GDPR

Last reviewed: 2026-09-26

A reversible masked copy can still be personal data under the GDPR. A review needs to cover the purpose, legal basis and recipients. Health information also needs an applicable special-category condition.

Where PHI Mask fits

Your file is masked in your browser and never sent to us. The Compliance page explains the masking workflow, browser storage and the separate handling of website and support information.

The service you send a masked copy to has its own purposes, settings, contracts and storage locations. Assess that service as part of your workflow.

Masked information can still be personal data

A reversible mask does not automatically make personal data anonymous. Review whether someone can identify the person from the remaining text or from additional information they could obtain.

Keep recovery information separate from the copy being shared. Assess the remaining context as well as the identifiers you removed.

Record the basis for the work

Document the purpose and an Article 6 legal basis. For health data, identify an Article 9 condition as well; consent is one possible condition, not a universal answer.

Limit the information to what the task needs. Include the use of the selected AI service in that assessment.

Assign roles and review agreements

Determine who decides the purposes and means of processing, and who processes information on their behalf. An Article 28 contract is required where a service acts as a processor.

Make that decision from the actual service and information access. Local masking does not decide the role of a separate AI provider.

Assess risk and overseas access

Complete a data protection impact assessment before processing likely to create a high risk to people. Record the safeguards and unresolved risks for the whole workflow.

Identify recipient and access locations. Where a restricted international transfer occurs, establish the applicable Chapter V transfer conditions.

Compliance and security