Serveur Design & Serveur Production illustration

Article written by Amina Belhassena, November 13, 2025

1. Why separate design and execution in an anonymization project?

In companies, sensitive data (customers, employees, transactions, healthcare) represents both a strategic asset and a major risk. Business, data, and IT teams need to manipulate this data to run tests, train AI models, or analyze trends… without compromising confidentiality.

This is where anonymization solutions such as DOT Anonymizer come into play—capable of transforming real data into coherent anonymized versions that remain usable without risk.

To ensure flexibility, security, and GDPR compliance, these solutions rely on two complementary environments: the Design Server and the Production Server.

2. The role of the Design Server: designing and testing anonymization rules

A true data laboratory, the Design Server is the environment where teams design, configure, and validate anonymization rules:

  • Identification of sensitive fields: names, addresses, card numbers, emails, etc.
  • Selection of suitable anonymization techniques (anonymization, pseudonymization, coherence).
  • Configuration of dictionaries, scripts, and transformation rules.
  • Testing and validation of results before running them on real data.

Typical users of the Design Server

  • Data and development teams experimenting with new scenarios
  • Consultants and integrators configuring the solution for a client
  • Project managers responsible for validating results before production

In short, the Design Server belongs to the Build world: it promotes innovation and quality prior to operational execution.

3. The role of the Production Server: executing processing securely

The Production Server is the secure factory of the system. This is where anonymization processes are executed on real data, in compliance with security, performance, and regulatory standards (GDPR, ISO 27001, etc.).

Characteristics of the Production Server

  • Hosted in a secure zone of the information system
  • Connected to production databases or isolated copies
  • Administered by IT and security teams
  • Integrated into automated processing chains or schedulers such as VTOM

The Production Server ensures reliable, fast, and traceable execution of anonymization processes, typically via a CLI (command-line interface) provided by DOT Anonymizer.

Transform your real data into anonymized, coherent, and fully usable data

4. Practical use cases: an architecture suited to all industries

Banking and insurance

Test and training teams need realistic data without accessing real customer information.

  • The Design Server configures anonymization scenarios.
  • The Production Server generates anonymized copies of customers and claims databases every week.

👉 Result: 100% anonymous but functionally coherent data (relationships between accounts, contracts, payments…). 

Pharmaceutical and healthcare

Patient data is extremely sensitive but essential for research and AI.

  • The Design Server defines anonymization and pseudonymization rules.
  • The Production Server applies these rules before any transfer to research environments.

👉 Objective: protect privacy while fostering medical innovation. 

Retail and e-commerce

E-commerce players test recommendation models or analyze purchase patterns.

  • The Design Server selects columns to anonymize (emails, IPs, credit card data…).
  • The Production Server runs large-scale anonymization jobs nightly to feed an anonymized data lake.

👉 Benefit: reliable analytics without exposing personal data.

5. From Build mode to Run mode: industrializing anonymization

Large enterprises organize their systems around two complementary modes: Build and Run(TOGAF).

Build Mode → Design Server

This is the preparation phase: design, test, and validate rules. Data engineers and consultants configure anonymization projects that comply with GDPR before handing them over to the Run teams.

Example: In a large bank or healthcare organization, consultants and data engineers work on the Design Server to configure compliant anonymization projects before transferring them to Run teams.

Run Mode → Production Server

This is the execution phase: processes are scheduled, monitored, and optimized. With tools like VTOM and the DOT Anonymizer CLI, anonymization integrates seamlessly into existing automation pipelines, ensuring stability, traceability, and performance.

6. A Design / Production architecture serving data governance

The Design + Production Server approach fits naturally into overall IT governance: it separates responsibilities between project teams and operations, ensures regulatory compliance, and supports controlled innovation.

In summary:

  • Design Server → creation, experimentation, validation
  • Production Server → execution, security, compliance
  • Together, they ensure reliable, industrialized, and GDPR-ready anonymization.

Want to take it a step further?

Deploy a secure, compliant, and fully automated Design / Production architecture

About the Author

Photo de l'auteur

Amina Belhassena

Solution Architect, ARCAD Software

Holder of a PhD in Computer Science and Technologies with a specialization in Big Data Processing, Amina worked for several years in various data-focused companies, where she gained solid experience in data processing, management, and value creation. She joined ARCAD Software in 2024 as a Product Manager before moving into the role of DOT Solution Architect, where she now supports clients in their data anonymization and sampling projects.