Skip to content
Guidance · EDPB NL LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Guidance

Full text

Pseudonymisation may be employed as one of several measures contributing to a level of security appropriate to the risk of the data processing activity, in accordance with Art. 32(1) GDPR. Pseudonymisation may lower the severity of the consequences of unauthorised access to data. No one in the pseudonymisation domain, who accesses the pseudonymised data without authorisation, should be able to easily use the data to the disadvantage of the data subject, unless they also manage to (illegitimately) access the relevant additional information needed for attribution. Controllers and processors still have to provide a level of security appropriate to the remaining risks involved in the processing of the pseudonymised data. For processors this includes, as per Art. 28(1) GDPR, providing sufficient guarantees that appropriate technical and 12 For example, Italian law mandates pseudonymisation in the course of the processing of genetic and judiciary data. 13 Cf. Article 29 Working Party, Opinion 06/2014 on the notion of legitimate interests of the data controller under Article 7 of Directive 95/46/EC, p42-43 . 14 See also Recital 50 GDPR for further context. Adopted - version for public consultation 16 organisational measures to ensure this level of security are implemented. The use of pseudonymisation for reducing security risks is illustrated in Example 6 in the Annex.

How it connects

C-77/21 Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority… CJEU ·First Chamber Oct 20, 2022 Retention Period Storage Limitation Personal Data
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… CJEU ·Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
ROT 25/7371 ING Bank N.V. (the controller) is a bank In 2022, several data subjects brought a complaint to the DPA regarding the controller’s contactless payments. The data subjects requested the controller to issue debit cards… ROT 25/7371 ·Rb. Rotterdam Jun 24, 2026 Personal Data Integrity and Confidentiality Principle Controllers
C-604/22 IAB Europe v Gegevensbeschermingsautoriteit In Case C-604/22, the Court of Justice of the European Union ruled on a preliminary reference from the Brussels Court of Appeal in proceedings between IAB Europe and the Belgian… CJEU ·Fourth Chamber Mar 7, 2024 IP Address Controllers Personal Data