Practical guide · GDPR

Which documents should you anonymize, and what for

10 min read

Contracts, CVs, invoices, complaints, minutes, medical reports and case files contain more personal information than they appear to. The key question is not whether you must always anonymize documents, but this: do we need to know people's identities for the use we intend to give the document? When the answer is no, keeping personal data increases risk without adding value.

Names are just the start: a document may include ID numbers, addresses, phone numbers, signatures, bank accounts, health data, licence plates or references that indirectly identify a person. Anonymization is a risk-based process that balances protecting identity with preserving the usefulness of the information.

1. Contracts and legal documentation

They may contain representatives' names, ID numbers, signatures, addresses, emails, phone numbers and bank details.

What is it for?

  • Getting a second legal opinion.
  • Comparing clauses across contracts.
  • Building templates or training new employees.
  • Analysing the document with AI.

The risk

Sending the full contract exposes confidential data and terms that the analysis does not need. An AI can review a termination clause without knowing the parties' names, ID numbers or bank accounts.

2. CVs and HR documentation

CVs, employment contracts, payslips, sick notes, performance reviews and disciplinary files may include photos, salaries, health data, disability or family circumstances.

The risk

A CV can identify someone even without the name: previous employer, role, dates, location and education combined are often enough. Anonymizing is not just deleting the header — indirect references matter too.

3. Invoices and financial documentation

They include names, tax IDs, addresses, emails, account numbers and line items that reveal personal habits.

The risk

Using real invoices in demos or test environments exposes customer data. Hiding only the name is not enough if the tax ID, address or IBAN remain visible.

4. Complaints, emails and support tickets

The team needs to know what happened, not who complained. "Maria García, ID 12345678Z, requests a 89 euro refund for order 45892" can become "A customer requests a refund for an incorrectly delivered order".

5. Medical, social and occupational health reports

Beyond names and ID numbers, review rare conditions, occupation, exact age, town or treatment date: combining several fields can identify the person.

6. Judgments, resolutions, minutes and case files

Anonymized to publish on transparency portals, answer access requests, build knowledge bases or share precedents. They may contain data on whistleblowers, minors, employees or witnesses that would stay searchable for years.

7. Databases, spreadsheets and lists

Removing direct identifiers is only the first step. A row without a name can still be identifiable: "63 years old, CFO, Málaga office, joined in 1998".

8. Documents used with AI

Before sending a file to ChatGPT, Copilot, Claude or Gemini, check whether it contains personal data. The right order is: pick the document, detect personal data, anonymize, review the result, and only then send the prepared version to the approved tool. Asking the AI itself to anonymize does not avoid the initial exposure.

9. Documents used to build or test software

A vendor may need the layout of an invoice, but not the customer's identity or bank account.

When should a company consider anonymization?

There is a clear signal: the document will be used outside its original purpose or environment — published online, sent to a vendor, shared with another department, used in training, analysed with AI or used to test software.

Anonymizing does not mean deleting everything

Anonymization should preserve the information each use case needs. The goal is the balance between usefulness and re-identification risk.

Checklist: should I anonymize this document?

  1. Does it contain names, ID numbers, phones, addresses or signatures?
  2. Does it include banking, medical, employment or family data?
  3. Could someone be identified by combining several fields?
  4. Does the recipient need to know the identity?
  5. Will it be published or shared outside the original team?
  6. Will it be used with AI?
  7. Does it contain comments, metadata or hidden information?

Automating document anonymization

anonimizia automatically detects and handles names, ID documents, addresses, phone numbers, emails, IBANs and other personal data in PDF, Word and Excel. The rule is simple: if identity is not needed for the intended use, the document should not keep it.

Do you anonymise documents daily?

Stop redacting by hand. Automate it with anonimizia.

Upload your PDFs and get GDPR-compliant anonymised documents in seconds.

Try it free