Guidelines of the EDPB on Pseudonymisation: A brief overview

Guidelines pseudonymisation

The European Data Protection Board (EDPB) has issued Guidelines 01/2025 on Pseudonymisation, offering detailed instructions on the application of pseudonymisation as a tool under the General Data Protection Regulation (GDPR). These guidelines highlight its importance as a safeguard for protecting personal data and enabling compliance with data protection obligations while facilitating data utility.

Key Highlights

1. Definition and Scope:

  • Pseudonymisation is defined in Article 4(5) GDPR as the processing of personal data in a way that prevents attribution to a specific data subject without additional information, provided that such information is kept separately and safeguarded.
  • Unlike anonymisation, pseudonymised data remains personal data and is subject to GDPR. However, it offers enhanced data protection and flexibility in processing.

2. Advantages of Pseudonymisation:

  • Reduces Risks to Data Subjects: Minimizes the likelihood of identifying individuals, particularly in cases of data breaches or unauthorized access.
  • Enables GDPR Compliance: Supports principles such as:
    • Data Minimisation: Only essential data is processed in an identifiable form.
    • Purpose Limitation: Limits data use to specific objectives.
    • Confidentiality: Adds a layer of protection to personal data.
  • Facilitates Further Processing:
    • Enhances compatibility with legitimate further processing under Article 6(4) GDPR.
    • Supports controllers’ ability to rely on legitimate interests as a legal basis for processing.
  • Enables Cross-Border Data Transfers: Serves as a supplementary measure under Articles 44–46 GDPR, protecting data from access by third-country authorities.

3. Legal and Compliance Implications:

  • Data Protection by Design and Default: Pseudonymisation is recognized as an effective technical and organizational measure for embedding privacy into processing activities.
  • Mandatory Security Measure: Required for ensuring a security level appropriate to risks under Article 32 GDPR.
  • Scope for Flexibility: Controllers have discretion to implement pseudonymisation tailored to their specific processing activities and risk profiles.

4. Implementation Guidance:

The guidelines provide actionable steps for adopting pseudonymisation effectively:

  • Technical Techniques:
    • Use cryptographic methods (e.g., encryption, keyed one-way functions).
    • Apply lookup tables to separate identifiers from other data securely.
  • Defining the Pseudonymisation Domain:
    • Limit access to additional information (e.g., keys, lookup tables) to a restricted set of individuals or systems.
    • Ensure that pseudonymised data cannot be linked to identifiable individuals within the domain.
  • Safeguards:
    • Secure storage and management of pseudonymisation secrets.
    • Regular review and update of cryptographic methods to maintain robustness.

5. Data Subject Rights:

  • Pseudonymised data does not exempt organizations from complying with GDPR rights such as access, rectification, and erasure.
  • If the controller cannot identify data subjects without disproportionate effort, specific exceptions under Articles 11(2) and 12(2) GDPR may apply.

6. Practical Examples:

The guidelines include real-world scenarios showcasing pseudonymisation in action:

  • Internal Data Analysis: Using pseudonyms for research while preserving confidentiality.
  • External Sharing: Sharing pseudonymised data with partners while ensuring data minimisation and controlled re-identification.
  • Cross-Border Transfers: Applying pseudonymisation to mitigate risks in third-country data transfers.

7. Technical and Organizational Challenges:

  • Mitigating Unauthorized Reversal: Emphasis on secure algorithms and strict access controls.
  • Linkage Control: Determining appropriate pseudonym types (e.g., person pseudonyms, transaction pseudonyms) to balance data utility with privacy.
  • Compliance Monitoring: Controllers are encouraged to perform risk assessments regularly and update pseudonymisation practices in line with evolving standards.

Why This Matters to You

Pseudonymisation is a cornerstone of modern data protection strategy, enabling:

  • Risk Mitigation: Strengthening defenses against breaches and unauthorized access.
  • Innovation and Data Use: Supporting data-driven projects like analytics and AI while protecting individuals’ privacy.
  • Compliance Confidence: Demonstrating accountability and adherence to GDPR standards.

For businesses handling sensitive or large-scale personal data, pseudonymisation offers the flexibility to unlock data’s potential without compromising on privacy or security.

At “Stergios Konstantinou and Associates – SGKLegal”, we specialise in data protection and cybersecurity law. We provide comprehensive services for compliance with GDPR and the new Law 5160/2024 (NIS 2).