Sustainability Language

Pseudonymisation

Processing personal data so they cannot be attributed to a specific person without additional information that is kept separately and protected by technical and organisational measures.

Established · Version master-draft-2026-08-10

Expert review openNo editor-accepted expert review yet

Definition

Processing personal data so they cannot be attributed to a specific person without additional information that is kept separately and protected by technical and organisational measures.

Overview

“A code can hide a name from a user without making the person disappear from the system. ”

Pseudonymisation is often described casually as anonymisation. A farmer's name is replaced with an identifier, the working file looks less personal and the organisation assumes data-protection obligations have been removed. The assumption is wrong. Pseudonymised data remain personal data because a route to attribution still exists.

Article 4(5) of the General Data Protection Regulation defines pseudonymisation as processing personal data so that they can no longer be attributed to a specific data subject without the use of additional information, provided that the additional information is kept separately and subject to technical and organisational measures. The separation is central.

If a spreadsheet contains FARMER-0047 in one column and the matching name in a hidden tab, the data are not meaningfully protected from users who can access both.

The lookup table, cryptographic key or other attribution information should have separate access, purpose and security. The public-consultation version of the European Data Protection Board's Guidelines 01/2025 explains how effective pseudonymisation can reduce risk and support compliance. The technique should be assessed against the people and systems that may receive the pseudonymised data.

A code unknown to an external analyst may still be easily attributable by the controller that holds the key. Pseudonyms should resist guessing and unauthorised correlation. Sequential farmer numbers, initials or hashes of national identity numbers can be reversible or linkable.

Random identifiers, keyed cryptographic techniques, tokenisation and domain-specific pseudonyms may provide stronger protection depending on purpose and threat. Purpose affects design.

A programme may need to link repeated surveys for the same household over time without revealing identity to analysts. A stable pseudonym supports longitudinal analysis. If the same pseudonym is reused across unrelated projects, it can enable broad profiling. Different domains may need different identifiers with controlled linkage. Access to attribution should be exceptional and logged.

Defined roles may reconnect records to correct data, respond to rights requests or deliver services. Broad administrator access defeats separation. Key loss and key compromise also need response plans because both can affect rights and operational continuity. Pseudonymisation can support data minimisation and security but does not establish a legal basis.

The underlying processing still requires lawfulness, fairness, purpose limitation, transparency and rights handling. People may have rights to access, correct, erase or object even where the working team cannot see their names. It can influence a legitimate-interest balancing test by reducing likely impact, but it does not make every processing fair.

The EDPB notes that risk reduction may help controllers rely on legitimate interests where other conditions are met. The three-step test remains necessary. Claims should identify the perspective. A dataset may be pseudonymous for one recipient and directly identifiable for another. Saying the data are pseudonymised without explaining who holds additional information can hide the real control structure.

The discipline is to design attribution as a governed capability. Who can reconnect the record, for which purpose, with which evidence and audit trail?

If everyone can reverse the code or the same identifier follows a person across systems, the measure offers appearance rather than meaningful separation.

Practical application

Map the parties that can identify data subjects and design pseudonyms for the intended context. Keep attribution information separately with stronger access, encryption, logging and retention controls. Avoid guessable or widely reused identifiers. Test linkability across datasets and recipients. Define authorised re-identification purposes and procedures.

Document residual risk, preserve data-subject rights and review the method when new data or recipients increase the possibility of attribution.

Why it matters

Pseudonymisation allows useful analysis and operations while reducing exposure of identity. It limits harm from ordinary access and some breaches, but only where separation and governance are effective.

Common misconception

Pseudonymised data are often described as anonymous and outside data-protection law. They remain personal data whenever additional information can reconnect the record to a person, even if another party holds that information.

Connections

Anonymisation seeks to remove reasonably likely identification altogether. Privacy by Design integrates pseudonymisation into architecture. Legitimate Interest and DPIA may take its risk reduction into account, while Data Governance controls keys and re-identification.

A question worth asking

Who can reconnect your pseudonymous record to a person, and what prevents that capability from becoming ordinary rather than exceptional?

Selected references

European Union. 2016. Regulation (EU) 2016/679, Articles 4(5), 25 and 32 and Recital 28. European Data Protection Board. 2025. Guidelines 01/2025 on Pseudonymisation, Version 1. 0 for Public Consultation. European Data Protection Board. 2025. Summary of Guidelines 01/2025 on Pseudonymisation, Consultation Materials. European Union Agency for Cybersecurity. 2019. Pseudonymisation Techniques and Best Practices.

International Organization for Standardization. ISO/IEC 20889:2018. Privacy Enhancing Data De-Identification Terminology and Classification of Techniques.

Review

Public comments appear only after editor acceptance. Draft comments stay in the review queue.

0
How people contribute

Reviewers choose the definition or an overview paragraph, leave a comment or replacement, and attach evidence or a source link.

How comments are used

Editors compare reviewer cards side by side. AI may help find agreement, conflicts, unsupported claims and possible source issues.

What gets published

Only an editor-accepted synthesis changes the public page. Reviewer identities are shown only with consent and verification.

No verified experts yet

Submitted reviews stay private until accepted.

Loading verified endorsements… Endorsements are not votes and never determine publication.

Endorse this definition

Endorse the exact version shown here. This is not a vote, and publication remains an editorial decision.

vmaster-draft-2026-08-10

Sign-in supplies your email for verification and necessary follow-up; it is not displayed publicly. We do not ask you to enter it again.

Sign in with a passwordless email link before submitting.

Review board

Comment on a specific line. Each reviewer stays separate until an editor accepts a merged draft.

1Separate reviewer cards

Each person comments on the definition or overview in their own draft card, with role, evidence and suggested wording kept together.

2AI comparison

AI can compare comments against the current text, flag conflicting claims, surface missing evidence and identify where reviewers agree.

3Editor synthesis

An editor merges compatible suggestions into a draft change, checks sources, records disagreements and decides what can be published.

Text to reviewChoose the exact definition or overview paragraph.
Reviewer commentDraft only. Not public until editor accepted.
Definition
Reviewer identityYour signed-in account identifies the submission. We use its email only for verification and necessary follow-up, and never display it publicly.
Before you submit

This proposal follows the editorial and AI-assistance rules. The live definition will not change until an editor accepts it.

  • Add the proposed wording or note.
  • Explain why the change is needed.
  • Ready
  • Ready

Sign in with a passwordless email link before submitting.

You can still save a draft, but completing these items makes editorial review faster. Multiple reviewers can suggest changes on the same text. Editors compare, merge, accept or decline them before any public change.