AI Policy Wiki
Dashboard

EDPB Guidelines 02/2026 on Anonymisation

high confidence · updated 2026-07-26

European Data Protection Board framework for determining whether data has been successfully anonymised and so falls outside the GDPR. Holds that anonymity is relative to each entity's perspective rather than absolute, and sets a three-criterion technical test — No Record Isolation, No Linkage, No Inference — applied either through a 'contextual approach' reflecting the full legal standard or a stricter 'simplified approach' that ignores differences in identifying capability.

Version 1.0, adopted July 7, 2026 by the European Data Protection Board under Article 70(1)(e) GDPR, for public consultation to October 30, 2026.

Why the question matters

Anonymous data falls outside the GDPR entirely, so the anonymisation threshold determines the reach of the regulation. The guidelines' stated aim is "to ensure that data is safely anonymised where possible and proportionate, allowing for free and fruitful use of data while preserving the rights and protections of natural persons."

Anonymity is relative, not absolute

The framework's organizing move is to reject a single global answer: "Under the GDPR, data is anonymous if it does not relate to an identified or identifiable natural person. Whether this is the case may vary from one entity to another. Consequently, anonymity should be assessed from each relevant entity's perspective – typically any party for whom the data is intended to be anonymous."

Two definitional points follow. Information "can relate to a natural person by reason of its content, purpose or effect," and "the existence of such a link need not be readily apparent and may require some processing to establish." And a person is identified or identifiable "if they can be distinguished from others in a given context using means reasonably likely to be used and in a way that makes it possible to treat them differently" — the second clause tying identifiability to differential treatment rather than to naming.

"Means" is read broadly: it "may include means that are only accessible through a third party," with the reasonable-likelihood question turning on the relevant entity's perspective "in light of all objective factors."

Two approaches

The contextual approach "considers the differences in capabilities between those who might identify the data subject" and "reflects the full nuances of the legal standard," allowing per-entity assessment.

The simplified approach ignores those differences. The board is candid that it is not the legal standard: it "can go beyond the legal standard and may lead an anonymising controller to treat data as though it is not anonymous even if it would actually be so for some relevant entities." Its compensations are convenience, "greater confidence that data is actually anonymous," and combinability with the contextual approach "to refine the findings."

The three criteria

Anonymity is tested against No Record Isolation, No Linkage, and No Inference, used "to assess the effectiveness of possible (re-)identification techniques."

The board's generalization about where risk concentrates: "(re-)identification is more likely to be successful against record-level data with high dimensionality and high resolution, but other factors are also important." Techniques are assessed "on their ability to generate accurate results, in particular whether they produce an answer which is sufficiently precise and reliable to allow the data subject to be distinguished and treated differently."

If all three criteria pass under either approach, "the given data can be safely considered anonymous." A failure is not automatically disqualifying — "further analysis should be done to determine if the data may nevertheless be considered anonymous," in particular "whether any isolated records, possibly together with linked data, allow for singling out individuals."

The guidelines include a glossary and a flowchart for the technical analysis, and address datasets containing a mix of anonymous and personal data and the GDPR status of the anonymisation process itself.

Relationships