New EU guidelines  redefine “anonymous” data 

Can you tell who it is, or not?

Twelve years after it first released guidance on anonymisation in 2014, the EU has published updated draft guidelines. For context, the GDPR became enforceable in 2018.

In other words, even before what is regarded as the most comprehensive privacy law came into being, the question of anonymising data—that is, processing data so that subjects are not identified or indefinable—was considered.  

Now, more than a decade later, when many countries and regions have modelled legislation off the GDPR, the conversation has returned to what is the appropriate bar for anonymity, as defined by the GDPR.

Importantly, if organisations or processing activities pass this bar, then they may fall outside the scope of the GDPR rules. This can mean many things, including the fact that anonymous data, as opposed to personal data, can be shared, processed and used with fewer constraints.  

These guidelines are not yet set in stone and are still out for public consultation. The final version, will, however, likely become part of compliance requirements for businesses across the world in the next couple of years. 

It’s worth understanding, therefore, just how they define anonymity, the criteria for anonymity and the anonymisation assessment techniques presented.

Anonymity is relative, not absolute 

According to the guidelines published earlier this month, if a natural person is not identified or identifiable in the data, then it is anonymous. At least for one entity. The same data set could be anonymous for say, a third party, but not for a data controller. The data could be anonymised for the third party who may not need the full data set to carry out required processing. In this case, the data would be personal for one organisation, but anonymous for another.  

At the same time, the question of identifiability is also treated as one of likelihood rather than certainty. Rather than asking whether identification is possible in an absolute sense, the question is how likely it is that some entity will identify the individual, and that likelihood does not need to be zero, but it needs to be insignificant for the data to be anonymous. 

Criteria for anonymity: No record isolation, no linkage, no inference 

If the data contains no unique combination of attributes that can identify a person, then criteria one—no record isolation—is met. An abbreviated example from the guidelines: In CCTV footage, many people are wearing black suits, and many are walking dogs. “The person in a black suit” is not a unique descriptor that allows for identification of a particular individual. Neither does “the person with a dog.” But there is only one person who is both wearing a black suit and walking a dog. So, a descriptor stating that combination of attributes is unique and allows the person to be identified.  

‘No linkage’ is met if data cannot be linked to data about the same individual in another data set. And ‘no inference’ is met if no meaningful or specific inference can be drawn about an individual from the given data rather than from general knowledge.  

Pass all three and the data is deemed anonymous. Fail one, and further assessment is needed before concluding either way.  

How to know if anonymisation worked 

Using the three criteria above as a base, organisations can either employ the contextual or simplified approach to know if anonymisation has worked. One approach asks who could identify the individual, and in what context and the other asks if anyone could. A combination of these approaches may prove most effective.  

An example from the guidelines: A controller wishes to anonymise a dataset containing a combination of demographic and medical information. They begin with the simplified analysis and discover that the demographic data alone could not allow for re-identification of the individuals.

However, they also discover that re-identification could be possible if the demographic information is combined with certain additional medical information. Under the simplified analysis, they would therefore conclude that the information is not anonymous.

The controller decides to extend the analysis and pivots to a contextual analysis. They therefore begin identifying the applicable perspectives and testing if the respective entities could access that additional medical information with means reasonably likely to be used.

One important thing to note 

Anonymisation itself is GDPR-regulated, and it is not permanent.

The process of anonymising data has requirements such as legal basis. This legal basis could, however, carry over from the initial purpose of processing the data. Additionally, because re-identification can become possible in the future due to occurrences such as security incidents, periodic assessment is necessary to ensure the data is still anonymous.

Consultations open until October 

Over the next three months, businesses, individuals, law firms, etc., can submit comments on these guidelines on the website of European Data Protection Board. The feedback will inform a revision process after which a final version will be accepted, effected and become standard. There is unlikely, however, to be significant changes between the draft and final versions. 

Now is a good time for businesses to become familiar with future of anonymity standards and to assess whether their practices hold up or need beefing up.  

Bloomfield can help with assessing and developing anonymisation policies suitable for your organisation and industry. Schedule a consultation to get started.