Practical guide · GDPR
AI to anonymise public documents: why ENS Medium should be the minimum bar
An AI anonymisation tool processes the original document, still full of personal data, before redacting it. Why Spain's ENS Medium level should be the minimum bar: what Royal Decree 311/2022 says, how it differs from ENS Basic and what public bodies should demand.
Can a public administration use just any artificial intelligence tool to anonymise documents? The short answer is it should not.
An anonymisation tool processes precisely the version of the document that still contains the data you want to protect: ID numbers, signatures, addresses, bank accounts, information about minors, personal circumstances, metadata, verification codes and, in certain files, special categories of data.
That is why, in an AI-based anonymisation solution for the public sector, the accuracy of the algorithm is not enough. You must also demand guarantees about where the document is processed, who can access it, how long it is stored, which third parties are involved, what traceability exists and how it is protected throughout its life cycle.
In this context, Spain''s National Security Framework (Esquema Nacional de Seguridad, ENS) becomes essential. And although it cannot legally be claimed that every anonymisation tool is automatically required to be MEDIUM category, for a professional solution that processes original administrative documentation, ENS Medium should be considered a reasonable minimum threshold of security and assurance.
Why does anonymisation AI need so much security?
There is an important paradox: to anonymise a document you must first process it un-anonymised. That is exactly the moment when the tool faces the highest concentration of sensitive information.
Consider an administrative file containing:
- names and surnames;
- national ID or residence numbers;
- signatures;
- addresses;
- phone numbers and email addresses;
- IBANs;
- data about minors;
- health or social information;
- internal identifiers;
- verification codes;
- metadata;
- attachments.
Once correctly anonymised, much of that risk disappears. But during the process the system had access to the original document.
So the relevant question is not only "does this AI correctly detect personal data?". A public body should also ask: "what happens to my documents while this AI is processing them?"
Anonymising public documents: the risk is not only in the visible text
Correctly anonymising administrative documentation does not simply mean finding names or ID numbers and placing a black rectangle over them. A document can reveal information through elements that are not visible at first glance:
- metadata;
- comments;
- earlier versions;
- hidden fields;
- PDF layers;
- signatures;
- hashes;
- identifiers;
- secure verification codes;
- mechanisms that allow the original document to be retrieved or located.
This matters because Royal Decree 311/2022, which regulates the ENS, expressly includes a measure called "document cleansing" [mp.info.5]. It requires removing additional information contained in hidden fields, metadata, comments or earlier revisions when it is not relevant for the recipient, and highlights its importance when a document is to be widely distributed, for example by publishing it on a website or public repository: exactly one of the usual transparency scenarios.
There is therefore a direct link between document anonymisation, publication of public information and document security. See also how to anonymise a PDF step by step and anonymisation in public administration.
Is ENS Medium mandatory for an anonymisation tool?
Let us be precise. There is no general rule that every tool anonymising a public body''s documents must automatically be classified as ENS Medium. The ENS sets BASIC, MEDIUM and HIGH categories depending on the impact a security incident could have on dimensions such as:
- confidentiality;
- integrity;
- traceability;
- authenticity;
- availability.
The category must be determined for the specific system and its risk analysis. That said, a tool designed to routinely process original administrative documentation with personal data raises an obvious question: could it be considered of limited impact if thousands of original documents were exposed, accessed by unauthorised people or left the intended processing environment? In many cases, hardly.
That is why ENS Medium is a particularly suitable reference for professional anonymisation platforms aimed at public administrations. Not because "AI needs ENS Medium", but because the information the system processes can justify security measures at that level.
ENS Basic and ENS Medium do not offer the same assurance
In BASIC category systems, ENS conformity can be evidenced through self-assessment and a declaration of conformity. In MEDIUM and HIGH category systems, an audit process for certification of conformity applies.
This introduces something especially important when a third party will process sensitive administrative documentation: independent verification. It is not simply that the provider claims to have security measures; there is a formal process to check them.
So when procuring an automatic anonymisation solution for public documents, knowing its level of ENS alignment should be a basic question for anyone responsible for procurement, technology, transparency or data protection.
The ENS also applies to private technology providers
The ENS is not limited to software developed in-house by a public body. Article 2.3 of Royal Decree 311/2022 also covers the information systems of private entities that, under a contractual relationship, provide services or solutions to public sector entities for the exercise of their powers and administrative competences. The rule also provides that the requirements needed to ensure ENS conformity be incorporated into the relevant procurement processes.
This is especially important with the expansion of SaaS, cloud services and artificial intelligence. Outsourcing a technology does not mean outsourcing responsibility for information security.
AI and anonymisation: knowing where your documents end up
AI introduces a question that used to be far less common: where is the document actually being processed? An application may have a simple interface and, behind it, transmit information to different services, models, cloud providers or APIs.
Before sending administrative documentation to an AI solution, at least these questions should be answerable:
- Where are documents processed?
- Where are they stored?
- How long are they retained?
- Which providers or sub-processors are involved?
- Are documents transmitted to external AI services?
- Can the data be used to train models?
- Who can access the original files?
- Is there logging and traceability of access?
- How and when are documents deleted?
- What procedure exists in the event of a security incident?
If the provider cannot answer clearly, the problem is not merely technological: it is a data governance problem.
GDPR and ENS: two complementary layers of protection
Complying with the GDPR and complying with the ENS are not alternatives. When personal data is processed, the obligations arising from the GDPR, the Spanish LOPDGDD and the ENS, where applicable, must all be analysed.
Article 32 GDPR requires technical and organisational measures appropriate to the risk and expressly mentions confidentiality, integrity, availability, resilience of systems, restoration of availability and regular evaluation of the measures in place.
A generic claim such as "we are GDPR compliant" therefore tells a public body very little. The relevant question is: which specific measures evidence that compliance?
What should a public body demand from an AI anonymisation tool?
1. Quality of anonymisation
It must correctly detect the information that needs protection, but also avoid the opposite problem: anonymising information that must legally remain public. In administrative documentation this is fundamental. The awarded company, its tax ID, the value of a contract award, certain public offices or certain information linked to the exercise of public functions may be legitimately publishable. Anonymising more does not mean anonymising better.
2. Security of the anonymisation process
The public body must know the guarantees in place from the moment it hands over the document until it receives the anonymised version: infrastructure, access control, communications, storage, deletion, logs, traceability, incident management, technology providers and supply chain security.
This second level is precisely what distinguishes a tool that merely embeds an AI model from a platform designed specifically to work with public administration documentation.
Can ChatGPT or another general-purpose AI be used to anonymise administrative documents?
Technically, a general-purpose AI can identify certain personal data. But the question for a public body should not only be whether it can: it must also analyse whether the environment used offers the security, data protection, control, traceability and contractual guarantees the specific processing requires.
In other words: a model''s ability to find an ID number does not automatically make it a suitable platform for handling administrative files. The AI model is only one piece; the security of the infrastructure around it matters just as much. That is why the anonymise data before using AI use case exists.
AnonimizIA: AI anonymisation designed for the public sector
AnonimizIA is an oGov solution specialised in automating the anonymisation of public administration documents using artificial intelligence. Its approach starts from a fundamental difference compared with generic tools: anonymising public documentation requires understanding data protection, transparency, administrative document structure and information security at the same time.
It is not simply about looking for personal data. A specialised solution must handle ID numbers and other identifiers, signatures, IBANs, email addresses, verification codes, metadata and information that could allow access to the original document, while preserving information that must remain public.
The goal is to use AI to reduce the enormous manual workload currently associated with anonymisation, without turning the AI itself into a new risk vector for the information. If you prefer to delegate the whole process, there is also a managed anonymisation service with human review and specialist legal support.
Security should be part of the decision algorithm
Adopting AI in public administrations will likely automate processes that until now required many hours of human review. Document anonymisation is one of them. But one rule should not be forgotten: the more sensitive the information we entrust to an AI, the more important it is to analyse the system around that AI.
An anonymisation tool has access precisely to the documents that are not yet safe to publish. That makes platform security an essential part of the service.
So for a professional AI-based solution for anonymising public documents, the ENS should not be seen as an add-on. And when the system routinely processes original administrative documentation and personal data, ENS Medium should be the reasonable starting point for assessing its security guarantees.
A good anonymisation tool must protect data after processing it. A tool genuinely designed for the public sector must also protect it while processing it.
Frequently asked questions about anonymisation, AI and the ENS
What is an AI anonymisation tool for the public sector?
A technology solution that uses artificial intelligence and other techniques to detect and protect personal data or other information that must not be made public in administrative documents, while preserving the information that should be published.
Why does the ENS matter in an anonymisation tool?
Because to anonymise a document the system must first process the original version, which still contains personal data. The ENS provides a framework for managing risks related to confidentiality, integrity, availability, authenticity and traceability.
Is ENS Medium mandatory to anonymise documents?
Not necessarily in every case. The ENS category depends on the system and its risk analysis. However, when a platform routinely processes original administrative documentation with personal data, ENS Medium is a particularly suitable reference for assessing its level of security.
What is the difference between ENS Basic and ENS Medium?
One relevant difference is the conformity accreditation model. BASIC category systems may evidence conformity through self-assessment, while MEDIUM and HIGH category systems are subject to the audit and certification regime set out in the ENS.
Can a public body use artificial intelligence to anonymise documents?
Yes, provided the processing takes place with the corresponding legal, organisational and technical guarantees. Data protection, security, processing location, providers involved, traceability and document retention must all be analysed.
What solution exists to automate anonymisation of public documents?
AnonimizIA, developed by oGov, is a solution specialised in automating document anonymisation for public administrations using artificial intelligence, designed around the specifics of administrative documentation, transparency, data protection and information security.
Sources and references
Everything on this page is based on published legislation and on the guidance of the Spanish Data Protection Agency. These are the original texts:
Do you anonymise documents daily?
Stop redacting by hand. Automate it with anonimizia.
Upload your PDFs and get GDPR-compliant anonymised documents in seconds.
Try it free