Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Data Typology: Anonymous vs Pseudonymous vs Sensitive Data
Courses Guides Blog Resources News
Français English Nederlands
Fiche 6/54 Part I — General Introduction Intermediate Reviewed 2026-08-23

Data Typology: Anonymous vs Pseudonymous vs Sensitive Data

Regulatory burden depends on data nature. Irreversible anonymisation removes data from GDPR scope, whereas pseudonymised data remains fully covered. Sensitive data (Art. 9) is subject to an outright g

Open in interactive reader
⚖️ Binding Classification 📋 WP29 Opinion 05/2014 (Anonymisation)

Typology: Anonymous, Pseudonymous & Sensitive Data

⚡ In 30 seconds

Data protection law differentiates three tiers of information: Anonymous data (irreversible, outside GDPR), Pseudonymised data (Art. 4.5, protected but still within GDPR), and Special categories of data (Art. 9, prohibited unless specific exemptions apply). Hashing an email or using numeric IDs is pseudonymisation, never anonymisation.

Category Legal Definition GDPR Applicability & Risk
Anonymous Data rendered irreversibly unidentifiable across all reasonable means. Excluded: GDPR does not apply (Recital 26).
Pseudonymised Personal data that cannot be attributed without separate, secured key information. Included: Full GDPR applies; acts as security safeguard (Art. 25 & 32).
Sensitive (Art. 9) Health, biometric, genetic data, racial origin, political/religious beliefs, sexual orientation. General Prohibition: Requires dual legal basis (Art. 6 + Art. 9.2).
⚡ Key Takeaways
  • Three WP29 anonymisation criteria: singling out, linkability, and inference.
  • Pseudonymisation is a compliance tool, not an exemption from the law.
  • Sensitive data requires proactive data protection impact assessments (DPIAs).
⚠️ Common Pitfall

Treating SHA-256 salted hashes as anonymous data; if individual records remain distinguishable, they remain personal data.

🛠️ In Practice

Separate pseudonymised operational datasets from key attribution tables and store encryption keys in isolated environments.

⚖️ Official Sources: Art. 4(5), 9 GDPR · Recitals 26, 28 · WP29 Opinion 05/2014 ✓ Legal review: 23 August 2026

✓ Key takeaways

  • True irreversible anonymisation entirely falls outside GDPR scope.
  • Pseudonymised data remains personal data subject to the full Regulation.
  • Special categories of data (Art. 9) demand reinforced legal justification.

⚠ Common pitfall: Assuming that hashing or tokenizing identifiers (pseudonymisation) exempts the processing from GDPR obligations.

→ Actionable practice: Deploy pseudonymisation as a technical safeguard without neglecting fundamental transparency and lawfulness obligations.

← What is Personal Data? (Art. 4.1) Special Categories of Data (Art. 9) & Criminal Offences (Art. 10) →