Pseudonymisation

Pseudonymisation, under Article 4(5) GDPR, is processing after which personal data can no longer be attributed to a person without additional information kept separately. For whoever holds that additional information, the data remain personal data. Anonymised data can no longer be attributed to anyone and fall outside the GDPR.

DSGVOLast reviewed:

What is pseudonymisation?

Pseudonymisation replaces the attributes that identify a person and keeps the key for reversing it separately under lock. Article 4(5) GDPR requires two things. Without additional information, the data can no longer be attributed to a person. And that additional information is "kept separately" and protected by technical and organisational measures.

Replacing attributes alone therefore does not meet the definition. A dataset whose mapping table sits in the same folder fails the second part. Where pseudonymisation fits into a data protection programme as a whole is covered in the GDPR guide.

What is the difference between pseudonymisation and anonymisation?

Pseudonymisation and anonymisation differ in whether they can be reversed, and that decides whether the GDPR applies.

AttributePseudonymisationAnonymisation
Attribution to a personpossible with additional informationnot possible, or no longer possible
Legal status for the controllerpersonal datanot personal data
GDPR appliesyes, in fullno
Purposereduce risk and keep using the datatake the data out of scope
Reversibilityintended and controllednot intended

Recital 26 GDPR records both: pseudonymised data that could be attributed to a person by the use of additional information count as information on an identifiable person. The principles of data protection do not apply to anonymous information. Treating a dataset as anonymous when it is only pseudonymised means processing personal data without the obligations that come with it.

Anonymous means no one is reasonably likely to re-identify

Data are anonymous when no one can attribute them to the person by "all the means reasonably likely to be used". That is the wording of recital 26 GDPR. The test is likelihood, not technical possibility, and it covers the means of the controller as well as those of "another person".

As objective factors, the recital names the cost of identification, the time it takes and the available technology, including technological developments. Because of that last factor, a dataset that is anonymous today can become re-identifiable with new technology; review the assessment when the available technology changes.

The Article 29 Working Party's Opinion 05/2014 on anonymisation techniques (WP216) names three routes back to the person:

  • Singling out: a record is unique through its combination of attributes, such as postcode, date of birth and occupation. Recital 26 names singling out explicitly.
  • Linking: a second dataset contains overlapping attributes.
  • Inference: patterns in the dataset reveal attributes of individual people.

Document which attributes were removed, generalised or perturbed and which additional datasets are realistically available.

For whom are pseudonymised data personal data?

Pseudonymised data are personal data for the controller who holds the additional information; for a recipient, it depends on the recipient's means. The Court of Justice of the EU (CJEU) ruled this on 4 September 2025 in judgment C-413/23 P (EDPS v SRB).

The case concerned Regulation (EU) 2018/1725 for the EU institutions. According to paragraph 52, its definition of personal data is to be interpreted in the same way as Article 4(1) GDPR.

Who holds the dataPersonal data?Paragraph of the judgment
Controller holding the additional informationyes, despite pseudonymisationpara. 76
Recipient who cannot lift the measures and cannot identify the person even by cross-checking other datanot for that recipientparas. 77, 86
Recipient for whom a cross-check with data available to it cannot be ruled outyes, including for later processingpara. 85

It follows that whether a service provider must treat pseudonymised data as personal data is assessed from its point of view. What counts is the data actually available to it.

Six places the GDPR uses pseudonymisation

In its articles, the GDPR names pseudonymisation in six places, each with a different function:

ProvisionFunction of pseudonymisation
Article 4(5)definition
Article 6(4)(e)appropriate safeguard when assessing whether a new purpose is compatible with the original one
Article 25(1)explicit example ("such as pseudonymisation") of data protection by design
Article 32(1)(a)named security measure, together with encryption
Article 40(2)(d)subject matter for codes of conduct drawn up by associations
Article 89(1)possible safeguard for archiving, research and statistical purposes

According to recital 28, pseudonymisation can reduce the risks to data subjects; it does not preclude other data protection measures. The obligations remain: legal basis, purpose limitation, information duties, erasure and data subject rights apply unchanged.

Four conditions for effective pseudonymisation

Pseudonymisation becomes effective by separating the mapping, not by replacing the identifiers. Four conditions decide:

  1. Store the mapping table or the key technically and organisationally apart from the dataset.
  2. Limit the group of people with access to both sides, name them and document it.
  3. Choose pseudonyms that cannot be derived from the original data. An unsalted hash of an email address can be reversed by trial.
  4. Treat re-identification as a process with a reason, an approval and a log.

The mapping table as an asset in Rizzqo

In Rizzqo you keep a pseudonymised dataset flagged as personal data, because for the controller it remains personal data. You record the mapping table or key register as a separate supporting asset. It has an assigned owner and links to the processes whose data it can re-identify.

From those primary assets, the table on which the whole pseudonymisation depends inherits the confidentiality rating and the personal-data flag.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework