New EDPB Guidelines on Anonymisation
The simplest way for any organisation to manage its GDPR compliance burden is to minimise the circumstances in which it processes personal data. Anonymisation is a crucial tool in this regard, since the GDPR does not apply to information that is not personal data. In this context, the long-awaited Guidelines on Anonymisation published by the European Data Protection Board for public consultation on 7 July 2026 warrant careful consideration. These Guidelines reflect the EDPB’s interpretation of this key concept, in light of recent CJEU case law (particularly the EDPS v SRB case) and advances in technology that are relevant to determining whether information is truly anonymous.
Legal Test
The Guidelines recite well-established principles for determining whether information is ‘personal data’. Key considerations include:
- whether the information “relates” to an individual by reason of its content, purpose or effect.
- whether that individual is “identified or identifiable”.
- for the purpose of determining whether the individual is “identifiable”, the means reasonably likely to be used.
Technical Framework
The Guidelines propose two approaches for an organisation to consider when assessing whether it can convert personal data into anonymous data. The contextual approach focuses on whether data is anonymous from the perspective of a specific entity. The simplified approach disregards differences between entities and focuses on whether re-identification is possible in theory. The simplified approach is easier to assess, but carries a risk of false positives, since it might result in data not being considered to be anonymous when re-identification is theoretically possible but so unlikely that it can reasonably be disregarded. According to the Guidelines, an organisation may rely on either approach and may often find that a combination is the most efficient method to assess anonymisation, where they start by applying the simplified approach and, if necessary, apply the contextual approach.
Irrespective of which approach is being applied, the Guidelines state that a framework based on the following three criteria (each of which also featured in the Article 29 Data Protection Working Party’s Opinion 05/2014 on Anonymisation Techniques) should be used to assess if data is anonymous:
No Record Isolation: the data does not contain a unique combination of attributes singling out one individual. (This was previously referred to as ‘No Singling Out’).
No Linkage: the data is not capable of being linked to another dataset relating to the same person.
No Inference: no specific and meaningful inference can be made about the person from the data.
The EDPB proposes that if all three criteria are satisfied, the data may be treated as anonymous. If any criterion is violated, further analysis is required to determine whether the data is nonetheless anonymous. While there are some useful examples that illustrate the EDPB’s views on where dividing lines should be drawn, this framework leaves considerable room for debate and dispute as to whether data may properly be considered to be effectively anonymised, or whether re-identification remains possible.
It also remains to be seen whether proposed amendments to the GDPR regarding the concept of personal data set out in the Digital Omnibus may have any impact on the subject matter of these Guidelines.
Noteworthy Opinions
Some of the more noteworthy views expressed by the EDPB (not all of which are underpinned by case law) include the following:
- When assessing the means reasonably likely to be used, a distinction should be drawn between a legal prohibition and a contractual prohibition. “While contractual terms may have an effect on the means reasonably likely to be used, they should only be used to complement technical measures”.
- When assessing whether data processed by a processor is anonymous, this should be assessed by reference to the controller’s perspective, not the processor’s. “In practice, this means that if an entity processes information on behalf of a controller (i.e. someone for whom the information is personal data, and who decides the purposes and means of the processing), that information should also be considered personal data for the processing entity.”
- When considering third parties who may be able to connect data to an identified or identifiable individual, depending on the circumstances it may be necessary to consider not only obvious third parties, such as intended recipients, but also less obvious ones such as: investigative journalists; domestic law enforcement or intelligence agencies; foreign intelligence agencies; unethical companies; and cybercriminals.
- Where a dataset contains a mix of personal data and anonymous data, the entire dataset should be treated as containing personal data, if the personal data parts and the anonymous data parts are not treated separately.
- The likelihood of re-identification typically increases over time due to advances in the technology and techniques used for re-identification, as well as the increased availability of additional information. If the likelihood of identification increases to a level that is no longer insignificant, data previously considered to be anonymous data should be reassessed to be personal data.
While the Guidelines will not enable organisations to conduct definitive black and white assessments of whether data is anonymous or personal data, they provide useful colour on the latest views of European data protection authorities regarding the key concept of anonymisation, particularly following the EDPS v SRB case. Organisations who are already relying on anonymisation as part of their toolkit for managing their GDPR compliance burden, or planning on doing so, will know what a DPA will expect them to be able to demonstrate, if their anonymisation assessments are scrutinised (subject to any changes that may be made to these Guidelines following the public consultation on them or in light of the Digital Omnibus).
For further guidance on the implications of the Guidelines for your business, please contact a member of our Technology and Innovation Group.
This content has been prepared by McCann FitzGerald LLP for general guidance only and should not be regarded as a substitute for professional advice. Such advice should always be taken before acting on any of the matters discussed.


Select how you would like to share using the options below