Privacy & Tech

Knowledge Base | Privacy & Tech | How is anonymization different from pseudonymization?

How is anonymization different from pseudonymization?

Anonymization makes people no longer identifiable, taking account of the means reasonably likely to be used to identify them. Pseudonymization reduces the direct link to a person while allowing identification using separately held additional information.

Aspect

Anonymization

Pseudonymization

Identifiability

Individuals are no longer identifiable in the relevant context.

Identification remains possible using additional information.

Example

Statistics sufficiently protected against identifying contributors.

Customer names replaced with codes, with a separate lookup table.

Data protection status

Effectively anonymous information falls outside the GDPR’s personal-data rules.

Remains personal data for an organisation able to reconnect it to individuals.

Removing names alone does not establish anonymity. Detailed locations, unusual purchases or combinations of attributes may still identify someone. Anonymization is assessed based on the means reasonably likely to be used for re-identification, while pseudonymization reduces exposure without removing identifiability.

Pseudonymization can therefore be an important privacy and security measure, but it does not by itself make personal data anonymous. Similarly, aggregation does not automatically produce anonymous information if small groups or unusual characteristics can still reveal individuals.

The ICO’s introduction to anonymization explains the distinction. Techniques such as tokenization in privacy can reduce exposure without necessarily producing anonymous information.