---
title: "Pseudonymisation"
description: "Processing personal data so it can no longer be attributed to a person without additional information kept separately and protected."
canonical: https://aigovernanceengineer.com/glossary/pseudonymisation
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Pseudonymisation

Processing personal data so it can no longer be attributed to a person without additional information kept separately and protected [1]. Pseudonymised data stays personal data for whoever can re-attribute it; it is a security measure, not anonymisation.

- Developed in: [ch. 19, Anonymisation versus pseudonymisation](https://aigovernanceengineer.com/bok/privacy-and-ai#anonymisation-versus-pseudonymisation)
- Chapters: [ch. 19, Privacy & AI](https://aigovernanceengineer.com/bok/privacy-and-ai)
- Contrast with: [Anonymous data](https://aigovernanceengineer.com/glossary/anonymous-data)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-pseudonymisation

## Commonly confused

- **Pseudonymisation** vs **Anonymous data**: Re-attributable with separately kept information, so still personal data, against not relating to an identifiable person at all Pseudonymised data keeps every GDPR duty; an anonymity claim needs a dated assessment

## Sources

[1] Regulation (EU) 2016/679 (General Data Protection Regulation) (Arts. 4(1), 4(5), 4(7), 4(8), 4(12), 4(14), 5, 6, 9, 12(3), 22, 25, 28(2) and 28(4), 30, 33, 35; Recital 26). Publications Office of the EU (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
