SummaryFinal

EDPB 01/2025 (Summary)

Pseudonymisation explained (EDPB summary of Guidelines 01/2025)

This document condenses the full document.

What it covers

This is a short quick-reference summary explaining that pseudonymised data remains personal data, and outlining how pseudonymisation can help organisations meet GDPR obligations such as security, data minimisation, and data protection by design and by default; the full Guidelines 01/2025 on Pseudonymisation carry the detailed analysis.

Why it matters

It gives a fast, plain-language entry point for understanding when and why pseudonymisation is useful, pointing readers to the full guidelines for detailed implementation requirements.

Refer to it when

  • needing a quick overview of pseudonymisation before consulting the full guidelines
  • explaining to non-specialists why pseudonymised data is still personal data
  • identifying illustrative examples of pseudonymisation use cases

Questions this document addresses

  • Are pseudonymised data still considered personal data?
  • How does pseudonymisation help organisations process data under the GDPR?
  • Is pseudonymisation always required?

Topics

  • Pseudonymisation
  • Security of processing
  • Data protection by design

Official EDPB page for this document

Plain-language EDPB summary of what pseudonymisation is, what it does not achieve, and how it supports security, data protection by design and by default.

Inline PDF preview is not supported in this browser. Open the PDF instead.

Mapped GDPR Articles

Reproduced from official EDPB publications for reference. Not legal advice.