Subject Access Request Redaction with anonym.plus

Clear other people's details from a SAR reply before you send it.

A subject access request reply is the package you give a person who exercises the right of access under UK GDPR Art. 15. Before you disclose it, you strip PII that belongs to other people. anonym.plus marks those details on your own device.

When this applies

An individual asks what information you hold on them. The export pulls logs and tickets that also name other customers and staff.

How anonym.plus handles it

  1. Open the export in anonym.plus on your device.
  2. The tool flags names, emails, phones, and account IDs.
  3. Keep the requesting person's own records intact.
  4. Mark every other person's PII for removal.
  5. Swap or black out each flagged item.
  6. Save the clean export on your machine.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONother customer → [PERSON]
ContactEMAIL_ADDRESSk.byrne@example.co.uk → [EMAIL]
AccountsCREDIT_CARD4111 1111 ... → [CARD]
IdentifiersUK_NINOQQ 12 34 56 C → [NINO]
ContactPHONE_NUMBER0161 496 0123 → [PHONE]
LocationLOCATIONdelivery address → [ADDRESS]

Compliance achieved

Anonymise subject access replies offline — see plans & start free →

Limitations & cautions

The tool flags PII; you decide what to share. A SAR gives a person their own records, not other people's. Sensitive fields like a full card or National Insurance number may need extra masking under other rules. Review each flag first.

Frequently asked questions

Whose details go into a SAR reply?

Only the requesting person's personal data. Strip anything tied to other people or staff. anonym.plus flags both so you can keep one and remove the rest.

Does it work on a bulk CSV export?

Yes. Tidy columns and free-text fields are both scanned, and a steady label map keeps rows for one person joinable after the swap.

Is anything sent to the cloud?

No. Work is local. The export stays on your device, which removes the breach risk of uploading raw personal data.