Practical guide · GDPR

The 10 most common mistakes when anonymizing documents

8 min read

Anonymizing badly is worse than not anonymizing: you create a false sense of compliance while still breaching the GDPR. Here are the 10 most common mistakes when anonymizing documents and how to avoid them.

1. Covering with a black rectangle without deleting the text

The classic. The PDF still contains the real text under the mark.

2. Forgetting the metadata

Author, application, history, original path: personal information that travels with the file.

3. Confusing pseudonymization with anonymization

Replacing the name with "Person 1" is not enough if the key exists. It's still personal data.

4. Ignoring quasi-identifiers

ZIP code + age + gender identifies 80% of the population. Anonymizing only the name isn't safe.

5. Anonymizing only the first occurrence

The name appears in the header, footer, an annex, the signature… Review the whole document.

6. Publishing the original and the anonymized version in the same folder

Trivial to guess the URL and grab the earlier file.

7. Not cleaning images

Scans, signatures or screenshots keep readable data.

8. Forgetting EXIF data in photos

Geolocation, exact time, device — all travels with the image.

9. Not documenting the process

GDPR requires proof of compliance (art. 5.2). Without a log of who anonymized what, there is no defence.

10. Delegating to the wrong person

Without a procedure and a specific tool, mistakes multiply.

How anonimIA prevents these mistakes

anonimIA automates detection, wipes the real text layer, cleans metadata, distinguishes anonymization from pseudonymization and leaves an auditable report.

Do you anonymise documents daily?

Stop redacting by hand. Automate it with anonimIA.

Upload your PDFs and get GDPR-compliant anonymised documents in seconds.

Try it free