Data Anonymisation and the GDPR — What Do the New EDPB Guidelines Bring?
“The data have been anonymised, so the GDPR no longer applies.” This assumption is common in many organisations. However, not every operation described as anonymisation actually results in anonymous data. Effective anonymisation means that the data cease to be subject to the GDPR. Achieving this result, however, is considerably more difficult than simply removing names, surnames or other obvious identifiers.
In July 2026, the European Data Protection Board (EDPB) adopted Guidelines 02/2026 on anonymisation, which update and further develop the approach previously set out in Article 29 Working Party Opinion 05/2014. The document reflects developments in case law, technology and the ways in which data are used. Most importantly from a practical perspective, the EDPB provides concrete mechanisms for assessing whether an anonymisation process has actually been successful.
It is important to note that the Guidelines were adopted as Version 1.0 for public consultation, which will remain open until 30 October 2026. Their final wording may therefore still change. Nevertheless, they already provide a clear indication of how the EDPB approaches the concept of anonymous data and which factors should be taken into account when assessing the effectiveness of anonymisation.
Why Effective Anonymisation Matters
Recital 26 GDPR makes clear that properly anonymised data fall outside the scope of the GDPR. In practice, this gives organisations considerably greater freedom to use such data, including for analytics, research, product development and the development and training of AI models.
There is, however, one essential condition: anonymisation must be effective. If, despite the measures implemented by an organisation, specific data subjects can still be identified, the information remains personal data and its processing continues to be subject to the GDPR. An organisation may otherwise find itself processing personal data without complying with requirements it mistakenly assumed no longer applied, such as having an appropriate legal basis, fulfilling transparency obligations or complying with retention and security requirements.
Ineffective “anonymisation” therefore does not eliminate regulatory risk. On the contrary, it may increase it, because the organisation operates on the assumption that the GDPR no longer applies while, in reality, it is still processing personal data.
The Relative Nature of Anonymity — a Key Starting Point
One of the key assumptions underlying the Guidelines is that anonymity is not absolute. The same dataset may constitute personal data for one entity while being anonymous for another. The assessment must therefore be made from the perspective of a particular entity, taking into account the means that it may reasonably be able to use to identify an individual.
In practice, the fact that one organisation can link certain information to a specific individual does not automatically mean that the same information will constitute personal data in the hands of another recipient who does not have the means to make that connection. This approach is supported by the judgment of the Court of Justice of the European Union of 4 September 2025 in Case C-413/23 P, EDPS v SRB, concerning the assessment of data status from the recipient’s perspective.
For this reason, when planning anonymisation, an organisation should first determine for whom the data are intended to become anonymous. If the data are to be transferred or made available to other entities, the assessment of the effectiveness of anonymisation should also take into account the perspective of those recipients and their actual ability to identify individuals.
A Two-Question Test
The new Guidelines propose structuring the assessment of data as follows:
- Does the information relate to a natural person by reason of its content, purpose or effect?
- Is the person to whom the information relates identified or identifiable, taking into account the means reasonably likely to be used?
An affirmative answer to both questions leads to the conclusion that the information constitutes personal data. If, on the other hand, the individual cannot be identified using means reasonably likely to be used, the data may be considered anonymous.
In practice, the key issue is therefore determining which means of identification are “reasonably likely to be used.”
“Means Reasonably Likely to Be Used” — the EDPB Takes a Broad View
The EDPB interprets the concept of means that may be used for identification broadly. These may range from simply reading a document or searching for additional information online to carrying out more sophisticated analyses. Importantly, the assessment is not limited to the means directly available to the entity concerned. Tools, information and capabilities accessible through other persons may also be relevant.
The Guidelines highlight several particularly important points:
- The range of entities that may need to be considered can be very broad. Depending on the circumstances, this may include not only the controller and data recipients, but also rogue employees, people in the data subject’s environment, investigative journalists, domestic and foreign intelligence or law-enforcement authorities, unethical businesses and cybercriminals. This does not mean that every such entity must be analysed in every case. The scope of the assessment depends on the specific context and on who may obtain direct or indirect access to the data.
- “Nobody will want to do it” is not a sufficient argument. The EDPB cautions against basing an assessment on an assumed lack of motivation to identify individuals. Motivation is difficult to establish objectively, may change over time, and identification may also occur accidentally, through negligence or as a result of other circumstances.
- Developments in AI may facilitate re-identification. The EDPB notes that many re-identification techniques are becoming increasingly accessible and that developments in artificial intelligence may further reduce the time and cost required to use such techniques and to combine information from multiple sources.
- A contractual restriction alone is not enough. A contractual prohibition on attempting to identify individuals may strengthen protection, but it is not equivalent to a statutory prohibition and does not, by itself, make data anonymous. Contractual safeguards should complement technical measures, and their effectiveness must be genuine — they should be credible, verifiable and enforceable.
In practice, this means that anonymisation cannot be assessed solely by looking at the dataset itself. The environment in which the data will be used, potential recipients, the information sources available to them and technologies that may enable re-identification must also be taken into account.
Two Approaches to Assessing Anonymity
The Guidelines provide for two possible approaches to assessing whether personal data can be considered anonymous.
The contextual approach examines the situation from the perspective of the individual entities that may have access to the data and could potentially attempt to identify a person. It therefore takes account of differences in their knowledge, technical capabilities, access to additional information and resources. This makes it possible to assess the anonymity of the data separately for each entity. It is more precise and most closely reflects the legal test of identifiability, but at the same time requires a more extensive analysis.
The simplified approach does not distinguish between the circumstances of individual entities and takes a more conservative perspective. As a result, data may be treated as personal even where, in practice, they would be anonymous for some recipients. This approach simplifies the assessment and provides a greater margin of safety.
The EDPB emphasises that the simplified approach does not constitute a separate legal test or a different standard of anonymisation. Rather, it is a more cautious method of applying the same criterion in practice. Depending on the nature of the data and the way in which they are used, the two approaches may also be combined.
Three Criteria for Effective Anonymisation
In the new Guidelines, the EDPB identifies three criteria that help determine whether data can genuinely be regarded as anonymous:
No possibility of singling out an individual (singling out). The data should not make it possible to distinguish a particular individual from others. The risk increases with the number and level of detail of the attributes available. Even if none of them identifies an individual on its own, their combination may be unique and allow a specific data subject to be singled out.
No possibility of linking data (linkage). The second criterion concerns whether a record can be connected with information contained in another dataset relating to the same person. Such linkage may occur through a common identifier or through a distinctive combination of attributes. The anonymisation assessment must therefore also take into account other datasets that may be available to the entity attempting identification.
No possibility of inference (inference). The data should not allow a specific and significant inference to be drawn about a particular individual. An inference is specific where it relates to one identifiable individual and significant where it may genuinely affect that person’s situation, rights or interests and is derived from the data being analysed rather than merely from general knowledge. The EDPB gives the example that a statement such as “Connor likes the colour green” may be specific but not necessarily sufficiently significant.
If the data pass all three tests, whether under the contextual or simplified approach, this supports the conclusion that they are anonymous. Failure to satisfy one of the criteria does not, however, automatically mean that the information constitutes personal data. It requires a more detailed assessment, in particular of whether the available information actually allows a specific individual to be singled out or identified.
To facilitate this assessment, the EDPB has also included a decision-making flowchart in the Guidelines, guiding organisations through the individual stages of the analysis.
Anonymisation Is Also Data Processing
It is important to remember that the process leading to the creation of anonymous data is itself still processing of personal data and is therefore subject to the GDPR.
This has several practical consequences for the controller:
- Anonymisation requires a legal basis. The anonymisation process must rely on one of the legal bases under Article 6 GDPR and, where special categories of personal data are involved, must also satisfy an appropriate condition under Article 9(2) GDPR.
- Transparency towards data subjects must be maintained. The controller should provide accurate information about the planned anonymisation. Data should not be described as “anonymous” or “de-identified” where individuals remain identifiable in practice.
- The anonymisation process should be documented. Documentation should cover not only the techniques applied but also the method used to assess their effectiveness and the tests performed on datasets considered anonymous. This is relevant both from the perspective of the accountability principle and as evidence that anonymisation was in fact effective.
- Prompt anonymisation may reduce the interference with privacy. Where source data are anonymised shortly after collection and subsequently deleted, this may weigh in favour of the controller when assessing the proportionality of processing, particularly as part of the balancing test for legitimate interests.
Merely declaring that the purpose of an operation is anonymisation does not exempt the controller from its obligations under the GDPR. Until the process has been successfully completed, the organisation is still processing personal data.
Anonymisation — What Else Should You Keep in Mind?
Anonymisation and pseudonymisation are not the same thing. Pseudonymisation reduces the possibility of directly attributing data to a particular person, but it does not remove their status as personal data. Similarly, encryption is a security measure and does not, in itself, result in anonymisation.
Mixed datasets may still be subject to the GDPR. If a dataset contains both anonymous data and personal data and the two parts are not processed in a manner that allows them to be clearly separated, the requirements applicable to personal data should be applied to the dataset as a whole.
Anonymity must also be assessed over time. A dataset considered anonymous today may not remain so indefinitely. Technological development, the emergence of new information sources and easier access to additional data may increase the possibility of re-identification. The effectiveness of anonymisation should therefore be reviewed periodically.
A security incident may change the assessment. If anonymity depended, among other things, on certain information remaining unavailable and that information is subsequently disclosed as a result of a security incident, the possibility of identifying individuals may need to be reassessed. If the data must then be treated as personal data, the personal data breach obligations under Articles 33 and 34 GDPR may also become relevant.
Common Mistakes and Myths About Anonymisation
“We removed names and surnames, so the data are anonymous.” The absence of direct identifiers does not determine whether data are anonymous. A distinctive combination of other information may be enough to single out or identify an individual.
Confusing anonymisation with pseudonymisation. Replacing identifiers with numbers or codes limits direct identification but does not automatically mean that the data cease to be personal data.
Assuming that “nobody will try to identify anyone.” The assessment of the effectiveness of anonymisation should not be based on the expected motivation of potential recipients. Motivation may change, and the possibility of identification should be assessed objectively.
Analysing a dataset in isolation from other sources of information. Information that appears anonymous on its own may enable identification when combined with other available datasets. The risk of linkage must therefore be considered.
Failure to test the effectiveness of anonymisation. Applying a particular technique is not enough. Organisations must assess whether, after its application, individuals can still be singled out, data can be linked with other sources or significant inferences can be drawn about them.
Failure to document the process. Without documenting the assumptions made, methods used and test results, it may be difficult to demonstrate that anonymisation was carried out correctly.
Treating anonymity as permanent. An assessment made today may no longer be valid several years from now. New technologies, additional data sources and changes in the way datasets are shared may increase the risk of re-identification. Anonymity should therefore be reviewed periodically.
Checklist — How to Assess the Effectiveness of Anonymisation
- Determine for whom the data are intended to be anonymous — identify the entities that may have access to them and the perspectives that need to be taken into account.
- Choose the assessment approach — contextual, simplified or a combination of both.
- Map the dataset and available additional information that could potentially be used to identify individuals.
- Apply the three anonymisation criteria — singling out, linkage with other datasets and inference about a particular individual.
- Assess the means reasonably likely to be used — taking into account, among other things, time, cost, access to additional data, technical capabilities and technological developments, including AI.
- Consider the context in which the data will be shared — the recipients, the scope of their access and the technical, organisational and contractual measures limiting the possibility of identification.
- Ensure that the anonymisation process itself has an appropriate legal basis and that the GDPR transparency requirements are met.
- Do not describe data as anonymous while there remains a realistic possibility of identifying individuals using means reasonably likely to be used.
- Document the entire process, including the assumptions made, techniques applied and results of the tests performed.
- Plan periodic reassessments of anonymity, taking into account technological developments and the emergence of new data sources.
- Reassess anonymity following a material change in circumstances, such as a change in the way the data are shared, the emergence of new datasets that can be linked to them or a security incident.
Do You Need to Assess Whether Your Data Are Really Anonymous?
At Dr Joanna Maniszewska-Ejsmont Law Firm, we support organisations in assessing the effectiveness of anonymisation, analysing re-identification risks and selecting appropriate technical and organisational measures. We also assist with documenting anonymisation processes and determining when pseudonymisation or continued processing of personal data on an appropriate legal basis may be a more suitable solution.
If you use data for analytics, research, product development or AI-related projects and want to determine whether they can genuinely be regarded as anonymous, explore our GDPR audit and compliance support services for data and AI projects or contact us.

Contact us — we can help assess the risks and structure the process in line with GDPR requirements.
