Anonymisation and privacy engineering
We help organisations use sensitive health and insurance data without exposing the people it describes, by designing how data is anonymised, pseudonymised, redacted and minimised around UK GDPR and the ICO's guidance.
Last updated
Anonymised or pseudonymised: what is the difference?
Truly anonymous data, from which a person can no longer be identified, falls outside UK GDPR. Pseudonymised data, where identifiers are replaced but the data could still be linked back to a person, is still personal data, and UK GDPR still applies to it.
The difference matters because the two are treated so differently in law. Calling pseudonymised data anonymous is a common and costly mistake.
Read the ICO's guidance on anonymisation and pseudonymisation
What we do
[TO CONFIRM: list, for example de-identification pipelines, redaction of names, numbers and addresses in transcripts, aggregation and data minimisation, re-identification risk testing]
Privacy by architecture
The safest personal data is data that never has to move. Where we can, we process data on the device, so there is less to protect.
Read how Prime Edge AI does thisWorking with your data protection officer
We work with your data protection officer from the start, so that the design supports your data protection impact assessment rather than arriving after it.