Redaction vs Anonymisation Before AI: Removing Names Does Not Automatically Make Data Anonymous
Published August 2026 by Solarc Labs
Redaction can reduce exposure without proving anonymity
Removing names, email addresses or account numbers can be useful data minimisation, but it does not by itself prove that the remaining document is anonymous. Free text can still contain job titles, events, locations, dates, relationships or unusual facts that make a person identifiable when combined with information already available to the recipient. The operational question is therefore not only “did we remove obvious identifiers?” It is “can a person still be identified, directly or indirectly, in the context in which this output will be used?” Treat that as a separate review decision rather than silently upgrading a redacted file to an anonymous-data label.
Pseudonymised information is still personal data
The ICO distinguishes anonymisation from pseudonymisation. Pseudonymisation replaces, removes or transforms identifying information while keeping additional information that can restore the link to a person. The ICO is explicit that pseudonymous information remains personal data and data protection law still applies. That matters for common document workflows. Replacing “Alice Smith” with “Employee 17” may reduce casual identification, but if your organisation retains the mapping or the surrounding facts make Employee 17 identifiable, the result should not be treated as anonymous merely because the visible name disappeared.
The 2026 EDPB anonymisation work makes this a current governance question
The European Data Protection Board published Guidelines 02/2026 on Anonymisation for public consultation on 8 July 2026, with feedback open until 30 October 2026. Because that text is consultation guidance rather than a final adopted rule, teams should not present draft language as settled law. The practical signal is still important: anonymisation is an active 2026 governance topic, especially for organisations reusing data in analytics and AI workflows. Build a review trail that records what was removed, what contextual identifiers remain, what additional information exists elsewhere and who approved the downstream use.
Before an AI upload, separate three decisions
First decide what information is necessary for the task and remove data that does not need to leave the source workflow. Second, review detected sensitive spans and the surrounding context rather than assuming automated entity detection found every identifying clue. Third, decide whether the output is merely reduced-risk personal data, pseudonymised data or information you can defensibly treat as anonymous for the intended recipient and context. Those are different claims. A privacy-preserving workflow is stronger when the export says what processing occurred and what it does not establish, rather than stamping every cleaned document “anonymous.”
PII Redaction Desk is a review workflow, not an anonymisation certificate
PII Redaction Desk is designed for candidate detection, mandatory human review and irreversible clean-text export. It can help remove reviewed sensitive spans before downstream AI or analysis, but it cannot guarantee that every person is non-identifiable from context, external datasets or information held separately. Use it as one control in a broader data-minimisation and privacy review. Do not represent a successful redaction run as legal clearance, formal anonymisation certification or proof that data protection obligations no longer apply.
Primary sources
Sources used for this article
Continue the job