Skip to content
Guidance · EDPB NL LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Guidance

Full text

Pseudonymisation reduces confidentiality risks when done effectively, which presumes that the additional information referred to in paragraph 20 are subject to the measures provided in Art. 7 Rec. 26 GDPR. 8 These guidelines distinguish between the purpose of the processing of personal data according to Art. 5(1)(b) GDPR, and the objective of a safeguard like pseudonymisation employed during that processing, which consists in a certain aspect of the fulfilment of data protection obligations. Adopted - version for public consultation 11 4(5) GPDR. It does so in two ways. First, it prevents the disclosure of direct identifiers of data subjects to some or all legitimate recipients of the pseudonymised data. Second, in the event of unauthorized disclosure or access to data that has been effectively pseudonymised, pseudonymisation can reduce the severity of the resulting confidentiality risk and the risk of negative consequences of such disclosure or access to the data subjects, provided that the persons to whom the data is disclosed are prevented from accessing additional data.

How it connects

C-413/23 European Data Protection Supervisor v Single Resolution Board The European Data Protection Supervisor (EDPS) appealed a General Court judgment that annulled its decision finding the Single Resolution Board (SRB) had failed to fulfil its… First Chamber Sep 4, 2025 Pseudonymization Anonymization Personal Data
C-604/22 IAB Europe v Gegevensbeschermingsautoriteit In Case C-604/22, the Court of Justice of the European Union ruled on a preliminary reference from the Brussels Court of Appeal in proceedings between IAB Europe and the Belgian… Fourth Chamber Mar 7, 2024 IP Address Controllers Personal Data
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
C-77/21 Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority… First Chamber Oct 20, 2022 Retention Period Storage Limitation Personal Data
C-268/21 Norra Stockholm Bygg AB v Per Nycander AB In Case C-268/21, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Swedish Supreme Court in proceedings between Norra Stockholm… Third Chamber Mar 2, 2023 Retention Period Anonymization Personal Data
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest