EDPB Publishes Draft Guidelines on Anonymisation
On 7 July 2026, the European Data Protection Board (the “EDPB”) published its long-awaited draft Guidelines 02/2026 on Anonymisation (the “draft Guidelines”). The draft Guidelines – which are intended, once finalised, to replace the former Article 29 Working Party’s Opinion 05/2014 on Anonymisation Techniques (the “WP Opinion”) – adopt a “relative” approach to identifiability, as endorsed by the EU Court of Justice (the “CJEU”) in the EDPS v SRB case (see previous blog). The practical consequence is that the same dataset can be considered personal data for one party and anonymous for another (i.e., anonymity is not an intrinsic property of the data itself but depends on who holds it and what they can realistically do with it). Organisations that work with data they regard as anonymised (e.g., training AI models or sharing research datasets) may find the draft Guidelines a helpful reference point for reviewing and strengthening existing practices.
Background
Anonymous data falls outside the scope of the General Data Protection Regulation (the “GDPR”). However, a central question has been whether to assess anonymity in “absolute” or “relative” terms. Under the absolute approach, any data that could be re-identified by any third party constitutes personal data, regardless of likelihood. The relative approach asks instead whether this party can realistically re-identify the individual using means they would reasonably use.
In the EDPS v SRB case, the CJEU confirmed the relative approach (i.e., pseudonymous data is not automatically personal data in all contexts). The draft Guidelines update the approach taken in the WP Opinion to take the CJEU’s judgment into account and to also reflect developments in AI, EU-wide data spaces, and evolving re-identification techniques.
Key Takeaways
- The Two Question Test.
Pursuant to the draft Guidelines, data is considered anonymous if either: (i) the data does not relate to a natural person; or (ii) the data relates to a natural person, but that natural person is not identified or identifiable.
- Anonymity is Assessed from Each Relevant Entity’s Perspective.
Data may be personal for one entity but anonymous for another, depending on the information and means each entity is reasonably likely to use. In light of this, determining the relevant entity for the assessment of the given data (the “Anonymisation Assessment”) is important. The draft Guidelines state that where a processor handles data on behalf of a controller, the controller’s perspective governs, meaning the data remains personal for the processor, regardless of whether the processor could independently identify anyone.
- Means Reasonably Likely to be Used.
Whether a person is identifiable depends on whether any entity with realistic access to the data is reasonably likely to use means that would identify them. The draft Guidelines interpret “means” extremely broadly (e.g., from reading a document to running AI inference to combining datasets through a chain of third parties). The draft Guidelines identify several factors bearing on whether particular means are reasonably likely to be used. These factors include: (1) the properties of the data itself, (2) the context of release and any access restrictions, (3) the availability and cost of auxiliary information, (4) the technical and financial resources of potential adversaries, and (5) any legal prohibitions on re-identification.
Regarding legal prohibitions on re-identification, the draft Guidelines note that these are relevant factors only where they constitute a genuine practical barrier – an assumption that can be rebutted where enforcement is ineffective or the prohibition has previously been breached in comparable situations. In addition, the draft Guidelines provide that contractual restrictions do not amount to a legal prohibition and should complement, not replace, technical measures.
Organisations seeking to determine whether data has been anonymised for these purposes may consider effectuating a robust analysis, which documents each relevant factor and explains why, in combination, the likelihood of identification is insignificant.
- Two Routes to the Anonymisation Assessment.
The draft Guidelines propose two routes for the Anonymisation Assessment:
- The contextual approach applies the full legal standard, assessing each relevant entity’s capabilities individually. For example, an entity with limited technical resources is assessed by reference to those limits, and a sophisticated data broker is assessed against its broader means. The approach is more resource-intensive but may yield a more permissive outcome.
- The simplified approach treats all entities as equally capable of using any available technique. The approach is more conservative, and it may result in data being treated as personal even where it would technically be anonymous for some recipients. However, it is also more straightforward to apply.
As recommended by the EDPB in the draft Guidelines, the two approaches can be combined, for example, by starting with the simplified approach and pivoting to the contextual approach to assess whether any identified technique is reasonably likely to be used in practice by the relevant entities.
- Three Criteria for Anonymity.
Once an approach is chosen, the Anonymisation Assessment turns on three criteria:
- No Record Isolation: whether any individual record in the dataset can be singled out from others (i.e., distinguished with sufficient precision to make it possible to treat that individual differently. If a record can be isolated, the dataset raises identification risk that requires further analysis).
- No Linkage: whether records in the dataset can be joined to external datasets or other available information in a way that would allow identification. Importantly, probabilistic linkage and inference-based linkage both count.
- No Inference: whether it is possible to deduce information about a specific individual with sufficient accuracy to identify or single them out, even without direct or linked identification.
According to the draft Guidelines, data “can be presumed anonymous” if these criteria are met. It is worth noting, however, that elsewhere in the draft Guidelines, the EDPB proposes less certain language (i.e., “it may be anonymous”).
Failing any one criterion does not automatically render data personal. It would, however, likely trigger the need for further analysis of whether the identified “weakness” enables an individual to be singled out or treated differently with sufficient accuracy and reliability. The draft Guidelines include a flowchart that maps out this decision logic.

- Mixed Datasets.
It is common for a dataset to include some records that are genuinely anonymous alongside records that remain personal. The draft Guidelines confirm that the presence of some personal records does not automatically render the entire dataset personal data. The draft Guidelines state that the Anonymisation Assessment should be made at the record level with each record evaluated on its own merits. The personal records within the dataset still implicate full GDPR obligations, and technical/organisational measures must be capable of treating the two categories differently.
- The Anonymisation Process is Subject to the GDPR.
The draft Guidelines confirm that the act of anonymisation is itself a form of processing under the GDPR and therefore requires the controller: (1) to establish a valid legal basis under Article 6 GDPR (and an Article 9(2) GDPR condition for special category data), and (2) to comply with the transparency obligations and ensure adequate documentation of the anonymisation processing to demonstrate its effectiveness. Importantly, the draft Guidelines confirm that a security incident may lead to a reassessment of anonymity. This would in turn trigger potential GDPR personal data breach notification obligations.
Practical Implications and Next Steps
The draft Guidelines seek to bring certain clarity to anonymisation assessments. That said, the evidentiary bar is demanding, and organisations treating data as anonymous must identify each relevant entity and their capabilities, document a structured Anonymisation Assessment against all three (refined) criteria, and commit to periodic reassessment.
Entities may want to consider calibrating the frequency of periodic reassessments based on the sensitivity of the data, how it is used or disclosed, and the pace of relevant technological development.
The draft Guidelines are open for public consultation until 30 October 2026, after which the EDPB will consider feedback and adopt a final version. Experience with prior EDPB guidelines suggests that a substantial proportion of the draft text typically survives the consultation process largely intact. Nonetheless, the consultation process does create a meaningful opportunity for targeted input, and the EDPB has in the past refined specific positions in response to stakeholder feedback. Organisations with questions or concerns about the draft Guidelines may wish to consider engaging with the public consultation while there remains an opportunity to shape the final text.
This post is as of the posting date stated above. Sidley Austin LLP assumes no duty to update this post or post about any subsequent developments having a bearing on this post.

