Guidance
Full text
July 2018 3 , Having regard to Article 12 and Article 22 of its Rules of Procedure, H AS ADOPTED THE FOLLOWING GUIDELINES 1 INTRODUCTION 1 These guidelines intend to clarify the use and benefits of pseudonymisation for controllers and processors. 2 The GDPR defines the term ‘pseudonymisation’ for the first time in EU law and refers to it several times as a safeguard that may be appropriate and effective for the fulfilment of data protection obligations. EU and Member State law is relying on that definition when requiring or recommending the use of pseudonymisation, see, e.g., Art. 17(1)(g) of Regulation (EU) 2023/2854 or Art. 44(3) of the European Commission’s Proposal for a Regulation on the European Health Data Space 4 . 3 Art. 4(5) GDPR defines pseudonymisation as a manner of processing with prescribed effects and calls for certain measures by which those effects are to be achieved. 4 The desired effect of pseudonymisation is to control the attribution of personal data to specific data subjects by denying this ability to some persons or parties. The GDPR does not specify who those persons or parties are to be, leaving it – absent specific requirements by other EU or Member State law – to the controller’s decision. Recital 29 makes clear that, when the pseudonymisation is carried out within the same controller, the effects might be confined to specific parts of the controller’s organisation. 5 There are three actions controllers should take to achieve the desired effect. First, they need to modify or transform 5 the data. Second, they need to keep additional information for attributing the personal data to a specific data subject separately, i.e. separate from those who are to be prevented from achieving such an attribution. Last, they need to apply technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person. In particular, they need to prevent the unauthorised use of the 3 References to “Member States” made throughout this document should be understood as references to “EEA Member States”. 4 See https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52022PC0197 . 5 The guidelines use the terms “transform” and “transformation” to refer to a modification of the data for pseudonymisation and fitness for subsequent processing in pseudonymised form. Adopted - version for public consultation 8 additional information they control and control the flow of pseudonymised data to the extent possible. 6 Pseudonymisation as a technical measure for the protection of the privacy of individuals has been around for a long time. The common understanding of pseudonymisation involves the replacement of identifiers of individuals by pseudonyms. In this process, the pseudonyms are to be chosen in a way that they do not reveal the identity of the individual they are assigned to. The legal definition presented by the GDPR differs from that understanding in three significant ways.