Before sharing text: how to check personal information
A work email, forwarded message or technical log may reveal more than it seems. This guide shows what to look for, how to use the local Rusadix Tools detector and, crucially, what you still need to review yourself.
1. Know why you are sharing it
A colleague fixing a technical fault, someone receiving an appointment and a public reader do not need the same information. Before removing anything, decide which details are essential to understand the message. Avoid copying a whole conversation when a sentence or a short log excerpt is enough.
2. Look for patterns that can be detected automatically
The Rusadix detector looks for specific formats: email addresses, certain IP addresses, possible telephone numbers, Spanish identity numbers, IBANs, payment-card patterns and signatures of some technical keys or tokens. In some cases it checks digits using Luhn or the IBAN mod-97 rule. This reduces certain false matches, but it cannot identify an owner, determine whether a number is in use or verify that a key works.
3. Example: an ordinary-looking message
This sample is entirely fictional. example.com is reserved for examples, and 192.0.2.44 belongs to an IP range reserved for technical documentation.
Escribe a persona@example.com. Servidor: 192.0.2.44. Mara trabaja en la oficina de Calle Inventada, 14.
The detector can spot the email and IPv4 address and replace them with [EMAIL] and [IPV4] in its generated copy. But it will leave phrases like 'Mara' and 'Calle Inventada, 14', because it does not reliably recognize personal names or postal addresses. Finding just a few matches does not mean the text is ready to publish.
4. What pattern matching can miss
An unusual name alongside a job title, neighborhood and specific date may identify a person even without a government ID. Health information, family stories, room numbers and internal company references can also reveal identities. Details that look harmless on their own may become identifying when combined with public information. A pattern-only detector cannot fully understand that context.
5. Replacing identifiers is not always anonymization
Replacing an email with [EMAIL] helps remove that identifier from a copy. However, if a person remains identifiable through other details or additional information, the text may still be personal data. The Spanish Data Protection Authority and European Data Protection Board distinguish pseudonymization from effective anonymization. Do not present the automatic output as legal or technical certification.
6. A five-step final check
- Copy only the essential excerpt and remove irrelevant details.
- Run it through the detector and inspect every match; some may be false positives.
- Read the entire text for names, addresses, personal circumstances and indirect clues.
- Review the actual version you will paste or send, not just the results panel.
- If reasonable doubt remains, avoid publishing it openly and consult the appropriate person in charge.
The 'Copy anonymized text' button replaces detected patterns; it does not guarantee anonymization. When sharing sensitive information, minimize the details and review the output manually.
Reference sources
- Spanish DPA: what personal data is
- Spanish DPA: pseudonymized data is still personal
- EDPB: anonymization and pseudonymization
Sharing a screenshot or photo? Check visible information in images too.