Skip to content
compliancebase

Anonymization

Processing that irreversibly prevents information from relating to an identified or identifiable person using reasonably likely means.

In practice

Test re-identification risk against available auxiliary data before treating a dataset as outside GDPR.

Common confusion

Removing names alone usually produces pseudonymized, not anonymous, data.

Related controls

Framework versions referenced in this page:

Last verified: August 2026 · Primary sources linked above