Information that does not relate to an identifiable person, judged against all the means reasonably likely to be used by anyone to identify them 1. It falls outside the GDPR, but the claim decays as auxiliary data and re-identification techniques improve, so it needs a dated assessment.
- Developed in
- ch. 19, Anonymisation versus pseudonymisation
- Chapters
- ch. 19, Privacy & AI
- Contrast with
- Pseudonymisation
- Source
- 1 numbered reference, listed below
Commonly confused
Pseudonymisation versus Anonymous data
- Pseudonymisation
- Processing personal data so it can no longer be attributed to a person without additional information kept separately and protected.
- Anonymous data
- Information that does not relate to an identifiable person, judged against all the means reasonably likely to be used by anyone to identify them.
The differenceRe-attributable with separately kept information, so still personal data, against not relating to an identifiable person at all.
Why it mattersPseudonymised data keeps every GDPR duty; an anonymity claim needs a dated assessment.
Where it is used
The term is not used under this name in running prose; the sections listed under "Developed in" treat it.
Sources
- [1] Regulation (EU) 2016/679 (General Data Protection Regulation) (Arts. 4(1), 4(5), 4(7), 4(8), 4(12), 4(14), 5, 6, 9, 12(3), 22, 25, 28(2) and 28(4), 30, 33, 35; Recital 26). Publications Office of the EU (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .