New EDPB Framework

GDPR Anonymisation vs Pseudonymisation: The 2026 EDPB Test

Published by GDPR Exam Trainer Editorial Team · Stand: 08/2026 · Primary-source reviewed

Is a hashed email anonymous? Does deleting names take a dataset outside the GDPR? Can data be anonymous for a recipient who lacks the key? These recurring practitioner and exam questions all turn on one distinction: GDPR anonymisation vs pseudonymisation.

Community discussions repeatedly confuse a protective technique with a change in legal status. This guide uses those questions only to identify the practical traps; the answers below are verified against Regulation (EU) 2016/679 and the European Data Protection Board’s Guidelines 02/2026, adopted for public consultation on 7 July 2026.

What is the difference between GDPR anonymisation and pseudonymisation?

Pseudonymisation keeps data within the GDPR (unless an exception such as the household exemption under Article 2(2)(c) applies) when a person can still be identified with additional information, while successful anonymisation produces information that does not relate to an identified or identifiable natural person and therefore falls outside the Regulation’s material scope.

Article 4(5) defines pseudonymisation as processing personal data so it cannot be attributed to a specific person without separately kept additional information protected by technical and organisational measures. Recital 26 supplies the anonymity test: consider the means reasonably likely to be used, taking objective factors such as cost, time and available technology into account. This builds on the definitions in our complete GDPR guide.

When is data truly anonymous under the EDPB’s 2026 framework?

Under EDPB Guidelines 02/2026, data may be regarded as anonymous when the relevant assessment finds no record isolation, no linkage and no specific, meaningful inference; the assessor must also choose whose capabilities and reasonably likely means matter.

The contextual approach assesses each relevant entity’s actual capabilities. The simplified approach ignores those capability differences, can go beyond the legal minimum and may provide greater confidence. The contextual approach is more precise; the simplified one is more conservative.

ScenarioExam-safe classificationWhy
Names replaced by codes; the controller retains a separate keyPseudonymised personal dataAdditional information can reconnect the records to people; Article 4(5) applies.
Unsalted hashes of known email addressesDo not assume anonymityA party may reproduce hashes and match records, creating isolation or linkage risk.
Independent recipient cannot identify people using means reasonably likely for itMay be anonymous for that recipientGuidelines 02/2026 allow entity-specific assessment, subject to the legal relationship and obligation.
Dataset passes all three EDPB criteria for every relevant entityMay be treated as anonymousNo record isolation, linkage or specific meaningful inference was found under the chosen approach.

What do no record isolation, no linkage and no inference mean?

The three criteria ask whether someone can single out one person’s record, connect the data with other information about that person, or derive specific and meaningful information about that person from record-level or aggregate data.

Exam trap: failing one criterion does not automatically prove that the dataset is personal data. Paragraph 52 of the Guidelines requires further analysis to assess the impact of the violation, as the data could still be considered anonymous.

Is a hashed email anonymous or pseudonymised data?

A hashed email is not anonymous merely because the original text is unreadable: if a party can hash a known address with the same method and match the result, the value can still enable record isolation or linkage and must undergo the full contextual assessment (or the simplified approach under the Guidelines).

EDPB Guidelines 01/2025 warn that a simple hash of a name can be reproduced across candidate names and matched to a pseudonymised dataset. Stronger secrets and technical controls can reduce risk, but pseudonymisation remains a safeguard rather than an automatic escape from GDPR duties. It can support data protection by design and security under Articles 25 and 32; it does not create its own lawful basis. For that separate question, see our legitimate-interest guide.

Whose perspective determines whether data is anonymous?

The relevant perspective depends on who is meant to receive or use the data and on the legal relationship: an independent recipient may be assessed from its own position, whereas a processor acting for a controller generally uses the controller’s perspective.

Guidelines 02/2026 incorporate the Court of Justice’s 4 September 2025 judgment in Case C-413/23 P, EDPS v SRB (paragraph 111). They also stress that perspective is obligation-specific: for the duty to inform data subjects about recipients when data is collected, the Court assessed the identifiable nature of the information solely from the controller’s perspective at the time of collection. Do not reduce the judgment to “no key means no GDPR”.

Frequently asked questions

The short answers below resolve the most common exam and implementation questions, but an anonymity conclusion still depends on the dataset, relevant entities, available additional information and means reasonably likely to be used.

Is pseudonymised data still personal data under the GDPR?

Yes, where the data can still be attributed to a person by using additional information. Article 4(5) defines pseudonymisation as a way of processing personal data, and Recital 26 says data that could be attributed to a person through additional information should be treated as information about an identifiable person.

Is a hashed email address anonymous data?

Not automatically. If an organisation can hash a known email using the same method and find a match, the hash can still help single out or link records. The result needs a contextual anonymity assessment; calling the technique hashing does not itself take the data outside the GDPR.

What are the EDPB's three anonymity criteria?

Guidelines 02/2026 use No Record Isolation, No Linkage and No Inference. Meeting all three supports treating the data as anonymous. If one criterion fails, the EDPB requires further analysis rather than treating the failure alone as conclusive.

Can the same dataset be anonymous for one recipient but personal data for another?

Potentially, yes. Guidelines 02/2026 state that anonymity may vary by entity because capabilities and reasonably likely means of identification differ. However, the relevant perspective depends on the legal obligation and relationship; a processor generally uses the controller's perspective rather than its own.

Practise the distinction, not a slogan

Test anonymisation, security and accountability concepts with realistic GDPR exam questions and answer explanations.

Start free

Primary sources

The legal analysis in this guide is based on the GDPR’s official EUR-Lex text and current EDPB guidance; community questions informed the structure but were not used as legal authority.

Who, how and why: The GDPR Exam Trainer Editorial Team prepared this guide for DPO exam candidates and practitioners. The method combined qualitative review of recurring community questions with paragraph-level checking against official EU texts. Automation assisted source discovery and consistency checks; no fictional reviewer or unpublished first-party statistic is claimed.