Practical guide · GDPR

Can a public administration use a general-purpose AI to anonymise documents? | GDPR and ENS

8 min readBy Ana Gloria Gómez Ruiz
Quick answer

Uploading a document containing personal data to an AI tool is already processing under the GDPR. We analyse the legal and technical requirements (Art. 5, Art. 28, ENS) that must exist before anonymisation.

Can a public administration use a general-purpose AI to anonymise documents?

A public administration should not feed documents containing personal data into a general-purpose AI simply because it is capable of anonymising them. Uploading the original document already constitutes processing of personal data, so the legal and technical safeguards must exist before the AI removes a single data point.

That is the main risk that is usually overlooked.

The problem starts before anonymisation

To anonymise a file, the AI must first access the version that still contains the personal data.

ID numbers, signatures, addresses, email addresses, IBANs, information about minors or especially sensitive data may enter the system before the anonymised version is produced.

Article 4.2 GDPR considers operations such as consultation, use, storage or transmission of personal data to be processing. Therefore, uploading a document to an AI tool is already processing.

The fact that the final output is properly anonymised does not remove the obligations that existed during the processing.

Asking whether the AI "is GDPR compliant" is not enough

Before using an AI with administrative documents, the administration should be able to answer at least these questions:

  • Where is the document processed?
  • Is it stored, and for how long?
  • Is it used to train or improve models?
  • Is it shared with other providers?
  • Are there sub-processors?
  • Can international transfers take place?
  • Who can access it?
  • What happens to the files after processing?

These questions derive directly from Article 5 GDPR principles such as purpose limitation, data minimisation, storage limitation, and integrity and confidentiality.

The provider may become a data processor

When a third party processes documents on behalf of an administration, Article 28 GDPR normally needs to be considered. The administration must use providers offering sufficient guarantees and regulate matters such as: purpose, duration of processing, instructions, security, confidentiality, sub-processors and deletion of the data.

That is why accepting an application's general terms is not necessarily sufficient to upload real administrative files. The administration needs to know exactly under what conditions the provider processes that information.

"We don't use your data for training" matters, but it is not enough

A no-training guarantee is highly relevant, but it only addresses part of the problem. A tool may not train models with the documents and yet still: store them, generate logs, make backups, transmit them to sub-processors or process them outside the originally intended environment.

That is why training, storage, reuse, third parties, location and deletion must be analysed separately.

In data protection, a marketing label is no substitute for technical or contractual evidence.

In the public sector, the ENS also comes into play

In Spain, the analysis does not end with the GDPR. Royal Decree 311/2022 extends the National Security Framework (Esquema Nacional de Seguridad, ENS) to certain systems of private providers that deliver services or solutions to the public sector.

When a solution is going to process original administrative documents on a recurring basis, ENS certification and the security level achieved should form part of the purchasing decision.

Not every tool automatically has to be ENS Medium: the category depends on the risk analysis. But there is a relevant difference: MEDIUM and HIGH category systems require an audit for their conformity certification, whereas BASIC can be evidenced through self-assessment.

A safer architecture: anonymise before using a general-purpose AI

In many cases there is an alternative more consistent with the data minimisation principle:

original document → specialised anonymisation solution → anonymised document → generative AI.

If an AI only needs to summarise a contract, classify a file or extract certain information, it probably does not need to know the ID number, address, signature or bank account of the people appearing in it. Anonymising first reduces the amount of personal information exposed to subsequent tools.

For more detail on this distinction, see our guide on anonymisation vs pseudonymisation and on how to anonymise a PDF step by step.

What kind of solution should an administration use?

An administration should prioritise a solution specifically designed for document anonymisation that can evidence: processing limited to the purpose, control over storage and third parties, no reuse for training, security, traceability and ENS compliance where applicable.

The ability to find an ID number is only part of the problem. The really important question is what happens to that ID number before it is removed.

AnonimizIA: anonymisation designed for the public sector

AnonimizIA, developed by oGov, is specifically designed to work with administrative documentation. Its approach combines AI-based anonymisation with security, traceability and data governance guarantees.

According to the service's public information, the models run on servers in the European Union without sending documents to external APIs, oGov holds ENS MEDIUM certification and the infrastructure used holds ENS HIGH. The platform also includes operation logging and a data governance certificate.

Because for an administration it is not enough that the final document is anonymised. It must also be able to trust everything that happens before obtaining it.

Frequently asked questions

Is uploading a document to an AI tool personal data processing?

Yes, when it contains personal data. Consulting, transmitting or using the document already constitutes processing under the GDPR.

Can an administration use ChatGPT, Gemini or Copilot to anonymise?

There is no general per-product prohibition. The specific modality used must be analysed, along with its guarantees on purpose, storage, training, sub-processors, location, security and contractual relationship.

What must an AI for public-sector anonymisation provide?

It must offer verifiable guarantees of data protection, security, third-party control, purpose limitation, traceability and ENS compliance where applicable.

Do you anonymise documents daily?

Stop redacting by hand. Automate it with anonimizia.

Upload your PDFs and get GDPR-compliant anonymised documents in seconds.

Try it free