Anonymisation vs pseudonymisation: differences and why they matter under the GDPR
They are often confused, and the confusion is costly: pseudonymising is not the same as anonymising. The GDPR still applies to pseudonymised data; it does not apply to truly anonymised data. This guide explains the difference with an everyday example.
An everyday example
Imagine a patient list. If you replace each name with a code and keep the “code ↔ name” table in a safe, you have pseudonymised: whoever holds the key can re-identify. If you destroy the table and the remaining data cannot identify anyone, you would have anonymised.
Key differences
- Reversibility: pseudonymisation can be reversed with the additional information; effective anonymisation cannot.
- Legal regime: pseudonymised data remains personal data; anonymous data falls outside the GDPR.
- Usefulness: pseudonymising keeps more useful detail; anonymising usually reduces it.
Common techniques
- Codes or tokens replacing identifiers.
- Generalisation: age ranges instead of exact age.
- Aggregation: working with totals rather than individual records.
- Suppression of identifying fields.
The re-identification risk
The key question is whether, by combining the data with other data, someone could identify a person using reasonable means. Removing name and ID number is rarely enough. The more detailed and unique the data, the higher the risk.
What to do
- Decide what you really need the data for.
- Use the minimum level of detail.
- If you pseudonymise, keep the additional information separate with restricted access.
- If you say you anonymise, document how you assessed re-identification.
- Review with your DPO or adviser before treating data as anonymous.
Frequently asked questions
What is pseudonymisation?
Separating identity from the data; it remains personal data (Art. 4(5)).
Is removing the name and ID enough?
Usually not: the re-identification risk must be assessed.
Informational content, not legal advice.
What's your Data Governance maturity?
Free assessment with your priority gaps, plus the self-assessment quiz and savings calculator on the Data Governance path.