Anonymisation means altering personal data in such a way that the data subject is not or is no longer identifiable.
When is data anonymous?
Data is anonymous if the data subject can no longer be identified, taking into account all the means reasonably likely to be used. Relevant factors include cost, the time required and the available technology.
Anonymous information does not fall under the GDPR. This makes anonymisation attractive, but the requirements are demanding: simply removing the name is usually not enough.
Distinction from pseudonymisation
Pseudonymisation replaces identifying features with codes, but the link to the person can be restored with additional knowledge. Pseudonymised data remains personal data; anonymised data does not.
Common anonymisation techniques include aggregation, generalisation (for example age groups instead of a date of birth) and adding noise. As data volumes grow and analysis tools improve, the risk of re-identification increases, so the result should be reviewed regularly.
Anonymisation as an alternative to erasure
Where data is no longer needed for its original purpose, effective anonymisation can take the place of erasure. Statistical analyses, for example, can then continue to be used without breaching the principle of storage limitation.
Legal provisions
- Recital 26 GDPR
- Clarifies that the GDPR does not apply to anonymous information and sets the standard for identifiability.
- Art. 4(1) GDPR
- Defines personal data and therefore when information relates to a person.
- Art. 4(5) GDPR
- Defines pseudonymisation as the counterpart concept.
- Art. 5(1)(e) GDPR
- Principle of storage limitation, which requires data no longer needed to be erased or anonymised.