MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Truly anonymized data falls outside the scope of the GDPR, but in practice, people often think they are anonymizing while actually pseudonymizing — and in that case, the GDPR applies. Four persistent misconceptions: pseudonymization is not anonymization, encryption is not anonymization, “anonymous” does not remain anonymous forever, and anonymization is not always possible without rendering the data unusable.
Anyone who processes personal data must comply with the GDPR . Anonymization can be a solution: if the person is no longer identifiable, the data may be processed freely (such as in scientific research). However, there are misunderstandings regarding anonymization. The European Data Protection Supervisor (EDPS) and the Spanish supervisor (AEPD) drafted a joint memorandum on the subject. They aim to correct these four misunderstandings.
1. Pseudonymization is not anonymization
Sometimes people think they are anonymizing, but they are actually pseudonymizing. With pseudonymization, individuals can still be identified using additional information; with true anonymization, this is never possible. Pseudonymization is permitted, but the GDPR still applies — you therefore need a valid legal basis, such as consent.
2. Encryption is not anonymization
Encryption is also a pseudonymization technique, not anonymization. With the secret key, the information—and thus the identity—can be restored. Whoever possesses the key does not anonymize. Even if the keys are deleted, this does not automatically constitute anonymization: that depends, among other things, on the length of the keys and the extent to which they can be traced.
3. Anonymous does not necessarily always remain anonymous
What is anonymous today may not be tomorrow. New techniques (such as quantum computing) can undermine existing anonymization methods, and stolen “anonymous” datasets may potentially be de-anonymized later. Information released or leaked later can also ensure that anonymous data can still be traced back to individuals. Complete anonymization is the goal, but it can never be 100% guaranteed.
4. Anonymization is not always possible
There is always a trade-off between the usability of data and the risk of re-identification. Sometimes that risk cannot be reduced sufficiently without rendering the data unusable, for example, if the group of potential individuals is too small. Consider the Wi-Fi tracking by the municipality of Enschede: this was not a problem in large crowds, but during quiet moments it was possible to determine who belonged to which code — and people could be tracked.
Frequently Asked Questions
What is the difference between anonymization and pseudonymization?
With anonymization, the person can no longer be identified, and the processing falls outside the scope of the GDPR. With pseudonymization, however, this is possible with additional information, and the GDPR remains applicable.
Does encrypted data fall outside the GDPR?
No. Encryption is pseudonymization: the identity can be restored with the key. Encrypted personal data remains personal data under the GDPR.
Can I always anonymize data?
Not always. Sometimes reducing the re-identification risk comes at the expense of usability, or the risk simply cannot be mitigated sufficiently.
Assistance with the correct application of the GDPR
Anonymization is more complex than it seems; it often involves pseudonymization, to which the GDPR applies. The privacy experts at MKB Juristen help you apply this correctly. View our expertise in privacy and data protection or contact us.