ARTICLE
19 August 2026

EDPB Issues Draft Guidance On When Data Is Anonymous

SM
Sheppard, Mullin, Richter & Hampton LLP

Contributor

Businesses turn to Sheppard to deliver sophisticated counsel to help clients move ahead. With more than 1,200 lawyers located in 16 offices worldwide, our client-centered approach is grounded in nearly a century of building enduring relationships on trust and collaboration. Our broad and diversified practices serve global clients—from startups to Fortune 500 companies—at every stage of the business cycle, including high-stakes litigation, complex transactions, sophisticated financings and regulatory issues. With leading edge technologies and innovation behind our team, we pride ourselves on being a strategic partner to our clients.
The European Data Protection Board has released draft guidelines addressing a critical question for data controllers: when does anonymized information remain anonymous after transfer to third parties? These guidelines explore how recipient capabilities and available re-identification techniques can transform seemingly anonymous data into personal information subject to GDPR, introducing new assessment frameworks that could reshape data sharing practices across Europe.
United States Privacy
Liisa M. Thomas’s articles from Sheppard, Mullin, Richter & Hampton LLP are most popular:
  • with readers working within the Automotive industries
Sheppard, Mullin, Richter & Hampton LLP are most popular:
  • within Strategy and Insolvency/Bankruptcy/Re-Structuring topic(s)

Earlier this year, as we wrote, the European Data Protection Board was gathering input about how to assess if data is anonymous and thus not subject to GDPR. The EDPB has now issued draft Guidelines on this topic, which are open for comment until October 30, 2026.

The draft guidance addresses how to assess anonymity when information is transferred to a third party. In these situations, the other entity may have information that, when combined with the transferred data, can identify a person. In other words, what is anonymous with one entity may be personal with another. To help decide if information is personal, the EDPB points to two core questions. First, is the data related to a natural person? If so, is the person identifiable? If the answer to either is no, then the information is anonymous.

The guidance reminds companies that removing identifiers does not, alone, make information anonymous. The EDPB also recommends looking at factors like whether or not the data is aggregated, the amount of data, the level of detail, and the variety of attributes in the dataset (among other factors). When transferring information, the EDPB reminds companies that they should assess if the recipient could use other information to identify a person. The draft guidance gives three criteria for evaluating anonymization. If any are true, then the data may not be anonymous:

  1. No record isolation: the data set does not have a unique combination of attributes that relate to a single person.
  2. No linkage:records about the same person cannot be linked to another record that both relates (or likely relates) to the same person and comes from another dataset.
  3. No inference: one cannot learn new information about a person from the data.

The EDPB notes that the criteria should be evaluated against re-identification techniques, whether simple or complex. For the latter, the EDPB specifically mentions “special-purpose AI agents.” The guidance goes on to describe two ways to perform the analysis. A context-based approach looks at the recipient’s actual tools, data, resources, and realistic ability to identify people. A simplified approach is not recipient-specific. Instead, data is treated as personal if there is a potential technique that would make it personal. Under the simplified approach, data could be viewed as personal even if, in some cases, the specific recipient doesn’t have the requisite tools. As part of the guidance, the EDPB provides a decision flowchart.

Putting It Into Practice: This draft provides insight into the EDPB’s perspective on anonymization. If transferring anonymized data to a third party, keep in mind the capabilities they may have on their end to associate the information with a specific individual. Those capabilities might render the information personal and subject to GDPR. We anticipate there will be many comments to these guidelines prior to the October 30, 2026 deadline.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More