Anonymisation under the GDPR requires the likelihood of identifying anyone to be insignificant, assessed from the perspective of whoever will use the data. The draft EDPB guidelines 02/2026 build on the SRB judgment and apply three criteria, singling out, linkability and inference. A processor inherits its customer's perspective, and the assessment must be repeated over time.
The marketing department wants to share customer data with an analytics agency. Names, email addresses and customer numbers have been removed, leaving postcode, year of birth, gender and everything the customer has bought over the past three years. The dataset is labelled “anonymous”. Under the new guidelines from the European Data Protection Board (EDPB), it probably is not.
Anonymous data falls outside the GDPR. That makes anonymisation one of the most valuable labels a business can put on a dataset, and one of the riskiest to get wrong.
What is anonymisation under the GDPR?
Data is anonymous when it does not relate to an identified or identifiable natural person. This follows from Recital 26 of the General Data Protection Regulation, the mirror image of the definition of personal data in GDPR Art. 4(1). The assessment must take account of all the means reasonably likely to be used to identify the person, and of objective factors such as cost, time and the technology available.
Anonymisation must be kept apart from pseudonymisation. Pseudonymisation under GDPR Art. 4(5) means that the data cannot be attributed to a person without additional information that is kept separately. For whoever holds the key, pseudonymised data is still personal data.
What is new in the EDPB guidelines on anonymisation?
The EDPB adopted Guidelines 02/2026 on Anonymisation on 7 July 2026. The document is a consultation version, and the public consultation runs until 30 October 2026. The content may therefore change before final adoption.
In practice the guidelines replace the Article 29 Working Party’s Opinion 05/2014 on anonymisation techniques, which has been the reference point for twelve years. The old opinion worked with three risks, singling out, linkability and inference. The EDPB keeps that way of thinking but rebuilds it on the case law of the Court of Justice of the EU.
The most important change is that anonymity is relative. The same dataset can be personal data for one business and anonymous for another. The question the EDPB asks is who the data is supposed to be anonymous for.
What did the Court of Justice decide in the SRB judgment?
On 4 September 2025 the Court of Justice gave judgment in Case C-413/23 P EDPS v SRB. The Single Resolution Board (SRB) had collected comments from shareholders and creditors of Banco Popular Español, pseudonymised them and sent them to Deloitte for a valuation. The case concerned Regulation 2018/1725, which applies to the EU’s own institutions, but the concepts are the same as in the GDPR.
The Court reached three conclusions, as set out in its press release. Personal opinions are personal data relating to the person who holds them. Pseudonymised data is not personal data in every case and for every person, because pseudonymisation may prevent anyone other than the controller from identifying the individuals. And the duty to inform is assessed from the controller’s standpoint at the time of collection, so the SRB had to name Deloitte as a recipient whether or not the data was anonymous for Deloitte. The Court set aside the General Court’s judgment and referred the case back.
The judgment builds on the Breyer judgment (C-582/14) from 2016. There, dynamic IP addresses were held to be personal data for a website operator that had legal means of obtaining additional information from the internet service provider.
How does the EDPB assess whether data is anonymous?
The guidelines rest on two conditions for data to be personal data. The information must relate to a natural person by reason of its content, purpose or effect, and the person must be identified or identifiable by means reasonably likely to be used. If either condition is missing, the data is anonymous for that actor.
The likelihood of identification does not have to be zero. It has to be insignificant in reality. In making the assessment, the business must look at the characteristics of the data, the context in which it is shared, access to additional information, cost and time, and the technology available now and in the foreseeable future. The range of possible actors is wide. The EDPB mentions, among others, disloyal employees, neighbours and colleagues, investigative journalists, foreign intelligence services and cybercriminals.
A contractual prohibition on re-identification is not treated as equivalent to a legal prohibition. The EDPB writes that contract terms can only supplement technical measures. That is a direct message to businesses that have based data sharing on the recipient’s promise not to try.
What are the three criteria for anonymisation?
The technical part of the guidelines tests the dataset against three criteria. If all are met, the data can be regarded as anonymous. If one fails, the business must go further and examine whether anyone can in fact be singled out.
| Criterion | The question | Typical failure |
|---|---|---|
| No singling out of records | Does anyone have a unique combination of values in the dataset? | Gender, date of birth and postcode in the same row |
| No linkability | Can a record be linked to a record about the same person in another dataset? | Purchase history that also appears on a public profile |
| No inference | Can anyone deduce specific and meaningful information about a person? | Statistics on groups so small that one person’s diagnosis can be read off |
The business can choose between a contextual and a simplified approach. The contextual approach assesses what means each recipient actually has. The simplified approach ignores the differences and assumes that someone has the means if they exist. It is safer, but it can lead to data that is in fact anonymous being treated as personal data all the same.
The EDPB notes that record-level data with many fields and a high level of detail is the most vulnerable. Aggregated data is safer, though not always safe.
What do the guidelines mean for processors?
A processor inherits the controller’s perspective. If an analytics agency processes data on behalf of a customer that can identify the individuals, the data is personal data for the agency too, even though the agency does not hold the key itself. The agency is then a processor with all the obligations that follow under the GDPR, and a data processing agreement under GDPR Art. 28(3) must be in place.
The opposite applies when the recipient determines the purposes and means itself. An independent research institute that receives extracts from patient records and never sends anything back must assess anonymity from its own standpoint. The act of anonymising is itself a processing of personal data. It requires a legal basis under GDPR Art. 6, and the business must inform the data subjects that their data will be anonymised.
Why must anonymisation be reassessed over time?
Data that is anonymous today may be personal data tomorrow. The EDPB writes that the likelihood of re-identification usually increases over time, because techniques improve and more additional information becomes available. The guidelines point in particular to AI and agentic AI making re-identification cheaper and faster.
A security breach can also change the assessment. If anonymity depended on a key or an internal register being kept secret, and that register leaks, the business may suddenly have a breach to notify.
Anonymity is an assessment that has to be renewed, and it only holds for the party it was made for.
What does this mean for analytics, sharing and AI training?
For analytics and sharing, the guidelines mean that “anonymous” has to be justified for each recipient. The EDPB also writes that businesses should not describe data as anonymous or de-identified if the individuals can still be identified. The label in the privacy notice can therefore itself breach the transparency principle.
For AI training, the inference criterion is the one that bites. The guidelines point out that both AI models and synthetic data can reveal information about individuals when queried with additional information. This is consistent with the EDPB’s Opinion 28/2024 on AI models, where the starting point is that a model trained on personal data is not automatically anonymous. Synthetic test data generated from the customer database must therefore be assessed in the same way, as discussed in the article on personal data in test environments.
Where anonymity is doubtful and the risk is high, the data should be treated as personal data, and a data protection impact assessment may be required. More articles on the subject are collected on the data protection topic page.
What should the business do?
- Find every dataset labelled anonymous, internally or in agreements, and note who has access to each of them.
- Test each dataset against the three criteria, and document the result.
- Assess each recipient separately, and remember that a processor inherits its customer’s perspective.
- Do not let a contractual ban on re-identification carry the assessment on its own.
- Set a date for a new assessment, and carry out an extraordinary one after a security breach or when new data sources become public.
- Correct privacy notices and agreements that call pseudonymised data anonymous.
Step 6 pays off fastest. An analytics agency that receives “anonymous” customer data with postcode, year of birth and full purchase history is, on the guidelines’ reasoning, probably a processor without a data processing agreement.
Questions and answers
Is pseudonymised data the same as anonymous data?
No. For anyone who holds the key or can obtain it, pseudonymised data is personal data. After the SRB judgment it may nevertheless be anonymous for a recipient that has no reasonable means of identifying anyone. This must be assessed case by case, and the conclusion falls away if the recipient is a processor for whoever holds the key.
Do we have to redo our anonymisation because of the new guidelines?
The EDPB states that a business which has assessed a dataset as anonymous under Opinion 05/2014 is not expected to carry out a new assessment. It is still good practice to review the risk of re-identification regularly, and new sharing or new data sources trigger a fresh assessment in any event.
Is an AI model anonymous when it has been trained on personal data?
Not automatically. The EDPB points out that inferences can be drawn from an AI model by querying it with additional information about a person. If the model can reveal meaningful information about individuals, the inference criterion is not met, and the model cannot simply be treated as anonymous.
- General Data Protection Regulation (EU) 2016/679 Arts. 4(1) and (5), 6, 28 and Recital 26
- EDPB, Guidelines 02/2026 on Anonymisation, version 1.0 for public consultation paras. 6–42 and 52–100
- EDPB, public consultation on Guidelines 02/2026 on Anonymisation consultation deadline 30 October 2026
- Court of Justice of the EU, C-413/23 P EDPS v SRB (4 September 2025)
- Court of Justice of the EU, press release 107/25 on C-413/23 P EDPS v SRB
- Court of Justice of the EU, C-582/14 Breyer (19 October 2016)
- Article 29 Working Party, Opinion 05/2014 on Anonymisation Techniques (WP216)
- EDPB, Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
Next legal review: 1 March 2027