Processing personal data so it can no longer be attributed to a person without additional information kept separately and protected 1. Pseudonymised data stays personal data for whoever can re-attribute it; it is a security measure, not anonymisation.
- Developed in
- ch. 19, Anonymisation versus pseudonymisation
- Chapters
- ch. 19, Privacy & AI
- Contrast with
- Anonymous data
- Source
- 1 numbered reference, listed below
Commonly confused
Pseudonymisation versus Anonymous data
- Pseudonymisation
- Processing personal data so it can no longer be attributed to a person without additional information kept separately and protected.
- Anonymous data
- Information that does not relate to an identifiable person, judged against all the means reasonably likely to be used by anyone to identify them.
The differenceRe-attributable with separately kept information, so still personal data, against not relating to an identifiable person at all.
Why it mattersPseudonymised data keeps every GDPR duty; an anonymity claim needs a dated assessment.
Where it is used
6 chapters of the Body of Knowledge use the term. Each link opens the first section that does.
- 04 · The Stack Data governance across the stack 1 mention
- 08 · Regulatory Map EU AI Act, post-Omnibus 2 mentions
- 11 · AI Defined Responsible-AI principle sets, engineered 1 mention
- 16 · Fairness & XAI Protected characteristics, proxies and the data you need to test 2 mentions
- 19 · Privacy & AI Principles applied to AI 7 mentions
- 20 · Existing Law Non-discrimination 1 mention
Sources
- [1] Regulation (EU) 2016/679 (General Data Protection Regulation) (Arts. 4(1), 4(5), 4(7), 4(8), 4(12), 4(14), 5, 6, 9, 12(3), 22, 25, 28(2) and 28(4), 30, 33, 35; Recital 26). Publications Office of the EU (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .