Guide
How to anonymise a document before using AI
Written by AI Tools AcademyChecked against the sources listed below on 27 September 2026
Helpful first: What can I put into ChatGPT at work? · Redaction that keeps the meaning
Removing identifying details before you use an AI tool is one of the most useful safety habits at work. Done well, it lets you get help with the shape of a problem while the details that could harm someone stay on your side of the screen.
Done carelessly, it gives false confidence. A document with the names crossed out can still point clearly to one person. This guide shows a careful method, a worked example, and the point where redaction stops being the answer.
It's practical guidance, not legal advice. Your organisation's policy and approved tools still take priority, and your data protection officer (DPO) or data protection contact has the final say on what's acceptable.
What redaction can and can't do
It can reduce what you share to what the task needs. If you want help with the tone of a reply, the AI doesn't need a customer's name, address or account number. Taking them out reduces risk, and the help is just as good.
It can't always make information anonymous. The ICO's anonymisation guidance judges anonymity by whether a person can still be identified, taking into account the means reasonably likely to be used. That includes the "motivated intruder": a reasonably competent person who wants to identify someone, using information that's easy to find or that they already know.
It can't make sensitive content safe. If the point of the document is a person's health condition, a disciplinary case or a safeguarding concern, removing the name leaves the sensitive part intact. In a small workplace, the context often identifies the person anyway.
Direct and indirect identifiers
Direct identifiers point to one person on their own. Indirect identifiers don't, alone, but can when combined with each other or with what the reader already knows.
| Direct identifiers | Indirect identifiers |
|---|---|
| Names, including in signatures and email addresses | Job titles, especially unique ones |
| Phone numbers and addresses | Team, site or branch |
| Account, customer, employee or case numbers | Specific dates and times |
| National Insurance numbers, dates of birth | Age, or age combined with role |
| Photos, voices, handwriting | Unusual events, incidents or circumstances |
| Vehicle registrations, IP addresses | Rare conditions, languages or characteristics |
Indirect identifiers are where most redaction goes wrong. "The only warehouse supervisor at the Coventry site" names someone as clearly as their name does.
First, decide whether redaction is the right approach
Before you start, ask what band the information is in. (The free AI-Safe Desk course explains the green, amber, red and black bands.)
- Green (public, nothing personal or confidential): no redaction needed.
- Amber (personal or commercial, but the task doesn't need those details): redaction is the right tool. This guide is for amber.
- Red (special category, criminal offence, safeguarding, privileged): redaction isn't enough. Use an approved tool with written permission, or do the task without AI.
- Black (passwords, keys, security settings): no AI tool, however it's redacted.
If you're not sure, the decision tool walks you through it.
The method, step by step
Step 1: Decide what the task needs
Write down, in one line, what you want the AI to do. Then list what it needs to do it. For "help me reply politely to this complaint", it needs the complaint, the tone and what you can offer. It doesn't need who complained. Anything not on the list is a candidate for removal.
Step 2: Strip the direct identifiers
Replace names, numbers, addresses and contact details with neutral labels: "the customer", "the account manager", "[account number]". Replace rather than delete, so the text still reads. Check signatures, email headers, greetings and sign-offs, where names hide.
Step 3: Generalise the indirect identifiers
Make specific details less specific: "3 September" becomes "earlier this month"; "the Tamworth depot" becomes "one of our sites"; "£48,312" becomes "about £50,000" or "[amount]". Remove anything the task doesn't need, especially personal circumstances.
Step 4: Check for combinations
Read what's left and ask: taken together, do these details point to one person or one organisation? A job title plus a site plus a month can be as identifying as a name. Generalise further until the answer is no.
Step 5: Check the file itself
If you're uploading a file rather than pasting text, check what's hidden inside it. File properties (author, company, last edited by), tracked changes, comments, hidden rows, columns and sheets in spreadsheets, speaker notes in slides, and earlier versions can all carry names. Pasting plain text into the chat avoids most of these.
Step 6: Check images, headers and footers
Logos, letterheads, headers, footers, page references and watermarks often carry the organisation's name and a reference number. Screenshots and photos can include names, faces, email addresses and other open windows. Remove or crop them, or leave them out.
Step 7: Re-read it as a motivated intruder
Read the redacted version as a colleague, the customer or a competitor would: someone who knows the context and wants to work out who it is. If they could, you haven't finished. If you can't get it to that point without losing what the task needs, stop and use an approved tool, or do the job without AI.
Step 8: Keep the key to yourself
If you used codes ("Customer A"), keep the list that links codes to real names out of the AI tool. Put the real details back yourself, in your own document, after the AI has helped.
A worked example
Alex Doyle, an account manager at Fernway Group (a fictional office equipment company), needs to update Priya Shah, head of operations, on a customer dispute. He'd like help making his notes into a short, clear briefing. Fernway's approved tool is Copilot, but Alex is working from his phone and is tempted to use a personal chatbot.
Call with Mark Hendry (facilities manager, Quillon Logistics, Unit 4, Tamworth), 3 Sept, 2.10pm. Account QL-20417. Mark says the two MFP copiers installed 18 Aug keep jamming on the second floor and his team has been printing at the Lichfield office. He's annoyed the engineer (Callum) didn't come back when promised on 28 Aug. Mark said he'd been off for three weeks after his heart operation and came back to find it still broken. He wants a replacement machine or a credit of £1,840 against the September invoice. Contract renewal due in January, worth about £62,000 a year. mark.hendry@quillonlogistics.example, 07700 900 123.
Alex works through the method.
The task: turn notes into a short briefing for his manager. It needs the problem, what went wrong, what the customer wants and why it matters. It doesn't need the customer's name, contact details, the engineer's name or the exact account.
The health detail: Mark's heart operation is health data, special category, and completely irrelevant to the briefing. It comes out entirely. It doesn't get generalised to "a medical issue" either; the task simply doesn't need it.
The combinations: "facilities manager at a logistics firm in Tamworth with a contract worth £62,000" narrows it to one customer for anyone at Fernway, or any competitor who knows the area. So the sector, site and exact figures get generalised too.
Notes from a call with a customer contact earlier this month. Two copiers we installed last month keep jamming on one floor, and the customer's team has had to print at another of their sites. An engineer missed a promised return visit, and the contact is frustrated that the fault is still unresolved. They want either a replacement machine or a credit of roughly £2,000 against this month's invoice. The contract is due for renewal early next year and is a significant account. Please turn this into a five-line briefing for my manager: what happened, the customer's request, the risk, and two options.
The AI gets everything it needs to help with structure. Alex puts the specific figures, names and dates back in when he sends the briefing to Priya from his work email.
Back at his desk, the simpler route would be Fernway's approved Copilot with his work account, where Fernway's policy allows customer notes. Redaction is the fallback for when the approved tool isn't to hand.
Pseudonymised is still personal data
Replacing names with codes or labels ("Customer A", "Employee 7", "the account manager") is called pseudonymisation. It's a good habit and it lowers risk. It doesn't make the information anonymous.
The ICO's anonymisation guidance is clear that pseudonymised data is still personal data, because it can be linked back to people using the key or other information. So the rules about personal data still apply: use approved tools, share only what the task needs, and follow your policy.
When redaction isn't enough
Stop redacting and choose a different route when:
- The sensitive detail is the point. A summary of a grievance, an occupational health report or a safeguarding note can't be redacted into something safe, because the content itself is the risk.
- The context identifies the person. Small teams, small schools, single-site businesses, rare events: some situations only happened to one person.
- Redacting removes what the task needs. If you've stripped so much that the AI can't help, the task probably needs the real information, and belongs in an approved tool.
- You're working with someone else's confidential document. Redaction doesn't override a confidentiality agreement.
- You're not confident you've caught everything. Long documents, spreadsheets and files with hidden content are easy to get wrong.
In those cases, the answer is one of two things: use an AI tool your organisation has approved for that kind of information, or do the task without AI. Doing it by hand is sometimes quicker than redacting carefully anyway.
A prompt that helps without seeing the original
You can use AI to plan your redaction without pasting the document. Describe what it is and what you need, and ask for a checklist.
I need to remove identifying details from a work document before asking an AI tool for help. I won't paste the document. Here's a description of it: [type of document, for example "notes from a customer call about a faulty product"]. Here's what I want the AI to help with: [the task]. Give me: 1) the details the task genuinely needs; 2) a checklist of direct and indirect identifiers typically found in this kind of document; 3) suggested replacement labels for each; 4) combinations of details that could still identify someone; 5) any reason this document might be unsuitable for redaction at all.
Why this works: The AI helps you think through what to remove, and the original never leaves your hands.
Then do the redaction yourself, and run the check below.
For the full picture of what can go where, read What can I put into ChatGPT at work? or take the free AI-Safe Desk course.
Questions people ask
- If I replace every name with a code, is the document anonymous?
- Usually not. Replacing names with codes is pseudonymisation, and the ICO is clear that pseudonymised data is still personal data. Other details in the document, or the key linking codes to names, can still identify people.
- Can I ask the AI to anonymise the document for me?
- Not by pasting the original into a tool that isn't approved for it, because that shares the very details you're trying to protect. You can ask an AI for a redaction checklist based on a description of the document, then do the redaction yourself.
Sources and further reading
This page explains good practice in plain English. It is not legal advice. Your organisation's policy and approved tools take priority.