Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

EDPB Publishes Draft Guidelines on Anonymisation

By Dan Cooper, Kristof Van Quathem & Alix Bertrand on August 4, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

Table of Contents

  • I. Legal Analysis of Anonymity
  • II. Technical Analysis of Anonymity
  • A. Contextual vs Simplified Approach
  • B. The Three Criteria

On July 7, 2026, the European Data Protection Board (“EDPB”) adopted draft Guidelines 02/2026 on Anonymisation (“Guidelines”), updating a 2014 Opinion on Anonymization Techniques. While the EDPB maintains a cautious approach to anonymization, the new Guidelines appear to offer a more structured and practical framework for assessing whether information can be considered anonymous. The Guidelines are open for public consultation until October 30, 2026.

Link to I. Legal Analysis of Anonymity I. Legal Analysis of Anonymity

The Guidelines anchor anonymization in the GDPR definition of personal data: information is anonymous if it either (i) does not “relate” to an individual or (ii) does not concern an identified or identifiable individual. Importantly, and triggered by the recent SRB case (see our blog here), the EDPB stresses that the answer to these questions may vary depending on the entity assessing the data. This forms the basis for one of the Guidelines’ central themes: anonymization is often a matter of perspective.

In this context, the EDPB clarifies that, when assessing anonymity, organizations should first identify relevant entities, before considering the likelihood of each of these entities re-identifying individuals from a given dataset.

Identifying relevant entities. This will require organizations to take into account several factors, including access, control, sharing arrangements, party relationships, and whether one party acts on another’s behalf. On this point, the Guidelines consider that where an entity processes a dataset on behalf of another entity, the anonymity assessment should be conducted from the perspective of the controlling entity. As a result, processors cannot escape their GDPR obligations – if the data are personal data for the controller, they are personal data for the processor. This is striking because the SRB case related precisely to the sharing of data with a processor, although the court could not take this aspect into account in its assessment.  The EDPB also reiterates that the act of anonymizing requires a legal basis in the GDPR (and an Art. 9 derogation in case of special categories of data) if the anonymization serves a different purpose than the original one.

Considering the likelihood of re-identification. Consistent with Recital 26 GDPR, the EDPB reiterates that organizations should assess whether a relevant entity could identify individuals through means “reasonably likely to be used.” Means that are impossible, disproportionate in time, cost or effort, or legally prohibited may fall outside this test. However, the Guidelines caution that such limits may offer little protection in certain circumstances, e.g., where actors are unlikely to comply with the law, such as cybercriminals, and that contractual restrictions should not be treated as equivalent to legal prohibitions. The EDPB also suggests that re-identification may remain reasonably likely where specialist third-party services are readily available, or where an entity has a legal avenue to access additional data.

Link to II. Technical Analysis of Anonymity II. Technical Analysis of Anonymity

Link to A. Contextual vs Simplified Approach A. Contextual vs Simplified Approach

The EDPB describes two methodologies for assessing anonymization. A contextual approach considers the means available to relevant entities and the likelihood they will use them to reidentify individuals, while a “simplified approach” applies a more generalized assessment that considers the ability of anyone to re-identify individuals. When assessing anonymity, organizations may use either approach, or combine them, depending on the circumstances. However, the Guidelines caution that contextual assessments may falsely conclude that a dataset is anonymous, reflecting continued regulatory caution toward findings of anonymity.  The simplified approach, on the other hand, will result in a higher standard, but may be overly restrictive.

Link to B. The Three Criteria B. The Three Criteria

At the technical level, the Guidelines retain and further develop three familiar criteria for evaluating the effectiveness of anonymization and re-identification techniques:

  1. Record Isolation, where no unique combination of attributes relates to a single individual;
  2. Linkage, where a record cannot be linked to another record from a different dataset that relates, with certainty or high likelihood, to the same individual;
  3. Inference, where the data does not support specific and meaningful conclusions about an individual.

If all three criteria are met, the dataset may be considered anonymous. If not, additional analysis is required – including potentially under the contextual approach.

*                         *                         *

Covington’s Privacy and Cybersecurity team will continue to monitor developments related to data anonymization. If you have any questions about the issues raised in this blog, or would like to participate in the Commission’s consultation phase, please do not hesitate to contact us.

Photo of Dan Cooper Dan Cooper

Daniel Cooper is co-chair of Covington’s Data Privacy and Cyber Security Practice, and advises clients on information technology regulatory and policy issues, particularly data protection, consumer protection, AI, and data security matters. He has over 20 years of experience in the field, representing…

Daniel Cooper is co-chair of Covington’s Data Privacy and Cyber Security Practice, and advises clients on information technology regulatory and policy issues, particularly data protection, consumer protection, AI, and data security matters. He has over 20 years of experience in the field, representing clients in regulatory proceedings before privacy authorities in Europe and counseling them on their global compliance and government affairs strategies. Dan regularly lectures on the topic, and was instrumental in drafting the privacy standards applied in professional sport.

According to Chambers UK, his “level of expertise is second to none, but it’s also equally paired with a keen understanding of our business and direction.” It was noted that “he is very good at calibrating and helping to gauge risk.”

Dan is qualified to practice law in the United States, the United Kingdom, Ireland and Belgium. He has also been appointed to the advisory and expert boards of privacy NGOs and agencies, such as the IAPP’s European Advisory Board, Privacy International and the European security agency, ENISA.

Read more about Dan CooperEmail
Show more Show less
Photo of Kristof Van Quathem Kristof Van Quathem

Kristof Van Quathem advises clients on information technology matters and policy, with a focus on data protection, cybercrime and various EU data-related initiatives, such as the Data Act, the AI Act and EHDS.

Kristof has been specializing in this area for over twenty…

Kristof Van Quathem advises clients on information technology matters and policy, with a focus on data protection, cybercrime and various EU data-related initiatives, such as the Data Act, the AI Act and EHDS.

Kristof has been specializing in this area for over twenty years and developed particular experience in the life science and information technology sectors. He counsels clients on government affairs strategies concerning EU lawmaking and their compliance with applicable regulatory frameworks, and has represented clients in non-contentious and contentious matters before data protection authorities, national courts and the Court of the Justice of the EU.

Kristof is admitted to practice in Belgium.

Read more about Kristof Van QuathemEmail
Show more Show less
Photo of Alix Bertrand Alix Bertrand

Alix advises clients on EU data protection and technology law, with a particular focus on French privacy and data protection requirements. She regularly assists clients in relation to international data transfers, direct marketing rules as well as IT and data protection contracts. Alix…

Alix advises clients on EU data protection and technology law, with a particular focus on French privacy and data protection requirements. She regularly assists clients in relation to international data transfers, direct marketing rules as well as IT and data protection contracts. Alix is a member of the Paris and Brussels Bars.

Read more about Alix BertrandEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Inside Privacy
  • Organization:
    Covington & Burling LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo