you must tell each one. A shared incident log or victim list names everyone, but each person should see only their own row.

How anonym.plus handles it

  1. Open the incident log in anonym.plus on your device.
  2. The tool flags every name, contact, and ID in the list.
  3. Keep the one person's data for their own notice.
  4. Mark all other victims' PII for removal.
  5. Black out or swap each one, then verify the notice.
  6. Save the per-person message on your machine.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONother victim → [PERSON]
ContactEMAIL_ADDRESSa.clarke@example.co.uk → [EMAIL]
AccountsCREDIT_CARDexposed card → [CARD]
IdentifiersNATIONAL_IDcustomer no. → [ID]
ContactPHONE_NUMBER07700 900188 → [PHONE]
LocationLOCATIONbilling address → [ADDRESS]

Compliance achieved

Anonymise breach notifications offline — see plans & start free →

Limitations & cautions

Art. 34 sets when and what to tell people, which is a legal judgment, and it is a different threshold and a different audience from the Art. 33 duty to tell the ICO. The tool flags PII so each notice stays specific; it does not decide if a breach is notifiable under either article. Confirm the threshold and content with your DPO, and report to the ICO where required.

Frequently asked questions

Why redact a breach notice at all?

A shared list names many victims. Sending it whole would itself disclose their PII to people it does not belong to. anonym.plus strips other rows so each person sees only their own notice.

How does Art. 34 differ from the 72-hour ICO rule?

Art. 33 requires telling the ICO without undue delay, and within 72 hours where feasible, for any breach with a risk to people's rights. Art. 34 is a higher bar: telling the affected people themselves, which only applies where the breach is likely to result in a high risk to them, and it has no fixed 72-hour clock.

Does it read a victim spreadsheet?

Yes. CSV and XLSX logs are scanned column by column, and a steady map keeps a person's rows together if you need them linked, which is common in a large incident export.

Could the tool cause a second breach?

No. It runs offline, so the log never leaves your device. That avoids the upload risk that a cloud service would add during an incident that is already under active response.