Practical guide · GDPR

Document anonymisation in public administration

7 min readBy Ana Gloria Gómez Ruiz
Quick answer

What the GDPR, the Spanish data protection act and the National Security Framework require when publishing or sharing documents with personal data.

Councils, universities and public bodies constantly publish and share documents: council minutes, resolutions, grant files, notifications, transparency reports. Each may contain personal data of citizens, public employees or third parties, and anonymising them before publication is not an optional good practice: it follows from three overlapping legal frameworks.

1. What does transparency law require?

Spanish Law 19/2013 on transparency and access to public information requires administrations to proactively publish a significant volume of information (agreements, grants, contracts, salaries, resolutions). That duty clashes with the GDPR when the document contains personal data that is not necessary for the transparency purpose: the name of a citizen who filed an objection, an applicant identity number, the contact details of an affected third party.

The AEPD has fined administrations for publishing on transparency portals without anonymising citizens data — see concrete examples in our article on AEPD fines for failing to anonymise documents. The general criterion: active publicity must be limited to strictly necessary data, and any additional personal data must be removed or anonymised before publication.

2. What role does the National Security Framework play?

Royal Decree 311/2022, which governs the ENS, does not mention "anonymisation" as such, but sets a framework requiring information to be handled with measures proportional to its security category:

  • System categorisation (arts. 40 and 41): each system is classified as BASIC, MEDIUM or HIGH according to potential impact on availability, integrity, confidentiality, authenticity and traceability.
  • Audit by category (art. 38): MEDIUM or HIGH systems require certification audit; BASIC ones may self-assess. The anonymisation process — which tool is used, where files are processed, what traceability remains — can form part of the audit scope.
  • Application of the GDPR (art. 3): the ENS expressly refers to the GDPR and Spanish data protection law when the system processes personal data.
  • Statement of Applicability (art. 28): requires documenting which security measures apply and which compensatory measures replace those that do not, meaning the anonymisation process must be documentable, not just executed.

3. How does the Spanish data protection act fit with transparency?

Organic Law 3/2018 (LOPDGDD) clarified how transparency should be applied without breaching data protection, reinforcing that active publicity does not cover the disclosure of personal data unnecessary for the informational purpose. This directly affects minutes, resolutions and files published on transparency portals.

What does this mean day to day?

These three layers converge on one operational point: before a document with personal data leaves the organisation — published, sent to a requester, shared with another administration or fed into an AI system — someone must have verified that unnecessary personal data has genuinely been removed, not just covered, and that the process can be documented on request. The difference between removing and hiding is covered in how to anonymise a PDF step by step, and the legal distinction in anonymisation vs pseudonymisation.

This is exactly where manual processes fail at scale. See how we approach it in the Anonimizia use cases.

Frequently asked questions

Does every document a council publishes need anonymisation?

Not all, but any containing personal data not strictly necessary for the publication purpose. Minutes with citizen interventions, resolutions with applicant data or grant files with third-party data are the most common cases.

Does my ENS category affect how I must anonymise?

It affects how much you need to document and audit the process. The higher the category, the more the treatment is expected to be consistent, traceable and subject to review.

Does anonymising before publishing replace the legal basis for processing?

No. Anonymisation solves later publication or transfer, but the initial processing still needs its own legal basis under the GDPR.

Sources and references

Do you anonymise documents daily?

Stop redacting by hand. Automate it with anonimizia.

Upload your PDFs and get GDPR-compliant anonymised documents in seconds.

Try it free