Redacted exhibits under CPR Part 31: pseudonymise non-party data in disclosed exhibits – UK GDPR-compliant anonymisation per CPR Part 31
Redacted exhibits are documents disclosed under CPR Part 31 — such as invoices, correspondence, and records — from which non-party personal data has been pseudonymised before production; anonym.legal applies consistent pseudonymisation across all exhibit documents — according to HMCTS Civil Justice Statistics, over 1.4 million claims were issued in 2023, generating millions of exhibits containing third-party personal data.
When this applies
Applies when a solicitor is preparing exhibits for disclosure under CPR Part 31 and the exhibits contain personal data about individuals who are not parties — for example, customer records in a commercial dispute above the £25,000 multi-track threshold or HR records in an employment claim. Data shows that large commercial disclosures can contain over 20,000 documents with third-party identifiers.
How anonym.legal handles it
- Upload the exhibit documents — invoices, emails, records — in PDF or DOCX format.
- Configure the party-names allow-list for the case parties.
- anonym.legal identifies and pseudonymises non-party names, addresses, account references, and other personal identifiers across all exhibits.
- Substantive content — dates, amounts, subject matter — is preserved so the evidential value of the exhibit is maintained.
- A reversible mapping is stored with EU data residency.
- Consider whether your disclosure statement should note that exhibits have been prepared with third-party data pseudonymised in accordance with UK GDPR data-minimisation principles.
What you provide
- Exhibit documents (PDF or DOCX)
- Party-names allow-list
Limitations & cautions
- Decisions on which documents are disclosable and whether any redaction is permissible under CPR Part 31 must be made by a qualified solicitor.
- Irrelevant redaction of substantive content may constitute a breach of disclosure obligations — only personal-identifier data should be pseudonymised, not substantive evidence.
- Misuse of non-party personal data in disclosed exhibits can attract UK GDPR fines of up to £17.5 million or 4% of global turnover under DPA 2018 s.157; the ICO fined British Airways £20 million in 2020 for inadequate data protections.
FAQ
Is pseudonymising non-party personal data in disclosed exhibits permissible under CPR Part 31?
Proportionate pseudonymisation of non-party personal data is consistent with data-minimisation principles under UK GDPR Article 5. Whether it is permissible in any given case should be confirmed with the court or agreed with the other side. According to the ICO Code of Practice on Anonymisation (2021), pseudonymisation is a recognised privacy-enhancement technique.
Can I pseudonymise personal data that is also part of the substantive evidence?
If the identity of a non-party is itself material to the issues in dispute, pseudonymisation may not be appropriate for that individual. Use the party-names allow-list or manually exclude individuals whose identities are evidentially material.
What if the exhibit is a spreadsheet with thousands of rows of third-party data?
anonym.legal processes large spreadsheets at row level, identifying personal-identifier columns and pseudonymising all relevant cells consistently across the dataset. Data shows that commercial disclosure datasets can contain over 50,000 rows of customer records requiring pseudonymisation.