[nonimo]
EN
Download

Is a PPSN personal data? What to take out before you use AI

· Updated · Written and maintained by Joaquín Trapero, Nonimo

A client file is open, a chatbot is open beside it, and the only thing between the two is your judgement about what has to come out first. In an Irish office that judgement is not the same as it would be in London or in Boston, because two of the things in front of you carry rules that exist nowhere else.

One is the PPS number, which has a statute of its own sitting on top of the GDPR. The other is the Eircode, which looks like a postcode and behaves like a front door key. Both survive most attempts to clean a file up, and both are the reason a file that looks tidy is still, in the eye of the Data Protection Commission, personal data with your name on it.

This guide takes them in order: what a PPSN is in law, what the DPC says about masking, what else in an Irish document still points at one person, and what to call the thing you did when you finished. That last question matters more than it sounds, because only one of the three available words takes a file out of the law, and it is almost never the one that applies.

Is a PPSN personal data? Yes, and a second rule sits on top of that

A PPS number is allocated to one person and stays with them, which is the textbook case of the identifier that the definition of personal data is built around. The DPC’s guidance on anonymisation names an identification number in its own list of the identifiers that make someone identifiable, directly or indirectly.

So the number is personal data, and that part is the same in Dublin as in Dresden. Our guide on whether any AI tool is GDPR compliant in Ireland covers what follows from it for the tools themselves. The more useful question is whether it is special category data. It is not, and getting that right changes what you do next.

It falls under Article 87, not Article 9

Article 9 of the GDPR lists the categories that get extra protection: racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data used for identification, health, sex life and sexual orientation. A national identification number is not on that list, and no amount of common sense puts it there. That list still reaches further than it seems, because a payslip line can reveal a category nobody wrote down.

The Regulation hands the question back to each country instead. Article 87 says member states may further determine the specific conditions for processing a national identification number, and that where they do, it may be used only under appropriate safeguards. Ireland took that up.

what you are askingwhere the answer liveswhat it decides
Is it personal data?GDPR Article 4(1)whether the Regulation applies at all
Is it special category?GDPR Article 9which lawful basis you need
May I use it at all?GDPR Article 87, then Irish statutewhether you should be holding it

The third row has no British or American equivalent, and it is the one that catches people out.

Section 262 and the bodies allowed to use the number

The statute is the Social Welfare Consolidation Act 2005, and the operative part is section 262(9). A person who is not the holder of the number, not a specified body, not someone in a transaction with a specified body where the number is relevant, and not someone obliged to comply with sections 260 or 261, and who uses a PPS number or seeks to have one disclosed to them, is guilty of an offence.

The Department of Social Protection puts it plainly on its page about who can use a PPS number: only bodies specified in legislation and their agents can use it. The same page publishes the register, grouped into government departments, local authorities, educational institutions, the HSE, hospitals and a category for everyone else.

Plenty of private offices hold PPS numbers perfectly lawfully: as employers, as agents of a specified body, or inside a transaction where the number is relevant. What matters is that the entitlement is narrow, attached to a purpose, and does not travel with the document.

What that means when the next reader is a chatbot

No Irish court has ruled on whether pasting a number into a prompt is use within the meaning of section 262(9), and this guide will not pretend otherwise.

An AI provider is not a specified body, has no transaction with the person, and has no statutory entitlement to the number. So in Ireland the question goes beyond whether the file was personal data: it is also who you put the number in front of, and under what entitlement.

There is a practical answer that makes the legal one academic. Nothing you are asking the model to do gets better because the PPSN is in the prompt, which makes it the cheapest thing on the page to remove.

What the DPC actually says about masking a document you keep

The Commission’s guidance note on anonymisation and pseudonymisation is unusually direct about the exact act this guide is about, and the sentence is worth reading twice.

Masking alone often allows a very high risk of identification, and so will not normally be considered anonymisation in itself.

That is the regulator describing, in advance, the thing most people do before they paste. It is not a criticism of masking. The same guidance calls it a necessary prerequisite: it says no direct or obvious identifiers may be present in an anonymised set. Necessary, and not sufficient.

If you kept the original, that is normally pseudonymisation

The second sentence is the one that settles most real cases. The guidance says that if the source data is not deleted at the time of anonymisation, the controller who holds both the source and the cleaned version will normally be in a position to identify individuals from the cleaned version, and so the cleaned version must still be treated as personal data.

Read that against what happens in an office. You open the client file, copy a paragraph, take out the name and the number, paste the rest. The original is untouched on the server, because of course it is, and it stays there for as long as your retention policy says.

So the file you pasted was never anonymised. It was pseudonymised, by the regulator’s own definition, and the guidance adds that pseudonymisation should never be considered an effective means of anonymisation, only a measure that reduces how easily a set can be linked.

Pseudonymised data is still yours to answer for

Irish law is not neutral about the word. Section 36(1)(e)(iv) of the Data Protection Act 2018 names pseudonymisation explicitly, as one of the suitable and specific measures a controller may take to safeguard people’s rights, listed beside encryption, logging and access limits.

That is the right way to think about what you did with the marker pen. The Oireachtas thought it worth naming as a safeguard, but it does not take the data outside the law. The Court of Justice has since said as much about the firm that keeps the key.

what you didwhat it is calleddoes the file leave the law?
Hid part of a value, kept the recordmaskingno
Replaced values, kept the key or the originalpseudonymisationno
Cut the link so no one can restore itanonymisationyes

The gap between the second row and the third is the whole subject. Our guide on deidentified versus anonymized works through the vocabulary in more detail, including how the same words behave under American law.

The Eircode is the one that gets left in, and here it is a single door

Ask an Irish office what it removes before sending something out and you will hear name, PPSN, date of birth, maybe the account number. You will not hear the Eircode, because it looks like a postcode, and everyone has learned that a postcode is a neighbourhood.

In Ireland that intuition is wrong, and Eircode says so on its own page. Its explanation of what an Eircode is states that unlike other countries where postcodes define a cluster or group of addresses, here a unique code is assigned to each residential and business postal address.

35 %
of Irish addresses are shared with at least one other property, which is why the Eircode had to be unique. Eircode

The reason is in the same page. More than 35 % of addresses in Ireland are shared with at least one other property, which made shared codes useless for delivery. The fix was to give every letterbox its own seven characters: a three character routing key for the post town, then a four character unique identifier that distinguishes one address from every other in that area.

A British postcode is a street. An Eircode is a letterbox

The practical consequence is easy to state. Leave a British postcode in a paragraph and you have narrowed the field to a run of houses. Leave an Eircode and you have named one property, with no further work required by anyone.

139
postal areas in Ireland. The first three characters of an Eircode pick one of them; the last four pick a single door. Eircode

There are 139 postal areas in the country, so the routing key on its own points at a region, and Eircode notes that those areas cross county borders. Everything that narrows a document to one household is in the last four characters.

That matters most in the documents people think are safe: the anonymised complaint, the redacted attendance note, the case study for a talk. It is also the identifier most likely to survive, because it hides in signature blocks, letterheads and property descriptions rather than in the fields you check.

The organisations holding the most of them are the ones with the least room for error. Our guide on AI in Irish local authorities covers the same problem at the scale of a council’s resident records.

The lookup is public and costs nothing

The Eircode Finder, described on Eircode’s own page, is a public website that lets anyone search by address or map. So the chain from a cleaned document back to a household needs no skill, no cost and no special access. It needs a browser, and under a test that asks about means reasonably likely to be used, that is not theoretical.

What to take out of an Irish file, in order

Of the seven steps below, the first six are mechanical and a machine does most of them. The seventh is judgement, and it decides whether the first six accomplished anything. If your office is going to do this more than once, the list belongs in writing, which is what our AI policy template is for.

  1. The direct identifiers. Name, PPS number, date of birth, account and card numbers, email address, phone number, passport or licence number.
  2. The Eircode, and the address line it sits in. Treat the code as a name, because functionally it is one. The street line usually goes with it.
  3. The employer, the school and the practice. An institution plus a role identifies as precisely as a name, and in a small county it identifies faster.
  4. The dates that are not the point. An exact date of an accident, a hearing or a transaction is a lookup key against public records. A month usually does the same work in a prompt.
  5. The amounts that are not the point. A precise balance or a precise settlement is as distinctive as a serial number once it sits beside anything else in the document.
  6. The internal references. Your file number, the client reference, the matter code. These are pseudonyms already, and reusing them across documents links records together, which is the failure mode the guidance warns about.
  7. Whatever is left that only fits one person. This is the step below.

The seventh step is the one that decides it

Read what remains as if you were someone who already knows the client. Not a stranger, and not an attacker with resources. A neighbour, a colleague in the same small professional world, someone who was in the room.

The DPC’s guidance calls that reader the intruder with personal knowledge, and gives two examples of its own: a doctor who recognises a patient in an anonymised study, and the residents of a village who work out who anonymised crime figures refer to. It says special care is needed where that knowledge might reach the data.

If the paragraph still fits one person under that reading, the previous six steps did not get you where you thought. A clinical letter is the hardest case, because the story a consultant needs is the one a neighbour recognises.

What still identifies when the name and the number are gone

The DPC’s guidance is blunt about this: removing direct identifiers does not render data sets anonymous. It names three ways identification happens, worth carrying as a checklist rather than as theory: singling out, data linking and inference.

Singling out is when a unique combination of attributes distinguishes one person from a group, even though none of the attributes is a name. Linking is when your cleaned document is matched against another source. Inference is when two facts in the same document imply a third that names somebody.

None of the three needs a machine. They need a reader, and at some providers a human reviewer is part of the service, which our guide on what Google does with Gemini prompts sets out from Google’s own documents.

12,961practising solicitors in Ireland
8,827of them based in Dublin
40in Leitrim
Law Society of Ireland, Snapshot of the Solicitors' Profession 2025, published June 2026

Ireland is small enough that the village example is the normal case

The Law Society’s snapshot of the profession counted 12,961 practising solicitors at the end of 2025, of whom 8,827 are in Dublin. Leitrim has 40. Laois has 39.

Set a masked paragraph against numbers like those. A farm partnership dispute between two brothers in north Leitrim, with the year left in, is not an anonymous example to the forty solicitors practising there. It is one family, and everyone local knows which.

That is the DPC’s village, except that outside Dublin it is the default condition of Irish professional life rather than a hypothetical, and it is why a masking standard borrowed from a larger country understates the risk here.

The registers the guidance tells you to think about

An intruder might match your document against any of the following, and the Irish versions are all open or cheap to reach:

A draft from July 2026 renames the three tests

If you go looking for the technical standard behind all of this, the DPC’s note points you at the Article 29 Working Party’s Opinion 05/2014 and its three criteria. That opinion is being replaced, and the replacement is recent enough that most guidance has not caught up.

The European Data Protection Board adopted Guidelines 02/2026 on anonymisation on 7 July 2026, in version 1.0, for public consultation. They are a draft and should be read as one, but they restate the three tests with new names.

the 2014 namethe 2026 namethe question it asks
singling outNo Record Isolationis any combination of values unique to one person?
linkabilityNo Linkagecan this be matched to another source?
inferenceNo Inferencecan a value be deduced from the others?

All three have to hold before a set counts as anonymous. Violating one does not automatically make the data personal, but it does mean the analysis is not finished, and that the word you reach for should be the cautious one.

The part that matters when you are about to send something

The guidelines add a point that lands on the act of pasting. Anonymity, they say, is assessed from the perspective of each relevant entity, and the means that count include means accessible only through a third party.

Paragraph 21 makes it concrete. If it is reasonably likely that you can transfer the data to a third party, and it cannot be ruled out that the recipient has the means to identify the person, the data should be considered personal for that transfer and for everything the recipient does with it afterwards. The transfer, they add, also makes the information indirectly personal for the sender.

So it is not enough for your cleaned paragraph to be anonymous on your screen; it has to be anonymous on the recipient’s too, and the recipient here is a company holding a great deal of other data.

Your professional body says anonymise. Your regulator says that is not what you did

The Law Society of Ireland publishes an AI use policy template for Irish firms to adopt, and it is a sensible document. Its prohibited uses list is short and specific, and the first entry covers entering personal data, confidential client information or trade secrets into public AI tools.

Its staff checklist is shorter still. Before using any AI tool, it asks whether you are about to enter personal data or confidential information, and if so it says stop: use an approved enterprise tool, or anonymise the data.

That instruction is right in substance and loose in one word, and the looseness is worth naming rather than quietly following. What a solicitor does to a document with a marker pen is not anonymisation in the sense the DPC uses, and the policy’s own permitted uses list knows it: the line about analysing datasets says anonymised or pseudonymised.

Prohibited

Entering personal data, confidential client information or trade secrets into public AI tools.

The staff checklist

About to enter personal data? Stop: use an approved enterprise tool, or make the data anonymous first.

Permitted with approval

Analysing anonymised or pseudonymised datasets.

What the Law Society's AI use policy template says about personal data, in its own lists

What the policy actually permits, read carefully

Read together, the template is consistent. Analysing anonymised or pseudonymised datasets sits under permitted with approval rather than permitted outright, which is the right place for work that stays inside the Regulation.

The practical reading is therefore: clean the document, call the result pseudonymised, get the approval the policy asks for, and keep treating the file as personal data. The Law Society’s general guidance on generative AI, issued on 12 November 2025, makes the same point about confidentiality and competence in broader terms.

If your firm is adopting the template, the section that needs the most local thought is the list of approved tools, and our comparison of the four assistants against Irish criteria is written for that job.

If you are a processor, disclosing without authority is an offence

Most guidance on this stops at administrative fines. Irish law does not, and small offices rarely hear about the distinction, not least because a criminal penalty is not the kind of loss a policy pays for. Our guide to what cyber cover in Ireland actually pays for goes through where that line falls.

Section 144 of the Data Protection Act 2018 says personal data processed by a processor may not be disclosed by that processor, or by its employee or agent, without the prior authority of the controller. Knowingly or recklessly breaching that is an offence, punishable on indictment by a fine of up to 50,000 euro or five years, or both.

Section 145 covers the adjacent case: obtaining personal data without authority and disclosing it, with the same penalties, and further offences for selling or offering to sell data obtained that way.

Why that changes the calculation for some offices and not others

Whether it applies to you turns on a question you may not have asked. A solicitor advising a client is usually a controller. A payroll bureau, a bookkeeping service, an outsourced HR function or an IT contractor is often a processor, acting on someone else’s instructions. An accountancy practice that runs payroll for clients is often on that side of the line, with an employee’s PPS number in every payroll query it might paste.

If you are a processor and the client’s contract does not authorise sending their data to an AI service run by a third party, then doing it is not only a GDPR problem to be resolved between organisations. There is a criminal provision with your name on it, and the penalty is written into the statute rather than left to a regulator’s discretion. The client can authorise it in advance, in the letter of engagement.

50,000
euro, the maximum fine on indictment under sections 144 and 145 of the Data Protection Act 2018, or five years, or both

Our guide on whether the EU AI Act applies to your business in Ireland covers the separate obligations that arrive from the other direction.

The regulator at the other end of the paste is the same one

Ireland is unusual here. The authority you would answer to is also the authority that supervises the company you are pasting into, for most of the European Union.

Multinational technology498
Charities and voluntary191
Public sector162
Private and financial127
DPC supervision engagements by sector in 2025, out of 1,222. Annual Report 2025

The DPC’s annual report for 2025, published in June 2026, describes its work regulating the training of generative AI models by the large technology firms based in Ireland, in its role as EU lead supervisory authority for those companies. Of its 1,222 supervision engagements that year, 498 were with the multinational technology sector, against 191 for charities, 162 for the public sector and 127 for private and financial firms.

The same report records the DPC reviewing OpenAI’s data protection impact assessment before an EU launch, and asking for a technical demonstration of how the product worked behind the scenes. That is the access an Irish regulator has to the tools on your desk.

What that changes for you, and what it does not

It does not make anything you paste lawful, and it moves your responsibility nowhere. The provider answers for what it does with the data. You answer for what you put in.

What it changes is how well documented the other side is. Much of what is known publicly about how these products handle European data comes out of Dublin, which is why our guides on what OpenAI keeps, what Anthropic trains on and which Copilot has your data rest on documents rather than guesswork.

The same paragraph, before and after

Abstractions are easy to agree with, so here is an attendance note of the kind that gets pasted into a chatbot to be tidied up. Every name and number in it is invented, and the Eircode is a reserved code that resolves to nothing.

Attending Mairéad Ní Bhriain, PPSN 4829471T, of 14 Cluain Ard, Co Leitrim, Z99 KX72, on 3 March 2026 regarding the sale of the family farm. Client’s brother Cormac disputes the 2019 transfer. Sale price agreed at 412,000 euro. Client’s employer, the community school in the town, has been notified of the hearing date.

Now the version most people would call anonymised, with the name and the number taken out:

Attending the client, of 14 Cluain Ard, Co Leitrim, Z99 KX72, on 3 March 2026 regarding the sale of the family farm. Client’s brother disputes the 2019 transfer. Sale price agreed at 412,000 euro. Client’s employer, the community school in the town, has been notified of the hearing date.

A real Eircode there would return the household on its own. The one community school in the town, the exact date, the price and the disputed year narrow it further, and together they single out one family without any of them being a name. Under the DPC’s criteria this is not anonymised data, and it is barely pseudonymised, because the identifying work was never being done by the name.

A version that would survive the seventh step reads differently: a client, a sibling dispute over a farm transfer from several years ago, a sale in the low hundreds of thousands, a hearing date pending. It answers whatever you were going to ask the model just as well, and if it goes into ChatGPT, what OpenAI then keeps of it matters a great deal less.

Where masking stops being enough

Two questions survive any amount of cleaning, and they are worth separating out.

The first is disclosure. Even a perfectly pseudonymised document has been sent somewhere it had not been before, and your obligations to tell people what happens to their data, and to be able to retrieve or delete it, follow the data rather than the name.

The DPC’s own note on AI and large language models puts the test as a question: if someone asks for access to, or deletion of, their personal data inside the AI system, can you do it?

The second is that the model may keep more than you think. The same note names memorisation, where passages of training data reappear in outputs, as an inherent risk of some models rather than a misconfiguration.

The mistake this most resembles

It is tempting to treat pasting into a chatbot as a new risk. The DPC’s own numbers suggest otherwise. It received 6,521 valid breach notifications in 2025, and 50 % of those arose from correspondence reaching the wrong recipient. Complaints rose 45 % over the same year, and the Commission’s foreword says many involved AI use by the people complaining.

6,521valid breach notifications in 2025
50 %sent to the wrong recipient
45 %rise in complaints
Data Protection Commission, Annual Report 2025, published June 2026

That is the same mistake wearing new clothes. A document reached a party it was not meant for, because the sender was moving quickly and the interface made it easy. Our guide on whether pasting client data into a chatbot is a breach works through when it has to be notified.

What Nonimo does here, and what it does not

Nonimo replaces the identifiers in a piece of text with labels before you send it, on your own machine. For the shapes that are unmistakable, an IBAN, a card number, an email address, a travel document, the substitution happens without asking, because there is nothing to judge.

National identification numbers work differently on purpose. A PPS number is detected and marked in place for you to confirm, rather than swapped in silence. A number on a page is sometimes the client’s, sometimes the firm’s own and sometimes an example in a precedent, and a tool that cannot tell those apart should not decide quietly. Every change the app makes is visible, explained and reversible.

The Irish identifiers it knows are the Irish ones: the PPS number with its check character, the Eircode, the address lines they sit in. What it produces is pseudonymised rather than anonymised, because you keep the original, and the file stays personal data. No product makes anyone compliant, and none of the four assistants is either.

What the app keeps is on our security page: the map back to the originals stays encrypted on your computer.

The question to ask before you paste

Not how much did I take out. Neither the DPC’s test nor the EDPB’s counts removals.

Ask instead whether anyone who might see this could put it back. Then ask it again as the person who already knows the client, because in a country this size that person is nearer than the framework assumes.

If the answer to either is yes, what you are holding is pseudonymised. That is a real safeguard, named in section 36 of the Act, and it is worth doing. It is simply not the thing that takes the file out of the law, and knowing the difference is what keeps you from claiming something you cannot support, whether to a client, to an insurer filling in the AI questions on a proposal form, or to the Commission.

Sources

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Is a PPSN personal data?

Yes. It is an identification number that points to one person, which is the textbook example in the definition the GDPR and the Data Protection Act 2018 share. The DPC's guidance lists an identification number among the identifiers that make someone identifiable.

Does a PPSN get the extra protection of Article 9?

No. Article 9 lists health, biometrics, religion, politics and a few others, and a national number is not among them. It sits under Article 87 instead, which lets member states add their own conditions, and Ireland has.

Who is allowed to use my PPS number?

Only specified bodies and their agents, you, anyone in a transaction with a specified body where the number is relevant, and anyone obliged by sections 260 or 261. Section 262(9) of the Social Welfare Consolidation Act 2005 makes other use an offence.

Is an Eircode personal data?

On its own it identifies a property rather than a person, but it resolves to one address through a free public lookup. Eircode states that a unique code is assigned to each residential and business address, unlike postcodes elsewhere that cover a cluster.

Does masking a document make it anonymous?

Usually not. The DPC's guidance says masking alone often allows a very high risk of identification and will not normally be considered anonymisation in itself. If you still hold the original, the result is pseudonymised and stays personal data.

What is the difference between anonymised and pseudonymised under Irish law?

Anonymised data falls outside the GDPR and the Data Protection Act 2018 entirely. Pseudonymised data does not: the link can be restored with information held separately, so it stays personal data and stays your responsibility.

Can I put client information into ChatGPT if I take the names out?

Taking names out reduces exposure but does not settle it. The Law Society of Ireland's AI use policy template prohibits entering personal data, confidential client information or trade secrets into public AI tools, and permits analysis of anonymised or pseudonymised datasets only with approval.

Do I have to report it to the DPC if I paste client data into a chatbot?

It depends on the risk to the people involved, which is the Article 33 test. The DPC received 6,521 valid breach notifications in 2025 and says half arose from correspondence reaching the wrong recipient, which is the same shape of mistake.

Who regulates ChatGPT and Google in Ireland?

The Data Protection Commission, and for much of the EU as well. Its 2025 annual report describes its role as EU lead supervisory authority for the large technology firms based in Ireland, and records 498 supervision engagements with that sector.