Skip to content

Anonymising documents under UK GDPR: what the ICO's guidance says

What the ICO's 2025 anonymisation guidance means for documents: the motivated intruder test, release context and pseudonymisation in UK law.

By Alexis de ONYRI

Under UK GDPR, a document is anonymous only if no one is reasonably likely to identify a person in it. The UK regulator, the Information Commission's Office (ICO), says the risk of identification must be “sufficiently remote” for the document and for each reader. Its guidance, Anonymisation, published on 28 March 2025, warns that masking alone, such as deleting names, is not enough.

Which UK rules apply to anonymising a document?

Since Brexit, the UK has its own regime: the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018). Recital 26 of the UK GDPR says the rules do not apply to anonymous information. But the ICO says anonymising is itself processing, so it needs a lawful basis.

Red-brick houses with sash windows and tall chimneys, a wooden utility pole and overhead wires against a blue sky
Own rules since Brexit: in the UK, anonymising a document is itself processing and needs a lawful basis.Photo: Suzy Hazelwood, Pexels

The guidance is not a statutory code, so it is advice, not law. It covers all media, including free text, images and audio.

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. The ICO says its data protection provisions are all in force. The Act did not change the wording of the definitions of personal data and pseudonymisation, only their numbers. Even so, the ICO marks its anonymisation guidance as under review because of the Act.

The regulator changed form too. On 30 September 2026, the Information Commission replaced the office of Information Commissioner, under S.I. 2026/1015, a government regulation. The ICO now calls itself the Information Commission's Office, and this guide keeps the short name.

How does the ICO decide if a person is identifiable?

The ICO sees identifiability as a spectrum. At one end, a document names people and is always personal data. At the other end, no reader could reliably link it to anyone. In between lies a blurred band, where the answer depends on the circumstances.

To place a document on it, you weigh the means reasonably likely to be used to identify someone: cost, time, available technology. The ICO adds that zero risk is not required.

The law gives no method for this check, so the ICO uses the motivated intruder test. Picture a reasonably competent person who wants to identify someone. They search the internet, libraries and public documents, and they ask around. The ICO lists the electoral roll, the Land Registry, social media, press archives and even generative AI chatbots.

Take a grievance report about Jane Example. You delete her name. But the text still says: the only night-shift supervisor at the Swindon depot, off sick since 3 March. A casual reader learns nothing. A colleague knows at once. The ICO warns that the intruder can be someone allowed to see the data.

Why does the release context change what you mask?

The ICO ties the test to your release model: public release, release to defined groups, or internal use only. Public release needs a very robust approach, because you lose control and can almost never take the data back.

Who gets the documentWhat the ICO saysFor the grievance report
The public: a website, a reportVery robust approach: you lose controlRemove the depot, the shift and the dates
A defined group under an agreementWeigh what the group knows. Contracts and access controls countMore detail may stay if they lack local knowledge
Another team in your organisationIf you keep the original, the copy is only pseudonymisedTreat it as personal data
Your processor or a joint controllerThe status in your hands decidesMasking helps security, but the report stays personal data
Release models in the ICO's anonymisation guidance, applied to one document

Is a pseudonymised document still personal data in the UK?

Yes, for anyone who holds the key. Point 5 of Article 4(1) of the UK GDPR (Article 4(5) before 5 February 2026) defines pseudonymisation. The data can no longer be linked to a person without additional information kept separately. Replace Jane Example with EMPLOYEE-1 and keep the list in HR. For you, the report is still personal data. Shared without the list, the ICO says it may be anonymous for the recipient.

UK law adds a criminal offence. Under section 171 of the DPA 2018, re-identifying de-identified personal data, knowingly or recklessly, is an offence. It applies when the controller who de-identified the data has not consented. The ICO says “de-identified” data includes pseudonymised data and data wrongly thought anonymous. Section 196 makes it punishable by a fine. Defences exist, for example the public interest.

What should you check in a UK document before release?

What to look forExamples in a UK documentWhat to do
Direct identifiersName, National Insurance number, NHS number, email, phoneRemove them all
Address and postcode14 Example Road, full postcodeKeep at most the town or region
Indirect identifiersJob title in a small team, rare event, exact datesGeneralise: broader role, month or year
Free textWitness accounts, quotes, signaturesRead line by line: the ICO says this can need careful human judgement
File detailsAuthor and other properties, comments, file nameExport a new, flattened file and rename it
Based on the ICO's guidance, except the file details row, which is practical advice

On a British document, ONYRI Sanitize uses its UK formats: National Insurance numbers, UK postcodes, UK phone numbers, IBANs and English first names and surnames. It has no NHS-number detector and no UK street-address detector. It also cannot judge a job title or a rare event. Mask those yourself with “Select text” or “Also mask”, then check the preview.

Then record the decision. The ICO says you must document and justify it, and keep it under review, for example before each new recipient. It recommends a data protection impact assessment (DPIA), a written risk review, to structure the work. Note who decided, for which reader, and why the risk is remote.

Can EU organisations still send personal data to the UK?

Yes. Through adequacy decisions, the European Commission has found that UK law protects personal data about as well as EU law does. It adopted them on 28 June 2021 and renewed them on 19 December 2025, until 27 December 2031. So personal data can flow from the European Economic Area to the UK without further safeguards. But adequacy concerns transfers, not anonymity. A document that still identifies people stays personal data on both sides.

This guide reflects the law as of October 2026 and is not legal advice. For a borderline case, ask your data protection officer (DPO) or a UK lawyer.

Frequently asked questions

Is the ICO's anonymisation guidance legally binding?

No. The ICO says there is no penalty for not following it, but you must then comply another way. And when it looks into an anonymisation issue, it takes the guidance into account.

If a reader guesses who is behind a masked document, is that a disclosure?

Not by itself, says the ICO, even if the guess is correct. The reader must be able to link the text to one person with a degree of certainty.

Does UK data protection law cover documents about people who have died?

No. The DPA 2018 covers identifiable living individuals only. But the ICO notes that such records may still be protected by confidentiality or other laws.

Does masking a document count as processing?

Yes, says the ICO. The anonymous result falls outside the law, but the masking step does not. The ICO adds that anonymising is generally likely to be fair and lawful, but you must still define your purpose.

Sources & references

Mask a document without uploading it

ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.