19/02/2025 - In January, the European Data Protection Board (“EDPB”) published new guidelines on pseudonymization. In the guidelines, the EDPB discusses how pseudonymization can contribute to the lawful processing of data in line with the General Data Protection Regulation (the “GDPR”), for example, in the context of data security and privacy by design and privacy by default (measures when designing a process and measures that are built into a process by default and ensure data minimalization). In this blog, we briefly discuss the implications following the EDPB Guidelines.
Pseudonymization means that personal data is replaced by information that cannot be directly traced back to a specific individual without the use of additional information. The additional information is stored separately and that technical and organizational measures are taken to ensure that the pseudonymized data cannot be directly traced back to a specific individual. An example of pseudonymization is encryption, where data is made unreadable using an algorithm. A “key” is required to make the encrypted data readable again.
Because it remains possible re-identify pseudonymized data to an individual with the use of additional information, pseudonymized data should be considered personal data. This differs from anonymization, where the data is impossible to re-identify to a specific individual, even using additional information.
The guidelines, recently published for consultation, discuss the definition and the legal- and technical implications of pseudonymization. The legal implications discuss the benefits of pseudonymization which include improved information security, increased data confidentiality, facilitating lawful sharing of personal data to third parties and of a transfer of personal data to third parties outside the European Economic Area (“EEA”). It also addresses the effects of pseudonymization on the rights of data subjects and unauthorized re-identification of pseudonymized data (which could potentially result in a data breach).
Also, the annex to the guidelines provides a number of practical examples of pseudonymization related to a particular privacy matter. For example, the reduction of confidentiality risks when a hospital wants to analyze treatment data. By pseudonymizing the data and placing it in a separate environment , the analysis of treatment data by non-medical administrative personnel can take place in a separate and protected environment where information cannot be directly traced back to an individual patient. In doing so, data analysts do not need access to actual patient data and still be able to analyze the treatment data. Because the pseudonymized data is not directly traceable in this separate environment, the processing of medical data in such an environment is more likely to be considered adequately secure and confidential.
The effectiveness of pseudonymization depends largely on how it is applied within an organization. When properly implemented, it can serve as a “supplementary measure” for a data transfer outside the EEA or as a valuable technical measure in the further processing of data based on a legitimate interest. This can be relevant for processing personal data for data analytics or in an AI-model (for more on privacy and AI models, see this blog).
Finally, the EDPB emphasizes that organizations should keep in mind that pseudonymized data indirectly relates to an individual and should be considered personal data. The (further) processing of data in pseudonymized form should also comply with the principles of the GDPR.
The pseudonymization of personal data can be an effective way to (further) process personal data in line with GDPR, but this requires implementing the appropriate technical and organizational measures. Do you have any questions about securely implementing pseudonymization in your organization? Feel free to contact Considerati for Privacy Support or, for example, to conduct a DPIA.
Our services ContactRecente blogs
The use of AI raises significant (ethical) questions, especially when personal data is processed. A critical question is: can your organisation process…