Practical guide · GDPR

What personal data to remove before publishing a document

8 min read

Before you publish a document on a transparency portal, in an official gazette or share it with third parties, you must anonymize every piece of personal data — not just the name. This guide lists which categories to remove and why they qualify as personal data under the GDPR.

Direct identifiers

  • Full name.
  • National IDs, passport and equivalent documents.
  • Social Security or health-insurance number.
  • Email address and phone number.
  • Full postal address.
  • Handwritten and visible digital signatures.
  • Photograph or image that identifies the person.

Financial and property identifiers

  • Bank account (IBAN, SWIFT).
  • Card numbers and payment codes.
  • Cadastral references and registry data linked to a person.
  • License plates and VINs.

Quasi-identifiers (the ones people forget)

Combined, they can identify someone even if the name is anonymized:

  • Exact date of birth.
  • ZIP code + gender + age.
  • A rare job title in a small organisation.
  • Disability or rare disease.
  • School, medical centre or parish.

Special category data (GDPR art. 9)

  • Health data and clinical reports.
  • Racial or ethnic origin.
  • Political, trade union, religious or philosophical views.
  • Genetic and biometric data.
  • Sexual orientation and sex life.
  • Criminal records and judicial data.

Technical data and metadata

  • Author and applications used.
  • System paths, network names and users.
  • IPs, MAC addresses and cookies.
  • Comments and tracked changes.
  • EXIF geolocation in images.

Data on minors and vulnerable groups

These need extra care. Anonymize anything that could identify minors, violence victims, irregular migrants or patients.

Pre-publish checklist

  1. Go through the document marking every item in the categories above.
  2. Anonymize direct identifiers and assess the risk of quasi-identifiers.
  3. Strip metadata and comments.
  4. Check attachments, images and links.
  5. Log the process to be able to prove it (GDPR art. 5.2).

How anonimIA automates it

anonimIA recognises all these categories with AI trained on Iberian administrative vocabulary and anonymizes them automatically, with a full audit trail of what was removed and who reviewed it.

Do you anonymise documents daily?

Stop redacting by hand. Automate it with anonimIA.

Upload your PDFs and get GDPR-compliant anonymised documents in seconds.

Try it free