Skip to content
Guidance · EDPB NL LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Guidance

Full text

July 2018 3 , Having regard to Article 12 and Article 22 of its Rules of Procedure, H AS ADOPTED THE FOLLOWING GUIDELINES 1 INTRODUCTION 1 These guidelines intend to clarify the use and benefits of pseudonymisation for controllers and processors. 2 The GDPR defines the term ‘pseudonymisation’ for the first time in EU law and refers to it several times as a safeguard that may be appropriate and effective for the fulfilment of data protection obligations. EU and Member State law is relying on that definition when requiring or recommending the use of pseudonymisation, see, e.g., Art. 17(1)(g) of Regulation (EU) 2023/2854 or Art. 44(3) of the European Commission’s Proposal for a Regulation on the European Health Data Space 4 . 3 Art. 4(5) GDPR defines pseudonymisation as a manner of processing with prescribed effects and calls for certain measures by which those effects are to be achieved. 4 The desired effect of pseudonymisation is to control the attribution of personal data to specific data subjects by denying this ability to some persons or parties. The GDPR does not specify who those persons or parties are to be, leaving it – absent specific requirements by other EU or Member State law – to the controller’s decision. Recital 29 makes clear that, when the pseudonymisation is carried out within the same controller, the effects might be confined to specific parts of the controller’s organisation. 5 There are three actions controllers should take to achieve the desired effect. First, they need to modify or transform 5 the data. Second, they need to keep additional information for attributing the personal data to a specific data subject separately, i.e. separate from those who are to be prevented from achieving such an attribution. Last, they need to apply technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person. In particular, they need to prevent the unauthorised use of the 3 References to “Member States” made throughout this document should be understood as references to “EEA Member States”. 4 See https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52022PC0197 . 5 The guidelines use the terms “transform” and “transformation” to refer to a modification of the data for pseudonymisation and fitness for subsequent processing in pseudonymised form. Adopted - version for public consultation 8 additional information they control and control the flow of pseudonymised data to the extent possible. 6 Pseudonymisation as a technical measure for the protection of the privacy of individuals has been around for a long time. The common understanding of pseudonymisation involves the replacement of identifiers of individuals by pseudonyms. In this process, the pseudonyms are to be chosen in a way that they do not reveal the identity of the individual they are assigned to. The legal definition presented by the GDPR differs from that understanding in three significant ways.

How it connects

C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
1 As 183/2023-62 Health insurer must disclose aggregated patient treatment data under Free Access to OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free… Supreme Administrative Court Aug 4, 2026 Pseudonymization Anonymization Personal Data
C-77/21 Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority… CJEU ·First Chamber Oct 20, 2022 Retention Period Storage Limitation Personal Data
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… CJEU ·Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
C-446/21 Maximilian Schrems v Meta Platforms Ireland Limited In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR… CJEU ·Fourth Chamber Oct 4, 2024 Retention Period Personal Data Marketing
C-413/23 European Data Protection Supervisor v Single Resolution Board The European Data Protection Supervisor (EDPS) appealed a General Court judgment that annulled its decision finding the Single Resolution Board (SRB) had failed to fulfil its… CJEU ·First Chamber Sep 4, 2025 Pseudonymization Anonymization Personal Data