Practical guide · GDPR
Sector guide to anonymisation: healthcare, education and law firms
Which data to remove in each sector, which rules apply and what to require from your provider in healthcare, education and legal practice.
Anonymisation does not mean the same thing in a hospital, a university and a law firm. The critical data, the legal basis and the risk level all change.
Healthcare
Critical data: names, clinical record number, social security and health card numbers, diagnoses, medication, admission and discharge dates, responsible clinician, and medical images with embedded identifiers.
Health data is a special category under Article 9 GDPR. A rare diagnosis combined with age and town can re-identify a patient even after the name is removed. Generalise dates of birth to year, group rare diagnosis codes, tokenise record numbers when traceability is needed, and check DICOM headers as well as text.
Education
Critical data: student and family names, ID numbers, file numbers, grades, guidance reports, special educational needs, grant and socio-economic data.
Most students are minors and many documents are published on boards or portals. Publish lists with the name plus four digits of the ID number, never the full number, keep guidance reports out of publishable files, and review scanned annexes sent by families.
Law firms and legal departments
Critical data: parties, witnesses, minors, addresses, bank accounts, amounts, case numbers and health data submitted as evidence.
Filings are shared with clients, experts and insurers, and each transfer is a disclosure. Anonymise before uploading anything to an external AI tool, use reversible pseudonymisation to rebuild the file internally, and keep allowlists with court and body names so they are not redacted by mistake.
Common to all three
- Metadata travels with the file: author, comments, revisions.
- Human review before delivery — responsibility is not delegated to software.
- Traceability of what was processed, when and under which rules.
- Data must stay in a controlled environment: encrypted in transit and at rest, never used to train models.
If you are a public body
Provider compliance with the Spanish National Security Framework (ENS, Royal Decree 311/2022) is indispensable. oGov holds ENS Medium, deployment servers hold ENS High, plus a data governance certificate and an auditable processing log.
Do you anonymise documents daily?
Stop redacting by hand. Automate it with anonimizia.
Upload your PDFs and get GDPR-compliant anonymised documents in seconds.
Try it free