On 7 July 2026, the European Data Protection Board (EDPB) adopted its draft Guidelines 02/2026 on Anonymisation for public consultation. The Guidelines provide long-awaited clarification on when data can truly be considered anonymous under the GDPR, updating the previous Article 29 Working Party’s 2014 Opinion on anonymisation to reflect significant legal, and technological developments, including recent CJEU case law, the growth of EU-wide data spaces, and rapid advances in AI and technology.

Anonymity remains a contextual concept

The draft Guidelines reaffirm that anonymous data is information that does not relate to an identified or identifiable natural person and therefore falls outside the GDPR. However, the EDPB emphasises that anonymity is not an absolute concept. Whether data is anonymous may vary depending on the perspective of the relevant entity and the means reasonably likely to be available to them for re-identification.

Building on recent European Court Justice (CJEU) case law, particularly EDPS v SRB, the EDPB emphasised that data may be personal data for one entity while being anonymous for another. In the SRB case, the CJEU held that whether the data constitutes ‘personal data’ and therefore falls within the scope of the GDPR, depends on whether the recipient has the means available to it to enable it to access the additional information necessary to re-identify the individuals. The fact that the sender has the means to re-identify individuals does not mean that the transmitted data is automatically also personal data in the hands of the recipient.

Importantly, the Guidelines clarify that the applicable perspective used for a particular entity “depends on whether they themselves determine the means and purposes of the processing. If an entity processes information on behalf of another, whether the given data is personal for that entity should be assessed by reference to the controlling entity’s perspective“.  In practice, this means that where an organisation is processing personal data on behalf of a controller, the data will remain personal data in the hands of the processor, even if it cannot identify individuals itself.

The Guidelines also highlight that anonymisation can be achieved for different purposes. In some cases, organisations may seek to render data anonymous for all parties. In others, anonymisation may be intended only for specific recipients, while the original controller continues to hold information that enables identification. The assessment must therefore be tied closely to the specific context in which the data is used and shared.

Introducing two approaches to anonymisation assessments

One of the most notable aspects of the new guidelines is the introduction of two distinct assessment methodologies.

The first is the contextual approach, which reflects the legal standard under the GDPR. This approach requires organisations to consider the actual capabilities, information and resources available to the entities that may seek to identify individuals. It recognises that different parties may have access to different datasets, technologies or legal powers that affect the likelihood of re-identification.

The second is the simplified approach, which disregards differences between entities and assumes a broader range of potential re-identification capabilities. While this approach may result in organisations treating some anonymous data as if it remained personal data, the EDPB notes that it offers a more conservative and practical means of demonstrating compliance.

In practice, the EDPB suggests that a combination of the two approaches may often be helpful, starting with a simplified assessment before conducting a more granular contextual analysis where necessary.

The EDPB’s three-part anonymisation test

Central to the Guidelines is a new framework centred on three criteria that organisations can apply when assessing whether data has been effectively anonymised. The EDPB states that if all three criteria are satisfied, the data may generally be regarded as anonymous.

1. No Record Isolation

The first criterion assesses whether an individual can be singled out through a unique combination of attribute values that relate to a single individual. Even where direct identifiers such as names or identification numbers have been removed, individuals may still be distinguishable if the remaining data points create a unique profile. The larger a record is, and the more attributes that it contains, the higher the likelihood that the record will be unique within the given data.

2. No Linkage

The second criterion examines whether the data can be linked to other datasets containing information about the same individual. The EDPB notes that seemingly innocuous information may become identifying when combined with additional data sources. Organisations must therefore consider what supplementary information may be available to relevant parties and how likely it is that those datasets could be matched.

3. No Inference

The third criterion focuses on whether specific and meaningful information about an identifiable individual can be inferred from the dataset. The EDPB explains that inference risks can arise from both record-level and aggregated data, including statistical outputs, AI models and synthetic datasets. An inference will be problematic where it relates to a specific individual and is capable of affecting that person’s rights or interests.

A stronger focus on re-identification risk

The Guidelines place considerable emphasis on the growing sophistication of re-identification techniques. Organisations are encouraged to assess anonymisation against the current state of the art, taking into account factors such as dataset dimensionality, data resolution, the availability of supplementary information and advances in computational tools.

The EDPB highlights the potential impact of developments in AI. The Guidelines acknowledge that AI systems may significantly reduce the time, cost and expertise required to combine datasets and uncover information about individuals. As a result, anonymisation assessments must take account not only of present-day risks but also reasonably foreseeable technological developments.

The EDPB also stresses that anonymisation is not a one-time exercise. Data that is effectively anonymised today may become vulnerable to re-identification in the future as new information becomes available or new analytical techniques emerge. The EDPB therefore recommends periodic reassessment of anonymised datasets to ensure that the risk of re-identification remains insignificant over time.

Implications for Organisations

The draft Guidelines provide organisations with a significantly more detailed framework for assessing and documenting anonymisation than was available under the previous 2014 Opinion. However, organisations will need to undertake more nuanced assessments of re-identification risks, consider different stakeholder perspectives and maintain evidence supporting their anonymisation conclusions. The EDPB also reminds organisations that the process of anonymisation itself remains subject to the GDPR and must comply with applicable legal bases, transparency obligations and accountability requirements.

The draft Guidelines are open for public consultation until 30 October 2026.