Pseudonymisation
Pseudonymisation is a technique that replaces, removes, or transforms the details that directly identify a person in a data record, while keeping the information needed to re-identify them stored separately. Because that additional information still exists and could be used to link the data back to an individual, pseudonymised data is generally still treated as personal data. It reduces risk but does not make the data anonymous.
Pseudonymisation refers to a set of data protection and de-identification measures by which identifying fields within a data record are replaced, removed, or transformed such that the data can no longer be attributed to a specific data subject without the use of separately held additional information. Under the UK GDPR and EU GDPR framing (see ICO guidance and Recital 28), that additional information must be kept separate and subject to technical and organisational measures to prevent re-identification. Critically, pseudonymised data remains personal data and stays within the scope of data protection law, because the re-identification is reversible where the additional information is available. This distinguishes it from anonymisation, which aims to render re-identification irreversible and generally places the resulting data outside the scope of most data protection regulation. Applying pseudonymisation can help controllers and processors reduce risk to data subjects and support their data protection obligations, but it does not by itself guarantee compliance, and its adequacy depends on context, implementation, and the effectiveness of the controls protecting the separated information. This entry does not address cross-border transfer mechanics, retention rules, specific lawful bases for processing, or enforcement penalties, and treatment of these concepts may differ across jurisdictions and instruments such as the CCPA/CPRA, HIPAA, or ISO/IEC 27701.
Why it matters
Pseudonymisation matters because it is one of the most frequently misunderstood techniques in data protection practice. A common and consequential mistake is to treat pseudonymised data as if it were anonymous and therefore outside the scope of data protection law. Under the UK GDPR and EU GDPR framing (see ICO guidance and Recital 28), pseudonymised data generally remains personal data, because the additional information needed to re-identify individuals still exists and could be used to link records back to a specific person. Any organisation that treats pseudonymised datasets as unregulated risks applying inadequate safeguards to information that remains within scope.
Applied correctly, pseudonymisation can reduce the risks to data subjects and help controllers and processors meet their data protection obligations, as reflected in the EU GDPR recitals. It supports a risk-reduction posture by limiting who can directly identify individuals from a working dataset and by keeping the re-identifying information under separate technical and organisational controls. This makes it a useful measure in contexts such as analytics, testing, and internal data sharing where working with directly identifying fields is unnecessary.
However, pseudonymisation does not by itself guarantee compliance, and its adequacy depends on context, implementation, and how effectively the separated additional information is protected. Because re-identification is reversible where that additional information is available, weak controls over the separated data can undermine the protection entirely. This entry does not address cross-border transfer mechanics, retention rules, lawful bases for processing, or enforcement penalties, and treatment of pseudonymisation differs across instruments such as the CCPA/CPRA, HIPAA, and ISO/IEC 27701.
Who it's relevant to
Inside Pseudonymisation
Common questions
Answers to the questions practitioners most commonly ask about Pseudonymisation.