← All posts

20/07/2026 · 5 min read

What actually counts as anonymised data? The EU's new guidelines, explained

The EDPB's draft anonymisation guidelines set a clearer, stricter test for when data truly stops being personal data, and when it is just pseudonymised and still fully in scope.

Genuinely anonymous data sits outside data protection law entirely: no ROPA entry, no retention limit, no subject access rights, nothing. Which is exactly why the label gets claimed more often than it is actually earned. On 7 July 2026, the European Data Protection Board published new draft guidelines on anonymisation, its first real update since 2014, open for consultation until October 2026. They set out a clearer, stricter test for what “anonymised” actually requires, and it is worth understanding even if you have never sent a byte of data to the EU.

Does this actually apply to a UK business?

Directly, only if you are in scope of EU GDPR too: you have customers, staff, or website visitors in the EU, or you offer goods or services there. The EDPB is the EU’s regulator, not the ICO, and this guidance carries no formal force in the UK on its own.

It is still worth reading if you are UK-only. UK GDPR’s definition of anonymisation is essentially the same wording as the EU version, both trace back to the same original text, and the ICO has a long history of paying close attention to EDPB reasoning even where it is not bound by it. New EU guidance on a shared concept is a reasonable signal for how the same question is likely to be read here, even before the ICO says anything of its own.

The test

The guidelines boil anonymisation down to two questions: does the data relate to an identified or identifiable natural person, and could that person still be identified by means “reasonably likely to be used”? That second phrase is doing the real work. It is not asking whether re-identification is theoretically possible somehow, but whether it is realistically achievable for whoever might try, given the time, cost, and technology actually available to them.

Practically, that gets tested against three criteria. Genuinely anonymous data should make it impossible to pick out one individual’s record on its own (no isolation), link records about the same person together (no linkage), or work out something new about a person from what is left (no inference). Fail any one of the three and what you are holding is pseudonymised, not anonymised, which means it is still personal data, still fully in scope.

Where this trips businesses up

The most common mistake is treating “removed the obvious identifiers” as the same thing as anonymised. Strip someone’s name and email from a customer list but leave their postcode, date of birth, and purchase history, and you very likely have not anonymised anything: that combination is often enough to isolate and re-identify a specific person, even with no name attached. That is pseudonymisation, and it still carries the full weight of UK GDPR: a lawful basis, a place in your ROPA, a retention period, the works.

Real anonymisation is usually a higher bar than people expect. Aggregated statistics, counts, averages, ranges, tend to sit on much safer ground than any dataset that still has one row per person.

What to do about it

  1. Do not label something anonymised just because the obvious identifiers are gone. Check it against the three-part test: isolation, linkage, inference.
  2. Treat pseudonymised data as personal data, because it is. It still needs a lawful basis, a place in your ROPA, and a retention period, exactly like anything else you hold.
  3. If you rely on “this is anonymised” to justify not treating something as personal data, write down why, using the test, rather than simply asserting it.
  4. If you do have EU customers, staff, or site visitors, this guidance applies to you directly. The consultation period is a chance to see where the EDPB’s thinking lands before it is finalised.

The underlying idea is straightforward even though the guidance is new: anonymisation is an outcome you have to actually achieve, not a description you get to choose. If you are not sure whether something in your own records qualifies, mapping out what you hold and why tends to make the answer obvious fairly quickly. Our free GDPR check is a fast way to see where the gaps might be.

Get your records in order

The Data Protection Register turns plain-English answers into the records the law asks for, and keeps them current. See where you stand with our free check.

This is general information, not legal advice.