Skip to Content
ANALYSISMEMBER

The EDPB's draft anonymization guidelines: What they mean for your data strategy

The draft guidelines seek to resolve uncertainty around GDPR anonymization standards while highlighting ongoing reidentification and compliance considerations.

Published
Subscribe to IAPP Newsletters

Contributors:

Arnav Joshi

CIPP/E

Partner

Ashurst Perkins Coie

Tom Brookes

Senior Associate

Ashurst Perkins Coie

Stacy Young

Associate

Ashurst Perkins Coie

On 7 July 2026, the European Data Protection Board published its long-awaited Draft Guidelines 02/2026 on Anonymisation as an update to the Article 29 Working Party's Opinion 05/2014. The backdrop to these draft guidelines, which are open for consultation until October, was the Court of Justice of the European Union's September 2025 ruling in EDPS v SRB. In that decision, the CJEU held that pseudonymized data is not automatically personal data for every recipient and that the same dataset can be personal data in one organization's hands and anonymous in another's. Though helpful, the judgment led to differences in interpretation and practical challenges in implementing meaningful anonymization across different contexts at a time when the use of personal data is accelerating at an unprecedented pace. 

Key points to note

The draft guidelines set out a two-question test to determine whether data is anonymous under the EU General Data Protection Regulation: Does the data relate to a natural person? If so, is that person identifiable? Identifiability turns on the "means reasonably likely to be used" standard, assessed from the perspective of each "relevant entity."

The European Data Protection Board provides two approaches organizations can use to assess anonymization. The contextual approach examines each relevant entity's actual capabilities individually, while the simplified approach ignores differences between entities' resources and produces a more conservative result. The EDPB notes that organizations may wish to use the simplified approach in the first instance and switch to the contextual approach where they require a more nuanced answer specific to a relevant entity.

Under both approaches, the EDPB tests against three technical criteria: no record isolation, no linkage and no inference. 

Contributors:

Arnav Joshi

CIPP/E

Partner

Ashurst Perkins Coie

Tom Brookes

Senior Associate

Ashurst Perkins Coie

Stacy Young

Associate

Ashurst Perkins Coie

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership