EDPB’s New Guidelines on Anonymisation: A more nuanced approach for the AI era
July 16, 2026
EDPB’s New Guidelines on Anonymisation: A more nuanced approach for the AI eraJuly 16, 2026 On 7 July 2026, the European Data Protection Board ("EDPB") adopted its non-binding Guidelines 02/2026 on Anonymisation for public consultation. The draft guidelines provide long-awaited guidance on the assessment of anonymisation under the GDPR and reflect the EDPB's response to both recent case law and rapid technological developments, particularly in the field of artificial intelligence ("AI"). Comments on the draft guidelines may be submitted until 30 October 2026. The guidelines arrive at a crucial moment. Over the last decade, advances in data analytics, artificial intelligence and re-identification techniques have increasingly challenged traditional assumptions about what it means for data to be truly anonymous. At the same time, recent case law from the Court of Justice of the European Union ("CJEU"), most notably the judgment in EDPS v SRB (C-413/23 P) of 4 September 2025, has clarified important aspects of the concept of personal data. In that case, the Court addressed whether pseudonymised data transmitted to a third party remained personal data, ultimately clarifying that the assessment of identifiability depends on the means reasonably likely to be used by each relevant entity. Following this landmark ruling, the EDPB organised a stakeholder event on 12 December 2025 to collect input on anonymisation and pseudonymisation, and subsequently established a dedicated team to finalise the guidelines. The EDPB now seeks to integrate these developments into a practical legal and technical framework for controllers, updating the 2014 Article 29 Working Party Opinion 05/2014 on anonymisation techniques in light of the current legal, technological and privacy landscape. The legal analysisThe guidelines start with a legal analysis of the concept of anonymisation under the GDPR. Data is anonymous where it does not relate to an identified or identifiable natural person. Information may relate to an individual by reason of its content, purpose or effect, while a person is identified or identifiable where they can be distinguished from others using means reasonably likely to be used. Against that background, the EDPB structures its assessment around two core questions: first, whether information relates to a natural person and, if so, whether that person is identified or identifiable. If the answer to either of these questions is negative, the data may be regarded as anonymous. Importantly, the EDPB emphasises that the answer to these questions may differ depending on the entity carrying out the assessment. As a result, the same information may constitute personal data for one entity while being anonymous for another. Moreover, identifiability should not be understood as an absolute concept. Rather than asking whether identification is theoretically possible, the relevant question is how likely it is that an individual can be identified in practice. In that sense, the guidelines proceed from the premise that anonymity is not an inherent characteristic of a dataset, but a conclusion that may vary depending on the circumstances and the perspective from which the assessment is carried out. Applicable perspectivesThe EDPB therefore first considers the perspective from which these questions should be answered. The starting point is to determine for whom the data is intended to be anonymous, as whether information constitutes personal data may vary from one entity to another. The guidelines further clarify that identifying the applicable perspective is a context-specific exercise and may require consideration of several factors, including who has access to or control over the data, whether data is transferred between parties, the relationship between those parties, and whether a recipient processes the data independently or on behalf of another entity. The EDPB also notes that the applicable perspective may, in certain circumstances, depend on the specific GDPR obligation being assessed, as illustrated by EDPS v SRB. Furthermore, where an entity processes data on behalf of a controller, whether the information qualifies as personal data should generally be assessed from the controller's perspective rather than that of the processor. As a result, information that constitutes personal data for a controller will typically also be treated as personal data for the processor acting on the controller's behalf. Whether the information “relates” to a natural personAs regards the first question, namely whether information relates to a natural person, the EDPB reiterates that such a link may arise by reason of the information's content, purpose or effect. Importantly, the guidelines stress that this connection may not always be immediately apparent and may only emerge following further analysis or processing. This is particularly relevant in the context of aggregate data, where information that appears to concern groups rather than individuals may nevertheless relate to one or more natural persons. Whether the natural person is “identified or identifiable”As regards the second question, the EDPB clarifies that it is not sufficient for information merely to relate to an individual; that individual must also be identified or identifiable. The guidelines recognise that, particularly in research and analytical contexts, anonymisation often seeks to preserve information about individuals while removing the possibility of identifying them. To that end, the EDPB distinguishes between direct and indirect identification. While an individual may be directly identifiable on the basis of the information itself, indirect identification may arise where additional information can realistically be obtained or combined with the data. Importantly, anonymity does not require the risk of identification to be reduced to zero. Rather, the relevant question is whether the likelihood of identification is insignificant in practice. To assess whether an individual remains identifiable, the guidelines provide extensive guidance on the notion of "means reasonably likely to be used". The EDPB emphasises that this assessment should focus on the realistic likelihood of identification and take into account factors such as the characteristics of the data, the availability of additional information, costs, time, available technology and reasonably foreseeable technological developments. The guidelines further make clear that this assessment is not limited to the intended recipient of the data, but may require consideration of other entities that could realistically contribute to the identification process. Finally, the EDPB stresses that the assessment must be based on objective factors and cautions against relying on an assumed lack of motivation to identify individuals. The three key tests: no record isolation, no linkage and no inferenceTo help organisations assess anonymity in practice, the EDPB translates its legal analysis into a technical framework built around three cumulative criteria. The framework can be applied in two ways: through a contextual approach, which considers the differences in capabilities between entities who might identify the data subject, or through a simplified approach, which disregards such differences for the sake of convenience. The simplified approach may lead a controller to treat data as though it is not anonymous even if it would actually be so for certain entities, but it offers greater confidence. The EDPB suggests that a combination of both approaches may often be the most practical strategy. If all three criteria are satisfied under either approach, the data may generally be considered anonymous. 1. No record isolationThe first criterion examines whether a record contains a unique combination of attributes relating to a single individual. Unique combinations of characteristics can allow a person to be singled out even where direct identifiers have been removed. The more detailed and granular the dataset, the higher the risk that a particular record will become unique. 2. No linkageThe second criterion addresses the possibility of linking a record to information contained in another dataset. Even if a dataset appears anonymous on its own, it may cease to be anonymous when combined with external data sources containing overlapping attributes. 3. No inferenceThe third criterion focuses on whether specific and meaningful information about an identifiable individual can be inferred from the dataset. An inference is “specific” if the inferred information relates to a single identified or identifiable individual, and “meaningful” if its processing is liable to have an effect on the data subject’s rights and interests, relies on the given data, and could not be obtained from general knowledge or from data about the population at large. This reflects growing concerns that modern analytics and AI systems may reveal sensitive information that is not explicitly contained in the data itself, including through membership inference attacks, the de-aggregation of statistical data, or the querying of AI models with additional information to elicit new personal information. The EDPB therefore recognises inference attacks as a distinct anonymisation risk. Importantly, the EDPB notes that failing one of these criteria does not automatically mean the dataset constitutes personal data. Rather, further analysis will be required to determine whether individuals can in fact be identified in light of the specific circumstances. If the data violates the No Linkage criterion, for example, it should be checked whether the linked data can directly lead to identifiability; if not, the new linked information should be re-tested against all three criteria. The analysis may also shift from the simplified to the contextual approach to refine findings and exclude methods that are not, in practice, means reasonably likely to be used by any entity. Accountability remains keyWhile the guidelines offer welcome clarification and a more sophisticated framework for assessing anonymisation, they also reinforce a familiar GDPR principle: accountability. The EDPB repeatedly stresses that controllers remain responsible for demonstrating that data has been effectively anonymised. The assessment cannot be reduced to a mechanical checklist exercise. Organisations must document their anonymisation processes, assess re-identification risks in light of available technologies, and periodically revisit those assessments as technologies evolve and new data becomes available. The EDPB also reminds controllers that the anonymisation process itself constitutes processing of personal data and must therefore have a legal basis under Article 6 GDPR, and comply with transparency obligations under Articles 12 to 15 GDPR. Controllers should clearly state that personal data will be processed to produce anonymous data falling outside the scope of the GDPR, and should avoid any ambiguous or misleading use of terms such as “anonymous” or “de-identified” if individuals are actually still identifiable. In other words, the new guidelines may provide a clearer roadmap, but they do not provide a safe harbour. Accountability cannot be delegated or reduced to a mere check-the-box exercise. The responsibility ultimately remains with the controller to show that individuals can no longer be isolated, linked or meaningfully inferred from the data, which places each controller firmly in control. Final thoughtsThe EDPB's Guidelines provide much-needed guidance on one of the most challenging concepts in modern data protection law. By recognising that anonymity may depend on the perspective of the entity involved and by explicitly addressing linkage and inference risks in the age of AI, the EDPB has taken an important step towards a more realistic and technologically informed understanding of anonymisation. The practical importance of these developments should not be underestimated. Data that can be regarded as anonymous falls outside the scope of the GDPR, enabling organisations to use and share information more freely for purposes such as research, innovation and AI development. As a result, the assessment of whether data can be regarded as anonymous has become a matter of considerable importance. At the same time, this greater freedom of use makes it all the more important to ensure that data is properly anonymised, so that the rights and interests of individuals are not put at risk. For organisations seeking to unlock the value of data while remaining outside the scope of the GDPR, the message is clear: anonymisation is no longer just about removing identifiers. It is about demonstrating, through a robust legal and technical assessment, that individuals cannot be isolated, linked or meaningfully inferred from the data. And that is a burden that remains firmly in the controller's hands. Key takeaways
Latest Insights
Latest News
Latest Events
firm news July 10, 2026 Eversheds Sutherland advises OCBC on the landmark secondary dual listing of... client news July 10, 2026 Setting sail: Eversheds Sutherland advises senior management of D-Marin on ... client news July 09, 2026 Eversheds Sutherland advises Costello Medical on transition to employee own... client news July 07, 2026 Eversheds Sutherland advises PCProfi Informatique SA on its acquisition by ... in-person A leadership conversation for Global GCs September 02, 2026 17:30 - 19:30 MS Wädenswil, Bürkliplatz, Zurich Schiffstation virtual UAE - Employment law in the Dubai International Financial Centre September 10, 2026 9.30am - 1.30pm (GMT) Virtual in-person Managing AI use in the workplace: what every UK HR team needs to know September 10, 2026 9.30am - 1.00pm (BST) London, United Kingdom in-person Interaktiver LIVE Cyber Security Event September 10, 2026 07:30 – 11:00 Kinokoni, Lagerstrasse 104, Europaallee Zürich |