Pseudonymiser

A JSC Workshop tool · Form JSC-02 · Rev. 2026-07

Swaps the real names, ID numbers and dates in a spreadsheet for made-up ones, so you can send it to your accountant or consultant without handing over anyone's personal details.

NOTHING LEAVES THIS COMPUTER. This page does all its work in your browser, and works with the internet off. No uploads, no servers, no copies. Close the tab and it forgets everything.

Don't take our word for it: turn your Wi-Fi off and carry on. Nothing here stops working.

No internet needed
EXAMPLE MODE: every name, number and date on this page is made up.
Step 1 of 3

Choose the spreadsheet

Excel (.xlsx, .xls) or CSV. A row of column headings above the data works best; if the table starts lower down, the tool finds it.

No file loaded yet
New here? Load a made-up staff list and watch every step work, including the download, before your own file goes anywhere near it.
Step 2 of 3

Check each column

We've already had a go at labelling every column. Look down the list and change any that seem wrong. "Keep as is" keeps a column, though any name already being swapped elsewhere gets swapped inside its text too. The same real name always becomes the same fake name, on every tab, so your data still lines up afterwards.

(change this if the table starts lower down)
This tab reads like a label-and-value sheet (labels down the first column, like an invoice), not a table. Column labels make no sense sideways, so the safest handling is row by row, each value treated by its own label.
Step 3 of 3

Check the result

This is your data after the swap. The fake names, IDs and dates you see are exactly what the file will contain. Flip to BEFORE and compare: you are checking that each column is handled right, and the same treatment then applies to every row, not just the few shown here. Figures get a fresh nudge at download but still add up, and dates keep the gaps between them. Want the exact detail? Open "How each change works" below.

first rows after the swap
How each change works
Numbers
Nudged up to 15 percent either way, keeping their size. Very small whole numbers and rates (a headcount of 3, a 0.5 rate) are nudged by one unit instead, which can exceed 15 percent, so the exact real value never shows through. The figures above get one more fresh nudge when you download; the swapped names, IDs and dates do not change.
Dates
Shifted by a secret number of days (different for each file), keeping their format. Month and week labels shift by whole months or weeks; anything the tool cannot read as a number or date is removed rather than left in.
Years and quarters
Bare years and quarters (2026, Q3 2026) are deliberately kept: the shift moves days, weeks and months, not reporting periods.
ID numbers
Keep their exact format but become random, reversible only with the key.
Row order
Rows are shuffled while "Shuffle the rows" is ticked; if the file's structure stops the shuffle moving much, the tool says so after you download.
Columns you keep
Scanned for obvious identifiers (emails, phone numbers, postcodes, NI numbers, name-shaped text), and any name already being swapped elsewhere is swapped inside kept text too. A scanner cannot read meaning, though.
Other tabs
All sheets are processed on download; check each tab here first.

The one thing the tool cannot do for you: read kept free text yourself before sending it.

This file keeps a running balance. Two honest ways to handle it; pick one:

This key matches the fake names back to the real ones. It is for your eyes only. Send the pseudonymised file; keep this key. Never send them together.

Straight talk: because this key exists, the result is a much safer working copy, not a legal guarantee the data is fully anonymous. Whether it counts as anonymous in someone else's hands depends on what else they already know. Run the same file again another day and the fakes will all be different, so a follow-up file will not line up with this one. Read any notes shown after you download before you send anything on.