Datasets

Personal data

How people are taken out of records before they reach Mora, and what Mora refuses.

Records must not name anyone. The provider's agent takes people out before sending; Mora checks every batch.

The rule

Replace every personal value with a generated id, and use the same id each time the same person appears. Records still link up, and nobody is named.

json
{ "ticket_id": "T-88412", "customer": "Dana Whitfield", "phone": "+1 415 555 0134", "complaint": "no heat on first floor" }

becomes

json
{ "ticket_id": "T-88412", "customer": "p_7f3a91", "complaint": "no heat on first floor" }

In the schema, mark the field:

json
{ "name": "customer", "type": "id", "about": "Who called", "personal": "replaced" }

What Mora refuses

submit_records scans every value of every record. A batch holding any of these is refused whole, and nothing from it is kept:

Found Example
An email address dana.w@example.com
A phone number +1 415 555 0134
A card number 4242 4242 4242 4242
A social security number 078-05-1120

The answer says where and what kind, never the value:

text
Nothing was kept: personal data is still in this batch.
record 3, field "text" looks like an email address.

What the scan cannot see

Patterns do not catch a bare name such as "Dana Whitfield". Replacing names is the agent's job, and a person at Mora reads every sample before a listing goes live.