Skip to content
Topic Contested in court

Anonymization

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Irreversible removal of identifying information from data

193 linked items 10 Laws39 Case Law48 Guidance47 Enforcement24 News

Overview

28 sources · Sep 25, 2026

Legal Framework

Anonymization falls outside the GDPR's scope entirely: once data is truly anonymous, the Regulation no longer applies. The critical boundary is defined negatively through Article 4(5), which defines pseudonymisation—not anonymisation—as a processing technique that reduces identifiability but does not eliminate it:

"the personal data can no longer be attributed to a specific data subject without the use of additional information, provided"
— GDPR Art. 4(5)

Pseudonymised data remains personal data. Article 25(1) lists pseudonymisation as an appropriate technical and organisational measure for data protection by design, while Article 89(1) permits pseudonymisation as a safeguard for archiving, scientific research, and statistical processing—provided those purposes can still be fulfilled. True anonymisation, by contrast, requires irreversible prevention of re-identification, taking into account all means reasonably likely to be used.

Key Developments

The CJEU's judgment in EDPS v SRB clarified the relationship between pseudonymisation and the definition of personal data. The Court held:

Crucially, the Court added that where such measures genuinely prevent attribution, pseudonymisation may influence whether data falls outside the personal data definition:

"provided that such technical and organisational measures are actually put in place and are such as to prevent the data in question from being attributed to the data subject, in such a way that the data subject is not or is no longer identifiable, pseudonymisation may have an impact on whether or not those data are personal"
— EDPS v SRB ¶75

The Belgian DPA reinforced this distinction in enforcement, finding that assigning a "randomly chosen identification number" to website visitors constitutes pseudonymisation, not anonymisation:

"anonymisation can only occur if it is no longer possible to attribute the data concerned directly or indirectly - if necessary on the basis of other information - to an individual"
— Belgian DPA, §44

The same decision emphasised that anonymisation is itself a further processing of personal data, meaning the original processing must comply with all GDPR requirements before anonymisation occurs. The Irish DPA separately cited pseudonymisation and encryption as measures under Article 32(1) for ensuring security appropriate to risk.

Status of the Debate

This topic is actively contested. The EDPS v SRB judgment established that pseudonymised data remains personal data in principle, but left open the possibility that robust technical and organisational measures could render data non-personal—a nuance that DPAs and controllers are now litigating. The EDPB held a stakeholder event in December 2025 specifically to collect input on anonymisation and pseudonymisation following the CJEU ruling, with forthcoming guidelines on both topics. Stakeholders flagged unresolved questions around the contextual assessment of identifiability, controller-processor relationships, and the impact of data granularity on re-identification risk. No court split is on record yet, but the EDPB's anticipated guidelines—particularly on the threshold for "reasonably likely" means of re-identification—will likely define the operational boundary.

Practical Guidance

  • Treat pseudonymised data as personal data. Pseudonymisation reduces risk but does not remove data from GDPR scope. All Article 5 principles, security obligations under Article 32, and data subject rights continue to apply.
  • Assess identifiability contextually. Following EDPS v SRB, the relevant perspective depends on the circumstances of each case. Document all objective factors—cost, time, available technology, and the nature and granularity of the data.
  • Separate additional information. Store mapping keys or decryption keys separately from pseudonymised datasets, with strict access controls, to satisfy the Article 4(5) requirement.
  • Comply before anonymising. The Belgian DPA confirmed that anonymisation is itself further processing; ensure a lawful basis, transparency obligations, and purpose limitation are satisfied before the anonymisation step.
  • Do not label pseudonymisation as anonymisation. The Belgian DPA sanctioned a controller for misrepresenting pseudonymised processing as "anonymous." Audit public-facing privacy notices for accuracy on this point.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
ICO: How can Privacy Enhancing Technologies help with data protection compliance? > How can PETs help with data protection compliance? At a glance • PETs can help you demonstrate a ‘data protection by design and by default’ approach to your processing. • PETs… News ICO Nov 2025 sharing sensitive data via PETs
why this is here
You can use PETs to give access to datasets which would otherwise be too sensitive to share

It discusses enabling access to sensitive datasets, which relates to anonymization and reducing re-identification risk, but does not detail anonymization techniques or the irreversible removal of identifiers.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 39 Case Law · all 48 Guidance · all 47 Enforcement · all 25 Literature · all 24 News