What is pseudonymisation?
Pseudonymisation replaces the attributes that identify a person and keeps the key for reversing it separately under lock. Article 4(5) GDPR requires two things. Without additional information, the data can no longer be attributed to a person. And that additional information is "kept separately" and protected by technical and organisational measures.
Replacing attributes alone therefore does not meet the definition. A dataset whose mapping table sits in the same folder fails the second part. Where pseudonymisation fits into a data protection programme as a whole is covered in the GDPR guide.
What is the difference between pseudonymisation and anonymisation?
Pseudonymisation and anonymisation differ in whether they can be reversed, and that decides whether the GDPR applies.
| Attribute | Pseudonymisation | Anonymisation |
|---|---|---|
| Attribution to a person | possible with additional information | not possible, or no longer possible |
| Legal status for the controller | personal data | not personal data |
| GDPR applies | yes, in full | no |
| Purpose | reduce risk and keep using the data | take the data out of scope |
| Reversibility | intended and controlled | not intended |
Recital 26 GDPR records both: pseudonymised data that could be attributed to a person by the use of additional information count as information on an identifiable person. The principles of data protection do not apply to anonymous information. Treating a dataset as anonymous when it is only pseudonymised means processing personal data without the obligations that come with it.
Anonymous means no one is reasonably likely to re-identify
Data are anonymous when no one can attribute them to the person by "all the means reasonably likely to be used". That is the wording of recital 26 GDPR. The test is likelihood, not technical possibility, and it covers the means of the controller as well as those of "another person".
As objective factors, the recital names the cost of identification, the time it takes and the available technology, including technological developments. Because of that last factor, a dataset that is anonymous today can become re-identifiable with new technology; review the assessment when the available technology changes.
The Article 29 Working Party's Opinion 05/2014 on anonymisation techniques (WP216) names three routes back to the person:
- Singling out: a record is unique through its combination of attributes, such as postcode, date of birth and occupation. Recital 26 names singling out explicitly.
- Linking: a second dataset contains overlapping attributes.
- Inference: patterns in the dataset reveal attributes of individual people.
Document which attributes were removed, generalised or perturbed and which additional datasets are realistically available.
For whom are pseudonymised data personal data?
Pseudonymised data are personal data for the controller who holds the additional information; for a recipient, it depends on the recipient's means. The Court of Justice of the EU (CJEU) ruled this on 4 September 2025 in judgment C-413/23 P (EDPS v SRB).
The case concerned Regulation (EU) 2018/1725 for the EU institutions. According to paragraph 52, its definition of personal data is to be interpreted in the same way as Article 4(1) GDPR.
| Who holds the data | Personal data? | Paragraph of the judgment |
|---|---|---|
| Controller holding the additional information | yes, despite pseudonymisation | para. 76 |
| Recipient who cannot lift the measures and cannot identify the person even by cross-checking other data | not for that recipient | paras. 77, 86 |
| Recipient for whom a cross-check with data available to it cannot be ruled out | yes, including for later processing | para. 85 |
It follows that whether a service provider must treat pseudonymised data as personal data is assessed from its point of view. What counts is the data actually available to it.
Six places the GDPR uses pseudonymisation
In its articles, the GDPR names pseudonymisation in six places, each with a different function:
| Provision | Function of pseudonymisation |
|---|---|
| Article 4(5) | definition |
| Article 6(4)(e) | appropriate safeguard when assessing whether a new purpose is compatible with the original one |
| Article 25(1) | explicit example ("such as pseudonymisation") of data protection by design |
| Article 32(1)(a) | named security measure, together with encryption |
| Article 40(2)(d) | subject matter for codes of conduct drawn up by associations |
| Article 89(1) | possible safeguard for archiving, research and statistical purposes |
According to recital 28, pseudonymisation can reduce the risks to data subjects; it does not preclude other data protection measures. The obligations remain: legal basis, purpose limitation, information duties, erasure and data subject rights apply unchanged.
Four conditions for effective pseudonymisation
Pseudonymisation becomes effective by separating the mapping, not by replacing the identifiers. Four conditions decide:
- Store the mapping table or the key technically and organisationally apart from the dataset.
- Limit the group of people with access to both sides, name them and document it.
- Choose pseudonyms that cannot be derived from the original data. An unsalted hash of an email address can be reversed by trial.
- Treat re-identification as a process with a reason, an approval and a log.
The mapping table as an asset in Rizzqo
In Rizzqo you keep a pseudonymised dataset flagged as personal data, because for the controller it remains personal data. You record the mapping table or key register as a separate supporting asset. It has an assigned owner and links to the processes whose data it can re-identify.
From those primary assets, the table on which the whole pseudonymisation depends inherits the confidentiality rating and the personal-data flag.