Skip to main content

Privacy workflow

Anonymize Personal Data in a CSV Before Sharing

Replace direct identifiers, assess indirect re-identification risk and preserve only the fields needed for the stated use.

Use the matching tool

Anonymize Data

Open Anonymize Data

What the error actually means

Removing names alone does not make a dataset anonymous. Email, phone, exact dates, locations and rare combinations can identify a person directly or indirectly. A defensible workflow starts from the sharing purpose and reduces fields accordingly.

Likely causes

  • Direct identifiers remain.
  • Quasi-identifiers form unique combinations.
  • Free-text fields contain names or contact details.
  • The recipient does not need the full dataset.

Purpose-limited data

Problem

Remove name but retain email, exact birth date and address

Correct pattern

Remove direct identifiers and generalize or suppress unnecessary quasi-identifiers

A safe repair workflow

  1. 1Define the recipient’s minimum data need.
  2. 2Classify direct and indirect identifiers.
  3. 3Transform a copy and inspect free text.
  4. 4Test uniqueness and review the release.

How to verify the result

A file that downloads successfully is not automatically a correct file. Check the result at both the structural and business-data levels:

  • Direct identifiers are absent.
  • Rare combinations are assessed.
  • Analytical fields still support the purpose.
  • The transformation is documented.

Read the deeper guides