Pseudonymization vs. Anonymization: What is the difference?

Last updated:
06.02.2025
Pseudonymization and anonymization can simplify data protection compliance for companies. Yet, these two terms often still leave many questions unanswered. We’re here to clear things up.
Pseudonymization vs. Anonymization: What is the difference?
Key Takeaways
  • Pseudonymization: Data can only be linked to individuals with additional information (Art. 4 GDPR).
  • Anonymization: Re-identification is impossible; data is no longer personal (GDPR).
  • Pseudonymized data: Identification is possible by combining data; GDPR regulations continue to apply.
  • Anonymized data: No longer subject to data protection regulations, as there is no longer any link to individuals.
  • Both methods: Reduce risks for data subjects, but the value of anonymization is often underestimated.

Anyone who pseudonymizes or even anonymizes personal data, reduces the risks for the data subjects and makes it easier to continue working with this data from a data protection perspective. But what is the difference between anonymizing and pseudonymizing data? These two terms must be clearly distinguished from one another in any case.

What is pseudonymization?

Pseudonymization means, according to Art. 4 of the GDPR, that the processing of personal data is designed in such a way that a link to a natural person is only possible with the use of additional information . The data is therefore pseudonymized by replacing names and other identifying features with, for example, ID numbers or codes. This additional information must be stored separately and must be protected against unauthorized access through technical and organizational measures (TOM). It is important to note here that identifying a natural person by combining pseudonymized data with their actual identity is still possible. The link to the person therefore remains, which is why some GDPR regulations continue to apply to pseudonymized data. For example, if the statutory retention period expires and there are no other reasons for retention, pseudonymized data must also be deleted.

Pseudonymization of personal data can be carried out in three different ways

  1. Assignment of the pseudonym by the data subject themselves, for example by using a freely chosen username
  2. Assignment of the pseudonym by third parties, such as a certification body
  3. assignment of the pseudonym by the controller, who knows the identity of the data subject, for example by using customer numbers.

What is the definition of anonymized data?

Unlike the old version of the BDSG, anonymization of data under the GDPR means that there is no possibility of re-identifying the data subject. This means that all personal data is removed or altered in such a way that re-identification is not possible. A restriction such as the one in Section 3 (6) of the old BDSG—"[...] or only with a disproportionately large amount of time, cost, and effort [...]"—is not included in the GDPR. Therefore, if there is any possibility of linking the data to an identified or identifiable natural person, the data is no longer anonymized. For this reason, all information that would make this possible must be deleted or replaced with, for example, numbers or similar. Unlike pseudonymized data, anonymized data is no longer considered personal data and does not fall under the scope of the GDPR. 

Examples of anonymized data include statistical surveys, such as the average income in a region, and aggregated health data, such as the percentage of the population with a specific disease. Survey results summarized in percentages and generalized location data (postal codes or districts) also count as such.

By the way: Re-identification also occurs if the data subject's legal name cannot be determined, but there is an individualization of a person and statements about their personal circumstances based on the data.

What are the benefits of pseudonymization and anonymization?

First, it is important to realize that even for personal data that is to be pseudonymized or anonymized, a legal basis for processing must exist; in other words, there must be a statutory legal basis or the consent of the data subject. However, if personal data has been successfully anonymized—meaning re-identification is no longer possible under any circumstances—the controller no longer needs to comply with data protection regulations in this case, as the information is no longer considered personal data.

But even correct pseudonymization supports the controller or processor in fulfilling their data protection obligations according to Recital 28 of the GDPR, as it actively reduces risks for data subjects. Furthermore, the technical and organizational protection requirements for pseudonymized data are lower. Pseudonymization does not replace other data protection measures; rather, it should be understood as a supplementary measure.

Despite these advantages, pseudonymization and anonymization of data are not particularly popular, as many still believe that pseudonymous or anonymous data is worthless to companies. This is a misconception, however, because many analyses and statistics can actually be useful without any specific reference to individuals, which is why data protection officers should also promote this practice more actively.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in