The EDPB's guidelines on anonymisation: one legal standard, two approaches, three criteria
On 7 July 2026, the European Data Protection Board (“EDPB”) adopted for public consultation the first version of its Guidelines 02/2026 on Anonymisation (the “Guidelines”).
The last time this topic was addressed by EU-level regulatory guidance was in 2014 (Opinion 05/2014) by the Article 29 Working Party, which was replaced by the EDPB when the GDPR came into effect. Since then, we have seen significant changes in the legal and technical landscape, including several important CJEU cases on the concept of personal data and anonymisation, which the updated Guidelines seek to reflect. This shift reshapes how organisations should think about anonymisation, particularly when sharing or re-using data on the basis that it is anonymous, and therefore not subject to the requirements of the GDPR.
Looking to the broader legislative reforms proposed to the GDPR under the Digital Omnibus Package, it is notable that the EDPB opposed the suggested change to the definition of personal data, which proposed codifying elements of the decision in EDPS v SRB (Case C-413/23 P) (“EDPS v SRB”), effectively rendering subjective the question of whether data constitutes personal data. This is in part why the EDPB has addressed this in such detail in the Guidelines, in recognition of the web of issues to navigate.
1. Legal Standard
A relative approach to personal data
The central legal proposition of the Guidelines is that anonymity is not a single, universal property of a dataset, but a relative one, assessed from the perspective of each entity that may come into contact with the data.
The Guidelines restate the core legal standard for determining if data is anonymous (i.e. whether the data "relates" to an "identified or identifiable" natural person), emphasising that:
the response may vary from one entity to another, with the result that the same dataset may be personal in the hands of one organisation and anonymous in the hands of another (i.e. as confirmed in EDPS v SRB); and
whether an individual is identified or identifiable is not assessed in an absolute sense, but rather on the basis of how likely it is that the individual will be identified or identifiable by the relevant entity; taking into account the means that such entity is reasonably likely to use in order to do so.
It is therefore important to consider both the different perspectives of each relevant entity– the aim being to ensure that the resulting data is anonymous for all of the relevant entities being considered – and the realistic likelihood of re-identification by that entity. Where such likelihood is “insignificant in reality”, data can be considered anonymous.
To properly frame this consideration, the EDPB provides a wide, non-exhaustive list of “relevant entities” who could contribute to identification - whether by receiving the data (directly or indirectly) or by supplying additional information that enables re-identification - from the controller itself and any data recipients, to cyber criminals illegally accessing data through prohibited means.
The Processor’s perspective
The Guidelines confirm that whether data is personal for a processor should be assessed by reference to their controller’s perspective, effectively preventing a controller from avoiding GDPR compliance obligations simply by outsourcing their processing activities to a third party.
"Means reasonably likely to be used"
Again leaning on the CJEU case law, including EDPS v SRB, the means reasonably likely to be used to identify an individual are judged against all objective factors, including the properties of the data, the context and any effective restrictions on access, the availability of additional information, the cost and time required to obtain it, and the state of the art, together with reasonably foreseeable technological developments.
The concept of "means" is broad and extends to means available through third parties (i.e. via a “chain” of means). The EDPB cautions against relying on an entity's supposed lack of motivation to re-identify, since motivations are difficult to demonstrate objectively and may change, and notes that a contractual prohibition on re-identification cannot be equated with a legal one; contracts may only complement technical measures, given that they can typically be revised or disregarded.
In response to the CJEU determination that “means” do not need to be considered if, in reality, the likelihood of their use is insignificant because they are prohibited by law, the Guidelines start from a general assumption that people will follow the law, but treat this as a rebuttable presumption if there is “sufficient evidence of a concrete risk that unlawful means are nevertheless reasonably likely to be used”, taking in to consideration, for example, evidence of weak enforcement, gains outweighing costs, particularly vulnerable data, or a history of breaches in comparable situations.
Anonymisation is a processing activity
Taking a brief look at additional considerations, the EDPB emphasises that the principles of data protection apply whenever personal data is processed. The EDPB reminds organisations that anonymisation, including processing operations carried out to obtain anonymous information, is itself a processing activity which requires compliance with the GDPR. Controllers should not describe data as "anonymous" or "de-identified" where individuals remain identifiable and should transparently inform data subjects that anonymisation will take place.
The Guidelines recommend adequately documenting the anonymisation process and its testing so that both the compliance of the anonymisation and its effectiveness can be demonstrated.
2. Approaches: contextual and simplified, and how to choose
Having addressed the legal analysis of anonymisation, the Guidelines then turn to the technical analysis of determining whether or not data is anonymous. They incorporate a framework that takes into account the state of the art of re-identification techniques. A significant feature of this framework is that it invites controllers to choose between two ways of assessing anonymity: applying a “contextual approach” and a “simplified approach”.
Contextual Approach
Under the contextual approach, the controller identifies each relevant entity, considers that entity's specific capabilities, and asks whether any of the means it is reasonably likely to use could result in identification. The EDPB acknowledges that this can be a complex approach, and is one that can lead to the conclusion that data is anonymous for a particular recipient even though it remains personal for the discloser.
The EDPB also warns that a contextual analysis can also run the risk of false positives – incorrectly concluding data is anonymous because a relevant entity's re-identification capabilities have been underestimated - and recommends building adequate safety margins into the assessment so that it remains robust as those capabilities evolve.
Simplified Approach
The simplified approach disregards differences between entities regarding their access to the given data, additional information or other resources that could contribute to re-identification. The Guidelines emphasise that this is not an alternative legal standard; instead, it is a voluntary shift of risk in which the controller accepts that data may be treated as personal even where it would in reality be anonymous for some relevant entities, taking a more cautious and consistent level of protection than might strictly be necessary.
For organisations processing sensitive information, subject to overlapping regulatory regimes, or unable to map recipient capabilities with confidence, the simplified approach may be the more defensible starting point, even at the cost of some analytical accuracy.
How to choose
The Guidelines do not require an "all or nothing" choice between the two frameworks. The EDPB envisages that many controllers will use them in combination - for example, beginning with a simplified analysis to test whether re-identification is even possible in theory and, if it is, shifting to a contextual analysis to consider whether those methods are reasonably likely to be used by the relevant entities.
The value of this hybrid approach lies in the sequencing: the simplified pass can filter matters quickly, while the contextual analysis is reserved for the matters where finer judgment is genuinely required. It also means that while the simplified approach could be useful for anonymising controllers to prove that the information is anonymous (and therefore not in scope of the GDPR), third parties cannot rely on it to establish that a controller is in fact processing personal data.
3. Criteria
Underpinning both approaches is a three-criteria test to be applied to assess if data is anonymous and evaluate the effectiveness of (re-)identification techniques that might be deployed against the data, whether intentionally or not:
No Record Isolation? Whether the data contains a unique combination of attribute values that relate to a single individual;
No Linkage? Whether any record can be linked to another record, in a different dataset, that also relates, with certainty or high likelihood, to the same individual; and
No Inference? Whether any "specific and meaningful" inference can be drawn that is liable to affect an individual’s rights and interests, which relies on the given data and could not be obtained from general knowledge or from data about the population at large.
The No Record Isolation criterion is assessed by reference to the given data alone.
The No Linkage criterion requires knowledge and understanding of other datasets that could be linked, and the means reasonably likely to be used to do so.
The EDPB is explicit that inferences drawn by querying or prompting AI models and synthetic datasets can violate the No Inference criterion where those inferences are meaningful - a warning for organisations treating model outputs as inherently anonymous.
Data is presumed anonymous where all three criteria are met. Otherwise, further analysis is required to determine if the data may nevertheless be considered anonymous.
Final thoughts and actions
The Guidelines are pragmatic where they need to be, providing practical, illustrative examples throughout and endorsing a relative, entity-specific standard that aims to allow organisations to share properly protected data with recipients that genuinely cannot re-identify individuals.
A flowchart to support the technical analysis of anonymity is also provided to support organisations with their assessments.
That said, the Guidelines are, in several respects, stricter than the position on which many organisations have been operating: the assessment for processors being done from the controller's perspective, the raised evidential bar for legal prohibitions, and the limited role afforded to contracts may require existing data flows to be revisited.
In our view, organisations will be using the Guidelines to determine what approach they should take to assess their anonymisation practices and explore what additional uses they could put anonymised data to, if they are able to conclude that their data points could be seen as being anonymised. We expect to see more organisations needing to undertake and document identifiability assessments to support their views, for accountability purposes.
The EDPB emphasises that, while new assessments are not required as a result of publication of the Guidelines, it is in any event good practice for organisations to periodically reassess the likelihood of re-identification of anonymous data being processed. Security incidents could trigger a fresh anonymity assessment, and technological advances in AI, and especially agentic AI, are expected to compress the time and cost of re-identification, so anonymisation which holds today may not hold tomorrow – another reason not to approach anonymisation as a “one and done” exercise.
When approaching a periodic reassessment, organisations should consider:
conducting a data-mapping exercise of data considered anonymous;
identifying the entities from whose perspective such anonymity must hold;
applying the three criteria and deciding whether the simplified or contextual approach - or a combination of them both - best fits the risk profile of the dataset;
documenting the anonymisation process, and retaining this documentation after the completion of the anonymisation process.
Feedback to the Guidelines can be provided until 30 October 2026 here.
If you would like to discuss the Guidelines in more detail, or have any questions about your anonymisation practices, please contact our Data Protection team or your usual Stephenson Harwood contact.