Pseudonymisation is the processing of personal data in such a way that it can no longer be attributed to a specific person without additional information that is kept separately.
How pseudonymisation works
Identifying features such as names are replaced by codes, for example a customer number or a cryptographic hash value with a secret key. The mapping table is kept separately and protected by technical and organisational measures.
Legal significance
Pseudonymised data remains personal data, so the GDPR continues to apply. Pseudonymisation does, however, reduce the risk and is mentioned several times in the GDPR as an appropriate safeguard, for example in connection with data protection by design, security of processing and research.
It differs from anonymisation in that the link to the person can be restored with the additional information.
Legal provisions
- Art. 4(5) GDPR
- Definition of pseudonymisation.
- Recital 26 GDPR
- Pseudonymised data as personal data.
- Arts. 25 and 32 GDPR
- Pseudonymisation as a technical safeguard.