Pseudonymization
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing data in a pseudonymized manner
Overview
24 sources · Jul 23, 2026Legal Framework
Pseudonymization is defined under Article 4(5) GDPR as the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, which is kept separately and subject to technical and organizational measures to ensure non-attribution. Critically, pseudonymized data remains personal data — it does not render data anonymous and does not fall outside the GDPR's scope. The rationale is to reduce risk to data subjects by separating identifiers from the substantive data, while still permitting meaningful processing.
Article 25 GDPR reinforces this by requiring data protection by design and by default: controllers must implement appropriate technical and organizational measures both when determining processing means and during processing itself. Pseudonymization is expressly identified as an example of such a measure. Article 32 GDPR further obliges controllers to ensure ongoing confidentiality, integrity, and resilience of processing systems, under which pseudonymization serves as a recognized safeguard. Under Article 5(1)(c), data minimization principles also support pseudonymization as a means of limiting identifiability where full anonymization is not feasible.
Key Developments
Dutch case law has established that pseudonymization is not merely optional but can function as a necessary balancing tool when courts weigh access rights against confidentiality interests. In the RET case, the Court of Appeal ordered an employer to disclose an investigation report to the employee but permitted pseudonymization of third-party references under the judiciary's pseudonymization guidelines. The court prohibited the employee from sharing the report with third parties, under a penalty of €5,000 per violation. This establishes that outright denial of access is impermissible where pseudonymization can adequately protect competing interests.
The Peter Puškár ruling from the CJEU clarifies that the right of access under Article 15 GDPR must be examined in its specific context and cannot be systematically refused on privacy grounds. Where pseudonymization can reconcile the data subject's access rights with third-party protections, it should be employed rather than withholding documents entirely.
The Hellenic DPA's enforcement against Hestia Publishers (€9,000 fine) demonstrates that failure to pseudonymize when disclosing personal data — particularly when revealing a data subject's identity is unnecessary for the processing purpose — constitutes a violation. The controller disclosed identity information where pseudonymization or redaction would have been appropriate.
Practical Guidance
Implement pseudonymization as a default design measure under Article 25 GDPR when processing involves large datasets or sensitive contexts. Replace direct identifiers with pseudonyms and store the key table separately, with access restricted to authorized personnel under Article 32 safeguards.
Apply pseudonymization when responding to access requests involving third-party data. The RET ruling confirms that courts expect controllers to pseudonymize rather than withhold documents entirely — blanket refusals of access are not defensible where redaction or pseudonymization can resolve the conflict.
Maintain separation between pseudonymized data and re-identification keys. The Article 4(5) definition requires that additional information be kept separately and subject to technical and organizational measures. Storing the re-identification key on the same server or in the same database as the pseudonymized dataset defeats the legal purpose.
Document the pseudonymization methodology as part of your Article 30 records and DPIA processes where applicable. Controllers must demonstrate that the chosen technique effectively prevents attribution without the key, particularly if challenged by supervisory authorities.
Recognize that pseudonymized data remains within the GDPR's scope. Do not treat pseudonymized datasets as anonymized for compliance purposes — all substantive GDPR obligations, including lawful basis requirements under Article 6 and data subject rights, continue to apply.