Anonimatum
Back to blog
Anonymization 14 August 2026 13 min read

Anonymize Excel: payrolls, lists and spreadsheets with personal data

Spreadsheets are where operational PII concentrates most densely: national IDs, IBANs, emails, addresses, amounts, employee codes, cost centres. An Excel file «without the Name column» can still re-identify people if you leave postcode + role + birth date, or if someone unhides a column.

This guide covers real risks when sharing .xls / .xlsx / .ods, a GDPR-aligned working method, and how to anonymize natively (without destroying tabular usefulness) with Anonimatum and local AI in the EU.

Typical scenarios where hand-cleaned Excel fails

  • Payroll and HR: name removed but social-security numbers, IBANs and internal emails remain.
  • Customer / member lists: active filters hide rows… until the recipient clears them.
  • ERP/CRM exports: query metadata, helper sheets and pivot caches with original values.
  • Due diligence: financial extracts with amounts and contract refs pointing to individuals.
  • Health or education data: «technical» IDs that remain personal in context.

Excel-specific technical risks

Hidden columns and sheets

Hiding ≠ deleting. Any basic user can show the ID column again.

Pivot table cache

Pivots may keep source data even after you delete the visible sheet.

Defined names and ranges

Formulas or names referencing sensitive cells outside the print area.

Re-identification by combination

Individually harmless fields (postcode + gender + role) identify people in small populations.

Properties and author

The file may expose who generated it and from which corporate path.

Which data usually needs treatment in payrolls and lists

There is no universal list: it depends on purpose. As a common EU starting point:

  • Direct identifiers: full name, national ID, social-security number, stable unique employee number.
  • Contact: personal/corporate email, phone, postal address.
  • Financial: IBAN, net/gross amounts when context allows identity inference.
  • Organizational fields sensitive in context: site, grade, seniority combined with other fields.
  • Health / affiliation / sanctions: special categories — maximize caution and legal basis.

Recommended operational method

1. Freeze the file’s purpose

Is it for publishing statistics? For a vendor to test an integration? For training new staff? Purpose decides whether you need irreversible anonymization, aggregation or controlled reversible pseudonymization.

2. Detect in cells, not only by eye

An Excel anonymizer should scan tabular values with patterns (IBAN, IDs) and contextual AI (names, addresses). Human review confirms exclusions: e.g. a product code that *looks* like an identifier but is not.

3. Decide column by column

Document in an internal control sheet which columns are deleted, masked, replaced or kept. That sheet is gold in audits and for repeating the process next month.

4. Verify like a curious attacker would

  • Unhide all sheets and columns.
  • Search for fragments of the original ID/IBAN.
  • Check file properties.
  • If pivots existed, regenerate or remove caches before distribution.

Anonymize Excel and ODS with automatic detection on EU servers.

Anonymize Excel

If the source is a PDF with tables

Many payrolls arrive as PDF. A sensible order is often: PDF → Excel (to recover structure) then anonymize the sheet. Anonymizing only the PDF may suffice for publication, but if the recipient must work with rows/columns, the tabular path is safer and more useful.

Convert tabular PDFs before anonymizing the sheet.

PDF to Excel

GDPR checklist for HR leads / DPOs

  • Purpose and legal basis documented for that export.
  • Minimum necessary fields (real minimization, not cosmetic).
  • Processor / EU location if you use SaaS.
  • Post-process verification evidence (who, when, what was searched).
  • Retention of original vs anonymized copy (different timelines).
  • Instructions to the recipient: no re-identification, no cross-linking with other databases.

How Anonimatum helps

Anonimatum handles Excel/ODS in the document anonymization flow with local AI in the EU, detection preview and batch integration when HR or finance move hundreds of files. Combine with custom patterns for internal codes.

Need patterns specific to your CBA or ERP?

Custom patterns

Talk to Politeia Soft about your payroll or list use case.

Contact