What is pseudonymisation? The tool for effective anonymisation that keeps on giving.
What is Pseudonymisation?
The General Data Protection Regulations (GDPR), apply to any information relating to and identified or identifiable natural person. We know from our experience working with a range of organisations how much of a challenge getting GDPR right is. But we also see the opportunities it can bring.
The GDPR does not apply to data that are anonymous or that have been pseudonymised. Article 4(5) of the GDPR say that
“‘pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person”
The key phrase is “rendered anonymous in such a way…”
One such way is pseudonymisation. It’s a technique encouraged by the Information Commissioner and by the GDPR. It broadly means separating out data from identifiers to make it effectively anonymous.
That means cleansing the data of identifiers to the people whose data you have cannot be identified without some additional information being added. Remember GDPR applies to any information that by itself or in combination with other data can lead to a person being identified. It’s important to bear in mind pseudonymised data can still count as personal data. However, using pseudonymisation techniques there are opportunities to use data more broadly. You can do this without getting explicit consent from the people whose data you have.
How to Pseudonymise Data
Pseudonymisation is relatively simple. What you do is:
- Take your existing data set, copy it, and strip out all the directly identifiable information from the copy. Now you have two data sets – your original one and your pseudonymised one
- Give each individual a unique reference number. You can use this to re-link the two data sets.
- Keep the original data set and which reference number links to which individual secure. Make them accessible only to those people who have permission to use identifiable data.
- You can share the pseudonymised data set more widely for the purposes of research and analysis. Examples include scientific purposes, or service improvement.
This way you can give people effectively anonymised data to use, while still being able to link it back to identifiable individuals if you ever need to.
Sign Up Here:
Pseudonymisation reduces to risk to people if their data are lost or stolen. For example, if you have a pseudonymised list of credit card transactions and these are stolen from you it is harder for people to use them for fraud. This is because they do not have the personal details of the individual card holders. You can use the pseudonymised data to check payments and refunds have been made, and if there is a problem, re-identify an individual using your reference number system. There are a number of advantages to using pseudonymised data, including incentives to encourage its use under GDPR. Firstly, you can keep pseudonymised data even after you have deleted the identifiable data. Remember you should not keep personal data longer than needed for the purpose it was collected. For de-identified data controllers do not need to provide people with access, rectification, erasure or data portability. This because they can no longer identify a data subject. Secondly, in some circumstances data breaches are notifiable to the individuals concerned but not if the data are pseudonymised. Thirdly, it is recognised that effective pseudonymisation can in most instances rely only on the removal of direct identifiers – name, address, date of birth and so on – rather than all possible identifiable data; enough to make it reasonably unlikely that a person can be identified from the pseudonymised data – so long as you have appropriate technical and organisational systems in place to prevent improper recombination with the identifiable data you have stripped out. Pseudonymisation is not currently a widely used tool. Going forward it is a critical weapon in your arsenal for demonstrating privacy by design. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence. Why use pseudonymisation?
Top tips:
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: