Privacy & Tech
What is tokenization in privacy?
Tokenization is a data protection technique that replaces personal or sensitive information, such as an email address or payment card number, with a substitute code called a token. Systems use this code in place of the original information, reducing how often that information needs to be shared or accessed.
For example, a company could replace a customer’s email address with customer_7K92 in its analytics records. Analysts could group purchases under that code without seeing the email address. In a vault-based system, the link between the code and the original value is kept in a separate, protected database.
Tokenization can help organisations:
Reduce the appearance of direct identifiers in working datasets.
Link authorised records without repeatedly exposing the original value.
Restrict recovery of the original information to permitted systems or users.
The ICO’s guidance on tokenisation-based pseudonymisation explains its use as a privacy safeguard.
Tokenization does not necessarily produce anonymous information. If a person can still be identified through a mapping or other available information, the data can remain personal data. A stable token may also allow activity to be linked over time.
The difference between anonymization and pseudonymization is therefore important: replacing a visible identifier reduces exposure, but does not automatically remove data protection obligations.
Türkçe
English