Anonymisation vs pseudonymisation: the difference for your documents
"It's anonymised, I took the names out": that is almost always wrong. Pseudonymise, anonymise or keep the text on a confidential model: the comparison, and when to choose which.
"It's anonymised, I took the names out": that is almost always wrong. Pseudonymise, anonymise or keep the text on a confidential model: the comparison, and when to choose which.
"It's fine, I've anonymised the file: I took the names out." You hear it in every office, just before a document goes into a consumer AI tool. It is almost always wrong: removing the names is, at best, pseudonymising. And that difference decides what is still personal data.
Pseudonymising means replacing whatever identifies someone directly (a name, an address, a case number) with a marker: "Mrs Martin" becomes [CLIENT A]. A lookup table lets you put the real names back into the result.
Anonymising means making the person impossible to identify, by anyone, even by cross-referencing with other information. There is no table any more, and deleting the names is not enough: you also have to neutralise whatever makes someone recognisable. A date of birth, an unusual job title, a small town, a sequence of employers: each detail looks harmless, but together they point to a single person.
The test is simple: could someone who knows the field tell who this is about? If so, the document is not anonymous, however many names you have removed.
The GDPR is unambiguous: pseudonymised data is still personal data. Only truly anonymous data falls outside its scope. The Swiss Federal Act on Data Protection (FADP) follows the same logic: it applies as soon as a person is identifiable, not only when they are named.
A document stripped of names and then sent to an outside service is therefore still a disclosure of personal data to a third party. And for professions bound by secrecy, it is the content of the file that is protected, not just the client's identity.
| Send as is | Pseudonymise | Anonymise | Keep on a confidential model | |
|---|---|---|---|---|
| What goes out | Everything | The text, names replaced by markers | A text in which nobody is recognisable | Nothing to a third party |
| What stays with you | Nothing | The lookup table | Nothing to restore | The entire text |
| Status of the data | Personal | Still personal | Out of scope, if the anonymity really holds | Personal, processed in a setting you chose |
| Who decides | Nobody | You, marker by marker | You, down to the smallest detail of context | You, by choosing the model |
| Effort | None | Low if the tool does it | High | None |
| Answer you get | Complete but exposed | Complete, names restored | Often generic | Complete |
Pseudonymisation works when the identity is irrelevant but the rest of the text matters: rewording a letter, fixing the tone of an email, summarising a standard contract. The AI works on [CLIENT A], and you find Mrs Martin again in the answer.
Anonymisation is for when the text has to circulate without you: a case study for a training course, an example in a presentation. It takes work, and the text often loses whatever made it useful.
A confidential model is the right choice when the context alone identifies someone: a CV, an identity document, a medical record, a well-known case in a small town. Masking a candidate's name while sending their whole career protects nothing; that is the case covered in our guide to summarising CVs.
By default, IA Confidential handles your questions with confidential models: open models installed on servers in Switzerland that pass nothing on to third parties. There is no need to mask the text.
If you choose an external model, the Confidentiality filter first detects the sensitive data in your message. It offers to answer with a confidential model, your message untouched, or to anonymise it for the external model: you review and correct the proposed version before it is sent. Sending it as it is remains your decision.
Attachments (text, PDF, Word, images) are read in your browser. When an external model is used, only the useful extracts go out, pseudonymised: names become markers, the lookup table is never sent, and the real names reappear in the answer you read. When a document remains identifying even once masked, the assistant flags it as an "Identifying document": it is then handled by a confidential model, or only your question is sent.
No detector can guess a project's code name or a client's nickname. In the Privacy panel, your anonymisation instructions say what must always be masked, for example:
Replace the name of my firm with [FIRM] and my clients' names with [CLIENT A], [CLIENT B], in order of appearance. Also mask case numbers, street names and the code name of the "Atlas" project.
These tools detect; they do not know your line of work: review the proposed version. AI can also get things wrong or make them up; whatever goes out under your name remains your responsibility. For what should never go out, even masked, see what not to paste into AI.
With a confidential model, your text and your attachments are processed on servers located in Switzerland, under the Swiss Federal Act on Data Protection, outside the reach of the CLOUD Act, and nothing is kept on our side: your conversation history stays in your browser.
With an external model, nothing goes out without passing through the filter: the anonymised version you reviewed, pseudonymised extracts, or the message as it is if that is what you decided. The lookup table for the markers stays with the conversation, in your browser.
On a shared computer, anyone using the same session can read this conversation: log out when you leave.
For the basic habits, also read our guide to using AI at work safely. And to see the filter at work on a fictitious text: open the chat.