Article · 9 MIN

EU Anonymization Guidelines 2026: Why Anonymous Data Must Now Be Proven Over Time

EU Anonymization Guidelines 2026: Why Anonymous Data Must Now Be Proven Over Time

Executive Summary

On July 7, 2026, the European Data Protection Board adopted draft Guidelines 02/2026 on anonymization.

The Guidelines update the European approach to anonymous data in light of recent case law, new data-sharing environments, and increasingly powerful re-identification technologies.

Their central message is clear: removing names or replacing identifiers is not enough to make a dataset anonymous.

Organizations must assess whether individuals can still be isolated, linked to other information, or identified through meaningful inferences. They must also consider who may access the data, what additional information those parties may obtain, and which technical or legal means could reasonably be used to identify individuals.

This makes anonymization more than a technical operation.

It becomes a documented, contextual, and evolving legal assessment.

Quick Answer: What Do the New EU Anonymization Guidelines Change?

The draft Guidelines clarify that data is anonymous only when it no longer relates to an identified or identifiable natural person from the perspective of the relevant entity.

The EDPB proposes three practical tests:

  • No Record Isolation
  • No Linkage
  • No Inference

Passing all three tests generally means the data can safely be considered anonymous. Failing one test does not automatically mean the data is personal, but it requires further analysis.

The Guidelines also confirm that anonymization itself is a processing operation subject to the GDPR while personal data is still involved.

Anonymization Is Not the Same as Removing Names

A common mistake is to assume that a dataset becomes anonymous once names, email addresses, or direct identifiers have been removed.

That assumption is increasingly unsafe.

A person may still be identifiable through a combination of apparently harmless attributes, such as:

  • age;
  • postcode;
  • occupation;
  • medical condition;
  • location history;
  • transaction patterns;
  • or behavioral data.

Even when no single attribute identifies a person, several attributes may create a unique profile.

The relevant question is therefore not whether names have been deleted.

The relevant question is whether someone can still distinguish a person from others and treat that person differently.

The Three Tests for Anonymous Data

1. No Record Isolation

The first test asks whether an individual record can be isolated from the rest of the dataset.

A record may be isolated when it contains a unique combination of attributes.

For example, removing a patient’s name may not be sufficient if the remaining information includes a rare illness, a precise age, and a narrow geographic area.

If one record can be distinguished from all others, the anonymity assessment becomes more difficult.

2. No Linkage

The second test asks whether the dataset can be linked to other information relating to the same person.

A dataset may appear anonymous in isolation but become identifiable when combined with publicly available data, another internal database, leaked information, or information held by a third party.

This is especially important for:

  • health data;
  • location data;
  • customer databases;
  • research datasets;
  • online behavior;
  • and data used to train AI systems.

Organizations must therefore examine not only the dataset itself, but also the wider information environment.

3. No Inference

The third test asks whether meaningful information about a person can be inferred from the data.

An inference may create personal data even when the person’s identity is not explicitly stated.

For example, a dataset may allow an organization to infer a person’s health condition, financial situation, political preferences, or likely behavior.

The EDPB focuses on inferences that are sufficiently specific and meaningful to affect a person’s rights or interests.

The Contextual Approach to Anonymization

One of the most important developments is the recognition that the same information may have a different legal status depending on who holds it.

A dataset may remain personal data for the organization that retains an identification key.

The same dataset may be anonymous for an independent recipient that cannot reasonably obtain the key or identify the individuals.

This is known as the contextual approach.

The assessment must consider:

  • the identity of the recipient;
  • the recipient’s technical capabilities;
  • access to additional information;
  • available financial and computational resources;
  • legal access rights;
  • security measures;
  • and reasonably foreseeable technological developments.

This means that anonymity cannot always be assessed universally.

It may need to be assessed separately for each relevant recipient or category of recipient.

What the CJEU’s C-413/23 P Judgment Clarified

The draft Guidelines reflect the Court of Justice’s judgment in Case C-413/23 P, EDPS v Single Resolution Board.

The Court confirmed that pseudonymized data does not necessarily constitute personal data for every person in every circumstance.

If a recipient cannot reasonably identify the individuals, the information may not be personal data from that recipient’s perspective.

However, this does not allow the original controller to ignore its own GDPR obligations.

For obligations connected to the original collection of the data, the assessment may still need to be made from the controller’s perspective and at the time the information was collected.

The practical lesson is important:

A transfer to a recipient that cannot identify the individuals does not automatically erase the controller’s earlier transparency and accountability obligations.

Anonymization Is Itself a GDPR Processing Operation

Organizations sometimes treat anonymization as a route outside the GDPR.

That is only partly correct.

Successfully anonymized data falls outside the GDPR.

The processing used to create that anonymous data remains subject to the GDPR while personal data is involved.

According to the draft Guidelines, organizations must consider:

  • an Article 6 legal basis;
  • an Article 9(2) exception where special-category data is involved;
  • transparency obligations;
  • purpose limitation;
  • security;
  • and documentation.

Organizations should also avoid describing information as “anonymous,” “de-identified,” or “de-personalized” when individuals remain identifiable.

The terminology used in privacy notices and contracts must reflect the real legal status of the data.

Mixed Datasets Create Additional Risk

A dataset may contain some genuinely anonymous records and other records that remain personal.

Where those parts are not effectively separated, the entire dataset should be treated as containing personal data.

This has practical consequences for data warehouses, research databases, analytics platforms, and AI training datasets.

Organizations cannot simply rely on the fact that most individuals are difficult to identify.

The risk of re-identification must be insignificant for all individuals covered by the anonymized dataset.

Why Anonymization Must Be Reassessed Over Time

Anonymization is not necessarily permanent.

A dataset considered anonymous today may become identifiable later because of:

  • a data leak;
  • access to new public databases;
  • technological advances;
  • improved linking techniques;
  • lower computing costs;
  • or newly available third-party information.

The EDPB therefore recommends periodic reassessment of re-identification risk.

This point is especially important because modern AI systems can accelerate the collection, comparison, and analysis of information across multiple sources.

Agentic AI may further reduce the time and cost required to perform re-identification attempts.

Anonymization should therefore be treated as an ongoing risk-management process rather than a one-time technical certification.

What This Means for AI, Health Data, Research, and Data Sharing

The Guidelines will have important consequences for organizations using large datasets.

Artificial Intelligence

AI training datasets often contain complex and high-dimensional information. Removing direct identifiers may not prevent linkage or inference.

AI projects should include re-identification testing before datasets are reused or shared.

Health and Scientific Research

Health data is particularly vulnerable because combinations of age, location, diagnosis, and treatment information may identify patients.

Research organizations should document the techniques used and assess the recipient’s ability to access additional information.

Open Data

Publishing a dataset openly creates a broader risk environment because an unlimited number of parties may attempt to link it with other information.

The more widely data is released, the harder it may be to rely on a contextual assessment limited to trusted recipients.

Corporate Data Sharing

Companies sharing datasets with partners, suppliers, investors, or potential buyers must assess the recipient’s actual capabilities.

Contractual restrictions can support anonymization, but contracts alone may not be enough. Their practical enforceability and the technical safeguards surrounding the data must also be examined.

Practical Steps for Companies

Organizations should consider the following process:

  • Map the original personal data and all remaining attributes.
  • Identify every entity that may receive or access the dataset.
  • Assess possible isolation, linkage, and inference techniques.
  • Review the additional information available to each recipient.
  • Document the technical and legal reasoning supporting anonymity.
  • Separate anonymous and personal records where necessary.
  • Maintain appropriate security and access controls.
  • Reassess the risk after data leaks, technological changes, or new data sources.
  • Avoid using the term “anonymous” unless the assessment supports it.
  • Retain evidence demonstrating why the dataset was considered anonymous.

Key Takeaways

Anonymous data is outside the GDPR only when individuals are no longer identifiable.

Removing direct identifiers does not automatically create anonymous data.

The EDPB proposes three tests: No Record Isolation, No Linkage, and No Inference.

The same dataset may be personal for one organization and anonymous for another, depending on their ability to identify individuals.

Anonymization itself remains subject to the GDPR while personal data is being processed.

Mixed datasets should remain within the GDPR unless anonymous and personal parts are effectively separated.

Re-identification risk should be periodically reassessed as technology and available information evolve.

Final Analysis

The new EDPB Guidelines do not make anonymization impossible.

They make unsupported claims of anonymity increasingly difficult to defend.

The decisive question is no longer which technical method was applied.

It is whether the organization can demonstrate that identification is not reasonably likely in the real context in which the data will be processed.

Anonymization is therefore becoming a legal and technical process built around evidence, recipient capabilities, changing technology, and residual risk.

Organizations that want to rely on anonymous data will need more than deleted columns and internal assurances.

They will need a defensible analysis.

What is anonymized data under the GDPR?

Anonymized data is information that no longer relates to an identified or identifiable natural person. Properly anonymized data falls outside the scope of the GDPR.

Is pseudonymized data anonymous?

Not automatically. Pseudonymized data generally remains personal data for an organization that can reconnect it to an individual. It may, depending on the circumstances, be anonymous for an independent recipient that cannot reasonably identify the person.

Is removing names enough to anonymize a dataset?

No. Individuals may still be identified through unique attributes, linkage with other datasets, or meaningful inferences.

What are the EDPB’s three anonymization criteria?

The three criteria are No Record Isolation, No Linkage, and No Inference.

Does failing one criterion automatically mean the data is personal?

No. Failing one criterion requires further analysis to determine whether the residual identification risk is still insignificant.

Must anonymization have a GDPR legal basis?

Yes. The processing used to anonymize personal data must have a legal basis under Article 6 of the GDPR. An Article 9(2) exception may also be required for special-category data.

Can anonymous data become personal data again?

Yes. New technology, additional information, data leaks, or improved linkage techniques may increase the likelihood of re-identification.