← All insights
Guides28 November 2025·6 min read

Pseudonymisation & anonymisation

The difference matters more than most teams realise. A clear guide to when each technique applies and what it actually buys you.

Pseudonymisation and anonymisation are not the same thing, and confusing the two is the single most common technical mistake we see in privacy programmes. The difference is not academic — it determines whether the resulting data is in scope of the UK GDPR at all, and it drives the controls you need to have in place.

Pseudonymisation is a security measure. It replaces direct identifiers with a token or key, in such a way that the data can no longer be attributed to a specific individual without the use of additional information held separately. Pseudonymised data is still personal data. The full obligations of the regime apply, including lawful basis, transparency, subject rights, and security. What pseudonymisation buys you is reduced risk in the event of a breach, and the ability to rely on it as evidence of appropriate security measures.

Anonymisation removes data from scope entirely. It requires that individuals can no longer be identified, directly or indirectly, taking into account all the means reasonably likely to be used to re-identify them. Once data is genuinely anonymous, it is no longer personal data, and the regime does not apply. What anonymisation requires is a rigorous re-identification risk assessment, and — critically — the assessment needs to consider not just the data in isolation but the data combined with other information reasonably available.

The re-identification risk assessment is the piece that most self-declared anonymisation efforts skip. A dataset that has had direct identifiers removed is not anonymous if quasi-identifiers — postcode, date of birth, occupation — allow re-identification through linkage with other datasets. The ICO's guidance on anonymisation sets out the framework: consider the singling-out risk, the linkability risk, and the inference risk, taking into account the anonymisation techniques applied and the state of the art.

Practical guidance. If you need the ability to link records back to individuals for operational purposes — customer support, fraud investigation, subject rights — you need pseudonymisation, not anonymisation, and you should design the workflow accordingly. If you genuinely do not need re-identification, anonymisation may be achievable, but budget for the risk assessment and the ongoing monitoring of re-identification risk as external datasets evolve.

The confusion between the two often arises when a business case describes "anonymisation" for what is really pseudonymisation with strong access controls. Get the terminology right in the design phase and the downstream controls follow naturally.

Companies we've supported

59AThe Compliance EngineersAikenCountry & Town HouseLightbulbGraffic JamSerenefounditAIMEaffiliate.ai59AThe Compliance EngineersAikenCountry & Town HouseLightbulbGraffic JamSerenefounditAIMEaffiliate.ai