Until 30 October, the European Data Protection Board’s (EDPB) Guidelines 2/2026 on anonymisation are open for public consultation.
The Guidelines seek to clarify when certain information can be considered truly anonymous and, therefore, fall outside the scope of the GDPR.
When is data considered anonymous?
The EDPB proposes two questions:
If the answer is “no” to either question, the information may constitute anonymous data.
However, caution is required: the same data may be anonymous for one entity while remaining personal data for another.
The assessment should therefore be carried out from the perspective of each relevant entity and taking into account the means reasonably likely to be used to identify the person concerned.
This means that anonymisation does not require identification to be absolutely impossible. What matters is that, in the specific circumstances, the likelihood of identification is insignificant.
And what are the technical criteria for anonymisation?
The EDPB identifies three criteria:
If the answer is “no” to all three questions, the three criteria are met and the data may be considered anonymous. If the answer is “yes” to any of them, further analysis is required in order to confirm whether the data can still be regarded as anonymous.
Is removing the name enough?
Not necessarily.
The mere removal of names, email addresses or other direct identifiers does not, in itself, guarantee that data are anonymous.
It is necessary to assess whether a person can still be identified through the combination of different elements, by linking the data to other sources of information, or through inference techniques.
And what if only part of the dataset has been anonymised?
Here too, caution is required.
If anonymisation is only effective in relation to some of the individuals included in the dataset, the dataset should not, in principle, be treated as anonymous as a whole.
Is anonymisation subject to the GDPR?
The outcome may cease to be subject to the GDPR; the anonymisation process itself does not.
As long as personal data are being processed to produce anonymous information, the GDPR rules continue to apply.
Accordingly, the anonymisation process should, in particular:
As good practice, organisations should:
This is because data that are anonymous today may cease to be anonymous tomorrow, particularly as a result of advances in technology, developments in re-identification techniques, or the availability of new information. If the likelihood of identification ceases to be insignificant, the data should once again be treated as personal data.