Threat feed liveUpdated — 04.08.2026 10:27 CET86 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 04.08.2026 10:27 CET86 dossiersMITRE ATT&CK mapping

Regulatory explainer: European Data Protection Boardmedium

Anonymous to whom? Europe's new guidelines move the question

Anonymisation is the way out of the GDPR: if data is genuinely anonymous, the Regulation no longer applies. Which makes the definition of "genuinely" worth a great deal. On 7 July 2026 the European Data Protection Board adopted Guidelines 02/2026 on Anonymisation, open to public consultation until 30 October 2026. The document follows a Court of Justice ruling — EDPS v SRB, Case C-413/23 P — holding that pseudonymised data is not necessarily personal data for every recipient. From there comes the shift that matters: anonymity stops being an absolute property of the file and becomes a relationship between the data and whoever holds it.

Why one definition is worth so much

The GDPR has exactly one real emergency exit: recital 26, which places anonymous information outside the Regulation's scope — information that does not relate to an identified or identifiable person. If data is anonymous, everything else drops away: legal bases, notices, data subject rights, impact assessments, transfer restrictions.

That makes "anonymous" the most contested word in the field. In daily practice it is used with a generosity that rarely survives scrutiny: datasets with direct identifiers stripped and everything else intact, linkage keys retained "for technical reasons", aggregations that dissolve the moment a second source is joined.

On 7 July 2026 the European Data Protection Board adopted Guidelines 02/2026 on Anonymisation. They are in public consultation from 8 July to 30 October 2026: anyone — companies, public bodies, researchers, associations, individuals — can send comments through the form on the EDPB site by that date.

  1. September 2025
    The ruling

    The Court of Justice decides EDPS v SRB, Case C-413/23 P.

  2. 7 July 2026
    Adoption

    The EDPB adopts Guidelines 02/2026 on Anonymisation.

  3. 8 July 2026
    Opening

    The public consultation on the text opens.

  4. 30 October 2026
    Closing

    Final deadline for comments, 23:59 CET.

The change of perspective

The document follows a Court of Justice of the European Union decision in EDPS v Single Resolution Board (SRB), Case C-413/23 P, of September 2025. The point the Court affirmed, and the guidelines take up, is that pseudonymised data is not necessarily personal data in every case and for every recipient.

Put that way it sounds like a technicality. It is in fact a shift of the centre of gravity.

The traditional reading treated identifiability as a property of the data: either the file is anonymous or it is not, and the answer is the same for whoever opens it. The reading emerging from this case law is relative: the same table can be personal data for whoever holds the reconciliation key and not be so for a recipient with no means reasonably likely to be used to get back to the individuals.

  1. 01
    Whoever holds the key
    the data stays personal: identification is within reach
  2. 02
    Whoever receives only the table
    may not be personal data, if no reasonable means allows the link
  3. 03
    The assessment
    is made on the recipient and the context, not on the file alone

The guidelines exist precisely to stop that principle being used as a shortcut. The document addresses the notion of anonymous data and the assessment of the effectiveness of anonymisation processes: it is not enough to assert that data is anonymous, you must be able to show relative to whom, with what means available, and on the basis of what analysis of re-identification risk.

Whose life this actually changes

The EDPB explicitly names among its addressees organisations processing data in the context of data analytics, technological development, information sharing and artificial intelligence. Not a random list: it is a map of the places where anonymisation is most often declared without having been achieved.

The recurring case is models. An "anonymised" training set that preserves rare combinations — an occupation, a small town, a date — is not anonymous, only inconvenient to reconcile. And inconvenience is not a legal test.

The second case is sharing between organisations. The relative reading of identifiability opens real space: you can design a sharing arrangement in which the recipient lacks the means to identify, and document it. But it requires writing that assessment beforehand, not invoking it afterwards.

What to do now

Reopen your inventory of anonymisations. For each set declared anonymous, three questions: who receives it, what that recipient already holds, and what analysis documents that re-identification is not reasonably possible for them. If the third answer does not exist on paper, it does not exist.

Keep distinguishing pseudonymisation from anonymisation. They remain different things: the first reduces risk and stays inside the GDPR, the second leaves the Regulation. The Court's ruling does not merge them: it says the classification must also look at the recipient.

Take part in the consultation, if the topic touches you. Until 30 October 2026 the text is open to comments, which are published on the EDPB site. For sectors with particular use cases — health, research, official statistics — this is the window in which those cases can enter the final document.

Two reading caveats. First: this is version 1, in consultation. It is not final and may change; building a definitive architecture on it today would be premature, ignoring its direction would be imprudent. Second: this article is a plain-language reading and does not replace the text of the guidelines or legal advice on a specific case. The full PDF is linked in the sources.

More dossiers