Skip to content
Localex
← All guides

Pseudonymisation vs anonymisation (GDPR, EDPB 01/2025)

The two words are often used as synonyms. Under the GDPR they lead to opposite results. A practical reading of the texts for Belgian lawyers.

Updated on 29 September 2026

"Anonymised" and "pseudonymised" are often used as synonyms, in legal writing as elsewhere. Under the GDPR they lead to opposite results: pseudonymised data remain personal data, while anonymous information falls outside the Regulation. Calling a pseudonymised document "anonymised" is therefore not a matter of style. It can mislead a client, a court or a co-contractor about the protection that was actually applied.

What the GDPR says

The GDPR defines pseudonymisation in article 4(5) as the processing of personal data "in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information", provided that this additional information is kept separately and protected by technical and organisational measures.

Recital 26 draws the consequence. Pseudonymised data that could be attributed to a person by the use of additional information are information on an identifiable person. To decide whether a person is identifiable, account is taken of all the means reasonably likely to be used, "such as singling out", by the controller or by another person, in the light of objective factors such as cost, time and available technology. Only anonymous information, which does not relate to an identified or identifiable person, escapes the data protection principles.

Pseudonymisation is not an end in itself: articles 25(1) and 32(1)(a) cite it as a measure that helps implement data protection by design and ensure the security of processing.

What EDPB Guidelines 01/2025 add

The European Data Protection Board adopted its Guidelines 01/2025 on pseudonymisation on 16 January 2025, in a version for public consultation. At the time of writing, that is the version published. Five points matter for a law firm:

  • Still personal data, whoever holds the key. Pseudonymised data that could be attributed to a person with additional information are personal data, and this remains true when the pseudonymised data and the additional information are not in the hands of the same person (para. 22).
  • Deleting the key is not enough. Even when all additional information has been erased, the data become anonymous only if the conditions for anonymity are met (para. 22).
  • The key is sensitive too. Additional information includes tables matching pseudonyms with the values they replace, and cryptographic keys. It must be kept separately and protected (para. 20). Such lookup tables are themselves personal data (para. 93).
  • The pseudonymisation domain. The controller defines the context in which attribution must be prevented, for example the set of recipients of the pseudonymised text (executive summary and section 2.3).
  • Quasi-identifiers. Attributes such as age, gender, profession, family status or income can, in combination, point to a person without any name. The Board describes three ways to deal with them: removal, generalisation or randomisation, or limiting the information available within the domain (paras. 101 to 103).

The Court of Justice: whose point of view?

In EDPS v SRB (C-413/23 P, 4 September 2025), the Court of Justice ruled on Regulation 2018/1725, the counterpart of the GDPR for EU institutions. According to the Court's press release, pseudonymised data must not be regarded as personal data "in all cases and for every person": depending on the circumstances, pseudonymisation may prevent persons other than the controller from identifying the data subject. The Court also held that the controller's duty to inform is assessed at the time of collection, from the controller's point of view.

For a lawyer, the practical reading is prudent. You hold the key, so for you the pseudonymised text is personal data. Whether a recipient, such as an AI provider, could identify the persons depends on what the text still reveals and what else that recipient knows. A practice should not rest on the assumption that the recipient only sees anonymous data.

A new draft on anonymisation

On 7 July 2026 the EDPB adopted draft Guidelines 02/2026 on anonymisation, open for comments until 30 October 2026. The draft assesses anonymity from the perspective of each relevant entity, and proposes three criteria: no record isolation, no linkage and no inference. Data that pass all three can be considered anonymous. It is a draft and may still change.

Side by side

PseudonymisationAnonymisation
ReversibleYes, with the additional information (the key)No
Status under the GDPRPersonal dataOutside the GDPR, if the conditions for anonymity are met
Typical use in a firmAI round trip, sharing with an expert, internal workPublication, training material, model documents
Accurate wording"pseudonymised""anonymised", only after an assessment
In LocalexPseudonymise mode: tokens and an encrypted restore keyAnonymise mode: no key is created

Why anonymising a legal text is hard

A judgment or a set of conclusions tells a story, and stories are unique. Remove every name and the text may still identify the persons through what remains: the municipality, the profession, the age, the number of children, the nationality, the employer, a school, a medical condition, an exact amount, the date of an unusual event. A reader who already knows the facts will recognise them; that is the "inference" risk of the EDPB draft.

This is why the Anonymise mode of Localex is a necessary condition, not a sufficient one. It produces no key, so nothing can be reversed with the tool. Whether the result is anonymous in law also depends on the content left in clear and on who will read it.

How to do it with Localex

  1. Open the tool and load the document.
  2. Choose the mode: Pseudonymise when you need the originals back (for example after an AI answer), Anonymise when nothing must ever be reversed.
  3. For anonymisation, prefer strategies that remove information: black bar, role tokens or generalisation (a birth date becomes an age band, an address a municipality or province, an amount a rounded figure).
  4. Treat the quasi-identifiers in the review: municipalities, workplaces, schools, exact amounts. With the AI features, free after e-mail verification, a re-identification risk analysis flags the details left in clear.
  5. Export. The leak scan checks that no original value masked in the review is left in the output file.

Wording that stays accurate

  • Write "pseudonymised" for any text that can be reversed with a key, even if you are the only one holding it.
  • Keep "anonymised" for texts you have assessed as such, and say how: "names of the parties and of the witnesses removed, places and dates generalised".
  • In a publication, a note such as "names replaced by the author" describes what was done without claiming more.

Honest limits

  • No tool can decide on its own that a text is anonymous in law: the assessment depends on the content, the context and the recipients.
  • The leak scan finds original values; it cannot detect a combination of harmless-looking details that identifies someone.
  • Detection is not exhaustive, and the review remains the lawyer's.