Practical guide · GDPR

Beyond the GDPR: ePrivacy, CCPA and what anonymisation means in each framework

8 min readBy Ana Gloria Gómez Ruiz
Quick answer

How the GDPR, the ePrivacy Directive and California CCPA/CPRA treat anonymisation, and what that means for organisations operating across borders.

Organisations that publish documents, serve clients in several countries or share data with non-EU providers operate under more than one framework at once. Anonymisation is not defined identically in all of them.

GDPR (European Union)

Recital 26 places anonymous information outside the scope of the Regulation: data that does not relate to an identified or identifiable person, considering all means reasonably likely to be used for re-identification. Pseudonymised data stays in scope. In Spain the LOPDGDD adds rules on how to identify people in official publications and notices.

ePrivacy Directive

It governs electronic communications and access to information stored on the user device: cookies, identifiers, traffic and location data. It requires prior consent for storing or accessing information on the device and requires traffic data to be erased or anonymised once no longer needed. It mainly affects web analytics and communication logs, not the contents of a PDF case file.

CCPA / CPRA (California)

Californian law uses deidentified information: information that cannot reasonably be linked to a consumer, provided the business applies technical safeguards, contractually prohibits re-identification and publicly commits not to attempt it. Unlike the GDPR, it demands explicit organisational commitments, not only a technical outcome.

Practical implications

  • Document the method: which categories are removed, with which technique and which review.
  • Assess re-identification risk from indirect data: dates, towns, roles, rare diagnoses.
  • Keep anonymisation and pseudonymisation separate, storing additional information under restricted access.
  • Control where processing happens: encryption in transit and at rest, auditable logs, no training of third-party models.

Working with the Spanish public sector

The National Security Framework (Royal Decree 311/2022) also applies and must be evidenced by the provider. oGov holds ENS Medium and the deployment servers ENS High, with a data governance certificate.

Do you anonymise documents daily?

Stop redacting by hand. Automate it with anonimizia.

Upload your PDFs and get GDPR-compliant anonymised documents in seconds.

Try it free