Navigating the Draft Guidelines 02/2026 on Anonymisation: A Fresh Perspective
On July 7, 2026, the European Data Protection Board (EDPB) released its highly anticipated draft Guidelines 02/2026 on Anonymisation, aiming to replace the earlier Article 29 Working Party’s Opinion 05/2014 on Anonymisation Techniques. This significant update adopts a "relative" approach to identifiability, as recently endorsed by the EU Court of Justice (CJEU) in the EDPS v SRB case. This approach introduces a nuanced understanding: a dataset can be regarded as personal data for one party while being considered anonymous for another, depending on their ability to identify individuals within that dataset.
Background on Anonymisation and Data Privacy
Anonymous data falls outside the purview of the General Data Protection Regulation (GDPR). Central to the discussion surrounding anonymisation has been whether to adopt an absolute or relative assessment framework. The absolute approach asserts that any data that could potentially be re-identified by any third party qualifies as personal data. In contrast, the relative approach considers whether a specific party realistically possesses the means to re-identify individuals, based on their resources and capabilities.
The CJEU affirmed this relative perspective in its ruling on the EDPS v SRB case, highlighting that pseudonymous data isn’t automatically classified as personal across all contexts. The draft Guidelines reflect this shift, taking into account technological advancements in AI, the emergence of EU-wide data spaces, and evolving re-identification strategies.
Key Takeaways from the Guidelines
1. The Two Question Test
The draft Guidelines stipulate that data is deemed anonymous if:
- First Question: The data does not relate to a natural person.
- Second Question: If it does relate to one, that person is neither identified nor identifiable.
This dual criterion paves the way for more rigorous assessments concerning the nature of data.
2. Entity-Specific Anonymity Evaluations
The determination of whether data is personal or anonymous is contingent on the perspective of the relevant entity. For example, data can be viewed as personal by one party while being anonymous to another based on their analytical capabilities. The Guidelines emphasize the need for an Anonymisation Assessment that considers the context of data handling, particularly when a processor operates on behalf of a controller.
3. Reasonable Means of Identification
The draft Guidelines expand on what constitutes "means" that can realistically lead to identification. They cover a broad range of actions, from simply reading documents to employing advanced AI techniques and even amalgamating datasets across third parties. Several factors play into this judgment, including:
- The inherent properties of the data
- The context in which it is released
- The availability of complementary information
- Technical and financial resources of potential adversaries
- Legal stipulations on re-identification
Notably, legal prohibitions are only considered genuine barriers if their enforcement is tangible. Contractual restrictions, in contrast, do not qualify as legal prohibitions.
4. Approaches to Anonymisation Assessment
The Guidelines propose two distinct routes for the Anonymisation Assessment:
-
Contextual Approach: This method evaluates each entity’s capacities individually, recognizing the varied capabilities among entities. While this route may demand more resources, it might lead to more favorable outcomes for assessing anonymity.
- Simplified Approach: In this route, it is assumed that all entities can utilize any technique available. While it offers a conservative assessment resulting in a higher probability of data being classified as personal, its straightforward application can be advantageous.
The EDPB suggests a hybrid approach, potentially beginning with the simplified method before transitioning to the contextual framework where necessary.
5. Criteria for Establishing Anonymity
Once a method of assessment is chosen, the Anonymisation Assessment hinges on three pivotal criteria:
- No Record Isolation: Can individual records be distinguished precisely enough to treat them differently?
- No Linkage: Can records within the dataset be connected to external datasets or information, allowing for possible identification?
- No Inference: Is it possible to deduce aspects about a specific individual with enough accuracy to identify them, regardless of direct identification means?
According to the draft Guidelines, fulfilling these criteria allows data to be presumed anonymous. However, the wording is slightly ambiguous, stating it "may be anonymous" in other sections.
6. Evaluating Mixed Datasets
In practice, datasets often contain a mix of genuinely anonymous records alongside personal ones. The Guidelines clarify that the presence of personal data does not automatically render the entire dataset personal. Each record must be evaluated on its individual merits. Personal records in a mixed dataset still carry full GDPR obligations, necessitating measures to treat both categories differently.
7. The GDPR and the Anonymisation Process
Importantly, the act of anonymisation itself is classified as a form of processing under the GDPR. This requires data controllers to establish a valid legal basis under Article 6 and, when applicable, conditions outlined in Article 9(2) for special category data. Moreover, the draft Guidelines stipulate that organizations must document their anonymisation processes effectively and can trigger reassessment of anonymity status after any security incident, potentially leading to GDPR personal data breach notifications.
Practical Implications
The draft Guidelines are a crucial step toward refining the understanding of anonymisation in the evolving data landscape. Organizations that operate with data they deem anonymous must engage in rigorous analyses—carefully documenting each factor and rationale behind their assessments and committing to regular reviews. The frequency of these assessments may vary according to the data’s sensitivity, its use, and the pace of technological changes.
These Guidelines are currently open for public consultation until October 30, 2026, giving stakeholders a chance to provide targeted feedback. Past EDPB consultations have demonstrated that while much of the draft text remains intact, input can still lead to meaningful refinements. Organizations with interests in the draft Guidelines should consider engaging actively in this process while they have the opportunity to influence the final text.