Please note: The algorithm descriptions in English have been automatically translated. Errors may have been introduced in this process. For the original descriptions, go to the Dutch version of the Algorithm Register.
Anonymisation tool
- Publication category
- Other algorithms
- Impact assessment
- DPIA, Information Security Quick Assessment
- Status
- In use
General information
Theme
Begin date
Contact information
Responsible use
Goal and impact
The anonymisation tool helps the organisation in two ways at once. On the one hand, it enables the organisation to be open about what it does. On the other hand, it protects the privacy of individuals, companies and institutions mentioned in the documents.
Being open means that the organisation can share information. This is required, for example, under the Open Government Act (Woo). For members of the public mentioned in the documents, this is good news: their privacy is not infringed. In this way, the organisation complies with data protection legislation (the GDPR/Wpg). This also applies to the privacy of its own staff.
Anyone submitting a Woo request will receive the information requested. Personal data has been removed. Sometimes other sections have also been redacted for other reasons. Organisations processing Woo requests thus comply with the law. The programme makes the work more efficient. As a result, it is easier to respond within the statutory time limit.
The system has a low impact on people. This applies to members of the public, staff, businesses and institutions. The programme only searches for (personal) data and flags it. It does not make any decisions itself. It makes a suggestion to a staff member. That staff member then makes the decision. You can also manually redact sections of text for other reasons. For example, to protect strategic information belonging to your own organisation or a partner. The programme always records the reason why something has been redacted.
Considerations
Sometimes documents contain information that must not be made public. The Open Government Act (Woo) sets out when this applies. The General Data Protection Regulation (GDPR) and the Police Data Act (Wpg) may also provide grounds for not sharing information.
Without this programme, it takes much longer to redact those sections of documents. This programme makes the work quicker and easier. It also makes fewer mistakes than a human would. This reduces the risk of a data breach. And people’s data is better protected.
Human intervention
A member of staff always checks the programme’s results. That is standard practice. The programme uses a settings file (a file containing all the preferences and requirements on the basis of which the software highlights data). This file contains the organisation’s preferences. This allows you to adapt the programme to your own situation.
The programme makes a suggestion to a staff member with knowledge of the subject. The programme does not make any decisions itself. It merely searches for (personal) data and flags it. The staff member reviews the suggestions. The staff member approves valid suggestions. The staff member amends any incorrect suggestions. If no suggestion is made, a staff member can apply a flag themselves. A second staff member can then also check the work (four-eyes principle).
For the public, this means that the organisation operates with due care. The risk of a privacy breach is minimised as much as possible. The organisation complies with the relevant legislation (the GDPR, the Wpg and the Woo).
Risk management
A member of staff always checks whether a document has been properly anonymised. This check is thorough. The programme makes it easy to amend or add information.
Without human oversight, risks may arise. This is particularly the case if privacy-sensitive data is accidentally disclosed. These risks are inherently intertwined with the business process and are not so much the fault of the programme. These risks are always present, regardless of whether this programme is used. The programme and human intervention work together to prevent or minimise these risks. These are the risks:
- Breach of data protection legislation: Accidentally disclosing personal data contravenes data protection legislation, such as the GDPR. This can lead to heavy fines and legal consequences.
- Identity theft: If personal data such as names, addresses and national insurance numbers are disclosed, malicious individuals could use this information to commit identity theft or fraud.
- Reputational damage: The reputation of the individuals whose data is leaked may be damaged. The same applies to the organisation that caused the leak.
- Loss of trust: People may lose trust in the organisation. This can lead to reduced support and engagement.
- Personal harm: People may suffer emotional harm. For example, if their medical or financial details are made public.
- Misuse: Publicly available data may be misused. For example, for stalking, harassment or discrimination.
Human oversight helps to minimise these risks. A person always checks whether the anonymisation has been carried out correctly. Only then is the information released.
Legal basis
Woo: Protection of sensitive information in accordance with the grounds for exemption under the Woo (Articles 5.1 and 5.2 of the Woo). GDPR: Protection of privacy-sensitive information. WPG: Protection of information compiled in the course of police duties.
Impact assessment
- Data Protection Impact Assessment (DPIA)
- Information Security Quick Assessment
Operations
Data
At the outset, the organisation and the supplier jointly created a configuration file. This file sets out the organisation’s preferences regarding what should be redacted.
The settings file is combined with Octobox’s base model. By default, this base model searches for data that can be traced back to individuals. Examples include national insurance numbers, bank account numbers, telephone numbers, email addresses, dates, home addresses and postcodes.
The organisation can add its own preferences. For example: the name of a government minister or director remains visible. Or: certain other names may, in fact, be redacted. The names of the organisation’s own staff are often not included in the base model. You can add these in advance. You can also choose how an email address is redacted.
Technical design
The programme scans every document in the file. It operates using pre-programmed rules, and users can add to or amend these rules whilst using the programme. It recognises text or sequences of numbers that could identify individuals. For example, national insurance numbers, bank account numbers, telephone numbers, email addresses, dates, home addresses and postcodes.
You can set the level of certainty required by the programme yourself. On the screen, you can see which text must definitely be redacted. You can also see which text is less certain. As a staff member, you can approve or reject the suggestions. You can also edit them first.
You can also highlight text yourself to make it unreadable. When doing so, you specify the reason why this is necessary. A second staff member can check the work of the first. Are all the pages of all the documents ready? Then the programme creates a final version. That version is ready for publication.
External provider
Similar algorithm descriptions
- Octobox Anonymisation is used when making information, such as personal data, unreadable (varnishing). This is mainly done in requests under the Open Government Act (Woo). The basis of the algorithm is formed by AVG rules. In addition, the algorithm has self-learning properties based on human input.Last change on 11th of September 2024, at 15:14 (CET) | Publication Standard 1.0
- Publication category
- Other algorithms
- Impact assessment
- Impact- en maatregelenanalyse Algoritmen, DPIA
- Status
- In use
- Recognise and anonymise privacy-sensitive information in documents.Last change on 3rd of July 2024, at 13:49 (CET) | Publication Standard 1.0
- Publication category
- Other algorithms
- Impact assessment
- Field not filled in.
- Status
- In use
- Anonymising privacy-sensitive information in documents.Last change on 21st of August 2025, at 10:30 (CET) | Publication Standard 1.0
- Publication category
- Other algorithms
- Impact assessment
- DPIA
- Status
- In use
- Recognise and anonymise privacy-sensitive information in documents based on AVG and Woo.Last change on 17th of April 2026, at 8:44 (CET) | Publication Standard 1.0
- Publication category
- Other algorithms
- Impact assessment
- Field not filled in.
- Status
- In use
- The algorithm in the software is mainly set to recognise and anonymise privacy-sensitive information in documents. Basis for this is the AVG. The tool is also used to highlight and mask information that cannot be shared for other reasons (based on another basis, e.g. the Woo) in a document.Last change on 13th of November 2024, at 13:53 (CET) | Publication Standard 1.0
- Publication category
- Other algorithms
- Impact assessment
- Field not filled in.
- Status
- In use