How to anonymize company data before licensing it

What to remove, what to keep, and how to check the result before anything leaves your systems.

Updated September 30, 2026

Before a buyer sees your records, the people in them have to disappear: customers, employees, suppliers. So do secrets, account numbers and anything you promised to keep confidential. The goal is a dataset that still shows how the work was done, but that nobody could use to identify a person or learn a customer's business.

This matters more than it might seem. Privacy advocates quoted on the closing-startup deals pointed out that internal chats describe identifiable people, not generic data (Gizmodo, reporting on Forbes, April 17, 2026).

What to remove

CategoryExamples
Direct identifiersNames, email addresses, phone numbers, street addresses, account and customer IDs, IP addresses, photos and signatures
Indirect identifiersJob titles on small teams, exact dates next to locations, rare events that only one person was involved in
SecretsPasswords, API keys and tokens, which turn up in tickets, chat and code history more often than anyone expects
Financial detailsBank account and card numbers, salaries, individual invoices
Other companies' confidential informationCustomer names, their pricing, contract terms, anything under NDA
Material to leave out entirelyHR files, medical information, privileged legal advice, board and M&A discussions

Ways to remove it

  • Consistent placeholders. Replace each person or company with a stable label, like Customer A or Engineer 3, so a thread still makes sense. Keep the mapping inside your company.
  • Generalizing. Replace exact dates with relative ones ("day 3 of the project"), exact amounts with ranges, and specific places with regions.
  • Removal. Delete fields that add nothing to the task, like signatures, footers and contact blocks.
  • Rewriting. Some buyers rewrite records so the structure of the work survives but the wording doesn't. It lowers the risk further, and it also changes what you're selling, so agree it in the contract.

Health information

If any records include protected health information, HIPAA sets the bar. HHS recognizes two methods: removing 18 specified types of identifiers (Safe Harbor), or having a qualified expert determine that the risk of re-identification is very small (US Department of Health and Human Services). If you can't meet one of those, leave the records out.

Who should do the cleanup

The safest option is to clean the data inside your own systems before anything leaves. Some buyers prefer to run the cleanup themselves after transfer. That can work, but only if the contract treats the raw copy as your confidential information, limits who can see it, and requires it to be deleted once you've accepted the cleaned version.

What doesn't work is leaving it to individuals. When contractors were asked to scrub their own past work before uploading it, an IP lawyer warned that it depended on their judgment about what was confidential (TechCrunch, reporting on Wired, January 10, 2026).

How to check the result

  1. Run pattern scans over the cleaned data for email addresses, phone numbers, card numbers and key formats. Anything they find means the first pass missed something.
  2. Have people who know the business read a random sample and try to work out who is involved.
  3. Search for your largest customers' and your staff's names directly.
  4. Fix the process, not just the examples you found, and scan again.
  5. Keep a written record of what was removed and how it was checked. Your lawyer and the buyer will both ask.

Once you're confident in the process, the licensing agreement should write it down as the standard the delivery has to meet.

Common questions

Is pseudonymized data the same as anonymized data?

No. Swapping names for consistent placeholders like Customer A is pseudonymization, and under GDPR it's still personal data because someone with the key could reverse it. Keep the key inside your company, or destroy it, and treat the output as personal data unless nothing could link it back.

Can AI tools do the redaction?

They help with volume, but they miss things and sometimes invent them. Use automated tools for a first pass, pattern scanners to catch what they missed, and people to review samples before anything leaves.

Sources

  1. US Department of Health and Human Services: Guidance on de-identification of protected health information
  2. TechCrunch, reporting on Wired, January 10, 2026: OpenAI is reportedly asking contractors to upload real work from past jobs
  3. Gizmodo, reporting on Forbes, April 17, 2026: Failed companies are selling old Slack chats and email archives to train AI

Find out what your records are worth to a buyer

Answer a few questions about your company and your records. It takes about five minutes, and you don't send us any files.

Check your data