Guidance
Full text
Pseudonymisation reduces confidentiality risks when done effectively, which presumes that the additional information referred to in paragraph 20 are subject to the measures provided in Art. 7 Rec. 26 GDPR. 8 These guidelines distinguish between the purpose of the processing of personal data according to Art. 5(1)(b) GDPR, and the objective of a safeguard like pseudonymisation employed during that processing, which consists in a certain aspect of the fulfilment of data protection obligations. Adopted - version for public consultation 11 4(5) GPDR. It does so in two ways. First, it prevents the disclosure of direct identifiers of data subjects to some or all legitimate recipients of the pseudonymised data. Second, in the event of unauthorized disclosure or access to data that has been effectively pseudonymised, pseudonymisation can reduce the severity of the resulting confidentiality risk and the risk of negative consequences of such disclosure or access to the data subjects, provided that the persons to whom the data is disclosed are prevented from accessing additional data.