Scrub PII from HR and Employee Data Before AI

Remove SSNs, IBANs, and employee email addresses from HR documents before AI processing. Protects employee privacy under GDPR, CCPA, and CPRA.

ZERO UPLOAD · ALL LOCAL
  1. Paste your original prompt or code into the input box - detections appear instantly in the Variables section.
  2. Review the detected items in the Variables JSON and the Scrubbed Output textarea with safe placeholders like [IP_1].
  3. Use the Download Variables buttons to save the mapping as JSON or CSV for later restoration.
  4. Copy the scrubbed text and paste it into your AI tool.
  5. Switch to the Restore tab, paste the AI response, upload your variables file, and the restoration happens automatically.

Worked examples for this use case

Performance review prep with employee contact details

Before
Draft a performance review for Sarah Chen ([email protected], employee ID E-10042). Salary: $95,000. Rating: Exceeds Expectations.
After
Draft a performance review for Sarah Chen ([EMAIL_1], employee ID E-10042). Salary: $95,000. Rating: Exceeds Expectations.

Payroll record with bank details

Before
Process final paycheck for Tom Garcia (SSN: 234-56-7890, IBAN: DE89370400440532013000, personal email: [email protected]).
After
Process final paycheck for Tom Garcia (SSN: [SSN_1], IBAN: [IBAN_1], personal email: [EMAIL_1]).

ORIGINAL PROMPT

SCRUBBED OUTPUT

VARIABLES

Scrub PII from HR and Employee Data Before AI

HR data is some of the most legally protected information an organization holds. Employee records combine direct identifiers such as name, SSN, tax ID, and bank account details with employment status, salary, performance ratings, and disciplinary history. Using AI tools to assist with HR tasks such as drafting performance reviews, analyzing salary bands, and preparing termination notices routinely exposes this data if the relevant fields are not removed first.

The scrubber removes the identifiable financial and contact fields from HR text before it reaches any AI provider. The employment context, the policy language, and the structural content that makes an HR document useful for AI assistance remain intact, and only the data that makes an individual identifiable is replaced with tokens.

HR data types the scrubber addresses

HR documents contain two categories of sensitive fields. Direct identifiers: email addresses (work and personal), phone numbers, Social Security Numbers, and IBAN bank account numbers for payroll. Financial identifiers: salary figures are not detected by pattern (they are plain numbers without a distinguishing format), but IBANs and credit card numbers in expense reports are caught. Furthermore, internal HR system hostnames (.hr.corp, .people.internal) and external personal email addresses (Gmail accounts used in onboarding documents) appear in HR records and are detected by the domain and email patterns respectively.

Employee names and unstructured PII in HR documents

Employee names are the most common PII type in HR documents and the one the scrubber cannot detect by pattern. Names are too variable to distinguish reliably from other text without natural language processing. For HR documents that require name removal, replace full names with role titles or employee IDs before pasting into the scrubber. This manual step combined with the scrubber's pattern detection covers the full range of HR PII: names are handled manually while emails, phone numbers, SSNs, and bank accounts are handled automatically.

Common HR AI use cases that involve PII

Performance review drafting is the most common HR AI use case and the one most likely to involve employee identifiers if the manager pastes the employee's record directly. Salary benchmarking queries often include the employee's current compensation and contact email. Disciplinary documentation sometimes includes the employee's personal email and phone for formal notice purposes. Building on this, termination notice drafting and severance calculation queries can include SSNs and bank account details for final payroll processing. Each of these is a scenario where a simple pre-paste scrub eliminates the identifiable fields before the AI sees the document.

Onboarding document preparation is another frequent use case that HR teams overlook. When a new hire's intake form contains their SSN, personal email, home address, and emergency contact phone number, pasting that form into an AI tool to generate a welcome packet or benefits summary exposes all of those identifiers. Scrubbing the intake form before the AI step lets the tool generate the structural content, such as benefits explanations and IT setup instructions, without receiving any of the new hire's personal data.

Employment law and data protection obligations

Employee data is subject to multiple overlapping protections: GDPR for EU employees who are data subjects with full rights, CCPA for California employees as extended by the CPRA in 2023,1 and various state labor laws governing employee privacy. Yet the most immediate risk is practical rather than legal: employee data sent to an AI provider can persist in that provider's systems under their data retention policy, creating a trail of sensitive HR records that the organization cannot audit or delete.2 Removing identifiable fields before the prompt eliminates this practical risk regardless of the specific legal framework.

Several US states have enacted employee-specific privacy laws that go beyond CCPA. Illinois BIPA requires informed consent before collecting biometric data, which includes fingerprints used for time-clock systems.3 New York's SHIELD Act requires reasonable security safeguards for private information, including employee SSNs and financial account numbers.4 When HR teams in these jurisdictions use AI tools for tasks involving biometric or financial data, the scrubber provides a technical control that satisfies the data minimization requirements embedded in these state laws.

EU employee GDPR rights and what HR teams must prepare for

EU employees are data subjects under GDPR with full rights over their personal data held by their employer. The right of access (Article 15) entitles any employee to request a copy of all personal data the employer holds about them. For HR departments that have used AI tools to process employee personal data, a data subject access request triggers an obligation to include any AI interaction records in the response if those records contain the employee's personal data and are still retained by the AI provider.

When personal data has been sent to an AI provider through unscrutched prompts, the employer may not be able to comply fully with an Article 15 DSAR because they cannot retrieve what the AI provider holds. AI providers with standard-tier agreements typically do not provide per-user data retrieval capabilities that satisfy Article 15 requests.5 Scrubbing employee personal data before AI submission prevents this problem: the AI provider received only tokens, which are not personal data under GDPR, so no AI provider data retrieval step is required for the DSAR response.

Responding to employee DSARs when AI tools were used in HR processes

An employee DSAR response for an HR process that used AI assistance must include documentation of what data was shared with the AI provider and under what legal basis. If a scrubbing workflow was in place, the DSAR response includes: the original data retained in the HRIS, the variables file showing what was tokenized, and a record confirming that only tokenized data reached the AI provider. This documentation demonstrates compliance with Article 5's accountability principle.6 Maintaining the variables file alongside each AI-assisted HR task record creates the audit trail needed to respond to any future DSAR with confidence.

HR AI tasks that create the highest risk for employee PII exposure

Termination notice drafting is the single highest-risk HR AI use case for employee PII. A termination notice includes the employee's name, employee ID, termination date, severance terms, COBRA information (in US contexts), and final paycheck details including IBAN or bank routing information. All of these fields may appear in the prompt if the HR professional pastes the employee record directly. A scrubbing step that removes the email, phone, SSN, and IBAN from the employee record before the prompt is constructed reduces the PII transmitted to the AI to the minimum necessary for the drafting task.

Compensation benchmarking queries using AI are a close second in risk exposure. HR professionals asking an AI to analyze compensation relative to market bands often include the full employee roster with current salary, job title, years of service, and work location. This combines multiple personal data categories (financial information under GDPR, sensitive personal information under CPRA for California employees) in a single prompt.7 For benchmarking, replace individual employee records with role-level summaries: anonymize to job family and pay quartile before the AI sees the data, rather than scrubbing individual names and SSNs from a full roster.

Structuring HR prompts to minimize identifiable content

The most robust approach to HR AI compliance is restructuring prompts to omit individual-level detail entirely. Instead of "Draft a performance improvement plan for Sarah Chen ([email protected], employee ID E-10042), who has consistently missed her Q2 quota by 30% over the past two quarters," use "Draft a performance improvement plan for a sales representative in a B2B software company who has missed quota by 30% for two consecutive quarters." The AI produces an equally useful PIP template without receiving any personal data. Reserve individual-level prompts for tasks where the employee's specific situation genuinely requires it, and apply the scrubber to those prompts before submission.

Even on individual-level prompts that genuinely need the detail, running the scrubber first removes the fields most likely to be exposed. CapyToolkit processes the record locally in your browser with no upload, so the employee's contact and financial data never reaches any AI provider, and only the variables file maps the tokens back to the real values for your own restoration.

When to use this

Use this before pasting any employee record, payroll document, performance review, or HR correspondence into an AI tool, especially when the document contains SSNs, bank account details, or personal email addresses.

Examples

Performance review prep with employee contact details

Before
Draft a performance review for Sarah Chen ([email protected], employee ID E-10042). Salary: $95,000. Rating: Exceeds Expectations.
After
Draft a performance review for Sarah Chen ([EMAIL_1], employee ID E-10042). Salary: $95,000. Rating: Exceeds Expectations.

Payroll record with bank details

Before
Process final paycheck for Tom Garcia (SSN: 234-56-7890, IBAN: DE89370400440532013000, personal email: [email protected]).
After
Process final paycheck for Tom Garcia (SSN: [SSN_1], IBAN: [IBAN_1], personal email: [EMAIL_1]).
Sources
  1. 1.

    Morgan Lewis, "California Consumer Privacy Act: Employee and B2B Exemptions Expire January 1, 2023," morganlewis.com, October 2022. https://www.morganlewis.com/pubs/2022/10/california-consumer-privacy-act-employee-and-b2b-exemptions-expire-january-1-2023

  2. 2.

    FirmAdapt, "Data Subject Access Requests Involving AI-Generated Records," firmadapt.com, May 2026. https://firmadapt.com/blog/dsar-ai-generated-records

  3. 3.

    Greenberg Traurig, "BIPA Update: Illinois Limits Liability and Clarifies Electronic Consent for Biometric Data Collection," gtlaw.com, August 2024. https://www.gtlaw.com/en/insights/2024/8/bipa-update-illinois-limits-liability-and-clarifies-electronic-consent-for-biometric-data-collection

  4. 4.

    Hunton Andrews Kurth, "New York SHIELD Act Requires Safeguards to Protect Private Information," hunton.com, March 2020. https://www.hunton.com/privacy-and-cybersecurity-law-blog/new-york-shield-act-requires-safeguards-to-protect-private-information

  5. 5.

    ICO, "How Do We Ensure Individual Rights in Our AI Systems?," ico.org.uk, accessed June 2026. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-individual-rights-in-our-ai-systems/

  6. 6.

    ICO, "Accountability Principle," ico.org.uk, accessed June 2026. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/accountability-principle/

  7. 7.

    UC Berkeley Labor Center, "Summary: Worker Rights Under the CCPA/CPRA," laborcenter.berkeley.edu, November 2023. https://laborcenter.berkeley.edu/wp-content/uploads/2023/11/Summary-Worker-Rights-Under-the-CCPA-CPRA.pdf

FAQ