Data Governance Atlas

Anonymisation and pseudonymisation

For the controller / DPO

One takes data out of scope entirely; the other does not. Why the distinction is the most consequential in the whole regime, and why most claimed anonymisation is not.

NIST PF PR-PCT-P
ISO 27701 A.7.4.5A.7.4.6
GDPR family Art 4(1)Art 4(5)Recital 26Art 11Art 32(1)(a)

These two words are used interchangeably in ordinary speech and mean entirely different things in law. Getting them the wrong way round is how organisations end up believing whole datasets are out of scope when they are not.

The distinction

Anonymous data is data that does not relate to an identified or identifiable person, or has been rendered anonymous such that the person is no longer identifiable. It falls outside the regime entirely. No basis, no rights, no retention limit.

Pseudonymised data is data that can no longer be attributed to a specific person without additional information, where that additional information is kept separately and subject to safeguards. It remains personal data in full. Every obligation continues to apply.

The test for anonymity is whether identification is reasonably likely, accounting for all means reasonably likely to be used — by you or by anyone else — and the cost, time and technology available, including how those will develop.

Three implications follow, and each one catches organisations out:

  • If you hold the key, it is pseudonymised, not anonymous. However strong the separation.
  • Anonymity is contextual. A dataset can be anonymous in one party’s hands and personal data in another’s, if that party holds something that re-identifies it.
  • It is not permanent. A release that was anonymous can stop being so when another dataset is published, because the means reasonably likely to be used have changed.

Why most claimed anonymisation is not

The common pattern is removing direct identifiers — name, address, account number — and declaring the result anonymous. It usually is not, because the remaining combination still singles people out. Postcode, date of birth and sex is the textbook example; so is a detailed sequence of timestamps, or any high-dimensional behavioural record.

The question is never “have we removed the obvious identifiers”. It is “can anyone be singled out, linked across records, or have attributes inferred about them”. If any of the three holds, you have pseudonymised data with the identifiers stripped, which is a good security measure and not an exit from scope.

Aggregation helps but does not settle it either. Small cell sizes re-identify, and repeated queries against aggregates can reconstruct individual records.

Pseudonymisation is still worth doing

Nothing above diminishes it. It is expressly named as a security measure and as a safeguard supporting compatible reuse and research. It reduces the severity of a breach, narrows who can see what, and can be the difference between a notifiable incident and one that is not.

The error is not doing it. The error is claiming the resulting data is out of scope, and then treating it accordingly — no retention limit, no rights process, sharing it freely.

Decide it deliberately, and write it down

Before treating any dataset as anonymous:

  1. State who will hold it and what else they hold.
  2. Test the three risks — singling out, linkability, inference.
  3. Consider what could be combined with it, including public data.
  4. Decide, record the reasoning and the date, and set a review trigger.
  5. If in doubt, treat it as personal data. The cost of doing so is a retention schedule and a rights process. The cost of being wrong is processing an entire dataset with no lawful basis.

One useful consequence

Where you can genuinely no longer identify someone, you are not obliged to acquire extra data purely to comply — and rights that require identification may not apply, though you must tell the person if you cannot identify them. That is a narrow provision, frequently over-claimed as a general excuse for not answering requests. It applies where identification is genuinely impossible, not where it would be inconvenient.

How this differs elsewhere

No departures recorded for this concept yet. That is not a finding. It means nobody has checked, not that the position is the same everywhere — see the coverage note on the governance index.

Where this connects

Sources

Never independently verified.