Choose which optional cookies and similar storage we may use. Strictly necessary storage is always on, because the site cannot work without it.

Anonymisation and privacy engineering

We help organisations use sensitive health and insurance data without exposing the people it describes, by designing how data is anonymised, pseudonymised, redacted and minimised around UK GDPR and the ICO's guidance.

Last updated

Anonymised or pseudonymised: what is the difference?

Truly anonymous data, from which a person can no longer be identified, falls outside UK GDPR. Pseudonymised data, where identifiers are replaced but the data could still be linked back to a person, is still personal data, and UK GDPR still applies to it.

The difference matters because the two are treated so differently in law. Calling pseudonymised data anonymous is a common and costly mistake.

Read the ICO's guidance on anonymisation and pseudonymisation

Draft (F10): What we do: confirm the list (for example de-identification pipelines, redaction in transcripts, aggregation and data minimisation, re-identification risk testing).

What we do

[TO CONFIRM: list, for example de-identification pipelines, redaction of names, numbers and addresses in transcripts, aggregation and data minimisation, re-identification risk testing]

Privacy by architecture

The safest personal data is data that never has to move. Where we can, we process data on the device, so there is less to protect.

Read how Prime Edge AI does this

Working with your data protection officer

We work with your data protection officer from the start, so that the design supports your data protection impact assessment rather than arriving after it.

Use sensitive data without exposing people.