Practical guide · GDPR

Anonymisation vs pseudonymisation: GDPR differences

7 min readBy Ana Gloria Gómez Ruiz
Quick answer

How anonymisation differs from pseudonymisation under the GDPR and the Spanish DPA, why only one takes you outside the regulation, and what it means for documents.

These two techniques are constantly confused because both "hide" a personal data point, but the difference is not a nuance: it decides whether the resulting document is still subject to the GDPR.

How does the Spanish DPA define anonymisation and pseudonymisation?

The Spanish Data Protection Agency (AEPD) draws the line as follows in its official guide (AEPD, "Anonimización y seudonimización"):

  • Anonymisation: the resulting dataset bears no relation to an identified or identifiable natural person. There is no way back.
  • Pseudonymisation: the dataset cannot be attributed to a data subject without additional information, and that additional information must be kept separate and protected with technical and organisational measures. There is a way back, if you hold the key.

In practice: if you replace "María López García" with the code "SUJ-00482" and store somewhere (even encrypted) the table linking that code to the real name, that is pseudonymisation. If you remove the data so that no reasonable combination of information can reconstruct who that person was, that is anonymisation. We expand on this in what document anonymisation is.

Why does the difference matter so much for a document?

The GDPR says it explicitly in recital 26: data protection principles do not apply to information anonymised in such a way that the person is no longer identifiable. In other words:

PseudonymisationAnonymisation
Still personal data?YesNo
Does the GDPR still apply?Yes, in fullNo
Reversible?Yes, with the right keyNo, if done properly
Does it reduce risk?Yes, as a security measureYes, it removes the risk at source
Does it remove information and retention duties?NoYes

A pseudonymised file still needs a legal basis, is still subject to retention periods and can still be the object of an access, rectification or erasure request. A genuinely anonymised document falls outside that perimeter.

What is the risk of assuming something is anonymised when it is not?

This is where most organisations get it wrong: they treat as anonymised a document that is in fact only pseudonymised or, worse, only visually covered. Consequences range from an undetected breach to a fine, as covered with real cases in our article on AEPD fines for publishing documents with personal data.

The AEPD itself warns that assessing whether something is truly anonymised requires considering the cost, time and technological means needed to re-identify someone, including those that may exist in the future. A common technical criterion for measuring that risk is k-anonymity, on which the AEPD has published a technical note.

Which one do I need?

  • Publishing or sharing outside your organisation (transparency portal, press, another entity without a legal basis)? You need real anonymisation.
  • Still need to identify the data subject internally to handle a claim, follow a case or pass an audit? Pseudonymisation may be enough, always as an additional security measure and never as a substitute for other GDPR obligations.
  • Feeding the document into an AI system? The general recommendation is to anonymise, not just pseudonymise: a model can memorise and later reproduce pseudonymised information if it is ever combined with the key.

In the public sector this also intersects with transparency law and the National Security Framework; see document anonymisation in public administration.

Frequently asked questions

Is encrypting data the same as pseudonymising it?

Not exactly. Encryption protects data while it is encrypted, but if the key travels with the data the protection disappears. Pseudonymisation, as defined by the GDPR, requires the re-identification information to be kept separate and specifically protected.

Can I reverse anonymisation if I later need the data?

No, and that is the point: if you can reverse it, it was not anonymisation but pseudonymisation. Before anonymising permanently, confirm you will not need the original data from that specific document again.

Does pseudonymisation exempt me from notifying a breach?

It does not exempt you, but the GDPR recognises it as a measure that can reduce risk for data subjects and therefore influence whether the breach requires notification, based on the risk assessment of each case.

Sources and references

Do you anonymise documents daily?

Stop redacting by hand. Automate it with anonimizia.

Upload your PDFs and get GDPR-compliant anonymised documents in seconds.

Try it free