🤔 Can Data ever truly become anonymous?
Determining when information ceases to be Personal Data remains one of the most important questions under the GDPR. For organizations operating in the Life Sciences sector, the answer has significant practical consequences. It affects how Health Data can be shared, whether research datasets remain subject to GDPR obligations, and how organizations design their broader data governance frameworks.
More than a decade after the Article 29 Working Party published Opinion 05/2014 on anonymization techniques, the European Data Protection Board (EDPB) has revisited this complex area in its Draft Guidelines 02/2026 on Anonymisation. The Guidelines aim to provide greater clarity on the distinction between Personal Data and Anonymous Data in an environment shaped by artificial intelligence, advanced analytics, and increasingly interconnected datasets.
The timing is significant. Since the publication of Opinion 05/2014, both technology and the legal landscape have evolved considerably. In particular, the Court of Justice of the European Union (CJEU) recently considered the concept of identifiability in EDPS v Single Resolution Board (Case C-413/23 P), confirming that whether information is anonymous cannot be determined in the abstract. Instead, the assessment depends on the circumstances of processing and the means reasonably available to identify individuals. Against this background, the EDPB’s Draft Guidelines move beyond a purely technical assessment of anonymization and emphasize the importance of context.
One of the key messages of the Guidelines is that anonymization is not achieved simply by removing names or obvious identifiers. While the Article 29 Working Party’s 2014 Opinion focused primarily on techniques such as randomization and generalization, the EDPB places greater emphasis on the broader circumstances in which data is processed. The central question is therefore not simply whether direct identifiers have been removed, but whether individuals remain identifiable considering the information available, the means reasonably likely to be used, and the capabilities of the relevant actors. This approach reflects the reasoning of the CJEU in EDPS v SRB, which confirmed that identifiability depends on whether identification is reasonably likely using available means, taking into account factors such as technology, cost, time, and practical feasibility. As a result, anonymity is not necessarily an inherent characteristic of information. The same dataset may be anonymous for one organization while remaining Personal Data for another organization with access to additional information or different technical capabilities.
📋 The EDPB’s framework for assessing anonymization
To determine whether anonymization has been achieved, the Guidelines introduce a structured assessment based on three key criteria:
- No record isolation: individuals cannot be singled out because of unique combinations of characteristics.
- No linkage: records cannot be connected with other datasets relating to the same individual.
- No inference: meaningful information about a specific individual cannot be derived from the dataset.
These criteria should be considered together. Failure to satisfy one criterion does not automatically mean that information remains Personal Data; rather, it indicates that further assessment is required to determine whether individuals can still be identified in practice. The Guidelines also reinforce an important principle: removing names and obvious identifiers is rarely sufficient. Information that appears harmless in isolation may become identifying when combined with other available datasets. These data points, often referred to as quasi-identifiers, can create re-identification risks through combinations of characteristics such as age, location, demographics, or health information.
The examples provided by the EDPB illustrate the risks associated with apparently anonymized datasets. One example considers a dataset where dates of birth have been reduced to birth years, postcodes have been partially masked, and medical information has been generalized. Although individual records may no longer appear unique, another dataset containing the same combination of characteristics could enable linkage and potentially reveal sensitive information, such as a medical diagnosis.
In addition, the Guidelines distinguish between two approaches to assessing anonymity.
- The contextual approach reflects the GDPR standard and the reasoning in EDPS v SRB. It considers the specific circumstances of processing, including the information and capabilities realistically available to the relevant entities.
- The simplified approach allows organizations to apply a more conservative assessment without distinguishing between different actors. While this may provide greater operational certainty, it may also result in organizations treating information as Personal Data even where it could be considered anonymous from the perspective of a particular recipient.
A further example in the Guidelines demonstrates how a contextual assessment may support a conclusion that data is anonymous. A research institute considers potential access by relevant groups, including employees, accidental recipients, malicious actors, and public authorities, and concludes that none would realistically possess the additional information needed to identify individuals. The example highlights that anonymization depends not only on technical safeguards, but also on governance measures, access controls, and documented evidence supporting the assessment.
⏳ Anonymization is not a permanent status
Another important message from the Guidelines is that anonymization should not be viewed as a permanent label attached to a dataset. The EDPB recognizes that technological developments, new datasets, and increasingly sophisticated analytical techniques, including AI systems, may change re-identification risks over time. Organizations should therefore be prepared to revisit anonymization assessments where circumstances materially change. This may have significant implications for organizations that rely on anonymized or de-identified datasets for research, collaboration, or innovation. Existing methodologies may need to be reviewed, assumptions documented more clearly, and assessments updated as new technologies and data sources emerge.
💡 Implications for Life Sciences organizations
For organizations operating in data-intensive sectors such as Life Sciences, a fundamental question follows: if a dataset is considered anonymous today, can organizations demonstrate that it will remain anonymous tomorrow?
This question is particularly relevant in Life Sciences, where anonymization supports research collaborations, secondary use of Health Data, real-world evidence initiatives, and AI-enabled Healthcare innovation. The EDPB’s emphasis on context, documentation, and ongoing reassessment may require organizations to strengthen governance processes, document anonymization decisions more clearly, and ensure that conclusions remain supported by evidence over time.
A key issue during the consultation process will be whether the Guidelines fully reflect the CJEU’s reasoning in EDPS v SRB, particularly where legislation creates a theoretical possibility of accessing additional information but such access would be unrealistic or unlikely in practice.
Ultimately, the Draft Guidelines represent the first comprehensive update on anonymization since the Article 29 Working Party’s Opinion 05/2014. They reinforce that anonymization is not simply the removal of identifiers or the application of a technical method, but a documented assessment based on the context of processing, the actors involved, and the means reasonably likely to be used for identification.
With the public consultation remaining open until October 30, 2026, organizations have an opportunity to contribute practical experience and help shape the final version of the Guidelines.
Author: Myrto-Amaryllis Lappa