---
title: "Model anonymity"
description: "The EDPB's test for when a trained model falls outside the GDPR: both direct extraction of training subjects' data and obtaining it through queries must be insignificant, given all means reasonably…"
canonical: https://aigovernanceengineer.com/glossary/model-anonymity
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-24
---

# Model anonymity

The EDPB's test for when a trained model falls outside the GDPR: both direct extraction of training subjects' data and obtaining it through queries must be insignificant, given all means reasonably likely to be used [1]. Evidenced by design records and attack evals.

- Developed in: [ch. 19, The EDPB anonymity test](https://aigovernanceengineer.com/bok/privacy-and-ai#the-edpb-anonymity-test)
- Chapters: [ch. 19, Privacy & AI](https://aigovernanceengineer.com/bok/privacy-and-ai)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-model-anonymity

## Sources

[1] Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models (three-step legitimate-interest test; anonymity test and evidence). European Data Protection Board. 2024-12-17. https://www.edpb.europa.eu/system/files/2024-12/edpb_opinion_202428_ai-models_en.pdf (verified: primary)
