You and I can replace every customer name in a test database and still leave the company exposed, because the same customer may appear in a payment table and a support export, the test breaks when each system assigns a different substitute, and the privacy control fails when the lookup key sits beside the output.
โ
Section 8(5) of the Digital Personal Data Protection Act, 2023 requires a Data Fiduciary to protect personal data through reasonable security safeguards. Rule 6 of the Digital Personal Data Protection Rules, 2025 names measures such as encryption and masking. A review therefore has to test discovery and replacement. It must also test key separation, access and evidence.
โ
The Schedule to the Digital Personal Data Protection Act, 2023 permits a penalty of up to โน250 crore for a breach of Section 8(5), yet the purchase decision still turns on proof, because a product claim does not show that the buyer separated keys, checked the output or retained an approval record.
โ
My shortlist is Redacto for an India-first DPDPA control record. Tonic Textual fits mixed document pipelines. IRI FieldShield fits teams that need deterministic masking across database estates. None removes the need for a DPO or security owner to approve purpose, access, and re-identification rules.
โ
Disclosure: Redacto is our product and appears in this assessment. The same evidence criteria apply to every entry.
โ
โ
I treated this as a vendor assessment. A demo that swaps names is easy. The harder question is whether the vendor can preserve joins without letting every operator reverse the result. I also checked whether the output can move into testing or analytics with a record that security and privacy teams can review.
โ
โ

Redacto joins pseudonymisation to the privacy control around it, starting with AI-Driven Data Discovery & Mapping and moving into Anonymization & Pseudonymization, while Audit & Reporting retains the record of what ran and why.
โ
That sequence matters during vendor assessment because the buyer needs to see where the original value sits, who can reverse a token and which purpose allowed the run. Redacto fits teams that want this evidence beside consent and PIA records, with ROPA and vendor risk work in the same operating model.
โ
โ
Redacto is quote-based under a licence model. No published โน0 free plan or trial exists.
โ
โ
โ
Choose Redacto when the control owner needs to trace a DPDPA obligation into a data workflow and its evidence, but consider an incumbent suite when a global group needs deep multi-law coverage, because that work reaches beyond Redactoโs India-first scope, and buyers needing public self-service pricing should keep looking.
โ
โWho should not choose Redacto: a buyer that needs one product for many privacy laws.
โ
โ
Tonic Textual detects entities in files and text, then either redacts them or replaces them with reversible tokens. A pipeline can process PDF and DOCX alongside CSV, JSON and image formats, using Python or REST.
โ
This fits support transcripts and document corpora, but the assessment still has to inspect model misses and verify that the same person receives a stable token across files when that link matters.
โ
โ
Tonic Platform Plus starts at $29 per month with $25 in usage credits. Textual usage is metered per 1,000 words and needs a quote. No separate free plan or trial is published for Textual.
โ
โ
โ
Tonic Textual makes sense when the main risk sits in tickets, reports or AI corpora, because its documented entity detection and reversible tokenisation cover document de-identification, while Redacto connects pseudonymisation to a wider DPDPA control record, including the approval evidence around that treatment.
โ
โ
IRI FieldShield works on fields in databases and files, where it can hash or tokenise values and apply encryption. It can also randomise or replace values, while deterministic functions preserve the same substitute across related records so a test copy keeps its joins.
โ
Its host-based licence changes the review because the buyer has to count where jobs run, inspect key management and account for the extra dev or test engine required for remote production work.
โ
โ
IRI FieldShield starts in the low five figures for a perpetual production licence. It has no published $0 free plan or trial. A discounted dev or test engine is required for remote jobs and maintenance costs 20% of the licence base after year one.
โ
โ
โ
The tool fits an enterprise with a mixed database estate and a need for repeatable values, since its documented field methods include hashing and tokenisation, alongside encryption and replacement, while Redacto gives the privacy owner a wider DPDPA workflow.
โ
โ
DataMasque replaces sensitive values while it builds a test or development copy, so the result keeps a useful shape without carrying source identifiers. It targets databases and files, plus SaaS data across cloud or on-prem environments.
โ
The product describes its replacement as irreversible, which can lower re-identification risk but rules it out when an approved workflow needs to restore identity later.
โ
โ
DataMasque starts at $49 per hour on AWS or Azure. Business and Enterprise licences are quote-based for unlimited runs. No $0 plan or trial limit is published.
โ
โ
โ
DataMasque fits a team that wants safe test copies and does not need reversal, while a research workflow that must reconnect approved records needs another method, and its $49 hourly entry makes a pilot easier to model, even when the later enterprise quote remains unknown.
โ
โ
Presidio separates detection from treatment, using the Analyzer to find an entity through recognisers and context. The Anonymizer can replace or redact the value, while also supporting hashing and masking, and its encryption can later be reversed with the key.
โ
Because it is a toolkit rather than a managed control, the buyer becomes the operator and owns model tuning, key custody and the evidence needed to monitor the service.
โ
โ
Microsoft Presidio costs $0 under Apache 2.0. That licence is the free plan and no hosted trial is included. Infrastructure and engineering costs sit with the buyer.
โ
โ
โ
Presidio fits a team that can own code and operations, since it has no licence fee but leaves engineering work with the buyer, and its documented Python and Docker options support an embedded text service, while Redacto links the control to DPDPA records.
โ

ARX transforms tabular data through generalisation and suppression, then applies privacy models that measure utility and re-identification risk, helping a team decide how much detail can remain in a research dataset.
โ
ARX is not a token vault, so a buyer looking for reversible pseudonyms should assess another option. It fits a release assessment where the output may become anonymous after risk tests.
โ
โ
ARX costs $0 under Apache 2.0. That licence is the free plan and no hosted trial applies. The buyer funds hosting and specialist work.
โ
โ
โ
ARX fits health or research teams that must test disclosure risk before data release, but an application that needs reversible identity at runtime requires another method, and pairing ARX with a privacy workflow can retain the release decision, its owner and the supporting evidence.
โ

MOSTLY AI learns patterns from source data and produces new records, without relying on a one-to-one token lookup. Teams can use the result for testing and analysis when direct record continuity is not required.
โ
Synthetic data still needs assessment because the buyer has to test rare records and leakage, then compare distributions so the dataset remains useful for its stated purpose.
โ
โ
MOSTLY AI has a $0 free tier with two credits each day. Enterprise plans use quote-based usage pricing and no public paid entry rate is published. The free tier provides the trial route.
โ
โ
โ
MOSTLY AI fits teams that can replace production records with synthetic ones, because its documented model generates new records without a one-to-one token lookup, but an approved user cannot restore a source identity from that mapping, so the purpose has to allow that break.
โ

Greenmask sits in a logical database dump flow, transforming values before the output reaches storage or restore. Deterministic functions can keep a substitute stable, while subsetting reduces the amount of production-shaped data copied into a test environment.
โ
Its narrow scope can help a PostgreSQL team. It becomes a limit when the review covers documents, SaaS exports or many database engines.
โ
โ
Greenmask costs $0 under Apache 2.0. That licence is the free plan and no hosted trial is published. Enterprise support is available by contact.
โ
โ
โ
Greenmask fits a PostgreSQL team that wants masking inside a dump and restore path, but it will not cover the wider vendor register or privacy evidence by itself, while a small pilot can still test transformation rules, role boundaries and restore behaviour without licence spend.
โ

PostgreSQL Anonymizer applies security-label rules to database columns, with support for static masking and dynamic masking, as well as anonymous dumps. Its functions include substitution and faking, plus partial scrambling and pseudonymisation.
โ
Keeping rules near the database can simplify enforcement. It also concentrates responsibility in the database team. The pilot should inspect role boundaries and rule changes before relying on it.
โ
โ
PostgreSQL Anonymizer costs $0 under the PostgreSQL licence. That licence is the free plan and no hosted trial is included. Operations and support costs sit with the buyer.
โ
โ
โ
PostgreSQL Anonymizer fits a database team with a bounded PostgreSQL estate, while Greenmask adds test-data subsetting and Presidio covers text, and Redacto provides the wider India-first control context, including evidence that sits outside the database.
โ
Start with reversibility. If no approved purpose requires identity to return then irreversible masking or synthetic data can reduce risk. If a fraud analyst or care team must restore identity then define the role and key path before selecting a product.
โ
Next trace one record across systems. Use a customer who appears in CRM and billing, then follow that person into support and analytics. Ask each vendor to show the same substitute where joins matter. Then ask it to break the link where the purpose changes.
โ
Finally request evidence. The proof pack needs the discovery result and approved policy. Add the transformation version, key owner and run log. Keep exceptions beside the validation result. Section 8(5) of the Digital Personal Data Protection Act, 2023 sets the safeguard obligation. The official DPDP Act text and the notified DPDP Rules, 2025 should anchor the control review.
โ
Pick one non-production copy this Monday. List every direct identifier and three quasi-identifiers in it. Name the person who can reverse a pseudonym. Then ask that owner to produce the last transformation log and approval record.
โ
If any part is missing then you have the first requirement for your vendor assessment. Redacto can connect that requirement to discovery, PIA, ROPA, vendor risk, and audit evidence. The DPO and security owner still decide the purpose and the reversal boundary.
โ

