What is PII and why is it a risk?
PII (personally identifiable information) is data that identifies a person directly or indirectly: name and surname, national ID (FIN), ID card number, phone number, address, card number.
This data appears in request texts, call transcripts and documents. Sent as-is to an external cloud AI service, it can leave the organisation.
What does the law require?
The Law of the Republic of Azerbaijan “On Personal Data” sets rules for collecting, processing and protecting personal data and grants rights to data subjects. Organisations must ensure a lawful basis, a defined purpose and security measures for processing.
Which requirements apply to a specific project should be confirmed with a lawyer; technically, the most reliable approach is to keep personal data from reaching the external service at all.
How does anonymisation work?
The anonymiser finds personal data in text with a named-entity recognition (NER) model and replaces it with placeholders such as [NAME_01] or [FIN_01]. Only masked text is sent to the AI service.
When the answer returns, placeholders can be restored to the original values for authorised users; every restoration is written to an audit log.
What matters for Azerbaijani?
General NER models often miss Azerbaijani names, address formats and local identifiers such as the FIN. The anonymiser must therefore be trained and tested on Azerbaijani text and local document formats.
Ideally the solution runs inside the organisation. An anonymiser that runs on standard CPU servers can be deployed in-house without GPU infrastructure.