GuidelinesPublic consultation versionAdopted 2025-01-16

EDPB 01/2025

Guidelines 01/2025 on Pseudonymisation

Version adopted for public consultation on 16 January 2025. The EDPB may adopt a revised version after the consultation; check the official EDPB page before relying on it.

What it covers

These guidelines, published in a consultation version, explain the legal definition and objectives of pseudonymisation under the GDPR, its role in meeting data minimisation, purpose limitation, security and data protection by design obligations, and its use as a supplementary measure for international transfers. They also set out technical measures and safeguards for pseudonymising transformations and for preventing unauthorised attribution or linkage of pseudonymised data.

Why it matters

It provides controllers and processors with detailed technical and legal criteria for using pseudonymisation effectively to reduce risk and support compliance, an area where the GDPR definition had previously received limited detailed guidance.

Refer to it when

  • designing a pseudonymisation scheme to reduce processing risk
  • relying on pseudonymisation to support a legitimate interest assessment
  • using pseudonymisation as a supplementary measure for international data transfers
  • assessing security measures needed to prevent re-identification
  • handling data subject rights requests concerning pseudonymised data

Questions this document addresses

  • What is the legal definition of pseudonymisation under Article 4(5) GDPR?
  • How can pseudonymisation help meet data protection by design and security obligations?
  • Can pseudonymisation serve as a supplementary measure for international transfers?
  • What technical measures prevent unauthorised attribution of pseudonymised data?
  • How does pseudonymisation affect the exercise of data subject rights?

Topics

  • Pseudonymisation
  • Security of processing
  • Data protection by design
  • Lawful basis

Official EDPB page for this document

Clarifies the GDPR definition of pseudonymisation, when pseudonymised data remains personal data, and how pseudonymisation supports data protection by design, security of processing, purpose limitation and international transfers, with technical and organisational measures and examples.

Inline PDF preview is not supported in this browser. Open the PDF instead.

Mapped GDPR Articles

Reproduced from official EDPB publications for reference. Not legal advice.