Fiche 16/54
Part 2 — Core Principles
Intermediate
Reviewed 2026-08-23
Anonymisation vs Pseudonymisation (Art. 4.5)
Anonymisation vs Pseudonymisation (Art. 4.5)
⚡ In 30 seconds
Under Article 4(5), pseudonymisation replaces direct identifiers with artificial pseudonyms, where re-identification remains possible via separately stored secret keys. Pseudonymised data is always personal data. By contrast, anonymised data can never be linked back to an individual by any reasonable means likely to be used; it entirely exits the scope of the GDPR.
| Criterion | Pseudonymisation (Art. 4.5) | Anonymisation (Recital 26) |
|---|---|---|
| GDPR Scope | Applicable in full: DPA, user rights, data breach notification. | Excluded: Regulation ceases to apply. |
| Reversible? | Yes, by using separate key or lookup attribution tables. | Irreversible across all state-of-the-art technological means. |
| Role in Compliance | Security measure (Art. 32) & Privacy by Design (Art. 25). | Definitive exit strategy for open-data publishing. |