Skip to main content

Explore Cross-Border Data Minimization

How to use this explorer

Move between stages with the arrows or the numbered stage list. Each stage shows the input it receives on the left and the output it produces on the right, with the lines that changed marked. The configuration that makes the change sits below the comparison, and the final stage shows the complete pipeline.

The 6 stages in order

  1. Tag data origin
    Record the EU region, source country, database, and extraction time before any field changes.
  2. Create a transformation record
    Write the legal basis, original PII fields, and transfer type into a GDPR transfer record.
  3. Delete high-risk fields
    Drop the name and address, and replace the date of birth with an age bucket.
  4. Hash identifiers
    Salt and hash the customer id, and reduce the email, IBAN, and IP address to coarse values.
  5. Generalize values
    Bucket the amount and truncate the timestamp to the hour while keeping the exact amount for sums.
  6. Validate anonymization
    Fail if any original PII field remains, then attest the verification in the transfer record.

Interactive pipeline

CROSS-BORDER GDPR REFERENCE

Sample records run through expanso-edge

Stage 1 of 6

Tag data origin

Record the EU region, source country, database, and extraction time before any field changes.

6HighlightsAuthored emphasis only—not a computed diff.
Copy & download

Input

{"transaction_id": "TXN-EU-2024-001842","customer_id": 50231,"customer_name": "Anneliese Vogel","customer_email": "[email protected]","customer_dob": "1987-04-12","customer_address": "Lindenstrasse 14, 10969 Berlin","iban": "DE89370400440532013000","transaction_amount": 249.9,"transaction_currency": "EUR","merchant_name": "Kaufhaus Nord","merchant_country": "DE","transaction_timestamp": "2024-01-15T13:42:07Z","ip_address": "85.214.132.117"}

Output

{Authored highlight: "_data_origin": {Authored highlight: "country": "DE",Authored highlight: "database": "transactions_eu",Authored highlight: "extracted_at": "2026-10-05T18:35:27.61303-07:00",Authored highlight: "pipeline": "eu-cross-border-compliance",Authored highlight: "region": "EU"},"customer_address": "Lindenstrasse 14, 10969 Berlin","customer_dob": "1987-04-12","customer_email": "[email protected]","customer_id": 50231,"customer_name": "Anneliese Vogel","iban": "DE89370400440532013000","ip_address": "85.214.132.117","merchant_country": "DE","merchant_name": "Kaufhaus Nord","transaction_amount": 249.9,"transaction_currency": "EUR","transaction_id": "TXN-EU-2024-001842","transaction_timestamp": "2024-01-15T13:42:07Z"}
Stage configuration01-tag-data-origin.yaml
pipeline:
  processors:
    # Step 1: Tag with source region (critical for compliance routing)
    - mapping: |
        meta archival_original = content()
        root = this
        root._data_origin = {
          "region": "EU",
          "country": env("SOURCE_COUNTRY").or("DE"),
          "database": "transactions_eu",
          "extracted_at": now(),
          "pipeline": "eu-cross-border-compliance"
        }