What Happened
On July 7, 2026, the European Data Protection Board published draft Guidelines 02/2026 on Anonymisation, changing how organizations must determine if data falls outside GDPR scope. The guidelines introduce a "relative" approach to identifiability, supported by the Court of Justice of the European Union in EDPS v SRB, replacing the Article 29 Working Party's Opinion 05/2014 on Anonymisation Techniques.
The key takeaway: the same dataset can be personal data for one entity and anonymous for another. Anonymity now depends on who holds the data and what they can realistically do with it.
Timeline
- Pre-2026: Organizations relied on the Article 29 Working Party's Opinion 05/2014, which was unclear on whether anonymity should be assessed in absolute or relative terms.
- EDPS v SRB case: CJEU confirms the relative approach, establishing that pseudonymous data isn't automatically personal data in all contexts.
- July 7, 2026: EDPB releases draft Guidelines 02/2026.
- October 30, 2026: Public consultation period closes.
Which Controls Failed or Were Missing
The failure isn't technical; it's structural. Organizations operating under the old framework likely relied on three flawed assumptions:
Missing Control #1: Entity-Specific Assessment
Most anonymization processes treated data as universally "anonymous" or "not anonymous." The draft Guidelines require you to identify each relevant entity that might access the data and assess identifiability from their specific perspective. If you share research datasets with academic partners, commercial vendors, and internal teams, you need separate assessments for each, considering their capabilities, resources, and access to auxiliary information.
Where a processor handles data on behalf of a controller, the controller's perspective governs. The data remains personal for the processor, regardless of whether the processor could independently identify anyone. If your anonymization documentation doesn't specify which entity's perspective you're assessing from, it fails the new standard.
Missing Control #2: Documented "Means Reasonably Likely to Be Used" Analysis
The draft Guidelines interpret "means" broadly: reading a document, running AI inference, combining datasets through a chain of third parties. Organizations that documented only direct re-identification techniques missed probabilistic linkage, inference-based linkage, and multi-hop dataset joins.
The guidelines identify five factors:
- Properties of the data itself
- Context of release and access restrictions
- Availability and cost of auxiliary information
- Technical and financial resources of potential adversaries
- Legal prohibitions on re-identification
If your anonymization process documented only factor #1, you're missing most of the required analysis. Worse, if you relied on contractual restrictions as your primary control, the draft Guidelines state that contracts don't amount to a legal prohibition and should complement, not replace, technical measures.
Missing Control #3: Record-Level Granularity
Organizations treating entire datasets as uniformly anonymous or personal failed to recognize that mixed datasets are common. The draft Guidelines require record-level assessment. If 80% of your records meet all three anonymity criteria (no record isolation, no linkage, no inference) but 20% don't, you can't treat the entire dataset as anonymous. You need technical and organizational measures capable of handling the two categories differently.
Missing Control #4: Breach-Triggered Reassessment Protocol
The draft Guidelines confirm that a security incident may lead to a reassessment of anonymity, which in turn triggers potential personal data breach notification obligations under GDPR. If your incident response plan doesn't include a step to reassess whether previously-anonymous data might now be identifiable due to the breach, you're missing a mandatory control.
What the Relevant Standard Requires
Article 4(1) GDPR: Personal Data Definition
The draft Guidelines operationalize the personal data definition through a two-question test:
- Does the data relate to a natural person?
- If yes, is that natural person identified or identifiable?
Data is anonymous only if it fails question #1 or passes question #1 but fails question #2 from every relevant entity's perspective.
The Three Criteria for Anonymity
Once you've chosen your assessment approach (contextual or simplified), you must test against three criteria:
- No Record Isolation: Can any individual record be singled out from others with sufficient precision to treat that individual differently?
- No Linkage: Can records be joined to external datasets or available information in a way that would allow identification (including probabilistic and inference-based linkage)?
- No Inference: Can information about a specific individual be deduced with sufficient accuracy to identify or single them out?
Failing any one criterion doesn't automatically render data personal, but it triggers the need for further analysis of whether the identified weakness enables an individual to be singled out or treated differently with sufficient accuracy and reliability.
Article 6 and Article 9 GDPR: Legal Basis for Anonymization Processing
The draft Guidelines confirm that anonymization itself is processing under GDPR. You need a valid legal basis under Article 6 GDPR (and an Article 9(2) condition for special category data) before you start. If you've been anonymizing sensitive health data without documenting your Article 9(2) condition, you've been processing special category data unlawfully.
Lessons and Action Items for Your Team
Action #1: Conduct Entity-Specific Assessments
List every entity that will access the data. For each, document:
- Their technical capabilities (can they run advanced inference models?)
- Their financial resources (can they purchase commercial re-identification tools?)
- Their access to auxiliary information (do they already hold datasets that could be linked?)
- Any legal prohibitions that constitute genuine practical barriers (not just contractual restrictions)
Start with the simplified approach (treating all entities as equally capable) and pivot to the contextual approach only where you can document why a specific technique isn't reasonably likely to be used by a specific entity.
Action #2: Test All Three Criteria at Record Level
Don't assess datasets as monolithic blocks. For each record, test:
- Can this record be isolated?
- Can this record be linked to external data?
- Can attributes of this individual be inferred?
If 15% of records fail the linkage criterion, separate them. The 85% may be anonymous; the 15% remain personal data and must be handled under full GDPR obligations.
Action #3: Replace Contractual Controls with Technical Measures
If your anonymization strategy relies on data-sharing agreements that prohibit re-identification, you're non-compliant. Contractual restrictions don't amount to legal prohibitions under the draft Guidelines. Add technical controls: noise injection, generalization, suppression, or cryptographic techniques that make re-identification computationally infeasible.
Action #4: Document Your Anonymization Processing
Create a record that includes:
- The Article 6 legal basis (and Article 9(2) condition if applicable)
- The anonymization technique applied
- The entity-specific assessment for each recipient
- The analysis of means reasonably likely to be used
- The three-criteria test results at record level
- The reassessment schedule
Calibrate reassessment frequency based on data sensitivity, how it's used or disclosed, and the pace of relevant technological development. If you're sharing genomic data with AI research teams, reassess quarterly. If you're publishing aggregate census statistics, annual review may suffice.
Action #5: Update Your Breach Response Plan
Add a step: "If the breach involved data previously assessed as anonymous, reassess whether the breach changed the identifiability analysis." If auxiliary information was exposed that enables linkage, or if the breach revealed a technical weakness that makes record isolation possible, the data may now be personal. That triggers Article 33 and Article 34 notification obligations.
Action #6: Engage with the Consultation
The public consultation closes October 30, 2026. If your organization has specific concerns about how the three criteria apply to your use case, or if you can document why a particular factor should carry more weight, submit feedback. The EDPB has refined specific positions in response to stakeholder input in past consultations.
The draft Guidelines don't create new obligations. They clarify existing ones. If your anonymization process can't survive this clarity, it was never compliant.



