In July this year the EDPB adopted the new draft “Guidelines 02/2026 on Anonymisation”, a long-awaited work to help bring clarity to the concept and uses of anonymous data, and to establish clear standards when assessing it. The draft is open for public consultation until 30 October 2026, therefore the EDPB will likely update the final version of the document in line with the feedback received.
The Guidelines update the previous Opinion from the Article 29 Working Party, taking into account recent developments and case law of the Court of Justice of the European Union (CJEU) on this topic (in particular, case C-413/23 P EDPS v SRB) and recent developments in AI.
For businesses, anonymization is a technical measure that matters more than expected, as one of the few tools allowing data to be taken entirely out of the GDPR's scope. If done properly, the great advantage is that a business can process, analyse or repurpose data with less stringent constraints and obligations. On the other side, if anonymization is not properly taken care of and exhaustively assessed, a company may find itself processing personal data falling squarely under the GDPR's scope and obligations and, without realising it, processing such data without a legal basis, a record of the processing, transparency, or anything else that matters.
Anonymization: Relative or Absolute Concept?
In primis, we should clarify when data is personal or anonymous. As the Guidelines clearly explain:
“The core test for anonymity asks two questions:
- Does the information 'relate' to a natural person?
- If so, b. Is that natural person 'identified or identifiable'?
If the answer to either of these questions is 'no', then the data should be considered anonymous.”
Anonymity is not a quality of the data itself, but has to be evaluated in view of the context. The Guidelines state that the same dataset can be personal data for one entity and anonymous data for another, depending on the context, means and capabilities of each entity, a principle grounded in the CJEU's EDPS v SRB judgement (read our article here). In that case, the same pseudonymized data was personal for the entity holding the re-identification key, but not necessarily for the independent recipient who didn't.
What does this mean in a practical scenario? A great example is the GDPR classification of vendors and third parties. If an entity processes data on the controller’s instructions (i.e. is acting as processor), the data keeps the same status it has for the controller. It's personal data for both controller and processor.
On the other hand, if an entity receives data and processes it independently, its status should be assessed from its own perspective, meaning that data can be personal data for the controller and, for an independent third party, the same data can be anonymous.
An example taken from the Guidelines: a hospital shares patient data, stripped of identifiers, with an independent research institute. The institute has no way to trace the data back to individuals and has no relationship of instruction with the hospital. For the institute, the data is anonymous. For the hospital, which still holds the original records, it isn't.
Assessing Identifiability in Practice
The anonymization of data depends, therefore, on many different factors, not only legal factors but, more importantly, practical factors. Part of the test is to assess whether an individual is or can be identified from the record an entity processes, through means reasonably likely to be used. The correct approach is to ask this question based on practical, objective factors (such as cost, time and legal barriers), not assumptions about possible motivations. The EDPB explicitly excludes “lack of motivation” as a valid factor in this assessment.
Three-Part Test
To determine whether these conditions are actually met, the Guidelines set out three criteria that decide the outcome of the anonymization process:
- No Record Isolation (the data must not “contain a unique combination of attribute values that relate to a single individual”). Practical example from the Guidelines: a research institute holds a dataset of patients, recording sex, date of birth, postcode and diagnosis. All the records turn out to be unique combinations, so the “No Record Isolation” condition is violated. A unique record isn't necessarily fatal on its own, though, as we'll see below: it only becomes a problem if that unique combination can actually be traced back to a real person.
- No Linkage (no record can be matched with information about the same person found in one or more other datasets).
- No Inference (no “specific and meaningful” inference can be drawn from the given data).
Failing One Criterion Doesn’t Automatically Mean the Data Is Personal
If a record turns out to be unique (failing No Record Isolation), the Guidelines ask one more question: can that unique record actually be traced back to a real person? This is called the “singling out” test.
The same logic works for a failure of No Linkage or No Inference: the question is always whether the failure actually leads to identifiability, not just whether it's theoretically possible.
Conclusion
The line between anonymous and pseudonymized data is easy to cross without noticing, and the consequences (missing legal basis, missing data protection impact assessment (DPIA), missing transparency notice) only surface later, usually during an audit or a complaint. Before you label and process any dataset as “anonymous” and start using it outside the GDPR's scope, always involve your DPO or privacy counsel.
No comments