A regulatory disclosure is the package you file with a supervisor or regulator. Where personal data is not needed, UK GDPR Recital 26 lets you anonymise it so the filing holds no PII. The confidentiality obligation usually runs the other way too: where the regulator is the FCA or PRA, s.348 of the Financial Services and Markets Act 2000 restricts what confidential information they may pass on, but that gateway protects what the regulator does with the filing after receipt, not what your firm should send in the first place. anonym.plus marks the unneeded personal data on your own device.
When this applies
A regulator asks for evidence. Your filing quotes emails and logs that name customers and staff who are not the subject of the inquiry.
How anonym.plus handles it
- Open the filing in anonym.plus on your device.
- The tool flags names, contacts, and IDs in the evidence.
- Keep the facts and figures the regulator needs.
- Mark personal PII that is not required for removal.
- Swap or black out each one, then review the file.
- Save the cleared filing on your machine.
What you need to provide
- The filing (PDF, DOCX, CSV, or document bundle).
- An operator: Replace keeps the evidence readable.
- Optional allow-list for data the regulator requires.
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | customer name → [PERSON] |
| Contact | EMAIL_ADDRESS | staff email → [EMAIL] |
| Identifiers | NATIONAL_ID | account ref → [ID] |
| Contact | PHONE_NUMBER | contact number → [PHONE] |
| Location | LOCATION | branch address → [ADDRESS] |
| Accounts | UK_BANK | sort 20-00-00 ... → [ACCOUNT] |
Compliance achieved
- Anonymisation under UK GDPR Recital 26 removes PII not needed.
- Reduces what you send in the first place, ahead of any onward FSMA 2000 s.348 confidentiality gateway the regulator itself operates.
- Keeps the facts and figures the regulator asked for.
- Offline work keeps the evidence inside your firm.
- 340+ entity types cover IDs, accounts, and contacts.
Anonymise regulatory disclosures offline — see plans & start free →
Limitations & cautions
Some filings must keep certain personal data by law. What you may anonymise is a legal judgment. The tool flags PII but cannot tell which fields the regulator requires. FSMA 2000 s.348 governs the FCA/PRA's own onward disclosure of what you send them, not your own duty to redact before sending. Confirm the scope before you redact.
Frequently asked questions
Can I anonymise a regulator filing?
Where personal data is not needed, yes. Recital 26 takes truly anonymous data out of scope. Keep any data the regulator requires via an allow-list, since a filing missing a required field is no better than an unredacted one.
Does the regulator's own confidentiality duty change what I should send?
Not directly. Where the FCA or PRA is the recipient, FSMA 2000 s.348 restricts how they may pass on confidential information they receive — it protects the filing after it arrives, not before. Minimising personal data before you file is still the firm's own job.
Will the evidence still make sense?
Yes. Replace swaps each ID for a steady label, so the facts, figures, and timeline still read clearly without naming people.
Is the filing uploaded anywhere?
No. The app runs offline, so the evidence stays on your device until you submit it yourself through the regulator's own channel.