Guidelines 01/2025 on Pseudonymisation European Data Protection Board

2025
Category
  • Execute
  • Data management
  • Data Protection

These draft Guidelines 01/2025 on Pseudonymisation were adopted for public consultation by the European Data Protection Board in January 2025. They explain, in plain terms, what pseudonymisation means under the General Data Protection Regulation, when it helps, and what its limits are. The document is written for organisations that handle personal data and need a clear, practical frame for designing, assessing or improving pseudonymisation.

Legal definition and scope
Explains the General Data Protection Regulation definition of pseudonymisation and how it differs from anonymisation, stressing that pseudonymised data are still personal data. Sets out basic terms such as attribution, additional information and pseudonymisation secrets.

Objectives and advantages
Describes pseudonymisation as a way to lower privacy risks, reduce unnecessary use of identifiable data and support re‑use of data in a safer way. Shows how it can help justify legitimate interests, further use of data and some international transfers when combined with other safeguards.

Introduces the idea of the pseudonymisation domain as the group of people, systems and organisations that should not be able to re‑identify individuals. Explains that clearly defining and isolating this domain is central to deciding how far data must be changed.

Shows how pseudonymisation can support key General Data Protection Regulation duties such as data protection by design and by default, data minimisation, purpose limitation, security of processing, research use and breach handling. Underlines that it is one measure among several and does not make data anonymous.

Gives a high‑level overview of common approaches, such as removing or replacing direct identifiers, treating quasi‑identifiers, and using cryptography or lookup tables. Highlights the need to protect keys and tables, control access and design pseudonyms so records cannot easily be linked back to a person.

Outlines how pseudonymised data can be shared with other parties and when a second layer of pseudonymisation is advisable and describes options for linking pseudonymised datasets from different sources under controlled conditions.

Clarifies that individuals still have rights over pseudonymised data, unless the controller truly cannot identify them with reasonable effort. States that any unauthorised undoing of pseudonymisation is a personal data breach that may have to be reported.