7 min read

EDPB draft guidelines on anonymisation: key points for organisations

Read more

By Charlotte Halford & Christopher Foo

|

Published 09 October 2026

Overview

On 7 July 2026, the European Data Protection Board (EDPB) published its draft guidelines on anonymisation for public consultation (Guidelines). The Guidelines provide a long-awaited update to the 2014 Article 29 Working Party Opinion on Anonymisation Techniques (the Article 29 Working Party being the precursor to the EDPB) to reflect the significant technological and legal developments that have occurred over the last decade, including advances in AI, increasingly sophisticated re-identification techniques, the entry into force of the GDPR, and recent case law in the EU.

Although the Guidelines remain in draft form, their core principles are unlikely to change materially before adoption. The Guidelines provide clarity on the criteria that data must fulfil in order to be considered anonymous. As a subjective assessment, anonymity depends on the perspective of the relevant recipients of personal data, and the Guidelines set out a framework for assessing anonymity comprising: (i) a three-part test for organisations to assess the anonymity of their data; and (ii) two methodologies that organisations can apply when carrying out this assessment.

 

What is anonymous data?

The Guidelines state that if information does not relate to a natural person, or if that natural person is not identified or identifiable, then that data can be considered anonymous. They also clarify the meaning of "relates to" and "identified or identifiable" as follows:

  • Relates to a natural person: The Guidelines state that information relates to a natural person by reason of its content, purpose, or effect
    • Content: The information describes one or several characteristics or actions of the person
    • Purpose: The information is used or is likely to be used for the purpose of evaluating, treating, or influencing the individual, and can include information about objects such as property owned by the person
    • Effect: Processing such information is liable to result in a "concrete possibility" of affecting that individual's rights and interests, such as where the location data of taxis can be used to monitor driver activity
  • Identified or identifiable: Information does not require a zero likelihood of identification in order to be considered anonymous, although the likelihood of identification must be "insignificant in reality". According to the Guidelines, identifiability depends on the attributes of that information and the means reasonably likely to be used for identifiability.
    • Attributes: Attributes encompass a wide spectrum of traits (i.e. psychological, behavioural, or cultural) and may be capable of identifying an individual either on their own or together with other attributes
    • Means reasonably likely to be used: When determining the means reasonably likely to be used by an entity to identify individuals from the information, the Guidelines set out several factors to consider, including the properties and context of the information itself (i.e. whether it has been aggregated and whether there are any restrictions on access to the information), whether additional information that would allow individuals to be identified can be easily obtained, and the costs and technology available to the entity at that time. When determining the relevant entity that may identify the individual, the Guidelines note that the list is broad and may include entities ranging from recipients to malicious actors. However, this does not mean that every theoretically unlawful re-identification scenario must be considered, as the Guidelines set out a rebuttable presumption that certain means may be disregarded where legal prohibitions make their use insignificant in reality. If there is evidence that unlawful means are reasonably likely to be used (i.e. where data is vulnerable to cyberattack, legal restrictions are ineffective in practice or similar breaches have previously occurred), such means should still be considered.

The Guidelines further acknowledge that the same dataset may be personal data to one organisation but anonymous to another, with the relevant perspective being that of the entity or entities for which the data is intended to be anonymous.

 

A framework for testing anonymous data

The Guidelines provide a framework for organisations to assess whether data has been effectively anonymised, setting out three criteria for assessing the re-identifiability of data and two methodologies for organisations to apply these tests, depending on the circumstances.

  • Three criteria for testing anonymisation: The Guidelines set out three broadly cumulative criteria for testing whether data is anonymous. If all three criteria are satisfied, the data can safely be regarded as anonymous. However, the failure of any individual criterion does not automatically mean that the information is personal data, and the Guidelines state that a deeper, contextual assessment should be undertaken to determine whether the actual risk of re-identification remains significant.
    1. No record isolation. A dataset should not allow a single record to be singled out through a unique combination of attributes. For example, a dataset about patients in which each patient record contains their gender, date of birth, postcode, and health information will fail this test, as an individual can be singled out through a record containing their unique attributes. For this reason, the more detailed and multidimensional a record is, the more likely it is that an individual can be isolated from it and identified. Aggregating data usually satisfies this criterion.
    2. No linkage. The dataset should not be linkable to other datasets in a way that reveals information about the individual. For example, a dataset containing de-identified customer purchase history may be matched with another dataset from a website where customers list their purchases and reviews; as the purchase history and website reviews may be linked, the dataset fails this criterion. This reflects the modern reality that re-identification can often occur through the combination of datasets.
    3. No inference. If no specific and meaningful inference can be drawn from the given data, a dataset will meet this criterion. For example, if a dataset contains movement records that show an individual spending every night at one address and every working day at another, it is possible to infer the person's home address and workplace.
  • Two methodologies: The EDPB provides two methodologies for organisations to apply the tests for anonymisation. The appropriate methodology depends on, among other considerations, the degree of precision and risk tolerance required: either (i) a conservative, simplified approach; or (ii) a more flexible contextual approach.
    1. The simplified approach: Under this approach, organisations take a conservative view of anonymisation, as it is assessed without differentiating between the capabilities of different entities. The approach considers whether relevant re-identification methods could theoretically be deployed if the necessary means existed. This can lead organisations to treat data as personal data even where it may be anonymous for a particular recipient. The EDPB views this as a cautious approach that favours avoiding false positives at the expense of potentially increasing false negatives.
    2. The contextual approach: Under this approach, organisations assess anonymisation by reference to the actual circumstances and capabilities of the relevant entities. It assesses the means reasonably likely to be used by each relevant entity, considering factors such as the availability of additional information, access rights, technical capabilities, legal restrictions, and the wider processing context. This approach provides a more nuanced assessment of anonymity but also carries a greater risk of false positives where an organisation overlooks information, resources or capabilities that may enable re-identification in practice.

The EDPB notes that a combination of the two approaches may often be helpful and anticipates that organisations will frequently adopt a hybrid approach. For example, organisations may use the simplified approach as an initial screening exercise to identify datasets that present theoretical re-identification risks, before moving to a contextual assessment to determine whether those risks are realistically capable of materialising for the relevant entities.

This allows organisations to reserve the more resource-intensive contextual analysis for datasets that require further scrutiny. Regardless, the EDPB emphasises that the contextual approach reflects the full nuances of the legal standard under the GDPR, whereas the simplified approach is a deliberately conservative methodology that may go beyond that standard by treating data as personal data even where it may, in practice, be anonymous for a particular recipient.

 

Key takeaways

Organisations should be considering how to incorporate the Guidelines into their existing governance frameworks and continuously adapt their procedures, processes, and assessments to ensure ongoing alignment. This is particularly important given the EDPB's acknowledgement that anonymity is not static and may erode over time as technology develops, additional datasets become available and increasingly sophisticated AI-enabled re-identification techniques emerge.

 

Flexibility and complexity

The subjective view taken by the EDPB in its guidance is helpful for organisations. By recognising that the same information may constitute personal data for one entity but anonymous data for another, the Guidelines introduce greater flexibility into the assessment of anonymity. However, organisations should be cautious about adopting blanket positions that data is anonymous without undertaking a documented assessment, as the contextual approach also introduces additional complexity. In practice, organisations will need a detailed understanding of the relevant data flows, intended recipients and the means reasonably likely to be used for re-identification. This may lead to more complex contractual negotiations, greater scrutiny of controller/processor role allocations, and a stronger incentive to invest in privacy-enhancing technologies (PETs) and robust anonymisation techniques.

 

Anonymisation and pseudonymisation

The Guidelines should also be read alongside the EDPB's pseudonymisation guidance. While pseudonymised data remains personal data and subject to the GDPR, the Guidelines clarify when data can move beyond pseudonymisation and fall outside the scope of the GDPR altogether (although the act of processing personal data to render it anonymous remains subject to the GDPR). Equally, where effective anonymisation cannot realistically be achieved, organisations may still be able to rely on pseudonymisation as an important safeguard to reduce the risks associated with processing personal data. In particular, the EDPB notes that anonymisation, and by extension privacy-enhancing measures such as pseudonymisation, may help mitigate the impact of processing on data subjects and therefore weigh positively in a legitimate interests assessment. Together, the two sets of guidance provide a more complete framework for organisations seeking to manage privacy risks associated with data sharing and analytics.

 

Potential implications for data subject access requests (DSARs)

The Guidelines may have implications beyond data-sharing exercises. As combinations of attributes can themselves constitute personal data, organisations may need to take a broader view of what information is capable of identifying an individual. As the Guidelines do not address the impact of this on DSARs, it is unclear whether this may increase the categories of information that need to be searched, reviewed, and disclosed pursuant to DSAR scoping exercises. Regardless, organisations should undertake and retain documented re-identification risk assessments to support any conclusion that a dataset has been effectively anonymised and help demonstrate compliance with the GDPR's accountability principle.

Authors