Anonymisation for image, audio and video data
Protecting participant privacy in audio and visual data
Image, audio and video data, including photographs, filmed interviews, observational footage, audio recordings, drawings, participant-created materials and other visual artefacts, often contain potentially identifying information that is intrinsic to the data itself. For example, faces, voices, distinctive environments and contextual enable individuals to be recognised. Even drawings and sketches can reveal identity through written labels, recognisable places, or unique lived experiences.
Anonymising multimedia data therefore requires careful judgement. In many cases, technical modification alone may not be sufficient, and governance arrangements form an important part of responsible sharing.
Direct identifiers may include:
- facial features
- voice characteristics
- written names within images or drawings
- signatures.
In drawings or participant-generated visuals, direct identifiers may appear as written labels, depictions of named locations, or identifiable personal details embedded within the image.
Even where explicit identifiers are removed, contextual elements may enable identification. These may include:
- recognisable community settings
- unique life events depicted visually
- distinctive uniforms or clothing
- accent or speech patterns in audio
- visual representation of a specific local layout.
Visual masking and editing
Techniques such as blurring, pixelation, cropping or obscuring parts of an image may reduce identification risk.
However:
- Extensive masking can significantly reduce analytical value.
- Background elements may remain identifying.
- Poorly applied masking may be reversible or ineffective.
For drawings or scanned visual materials, editing may involve removing written names, redrawing elements, or cropping identifiable sections. Care should be taken not to distort the meaning of the original material.
Audio editing
Bleeping names or altering voice pitch may reduce identification risk.
However:
- Voice alteration may compromise research usefulness.
- Speech patterns or contextual information may still enable identification.
- Extensive editing can be labour-intensive and may alter meaning.
Transcription or descriptive summaries
In some cases, sharing anonymised transcripts or structured descriptions of audio-visual material may be more appropriate than releasing original audio or video files.
Where this approach is used:
- The relationship between the original and the derived material should be documented.
- It should be clear that transcripts or summaries are not verbatim or complete representations.
- Decisions should be recorded in an anonymisation log.
When governance is more appropriate than editing
For many audio-visual datasets, particularly those involving identifiable individuals, anonymisation through technical modification may not sufficiently reduce risk.
In such cases, alternative approaches may be more appropriate, including:
- Ensuring participants understand the risks of disclosure and agree for the data to be shared even with these risks
- Sharing under strict access conditions such as limiting access to accredited users
- Withholding particularly sensitive material from the collection.
Note, consent to share identifiable material does not remove the need for risk assessment. Even where participants agree to identifiable sharing, data producers should consider foreseeable risks and apply proportionate safeguards.