Replacing a customer’s name with an ID does not necessarily make a support record anonymous. If the business can connect that ID back to the person, the link still exists.
That distinction matters when preparing iGaming support examples for an AI assistant. A file labelled “anonymous” may still contain information that identifies someone.
Pseudonymised means the link is separated
Pseudonymisation replaces or transforms identifying information while keeping the additional linking information separately protected. For example, a record might use Customer 4711 instead of a name, with the matching table stored elsewhere.
Under the ICO’s UK guidance, the record remains personal data in the hands of someone holding that additional information. Its status for another recipient requires considering whether that recipient can identify the person. Pseudonymisation reduces risk; it is not an automatic exemption from data-protection duties. See the ICO’s explanation.
Anonymous means people are no longer identifiable
Effective anonymisation asks whether someone is identifiable, including through information combined from other sources. Removing direct identifiers alone may leave revealing details. The ICO’s introduction explains this threshold in the UK framework.
Consider a fictional support note: “Customer 4711 contacted us at 09:14 about a €127.43 payment.” The matching account table could directly reveal the person. An exact time plus an unusual amount might also narrow the possibilities when compared with other records.
Changing the name to an ID has changed one field. It has not established that nobody can reconnect the remaining details.
Start with what the AI task actually needs
If the task is to test whether a help assistant explains a policy clearly, a fully invented scenario may be sufficient. Our example could become: “A fictional customer asks what information support needs to investigate a payment.”
That test contains the question without copying a real customer’s history. It would not, however, establish whether the assistant handles all the complexity of real cases. State what the test covers.
NIST’s de-identification guidance treats this as a process involving disclosure risk, useful analysis & governance. It warns that tools which merely mask information may not be sufficient. Although written for government datasets, that technical distinction is useful here.
Follow the data through the whole system
For any proposed use of real records, establish what enters prompts, document indexes, logs & backups; who can access it; how long it is kept; & what deletion covers. Check the actual service settings & agreements instead of assuming every AI provider handles data identically.
A changed label is easy to see. A defensible explanation of who can still identify a person requires examining the remaining information & the surrounding system.
Sources checked 14 September 2026. The ICO marks this guidance as under review. This explains technical distinctions, rather than determining compliance for a particular business or jurisdiction.



Discussion
Ask a question, add useful context or share a source. Keep it relevant & respectful.
Comments are reviewed before publication.