Regulatory explainer: European Data Protection Boardmedium
Anonymous to whom? Europe's new guidelines move the question
Anonymisation is the way out of the GDPR: if data is genuinely anonymous, the Regulation no longer applies. Which makes the definition of "genuinely" worth a great deal. On 7 July 2026 the European Data Protection Board adopted Guidelines 02/2026 on Anonymisation, open to public consultation until 30 October 2026. The document follows a Court of Justice ruling — EDPS v SRB, Case C-413/23 P — holding that pseudonymised data is not necessarily personal data for every recipient. From there comes the shift that matters: anonymity stops being an absolute property of the file and becomes a relationship between the data and whoever holds it.
Why one definition is worth so much
The GDPR has exactly one real emergency exit: recital 26, which places anonymous information outside the Regulation's scope — information that does not relate to an identified or identifiable person. If data is anonymous, everything else drops away: legal bases, notices, data subject rights, impact assessments, transfer restrictions.
That makes "anonymous" the most contested word in the field. In daily practice it is used with a generosity that rarely survives scrutiny: datasets with direct identifiers stripped and everything else intact, linkage keys retained "for technical reasons", aggregations that dissolve the moment a second source is joined.
On 7 July 2026 the European Data Protection Board adopted Guidelines 02/2026 on Anonymisation. They are in public consultation from 8 July to 30 October 2026: anyone — companies, public bodies, researchers, associations, individuals — can send comments through the form on the EDPB site by that date.
- September 2025The ruling
The Court of Justice decides EDPS v SRB, Case C-413/23 P.
- 7 July 2026Adoption
The EDPB adopts Guidelines 02/2026 on Anonymisation.
- 8 July 2026Opening
The public consultation on the text opens.
- 30 October 2026Closing
Final deadline for comments, 23:59 CET.
The change of perspective
The document follows a Court of Justice of the European Union decision in EDPS v Single Resolution Board (SRB), Case C-413/23 P, of September 2025. The point the Court affirmed, and the guidelines take up, is that pseudonymised data is not necessarily personal data in every case and for every recipient.
Put that way it sounds like a technicality. It is in fact a shift of the centre of gravity.
The traditional reading treated identifiability as a property of the data: either the file is anonymous or it is not, and the answer is the same for whoever opens it. The reading emerging from this case law is relative: the same table can be personal data for whoever holds the reconciliation key and not be so for a recipient with no means reasonably likely to be used to get back to the individuals.
- 01Whoever holds the keythe data stays personal: identification is within reach
- 02Whoever receives only the tablemay not be personal data, if no reasonable means allows the link
- 03The assessmentis made on the recipient and the context, not on the file alone
The guidelines exist precisely to stop that principle being used as a shortcut. The document addresses the notion of anonymous data and the assessment of the effectiveness of anonymisation processes: it is not enough to assert that data is anonymous, you must be able to show relative to whom, with what means available, and on the basis of what analysis of re-identification risk.
Whose life this actually changes
The EDPB explicitly names among its addressees organisations processing data in the context of data analytics, technological development, information sharing and artificial intelligence. Not a random list: it is a map of the places where anonymisation is most often declared without having been achieved.
The recurring case is models. An "anonymised" training set that preserves rare combinations — an occupation, a small town, a date — is not anonymous, only inconvenient to reconcile. And inconvenience is not a legal test.
The second case is sharing between organisations. The relative reading of identifiability opens real space: you can design a sharing arrangement in which the recipient lacks the means to identify, and document it. But it requires writing that assessment beforehand, not invoking it afterwards.
What to do now
Reopen your inventory of anonymisations. For each set declared anonymous, three questions: who receives it, what that recipient already holds, and what analysis documents that re-identification is not reasonably possible for them. If the third answer does not exist on paper, it does not exist.
Keep distinguishing pseudonymisation from anonymisation. They remain different things: the first reduces risk and stays inside the GDPR, the second leaves the Regulation. The Court's ruling does not merge them: it says the classification must also look at the recipient.
Take part in the consultation, if the topic touches you. Until 30 October 2026 the text is open to comments, which are published on the EDPB site. For sectors with particular use cases — health, research, official statistics — this is the window in which those cases can enter the final document.
Two reading caveats. First: this is version 1, in consultation. It is not final and may change; building a definitive architecture on it today would be premature, ignoring its direction would be imprudent. Second: this article is a plain-language reading and does not replace the text of the guidelines or legal advice on a specific case. The full PDF is linked in the sources.