{"id":13617,"date":"2026-07-27T15:30:51","date_gmt":"2026-07-27T13:30:51","guid":{"rendered":"https:\/\/orsingher.com\/data-protection-edpb-releases-guidelines-on-anonymisation\/"},"modified":"2026-07-27T17:12:33","modified_gmt":"2026-07-27T15:12:33","slug":"data-protection-edpb-releases-guidelines-on-anonymisation","status":"publish","type":"post","link":"https:\/\/orsingher.com\/en\/data-protection-edpb-releases-guidelines-on-anonymisation\/","title":{"rendered":"DATA PROTECTION | EDPB releases guidelines on anonymisation"},"content":{"rendered":"<p>On\u00a07 July 2026, the European Data Protection Board (<em>EDPB<\/em>) adopted\u00a0<a href=\"https:\/\/www.edpb.europa.eu\/system\/files\/2026-07\/edpb_guidelines_202602_anonymisation_v1_en_0.pdf\" target=\"_blank\" rel=\"noopener\">Guidelines 02\/2026 on\u00a0anonymisation<\/a>\u00a0(the <strong><em>Guidelines<\/em><\/strong>),\u00a0providing\u00a0updated guidance on when data may be considered anonymous and therefore fall outside the scope of the GDPR. The Guidelines include practical examples on effective anonymization operations and expand\u00a0upon,\u00a0while\u00a0remaining\u00a0coherent with, the principles\u00a0set out in\u00a0<a href=\"https:\/\/ec.europa.eu\/justice\/article-29\/documentation\/opinion-recommendation\/files\/2014\/wp216_en.pdf\" target=\"_blank\" rel=\"noopener\">Art.\u00a029 Working Party\u2019s Opinion 05\/2014<\/a>\u00a0(the <strong><em>Opinion<\/em><\/strong>).<\/p>\n<p>The Guidelines\u00a0recognise\u00a0two complementary approaches for assessing whether\u00a0personal\u00a0data can be regarded as anonymous.\u00a0EDPB\u00a0confirms the\u00a0continued relevance of the so-called \u201csimplified approach\u201d,\u00a0developed in the Opinion. This\u00a0framework revolves\u00a0around three criteria\u00a0(a)\u00a0no\u00a0record\u00a0isolation:\u00a0no individual is singled out through one or more unique attributes; (b)\u00a0no\u00a0linkage: records cannot be connected across different datasets for identification; and (c)\u00a0no\u00a0inference: no specific and meaningful deductions can be drawn from given data. If all three criteria are met, the information may be regarded as anonymous. The violation of one or more criteria does not automatically classify the information as personal data;\u00a0rather\u00a0further analysis is\u00a0required\u00a0to conclude whether the data is\u00a0ultimately anonymous.<\/p>\n<p>Most relevantly, the Guidelines uphold the\u00a0so-called \u201ccontextual\u00a0approach\u201d\u00a0expressed by\u00a0EU\u00a0Court of Justice (<em>CJEU<\/em>) in <a href=\"https:\/\/infocuria.curia.europa.eu\/tabs\/affair?sort=AFF_NUM-DESC&amp;searchTerm=%2522C%252D413%252F23%2522&amp;publishedId=C-413%2F23&amp;lang=EN\" target=\"_blank\" rel=\"noopener\">Case C-413\/23<\/a><em>\u00a0(EDPS v. SRB<\/em>).\u00a0Under this approach, the same dataset may\u00a0constitute\u00a0anonymous information for one entity while\u00a0remaining\u00a0personal data for another, depending on whether the relevant entity has access to means that are\u00a0reasonably likely\u00a0to enable the re-identification of data subjects.\u00a0Accordingly, data may be considered anonymous from the perspective of a specific recipient where that recipient\u00a0does not\u00a0possess, and cannot reasonably\u00a0obtain,\u00a0the\u00a0additional\u00a0information or other means necessary to re-identify\u00a0individuals.<\/p>\n<p>Stakeholders can adopt this framework through either a\u00a0simplified approach\u00a0or a\u00a0contextualised\u00a0approach. Notably, the EDPB\u00a0suggests\u00a0the latter offers greater compliance confidence.\u00a0The Guidelines\u00a0are open for public consultation until\u00a030 October 2026,\u00a0providing stakeholders with the opportunity to comment and provide feedback.<\/p>\n<p>Newsletter n. 120 &#8211; July 2026<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On\u00a07 July 2026, the European Data Protection Board (EDPB) adopted\u00a0Guidelines 02\/2026 on\u00a0anonymisation\u00a0(the Guidelines),\u00a0providing\u00a0updated guidance on when data may be considered anonymous and therefore fall outside the scope of the GDPR. The Guidelines include practical examples on effective anonymization operations and expand\u00a0upon,\u00a0while\u00a0remaining\u00a0coherent with, the principles\u00a0set out in\u00a0Art.\u00a029 Working Party\u2019s Opinion 05\/2014\u00a0(the Opinion). The Guidelines\u00a0recognise\u00a0two complementary approaches [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[65],"tags":[],"class_list":["post-13617","post","type-post","status-publish","format-standard","hentry","category-newsletters-en-2"],"acf":[],"_links":{"self":[{"href":"https:\/\/orsingher.com\/en\/wp-json\/wp\/v2\/posts\/13617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/orsingher.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/orsingher.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/orsingher.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/orsingher.com\/en\/wp-json\/wp\/v2\/comments?post=13617"}],"version-history":[{"count":3,"href":"https:\/\/orsingher.com\/en\/wp-json\/wp\/v2\/posts\/13617\/revisions"}],"predecessor-version":[{"id":13683,"href":"https:\/\/orsingher.com\/en\/wp-json\/wp\/v2\/posts\/13617\/revisions\/13683"}],"wp:attachment":[{"href":"https:\/\/orsingher.com\/en\/wp-json\/wp\/v2\/media?parent=13617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/orsingher.com\/en\/wp-json\/wp\/v2\/categories?post=13617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/orsingher.com\/en\/wp-json\/wp\/v2\/tags?post=13617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}