Article content
In briefShow moreShow lessThe EDPB published draft guidelines on pseudonymisation.
- The EDPB published draft guidelines on pseudonymisation.
- The measure must be assessed across the whole system: who holds the linking key, who can combine datasets, and what means are reasonably available?
- Relevant EDPB draft guidance for Norway's EEA GDPR regime; it did not change the GDPR and was open for consultation.
What happened
The EDPB published draft guidelines on pseudonymisation. Data remains personal data when it can be attributed to a person using additional information. Pseudonymisation can still reduce risk and support privacy by design and security.
The measure must be assessed across the whole system: who holds the linking key, who can combine datasets, and what means are reasonably available? Key separation, access control and logging determine whether risk reduction is real.
Legal status in Norway
Relevant EDPB draft guidance for Norway's EEA GDPR regime; it did not change the GDPR and was open for consultation.
What the sources clarify
The guidelines distinguished pseudonymisation from anonymisation. A code, token or separate key table can make data harder to connect to an individual and reduce the effect of unauthorised access. Where additional information exists and re-linking remains possible, the GDPR still applies. Organisations therefore need to control the key, assess whether datasets can be joined through other attributes and state which threat actors the measure addresses.
Pseudonymisation can support data minimisation, security and legitimate-interest assessments, but it does not remove requirements for a legal basis, transparency, rights handling or retention control.
Key material should be managed separately from pseudonymised data, with restricted access, logging and clear deletion rules. Reidentification tests should account for data the recipient already holds, not merely the dataset being transferred. That assessment determines both how much the measure reduces risk and which parties can still identify individuals.
Practical implications
Approval of a pseudonymisation design should describe the attacker it addresses, who can re-link data and how quickly the key can be disabled. If a recipient can identify people using its own information, sharing must be treated accordingly. A new linkage or recipient should trigger a fresh reidentification assessment.
Sources
European Data Protection Board: “EDPB adopts pseudonymisation guidelines,” 17 January 2025.
European Data Protection Board: “EDPB Guidelines 01/2025 on pseudonymisation,” 17 January 2025.
For discussion
Which control should we verify first?

