On 7 July 2026, the European Data Protection Board (“EDPB”) adopted new Guidelines on Anonymisation. These Guidelines clarify the notion of anonymous data under the GDPR and provide a practical framework for determining whether data has been successfully anonymised.
As anonymised data falls outside the scope of the GDPR, the Guidelines are particularly relevant for organisations seeking to share, reuse or analyse data while reducing GDPR compliance burdens. However, the EDPB warns that organisations often mistakenly assume that data has been anonymised when, in reality, individuals could still be re-identified.
1. A new focus on the recipient’s perspective
Anonymity is a relative concept rather than an absolute concept.
Under the GDPR, data is anonymous if it does not relate to an identified or identifiable natural person. Whether this is the case may vary from one entity to another. Anonymity must therefore be assessed from each relevant entity’s perspective.
This approach reflects recent CJEU case law, which confirmed that the same dataset may be regarded as anonymous for one organisation while remaining personal data for another, depending on the means available to identify the individuals concerned. The EDPB therefore emphasises that it is necessary to consider the different perspectives of the relevant entities when assessing whether data is anonymous.
2. Anonymisation is more than removing names
The EDPB reiterates that the absence of direct identifiers such as names, email addresses or identification numbers does not automatically make a dataset anonymous. Individuals may still be identifiable through combinations of attributes, additional datasets or further analysis.
Under the GDPR, information remains personal data if it relates to an identified or identifiable individual. Information can relate to a natural person because of its content, purpose, or effect. The existence of such a link may not be immediately obvious and could require further analysis.
An individual is considered ‘identified or identifiable’ if they can be distinguished from others in a specific context using means reasonably likely to be used in a way that makes it possible to treat them differently. Whether the means are reasonably likely to be used will depend on the relevant entity’s perspective and should be assessed in light of all objective factors.
3. The EDPB’s three-step anonymisation test
The Guidelines provide a practical framework for organisations to assess whether anonymisation has been successful. The EDPB frames this as the ‘No Record Isolation, No Linkage, No Inference’ test:
- No Record Isolation: the “No Record Isolation” criterion is met if the data does not contain a unique combination of attribute values that relate to a single individual;
- No Linkage: the “No Linkage” criterion is met if the data does not contain an individual’s record that could be linked, using means reasonably likely to be used, to another record relating to the same individual in a different dataset (re-identification likelihood must be “insignificant in reality”);
- No Inference: the “No Inference” criterion is met if no specific and meaningful inferences can be drawn from the given data.
The Guidelines further provide detailed explanations and examples to help organisations apply those criteria in practice.
If all three of the criteria are met, the data may be regarded as anonymous. Where one of the criteria is not satisfied, further assessment is required.
4. Two possible approaches
The EDPB also introduces two different assessment methods.
- Under the contextual approach, organisations assess anonymisation by taking into account the respective capabilities of the entities that may attempt to identify individuals.
- Under the simplified approach, organisations deliberately ignore differences between entities and assess whether re-identification is possible in a broader sense. According to the EDPB, the simplified approach may offer a more convenient option and provide greater confidence that data is genuinely anonymous. It can still be combined with the contextualised approach to refine the findings.
5. Why has the EDPB issued these Guidelines?
The Guidelines reflect the EDPB’s growing concern regarding increasing re-identification risks, particularly considering technological developments and advances in AI. The EDPB expressly notes that techniques used to link datasets, infer information and re-identify individuals are becoming more accessible and more powerful over time. Organisations are therefore encouraged to periodically reassess anonymised datasets and not assume that anonymisation remains effective indefinitely.
The Guidelines also remind organisations that the anonymisation process itself remains subject to the GDPR. Organisations must therefore ensure that they have an appropriate legal basis for the processing activities leading to anonymisation and that the anonymisation methodology is properly documented.
6. Key takeaways for organisations
The Guidelines provide a structured and practical framework for assessing whether data can genuinely be considered anonymous and for reducing re-identification risks.
Organisations wishing to rely on anonymisation should in particular:
- Avoid assuming that the removal of direct identifiers is sufficient;
- Assess anonymisation from the perspective of the relevant recipients of the data;
- Test datasets against the three criteria of No Record Isolation, No Linkage and No Inference;
- Carefully document the assessment performed; and
- Periodically reassess anonymised datasets in light of technological developments and evolving re-identification techniques.
These Guidelines are now open for public consultation until 30 October 2026.
If you have any questions regarding the EDPB’s new Guidelines on Anonymisation, their impact on your organisation, or your data sharing and anonymisation practices, feel free to reach out to the authors of this article: Maïka Bernaerts, Arnaud Bouten or Marie-Ysaline Lannoye.
***
This newsletter does not constitute legal advice or a legal opinion. Please consult with a legal counsel before taking any action based on the information provided.
