I must give certain employees access to a report which contains email addresses. I would like to redact or partially mask these email addresses, but I am having trouble finding official guidance on how to properly mask email addresses so that they cannot be de-anonymized.
From googling, I can see others are going with masked addresses in the following formats (assuming the email address to be masked is firstname.lastname@provider.com):
f***e@provider.com.au
f***e@p***r.com.au
f***e@p***r.***
I'm concerned that none of the information I'm finding is official, and I have no idea if this will stand up to an audit.
Can anyone point me to official guidance on how to partially mask email addresses so that they are no longer considered to be PII by the GDPR, please?