Anonymization
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Irreversible removal of identifying information from data
Overview
24 sources · Jul 23, 2026Legal Framework
Anonymization is not separately defined in the GDPR, but its conceptual boundary is drawn by what falls outside the definition of personal data in Article 4(1). Data that can no longer be linked to an identified or identifiable natural person by any reasonably likely means falls outside the Regulation's scope entirely. By contrast, Article 4(5) defines pseudonymisation as a form of processing that still operates on personal data:
"the personal data can no longer be attributed to a specific data subject without the use of additional information"
— GDPR Art. 4(5)
This distinction is critical: pseudonymised data remains personal data and is subject to the full GDPR, whereas genuinely anonymised data is not. The difference hinges on whether re-identification is possible, not merely whether it is difficult.
Article 25(1) requires controllers to implement data-protection-by-design measures — explicitly naming pseudonymisation — while Article 32(1)(a) lists pseudonymisation and encryption as security measures. Neither provision mentions anonymisation directly, but both reinforce that reducing identifiability is a structural obligation, not an afterthought. Article 6(1) governs the lawfulness of any processing that precedes anonymisation: the legal basis must exist before the data is anonymised, since the anonymisation act itself constitutes processing.
Key Developments
The CJEU in Bundesverband der Verbraucherzentralen v Planet49 confirmed that even seemingly anonymous identifiers can constitute personal data when they can be linked to other data sets:
"by linking that number with that data, a connection between a person to the data stored by the cookies arises if the user uses the internet, such that the collection of that data by means of cookies is a form of processing of personal data"
— Planet49 ¶45
This establishes a dynamic, context-dependent threshold: data is personal if linkage is feasible, regardless of whether the controller holds the linking key. The EDPB reinforces this functional approach in its consent guidelines, treating anonymisation as the gold standard where processing can be avoided:
"Anonymisation is the preferred solution as soon as the purpose of the research can be achieved without the processing of personal data."
— EDPB Guidelines 05/2020 §160
The EDPB's breach guidelines further recognise "unauthorised reversal of pseudonymisation" as a concrete harm, underscoring that pseudonymisation alone does not remove data from the GDPR's protective perimeter. Enforcement actions — including the Italian Garante's proceedings against Character.AI and Ireland's DPC fine against Permanent TSB for insufficient technical measures — signal that regulators scrutinise whether controllers have genuinely anonymised data or merely pseudonymised it while claiming exemption.
Status of the Debate
This topic is contested and actively litigated. The core tension lies in the re-identification standard: must anonymisation be irreversible in absolute terms, or is it sufficient that re-identification is not reasonably likely given available technology and effort? Courts have not yet drawn a bright line. The Planet49 ruling leans toward a broad, linkage-based conception of personal data that narrows the space for true anonymisation. Meanwhile, the EDPB has scheduled anonymisation and pseudonymisation as priority topics in its work programme and held a stakeholder event in December 2025, signalling that authoritative guidance is still forthcoming. What would resolve the open question is a CJEU ruling directly addressing whether anonymisation must withstand every theoretical re-identification attempt or only those that are reasonably likely — a question the Court has not yet answered head-on.
Practical Guidance
- Assess identifiability dynamically, not statically. Document what additional information exists, who holds it, and whether linkage is reasonably likely given current technology. The Planet49 standard means that data is personal if any party can link it, not just the controller.
- Distinguish pseudonymisation from anonymisation in records. Pseudonymised data remains fully subject to the GDPR. Label datasets accurately in your processing records to avoid inadvertently claiming an exemption that does not apply.
- Build anonymisation into design. Article 25(1) requires data-protection-by-design measures from the outset. Where a processing purpose can be achieved with anonymised data, prefer it — the EDPB treats this as the default for research contexts.
- Secure any re-identification key separately. Article 32(1)(a) requires technical and organisational measures for pseudonymised data. Store linking keys under separate access controls, encryption, and authentication to prevent unauthorised reversal.
- Establish a legal basis before anonymising. The act of anonymising personal data is itself processing under Article 4(2) and requires a lawful basis under Article 6(1) before it is carried out.