Document anonymization for public administrations
Publishing transparently and protecting citizens’ data are not contradictory obligations: both are met by anonymizing systematically before publication. anonimiza.do automates the detection and removal of personal data from resolutions, contracts, minutes and tender documents, with an audit log, ENS certification and data kept in the European Union.
What a public body publishes, and where
Transparency legislation requires local authorities, regional governments, autonomous agencies and public universities to publish:
- Resolutions and administrative acts closing procedures.
- Contracts and tenders on the contractor profile: specifications, technical memoranda, procurement panel and award minutes.
- Grants awarded, with beneficiary, amount and purpose.
- Minutes of council meetings and other collective bodies.
- Sanction decisions, only in the cases explicitly provided for by law.
- Responses to requests for access to public information.
What data must be removed before publishing
Data protection authorities have set clear criteria on which personal data must not reach the portal:
In resolutions and administrative acts
The full national ID —replaced with the last four digits or removed—, the postal address, phone number and email, the bank account number, common in grant award decisions, and health or family data not relevant to the act.
In contracts and tenders
The national ID of the legal representatives of tendering companies, the personal data of technical staff who signed documents but are not public officials, personal phone, email and address, the detailed CV of proposed technical staff, family data in solvency reports and handwritten signatures. The contracting body, the identity of the awardee, the amount, the deadlines and the subject matter are published with identification.
In minutes of collective bodies
Minutes of council meetings may be published with the names of elected officials, but must protect the data of citizens who intervene as private individuals, for example during public question periods.
In grants
When the beneficiary is a natural person, publishing name, amount and purpose is proportionate; publishing name, ID and address is not.
In sanction decisions
Publication is only mandatory in the cases explicitly provided for by law, and subject to the limitations set for each type of procedure.
Anonymize, do not pseudonymize
It is the technical point that causes the most confusion in document management teams:
- Pseudonymization replaces the data with a code —ID 12345678A → CITIZEN-0042— and keeps a correspondence file: the document still contains personal data from GDPR’s perspective.
- Anonymization deletes or transforms the data irreversibly: the resulting document no longer contains personal data and falls outside GDPR.
- For the transparency portal, data protection authorities recommend true anonymization, except where the law explicitly requires identifying the individual, such as certain official gazette publications or public notice boards.
- The practical test: if someone reading the published document, combined with other public sources, could identify the person, it is not anonymized.
- Three GDPR principles underpin the workflow: data minimization (Art. 5.1.c), privacy by design (Art. 25) and accountability (Art. 5.2), which requires being able to show what was published, what data it contained and what measures were applied.
How to implement an anonymization workflow in your organization
The usual process is manual —a civil servant reviews the document and removes the data they remember is sensitive— and has three problems: it is slow, inconsistent and leaves no audit trail. A systematic workflow includes:
- Classification of the document types that get published and of the personal data each category typically contains.
- Automated detection with tools capable of identifying personal data in unstructured text, including country-specific formats: national ID numbers, social security numbers, vehicle registration plates, IBANs.
- Human review of ambiguous cases, such as a name that is also a company name or an address that is part of a cadastral reference.
- An audit log per published document: which anonymization process was applied, on what date and by which person or system.
- A review of the criteria at least annually, because data protection authorities periodically update their guidance.
What anonimiza.do brings to a public body
- Automatic detection of the 20 data types of the catalogue across seven families, with Spanish formats —DNI, NIE, Social Security number, IBAN, license plate— validated by their check digit.
- Your own data types described in plain language, such as «disciplinary case reference», with no rules to program and nothing to train.
- OCR for scanned files, batch processing and a REST API to integrate it into the publication workflow.
- Irreversible anonymization or reversible pseudonymization, plus k-anonymity verification.
- An audit log for every processed document: the evidence that protects the body against a complaint.
- Spanish National Security Framework (ENS) MEDIUM category (Royal Decree 311/2022), data in the European Union (AWS Frankfurt) with an optional deployment in the AWS region in Spain, and a data processing agreement.
- Enterprise plan with unlimited volume and SSO/SAML for public bodies; free plan with 3 documents a month to try it out.
Try for free: 3 documents a month
Frequently asked questions
Can a public body publish the names of grant recipients?
Generally yes: transparency legislation requires publishing grants with amount and beneficiary. But when the beneficiary is a natural person, GDPR limits what else may be published alongside their name: name, amount and purpose is proportionate; name, ID and address is not.
Are small local authorities also required to comply with GDPR?
Yes, without exception. GDPR applies to any body that processes personal data, regardless of size. What varies with size is the obligation to designate a Data Protection Officer, not compliance with the fundamental principles.
What happens when a citizen requests information that contains data about third parties?
The right of access to public information does not automatically override GDPR. The body must balance both rights and, in general, provide the information in anonymized form when this can be done without undermining the substance of the request.
Can data protection authorities sanction a public body?
Yes. Although public bodies are not fined in the same financial terms as companies, data protection authorities can issue public reprimands and require corrective measures with binding deadlines. In addition, individual officials may face disciplinary liability.