Privacy & Data Protection

PII sanitization

PII sanitization removes or replaces personal information before data is shared or sent to an AI tool, so it stays useful without identifying anyone.

PII sanitization is the process of finding personally identifiable information in text, documents, or datasets and removing or replacing it before the data moves somewhere less trusted: a vendor, a test environment, a public AI tool. Done well, the result still supports the task (a summary, an analysis, a draft) without exposing who it is about.

Common techniques, from least to most reversible: deletion removes the value outright; masking hides part of it (***-***-286); redaction replaces it with a label such as [NAME] or [SIN]; generalization coarsens it (an age range instead of a birthdate); pseudonymization or tokenization swaps in a consistent stand-in that can be mapped back under control. Synthetic substitution replaces real values with realistic fake ones, so formats and downstream steps keep working.

PHI sanitization applies the same idea to health information, with a higher bar. Under HIPAA, health data counts as de-identified either when 18 specified identifiers are removed (the Safe Harbor method) or when an expert determines the re-identification risk is very small. Canadian health privacy laws such as Ontario's PHIPA apply to identifying health information, which is why de-identification matters there too.

For AI prompts, sanitization has to happen before submission. Once a prompt is sent, the data sits under the AI vendor's retention and training terms and can't be recalled. The practical pattern is to detect names, ID numbers, account details, and health data in what is pasted or uploaded, replace them with placeholders, and let the request proceed.

Sanitization reduces risk; it doesn't eliminate it. Free text can identify someone through context (a rare diagnosis, a job title in a small town), and combinations of harmless-looking fields can single a person out. Treat sanitized data as lower risk, not as anonymous, unless it has been assessed as such.

Where this shows up

Related terms

See it in your own organization.

Sanitized Ai inventories the AI tools in use and redacts sensitive data from prompts before it leaves.

Get a demo