What is pseudonymisation, and why use it?

What is pseudonymisation? The tool for effective anonymisation that keeps on giving.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

What is Pseudonymisation?

The General Data Protection Regulations (GDPR), apply to any information relating to and identified or identifiable natural person. We know from our experience working with a range of organisations how much of a challenge getting GDPR right is. But we also see the opportunities it can bring.

The GDPR does not apply to data that are anonymous or that have been pseudonymised. Article 4(5) of the GDPR say that 

“‘pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person”

The key phrase is “rendered anonymous in such a way…”

One such way is pseudonymisation. It’s a technique encouraged by the Information Commissioner and by the GDPR. It broadly means separating out data from identifiers to make it effectively anonymous.

That means cleansing the data of identifiers to the people whose data you have cannot be identified without some additional information being added. Remember GDPR applies to any information that by itself or in combination with other data can lead to a person being identified. It’s important to bear in mind pseudonymised data can still count as personal data. However, using pseudonymisation techniques there are opportunities to use data more broadly. You can do this without getting explicit consent from the people whose data you have.

How to Pseudonymise Data

Pseudonymisation is relatively simple. What you do is:

  1. Take your existing data set, copy it, and strip out all the directly identifiable information from the copy. Now you have two data sets – your original one and your pseudonymised one
  2. Give each individual a unique reference number. You can use this to re-link the two data sets.
  3. Keep the original data set and which reference number links to which individual secure. Make them accessible only to those people who have permission to use identifiable data.
  4. You can share the pseudonymised data set more widely for the purposes of research and analysis. Examples include scientific purposes, or service improvement.

This way you can give people effectively anonymised data to use, while still being able to link it back to identifiable individuals if you ever need to.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Why use pseudonymisation?

Pseudonymisation reduces to risk to people if their data are lost or stolen. For example, if you have a pseudonymised list of credit card transactions and these are stolen from you it is harder for people to use them for fraud. This is because they do not have the personal details of the individual card holders. You can use the pseudonymised data to check payments and refunds have been made, and if there is a problem, re-identify an individual using your reference number system.

There are a number of advantages to using pseudonymised data, including incentives to encourage its use under GDPR.

Firstly, you can keep pseudonymised data even after you have deleted the identifiable data. Remember you should not keep personal data longer than needed for the purpose it was collected. For de-identified data controllers do not need to provide people with access, rectification, erasure or data portability. This because they can no longer identify a data subject.

Secondly, in some circumstances data breaches are notifiable to the individuals concerned but not if the data are pseudonymised.

Thirdly, it is recognised that effective pseudonymisation can in most instances rely only on the removal of direct identifiers – name, address, date of birth and so on – rather than all possible identifiable data; enough to make it reasonably unlikely that a person can be identified from the pseudonymised data – so long as you have appropriate technical and organisational systems in place to prevent improper recombination with the identifiable data you have stripped out.

Pseudonymisation is not currently a widely used tool. Going forward it is a critical weapon in your arsenal for demonstrating privacy by design.

Top tips:

  • Your data privacy notice still needs to make clear all of the ways and reasons you use data, including when it has been pseudonymised.
  • This is so people can object to the use of their data, as under GDPR they have this right.
  • People can still be identified from anonymised characteristics if your data set relates to only a small number of them (for example, if you had a small family – mother, father and infant – and you only knew their shoe sizes you could easily guess which one had size 11, which one had size 5, and which one had size 2) so think about ways of handling small numbers.
  • You still need to ensure data are kept safe and secure, and limit access to data on a need to know basis. Don’t compromise on data security for pseudonymised data.
  • If you subscribe to a code of conduct pseudonymisation must be discussed as part of the code. Adhering to a code of conduct can be considered a mitigating factor if a data breach occurs

 


Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial