Practical guide · GDPR

10 Requirements for Hiring an AI Anonymisation Tool in the Public Sector | 2026 Guide

10 min readBy Ana Gloria Gómez Ruiz
Quick answer

A practical guide to the 10 legal and technical requirements public bodies should check before procuring an AI anonymisation tool: GDPR, ENS, traceability, no training, metadata and human review.

What should a public body check before procuring an AI anonymisation tool?

Choosing an AI anonymisation tool is not just about checking whether it finds names or ID numbers. The solution will receive documents before they are anonymised, so the public body must also evaluate data protection, security, storage, third parties and traceability.

These are the ten basic requirements that should be reviewed before contracting.

1. A clearly regulated data processor

What to ask for

If the provider processes documents on behalf of the public body, Article 28 GDPR must be analysed. The data processor agreement should regulate purpose, duration, instructions, security obligations and the list of subprocessors.

2. Use limited exclusively to anonymisation

What to ask for

The provider should not reuse documents for purposes incompatible with the contracted service. A clear clause limiting processing to the provision of the service should be required.

3. Documents are not used to train models

What to ask for

The public body must know expressly whether its documents may be used for training or improving systems. A contractual no-training guarantee and absence of reuse should be required.

4. Clear storage and deletion policy

What to ask for

"No training" does not mean "no storage". It is necessary to know how long the document remains, what happens to temporary copies, logs and backups, and when it is finally deleted.

5. Control of external APIs and subprocessors

What to ask for

It must be known whether documents leave the platform to be processed by other models or providers. The service architecture and the full list of subprocessors should be requested.

6. Data processing and location

What to ask for

The public body must know where documents are processed and stored and whether there are international transfers. The location of servers, cloud providers and support teams should be requested.

7. Demonstrable ENS compliance

What to ask for

For solutions aimed at the Spanish public sector, the National Security Scheme must be analysed. It is not enough to claim to be "aligned with ENS". A declaration or certificate of conformity, category, scope and validity should be requested.

8. Traceability of every operation

What to ask for

Anonymisation should not be a black box. The public body should be able to know who processed the document, when and what action was taken. An operations log and data governance certificate should be requested.

9. Real data deletion, not just visual hiding

What to ask for

Painting a black rectangle over an ID number does not guarantee that the text has disappeared from the file. Metadata, hidden fields, comments, signatures and codes that may reveal information must also be analysed.

10. Specialisation in administrative documents

What to ask for

Anonymising more does not mean anonymising better. A public-sector solution must distinguish between information that must be protected and data that should legitimately remain public, such as certain public offices, awardee companies, VAT numbers or contract amounts.

The question that summarises the whole procurement

Before choosing a provider, a public body should be able to answer:

Can I demonstrate what happens to my documents from the moment they enter the system until they leave anonymised?

If the answer depends solely on trusting claims such as "private AI", "secure" or "GDPR-compliant", safeguards are missing. A professional solution should combine data protection, secure architecture, no reuse, storage control, ENS and traceability.

How does AnonimizIA address these requirements?

AnonimizIA is designed specifically for the anonymisation of administrative documents. According to the public information of the service, the models run on servers in the European Union without sending documents to external APIs. oGov holds ENS category Medium certification and the infrastructure used has ENS High certification. Managed anonymisation service.

The solution also includes traceability of operations, data governance certificate, configurable rules, human review and handling of elements such as metadata. The fundamental difference is simple: a generic AI may find personal data; a public-sector anonymisation solution must also be able to demonstrate how it protects it. To learn more about the software, see the More about the software.

Frequently asked questions

Is ENS mandatory for an anonymisation tool?

Not always, but for the Spanish public sector the National Security Scheme is a mandatory reference framework for many public bodies. The key is to require a declaration or certificate of conformity with category, scope and validity, not to settle for generic claims of being "aligned with ENS".

Can a general-purpose AI meet these ten requirements?

It should not be assumed. A general-purpose AI may lack a data processor agreement, use uncontrolled subprocessors, store documents to improve models or process outside the EU. That is why each requirement should be checked explicitly.

What is the difference between visually hiding data and anonymising it?

Painting a black rectangle over an ID number does not guarantee that the text has disappeared from the file. Real anonymisation removes the data from the delivered document and cleans metadata, hidden fields, comments and other layers that may still reveal information.

Where can I try AnonimizIA?

You can request a free trial from the registration page, with no credit card required.

Sources and references

Do you anonymise documents daily?

Stop redacting by hand. Automate it with anonimizia.

Upload your PDFs and get GDPR-compliant anonymised documents in seconds.

Try it free