Sustainability Language

Anonymisation

The transformation of data so that no individual is identifiable by means reasonably likely to be used, taking the data, available auxiliary information and context into account.

Established · Version master-draft-2026-08-10

Expert review openNo editor-accepted expert review yet

Definition

The transformation of data so that no individual is identifiable by means reasonably likely to be used, taking the data, available auxiliary information and context into account.

Overview

“Removing a name is easy. Removing the possibility of identification is the real test. ”

Anonymisation is frequently claimed after direct identifiers have been removed. Names become numbers, phone numbers are deleted and the dataset is described as anonymous. Yet a precise farm coordinate, rare job title, household composition or combination of dates may still identify a person when linked with other information.

Recital 26 of the General Data Protection Regulation distinguishes anonymous information from personal data by asking whether a person is identifiable, considering all means reasonably likely to be used by the controller or another person. Truly anonymous data fall outside the GDPR. The threshold is therefore demanding because the legal consequence is significant.

In July 2026, the European Data Protection Board adopted draft Guidelines 02/2026 on Anonymisation for public consultation.

The guidance uses three practical tests: whether a record can be isolated, whether records can be linked and whether information can be inferred about a person. Failure on one test does not automatically settle every case, but it signals that further analysis and protection are required. Location data show the difficulty. A map of farms may contain no names.

In a sparsely populated area, boundaries can be matched with public land records, satellite imagery or local knowledge. The person behind the polygon may be obvious to neighbours and buyers. Removing a lookup table does not make the geography anonymous. Context changes the result. A dataset shared with the public faces different auxiliary information and attackers from a dataset held in a secure research environment.

Anonymisation should be assessed for the intended release, recipients, technology, incentives and time.

Data that are effectively anonymous in one setting may remain personal in another. Techniques involve trade-offs. Aggregation can combine records into groups. Generalisation can replace exact age or location with ranges. Suppression removes rare values. Noise can reduce precision. More advanced approaches such as differential privacy can limit what repeated queries reveal.

Each technique protects against particular risks and can reduce usefulness. Utility should not be preserved at any cost. An organisation may claim data are anonymous while retaining enough detail to perform individual-level targeting. That contradiction should prompt challenge. If the use still depends on distinguishing the same person or farm over time, pseudonymisation may be the more honest description.

Anonymisation is not a one-time deletion step. New datasets, improved computing and changing public information can increase re-identification risk. Release governance should include periodic review, controls on linkage and clear response if the original assumption no longer holds. Group harms can remain even when individuals are not identifiable.

Aggregated data may stigmatise a region, expose an Indigenous community or influence prices and policing. Falling outside personal-data law does not remove ethical responsibility for collective effects. Claims should be precise. De-identified, aggregated, masked, pseudonymised and anonymised are not interchangeable.

If the organisation retains a practical route to reconnect the data or if recipients can reasonably identify people, the data remain personal and associated obligations continue.

The discipline is to test an adversarial question: who might want to identify someone, what other information could they obtain and what would count as reasonable effort in this context? Anonymisation is not the absence of a name. It is the absence of a reasonably likely path back to a person.

Practical application

Define the release context and plausible attackers. Test singling out, linkage and inference using available auxiliary data. Apply appropriate aggregation, suppression, generalisation, noise or controlled-access measures, and document the effect on utility. Separate public release from restricted research access. Review re-identification risk over time and prohibit unauthorised linkage where enforceable.

Use accurate labels and retain GDPR controls whenever the anonymisation threshold is uncertain.

Why it matters

Anonymisation can enable research, transparency and data sharing while protecting individuals. Overclaiming it removes legal and organisational safeguards from data that still carry identifiable risk.

Common misconception

Anonymisation is often equated with deleting names or replacing them with codes. Those actions usually produce pseudonymised or de-identified data. Anonymous data must resist reasonably likely identification in context.

Connections

Pseudonymisation reduces linkability while preserving a controlled path back to the person. Data Minimisation reduces the information available for re-identification. Privacy by Design and Data Governance determine release context, access and ongoing review.

A question worth asking

What outside dataset, local knowledge or repeated query would make the people behind your anonymous records visible again?

Selected references

European Union. 2016. Regulation (EU) 2016/679, Recital 26. European Data Protection Board. 2026. Guidelines 02/2026 on Anonymisation, Version 1. 0 for Public Consultation. Article 29 Data Protection Working Party. 2014. Opinion 05/2014 on Anonymisation Techniques. Ohm, P. 2010. Broken Promises of Privacy: Responding to the Surprising Failure of Anonymization. UCLA Law Review 57: 1701-1777.

National Institute of Standards and Technology. 2015. De-Identification of Personal Information, NISTIR 8053.

Review

Editor-accepted expert reviews only.

0
No verified experts yet

Submitted reviews stay private until accepted.