Practical guide · GDPR
Document anonymisation: 15 frequently asked questions
Direct answers to the most common questions about anonymising documents: what counts as valid redaction, metadata, ID numbers and what to demand from your provider.
These are the questions privacy officers, clerks and law firms ask most often before publishing or sharing documents that contain personal data.
Basics
What does anonymising a document mean?
Irreversibly removing the data that identify a person (name, ID number, address, phone, email, bank account, licence plate, health data), so the delivered file no longer contains that data and it cannot be recovered.
Is anonymisation the same as pseudonymisation?
No. Pseudonymisation replaces the value with a code, token or synthetic value and can be reversed with separately stored information. Under the GDPR pseudonymised data is still personal data.
Is a black rectangle over the text enough?
No. A shape drawn on top leaves the text selectable underneath and the metadata untouched. The content must be removed from the file itself.
What about flattening the PDF into an image?
It makes copy and paste harder, but the data is still visible and the document stops being accessible. It is not a substitute for real removal.
Common mistakes
- Metadata: author, revisions, comments and file paths.
- Headers, footers and registry stamps.
- Scanned annexes, which need OCR before detection works.
- File names containing an ID number or surname.
- Indirect identifiers: a unique role in a small town identifies the person.
Process and control
Is human review still needed?
Yes. Automatic detection speeds the work up, but responsibility for publication stays with the organisation, so review before download matters.
Can documents be processed in bulk?
Yes: batch processing, review and download is the normal workflow for procurement files, grants and minutes.
What is logged?
Which document was processed, when and under which rules, so diligence can be evidenced if a complaint arrives.
Provider requirements
What should public bodies require?
Compliance with the Spanish National Security Framework (ENS, Royal Decree 311/2022). For Spanish public sector systems this is mandatory, not optional. oGov holds ENS Medium and the deployment servers ENS High.
Why does a data governance certificate matter?
It evidences rules on who accesses data, where it is stored and for how long — the life cycle you must be able to document.
Are documents used to train models?
Not in anonimizia. Files are processed to return the anonymised document, encrypted in transit and at rest with an auditable log, and are not used to train third-party models. Ask any free tool the same question before uploading a case file.
Can I define my own rules and allowlists?
Yes. Terms that must not be redacted can be protected, and the categories removed can be tuned per document type.
Which formats are supported?
PDF, Word, Excel, ODT, images and scanned documents via OCR.
Sources and references
Everything on this page is based on published legislation and on the guidance of the Spanish Data Protection Agency. These are the original texts:
Do you anonymise documents daily?
Stop redacting by hand. Automate it with anonimizia.
Upload your PDFs and get GDPR-compliant anonymised documents in seconds.
Try it free