Anonymization vs pseudonymization under the GDPR

What the law says, and what it means for sharing a spreadsheet

The two words are often used as if they meant the same thing. Under the GDPR they do not, and the difference decides whether the regulation still applies to the data you share.

Anonymous data: outside the GDPR

The GDPR does not apply to anonymous information: data that does not relate to an identified or identifiable person, or personal data "rendered anonymous in such a manner that the data subject is not or no longer identifiable" (Recital 26). To decide whether someone is identifiable, you take into account all the means "reasonably likely to be used" to identify them, directly or indirectly, considering cost, time and available technology.

That is a high bar. Removing names is rarely enough: a date of birth, a postal code and a job title together can point to one person.

Pseudonymised data: usually still personal data

Pseudonymisation means processing personal data so that it "can no longer be attributed to a specific data subject without the use of additional information", provided that information is kept separately and protected (Article 4(5)). Replacing names with consistent fakes or keyed hashes, and keeping the key or mapping yourself, is pseudonymisation.

For whoever can re-identify the data, it remains personal data, as the European Data Protection Board confirms in its Guidelines 01/2025 on pseudonymisation. It is still worth doing: the GDPR names pseudonymisation as a safeguard, for example as part of data protection by design (Article 25), and it greatly reduces the harm if data leaks.

What changed in 2025: the recipient's point of view

In EDPS v SRB (C-413/23 P), decided on 4 September 2025, the EU Court of Justice held that sufficiently strong pseudonymised data can be personal data for the organisation that holds the key, but not for a recipient who cannot reverse the pseudonymisation and has no other reasonable means to identify the people. Whether data is personal is judged from the position of whoever has it.

In practice: when you send a pseudonymised spreadsheet to a supplier and keep the mapping to yourself, the data can fall outside the GDPR for them. For you it stays personal data, and you still need to tell people who receives their data where the law requires it.

Which method does what

Method Result Typical use
Clear or redact The value is gone Columns nobody needs
Generalize Less precise (year, postal area, range) Reduce what can single someone out
Mask Partly hidden, like ****1234 Recognising a value without seeing it
Consistent fake or keyed hash Pseudonymised: reversible with the key or mapping Analysis, test data, joining files
Shuffle Real values, moved between rows Keeping a column's distribution

Anonymization usually needs a combination: drop direct identifiers, generalize the indirect ones, and never keep a way back. If you keep a mapping or a secret key, treat the result as pseudonymised.

This guide explains the rules as we understand them; it is not legal advice. Whether a particular dataset is anonymous depends on its content and on who receives it.

Try it on your own file. The Scrubsheet browser tool anonymizes Excel and CSV files in your browser, free and without uploading anything. In Excel, use the Scrubsheet add-in.

Anonymize a spreadsheet

More guides