PT
COMPLIANCE ALERT! EDPB Guidelines 2/2026 on Anonymisation
Insight
09 Oct 2026

COMPLIANCE ALERT! EDPB Guidelines 2/2026 on Anonymisation

COMPLIANCE ALERT! EDPB Guidelines 2/2026 on Anonymisation

Until 30 October, the European Data Protection Board’s (EDPB) Guidelines 2/2026 on anonymisation are open for public consultation.

The Guidelines seek to clarify when certain information can be considered truly anonymous and, therefore, fall outside the scope of the GDPR.

 

When is data considered anonymous?

The EDPB proposes two questions:

  • Does the information relate to a natural person?
  • Is that person identified or identifiable?

If the answer is “no” to either question, the information may constitute anonymous data.

However, caution is required: the same data may be anonymous for one entity while remaining personal data for another.

The assessment should therefore be carried out from the perspective of each relevant entity and taking into account the means reasonably likely to be used to identify the person concerned.

This means that anonymisation does not require identification to be absolutely impossible. What matters is that, in the specific circumstances, the likelihood of identification is insignificant.

 

And what are the technical criteria for anonymisation?

The EDPB identifies three criteria:

  • Is it possible to single out a person through a unique combination of characteristics (no record isolation)?
  • Is it possible to link those data to information held in another dataset and thereby identify the same person (no linkage)?
  • Is it possible to derive a specific and meaningful conclusion about an identified or identifiable person from the data, capable of affecting their rights or interests (no inference)?

If the answer is “no” to all three questions, the three criteria are met and the data may be considered anonymous. If the answer is “yes” to any of them, further analysis is required in order to confirm whether the data can still be regarded as anonymous.

 

Is removing the name enough?

Not necessarily.

The mere removal of names, email addresses or other direct identifiers does not, in itself, guarantee that data are anonymous.

It is necessary to assess whether a person can still be identified through the combination of different elements, by linking the data to other sources of information, or through inference techniques.

 

And what if only part of the dataset has been anonymised?

Here too, caution is required.

If anonymisation is only effective in relation to some of the individuals included in the dataset, the dataset should not, in principle, be treated as anonymous as a whole.

 

Is anonymisation subject to the GDPR?

The outcome may cease to be subject to the GDPR; the anonymisation process itself does not.

As long as personal data are being processed to produce anonymous information, the GDPR rules continue to apply.

Accordingly, the anonymisation process should, in particular:

  • Be based on an appropriate lawful basis;
  • Comply with the applicable transparency obligations;
  • Be properly documented.

 

As good practice, organisations should:

  • Identify the data and any additional information that may enable identification or re-identification;
  • Test the effectiveness of the anonymisation techniques used;
  • Consider the means and sources of information that different relevant entities may reasonably use;
  • Document the anonymisation process and the tests carried out;
  • Retain documentation demonstrating the effectiveness of the anonymisation;
  • Periodically reassess, where possible and appropriate, the risk of re-identification.

This is because data that are anonymous today may cease to be anonymous tomorrow, particularly as a result of advances in technology, developments in re-identification techniques, or the availability of new information. If the likelihood of identification ceases to be insignificant, the data should once again be treated as personal data.