Pseudonymised Data Is Still Personal

Pseudonymised Data Is Still Personal

Strip the names out of a dataset, replace them with reference numbers, lock the key in a separate system, and you have done something worth doing. You have not taken the data outside the GDPR. Pseudonymised data is personal data, and the exam will hand you a scenario written by someone who thinks otherwise.

This distinction sits in Domain II of the Body of Knowledge, the blueprint the IAPP publishes to set out what the exam covers. It looks like a definitions question. It is really a scope question, and scope decides everything that follows.

What pseudonymised data actually is

Article 4(5) of the GDPR defines pseudonymisation as processing personal data so that it can no longer be attributed to a specific data subject without the use of additional information, where that additional information is kept separately and subject to technical and organisational measures. Every clause matters, but the phrase that decides the answer is "without the use of additional information".

The additional information is the whole test

Pseudonymisation assumes the key still exists. If nobody could ever reverse the process, you would not need the separation requirement in the definition. Recital 26 makes the consequence explicit: data which could be attributed to a natural person by the use of additional information is information on an identifiable natural person. The EDPB restated the point in its Guidelines 01/2025 on pseudonymisation, published for consultation in January 2025: pseudonymised data which could be attributed to an individual by the use of additional information remains information relating to an identifiable natural person.

So the controller holding both the dataset and the key is processing personal data. Nothing about that is close to the line.

Anonymised data leaves the regulation

Anonymisation is a different thing entirely, and the line between it and pseudonymised data is where the marks sit. Recital 26 handles both in the same breath. The principles of data protection do not apply to anonymous information, or to personal data rendered anonymous in such a way that the data subject is not or no longer identifiable. If you get there, the GDPR stops applying to that data. No lawful basis, no rights requests, no retention schedule.

The test is means reasonably likely to be used

Recital 26 sets the standard: account should be taken of all the means reasonably likely to be used to identify the person, whether by the controller or another person, including the costs, the time required, and the technology available at the time of processing and technological developments. That is a moving target by design. A dataset that was anonymous on the available technology in 2019 is not guaranteed to be anonymous now.

The EDPB has a public consultation open on its Guidelines 02/2026 on anonymisation, running to 30 October 2026. The direction of travel is worth watching, because the practical bar for genuine anonymisation is higher than it looks from inside a project plan.

Pseudonymised data still earns you something

None of this makes pseudonymisation pointless, and the exam will test whether you know what it does buy. Article 32 lists it as an example of an appropriate technical measure for security. Article 25 puts it among the measures that implement data protection by design. Article 6(4) names it as a safeguard when you assess whether processing for a new purpose is compatible with the original one. Article 34 lets you avoid telling data subjects about a breach where measures such as encryption render the data unintelligible.

Pseudonymised data therefore changes your risk profile and your obligations at the margin. It does not change whether the regulation applies. Keep that sentence intact and a whole class of questions resolves itself, in the same way the seven data protection principles resolve questions about purpose and retention.

Where the exam sets the trap

The classic stem describes a company that replaces customer names with identifiers, sends the file to an analytics vendor, and concludes the transfer is outside the GDPR. The distractor is attractive because the middle step is genuinely good practice. The answer is that the pseudonymised data remains personal data for the sending controller, so the transfer needs a basis, a contract and, if it leaves the EEA, a transfer mechanism.

Whose hands the data is in

There is a wrinkle worth knowing. In Case C-413/23 P, EDPS v SRB, decided on 4 September 2025, the Court of Justice held that pseudonymised data must not be regarded as constituting, in all cases and for every person, personal data. Whether it is personal data in a recipient's hands depends on the means that recipient reasonably has.

Read that carefully before you let it loosen anything. It does not say pseudonymisation strips data of its character; it says the assessment is done from the position of the person holding the data. For the controller who holds the key, the answer is unchanged. On the exam, unless the question tells you the recipient has no route back to the individual and no realistic way of getting one, treat pseudonymised data as personal data and move on.

Work through a few past scenarios and mark, for each one, whose hands the data is in. More study material is at 22academy.com/study.

Share this Post

Exam Question Masterclass



Ready to kick-start your career?

GET STARTED NOW



About The Blog


Stay up to date with the latest news, background articles, and tips for your study.


Our latest video





22Academy

Tailored Training Solutions

Let's find the best education solution for your situation. We will contact you for Free Support!

Success! Your message has been sent to us.
Error! There was an error sending your message.
It’s for:
We will only use your email address to contact you regarding your education needs. We do not sell your personal data to third parties.