Anonymisation After SRB: The EDPB Chooses Context, Not Evasion
The new anonymisation guidelines are better than the privacy maximalists will say, and less usable than the Omnibus needs.
This is the first post in a five-part series on the EDPB’s new anonymisation guidelines and what they mean for the EU’s Digital Omnibus. This opening general summary post sets out the overall argument: the EDPB has accepted a contextual approach to anonymisation, and that is a significant and welcome development, but the resulting framework remains too operationally burdensome to serve as a serious simplification agenda. Subsequent posts go further in depth. The second post will deal with the privacy critique of contextual anonymisation through the lens of EDPB v SRB; the third will examine the effects on research, SMEs and AI development; the fourth will set out what the Omnibus should do next; and the fifth will turn to the larger taxonomy problem, namely the difference between anonymous, anonymised, synthetic and other non-personal data. Additionally, I plan on analysing the different approaches between the 6(11) DMA anonymisation and the EDPB.
Anonymisation should be a disciplined process for transforming personal data into non-personal data, not a rhetorical device for avoiding the GDPR.
The EDPB’s new anonymisation guidelines arrive at an interesting moment. In the same broad regulatory cycle, the Board has also issued guidance on web scraping in the context of generative AI, where it accepts that private entities often use legitimate interest for scraping for AI training, but insists that the balancing test must do real work and that controllers should consider targeted collection, filtering, exclusion of certain sources, synthetic data, anonymisation and pseudonymisation as part of the compliance architecture.1 That matters because the anonymisation guidance is part of a wider attempt by EU data protection law to find a workable middle ground between two unhelpful positions: first, the view that personal data can be repurposed at scale because technological development demands it, and second, the opposite view that risk can only be managed by treating every residual human trace as permanently personal.
The anonymisation guidelines are not a technical manual, and anyone expecting detailed operational recipes will be disappointed. They do not tell the reader when to use k-anonymity, differential privacy, suppression, generalisation, perturbation, secure enclaves or synthetic data generation, and they certainly do not offer a ready-made assurance model for data spaces, research environments or AI development pipelines. The EDPB is explicit that the diversity of datasets, techniques and future re-identification methods means that assessments will often require case-by-case analysis, and that the guidance provides a framework rather than an exhaustive technical settlement.2 That limitation is important, because it tells us something about the broader Omnibus problem. In EU digital law, more guidance is not the same thing as legal certainty, and a sophisticated legal framework is not the same thing as an operationally usable route to compliance.
Still, the document is more important than its technical thinness suggests. Its central move is to accept that anonymity is assessed from a perspective, and that information may be personal data for one entity while being anonymous for another. The EDPB says that under the GDPR, data is anonymous if it does not relate to an identified or identifiable natural person, and that whether this is the case may vary from one entity to another. It follows that anonymity should normally be assessed from the perspective of each relevant entity, typically the party for whom the data is intended to be anonymous.3 That is the crucial point. The guidelines do not treat anonymisation as a metaphysical state in which all possible connections to all possible people have been destroyed for all possible observers forever. They ask a more legal and more useful question: from whose perspective is the person identified or identifiable, by what means, in what context, and with what realistic likelihood?
This is where the guidelines absorb the significance of EDPS v SRB without reducing it to a simplistic slogan. In SRB, the CJEU rejected the idea that a controller could assess the application of a transparency obligation solely from the recipient’s perspective at a later stage, because the obligation to inform data subjects about recipients had to be assessed at the time of collection and from the controller’s perspective.4 That point remains important, but it does not abolish contextuality. The EDPB’s approach is instead more subtle: some GDPR obligations have their own perspective built into them, and some relationships, particularly processor relationships, require the controller’s perspective to follow the processing. Outside those situations, however, the legal test for identifiability remains contextual. This is a sensible reading of SRB, because it prevents the case from becoming either a deregulatory escape hatch or a maximalist veto on anonymisation.
The practical significance of this is considerable. The EDPB asks the basic question, “for whom is the data intended to be anonymous?”, and that question does a lot of work. If the data is anonymised for the controller’s own internal use, the controller’s perspective is central. If the data is anonymised for independent recipients, the recipient’s position matters. If the data is made public, the relevant universe of possible access and auxiliary information becomes much wider. If the data is kept within a controlled research environment, the access conditions, security controls, available auxiliary data and realistic re-identification pathways all matter.5 This is not a loophole. It is an attempt to apply the GDPR’s own identifiability test in a fact-sensitive way.
The contextual approach asks who can realistically identify whom, by what means, and under which access conditions.
The guidelines also make an important move on the meaning of identification. Identification is not reduced to the mere existence of a unique row in a dataset. To identify a natural person means to distinguish them from others within a given context in a way that makes it possible to treat them differently, and the likelihood of that happening need not be zero for data to be anonymous; it must be insignificant in practice.6 This is a major victory for common sense. It means that anonymous row-level data is not conceptually impossible, and that “singling out” must not be treated as a magic word that collapses all analysis into personal data. A record may be unique; the harder question is whether that uniqueness enables the relevant entity to distinguish and treat the individual differently using means reasonably likely to be used.
The technical framework is built around the familiar three criteria from the 2014 Opinion: No Record Isolation, No Linkage and No Inference. The first asks whether a record contains a unique combination of attributes relating to a single individual. The second asks whether a record can be linked to another record about the same individual in another dataset. The third asks whether a specific and meaningful inference can be drawn from the given data. These criteria are useful, but the EDPB is careful not to make them mechanical. If all three are satisfied, the data may be regarded as anonymous; if one or more is violated, that does not necessarily mean the data is personal data, but it does require further analysis of the effect of that violation.7 This distinction is one of the most practically valuable parts of the guidance, because it prevents the three criteria from becoming a crude checklist in which any imperfection automatically returns the dataset to GDPR.
The No Inference criterion deserves particular attention because it is where the guidelines most clearly address the anxiety created by AI, synthetic data and statistical learning. The EDPB says that an inference defeats anonymity only where it is both specific and meaningful. It is specific if the inferred information relates to a single identified or identifiable individual, and meaningful if the processing of that inferred information is liable to affect the person’s rights and interests, relies on the given data, and could not be obtained from general knowledge or from information about the population at large.8 This matters because nearly all useful analytics, and certainly most machine-learning applications, produce inferences of some kind. If every downstream inference about a future person were enough to make the source dataset personal data, then the category of anonymous training or research data would become practically useless.
At first reading, the EDPB avoids that error. Its bank-loan example is helpful: an anonymised historical loan dataset may show that people with a particular combination of attributes are likely to default, and a bank may use that insight in relation to a new applicant who was never part of the original dataset; that inference may be personal data about the new applicant, but it does not automatically make the historical dataset personal data.9 This is a vital distinction for AI policy. It preserves a boundary between generalised learning from a population and leakage about a person represented in the original data. The EDPB is also right to warn that AI models and synthetic data may still permit specific and meaningful inferences about individuals, for example where prompting or querying elicits information about a particular person.10 The point is not that AI outputs are always anonymous, but that the legal analysis must distinguish population-level learning from individual-level disclosure.
The three criteria are warning lights, not a guillotine. Failing one criterion requires analysis; it does not automatically end the inquiry.
The processor point is the sleeper issue in the document, and it may be the most politically important. The EDPB accepts that data can be anonymous for some entities and personal for others, but it does not allow controllers to outsource their way out of the GDPR. Where an entity processes information on behalf of another, whether the data is personal for that entity is assessed by reference to the controlling entity’s perspective. In practical terms, if the controller can identify the individuals and determine the purposes and means of processing, the processor must treat the information as personal data as well, even if the processor itself cannot identify anyone.11 The EDPB describes this as a teleological application of the GDPR, because the processor concept exists precisely to prevent controllers from avoiding data protection obligations by outsourcing processing to third parties.12
This is the strongest answer to the claim that contextual anonymisation is a laundering device. It is not. The guidelines draw a hard boundary between genuinely independent recipients and processors acting on behalf of a controller. A retailer sending customer-record excerpts to an analytics agency remains in controller-processor territory, so the retailer’s identifiability governs both parties. By contrast, a hospital sending excerpts from patient records to an independent research institute may be different where the institute determines its own purposes and means, the data is not returned to the hospital, and the institute is not acting on the hospital’s instructions.13 That distinction will not always be easy to apply, but it is the right distinction. It preserves contextuality without creating an obvious outsourcing loophole.
At the same time, this is also where the guidelines expose a design problem for Europe’s data economy. Much of the infrastructure that Europe says it wants (e.g., data spaces, secure processing environments, clean rooms, AI evaluation services, cloud analytics, trusted research environments, and synthetic data services) is processor-mediated or at least structurally close to it. The EDPB’s position means that the service provider’s technical blindness will often not remove processing from the scope of the GDPR if the provider is acting on behalf of an identifiable controller. That is defensible as a matter of anti-evasion logic, but it also means that privacy-enhancing architecture does not always translate into reduced legal burden. The Omnibus question is therefore not whether to abolish the processor rule, which would be a mistake, but whether the legal system can recognise lower-risk processor configurations through more proportionate obligations, certifications and assurance pathways.
Contextual anonymisation is not outsourcing by another name. In processor relationships, the controller’s perspective follows the data.
The weaknesses of the guidelines are therefore operational, not doctrinal. The first weakness is that the document provides a legally sound framework without sufficient technical assurance architecture. The EDPB tells controllers to consider the state of the art, future developments, the properties of the dataset, the availability of auxiliary information, the relevant entities’ capabilities, and whether re-identification techniques can produce sufficiently precise and reliable results.14 Those are the right questions, but they are not yet a usable pathway for an SME, a hospital trust, a research consortium or a start-up trying to decide whether a dataset can be used outside the GDPR. In that respect, the guidelines are a good legal map but a poor engineering standard.
The second weakness is what might be called adversarial sprawl. The EDPB says the relevant entities may include not only controllers and recipients, but also rogue employees, friends and neighbours, investigative journalists, domestic and foreign intelligence agencies, unethical companies and cybercriminals, depending on the circumstances.15 The caveat matters: not every perspective must be considered in every case. But the list still leans toward a broad, anxiety-inducing threat model. A contextual approach should not collapse into a worst-case approach merely because a motivated adversary could be imagined. If Europe wants contextual anonymisation to become a serious compliance route, it needs clearer rules about when particular adversary classes are relevant and what evidential threshold is required before they shape the assessment.
The third weakness is the treatment of contractual and organisational safeguards. The EDPB is right that a contractual prohibition should not be treated as a prohibition by law, and that contract alone cannot make data anonymous. It is also right that contractual measures must be reliable, verifiable and enforceable, and that they should complement technical measures rather than substitute for them.16 But this is still underdeveloped. Modern data governance depends on layered controls: technical access restrictions, key separation, audited environments, contractual sanctions, logging, monitoring, organisational separation, researcher accreditation and purpose limitations. If these controls are always treated as secondary to a technical anonymisation question, the law will under-recognise precisely the governance environments that enable responsible data use.
The fourth weakness is time. The EDPB says the likelihood of re-identification typically increases as technology advances and additional information becomes available, and that previously anonymous data should again be treated as personal data if the likelihood of identification exceeds the relevant threshold.17 This is intellectually honest, but it leaves hard questions unanswered. How often must reassessment take place? Who is responsible after onward sharing? What is the position where the original data has been deleted? What happens where a later breach elsewhere creates the auxiliary data needed for linkage? The guidelines say that reassessment is good practice wherever possible and appropriate, but they do not give the kind of trigger-based model that organisations can operationalise.
The EDPB provides the analytical flowchart; the Omnibus should provide the assurance infrastructure.
This is where the Digital Omnibus enters the argument. The Commission’s own framing of the Digital Omnibus is a simplification across AI, cybersecurity, and data, and the official line is that this simplification should maintain the level of protection while reducing unnecessary complexity.18 That is also the core of my Innovation Mandate. The point is not to weaken data protection, AI safety or fundamental rights, but to recognise that Europe has built a digital supervisory state whose guidance, enforcement priorities, remedies, timelines and consistency positions increasingly determine the practical conditions for lawful deployment, investment and scale.19 In that setting, anonymisation guidance is not merely interpretive. It is part of the operating system of the European data economy.
The Omnibus should therefore avoid two opposite mistakes. It should not codify a permissive fiction in which “de-identified,” “synthetic” or “anonymous” becomes a label that firms can apply without serious testing. The EDPB is right that controllers should not use descriptions such as anonymous, de-identified, or de-personalised when individuals are still identifiable, and that anonymisation processing itself remains subject to the GDPR where personal data is processed to produce the anonymous output.20 But the Omnibus should also avoid the opposite fiction, in which anonymisation remains a theoretical category available only to large actors with the budget to conduct bespoke legal, statistical, technical and threat-intelligence assessments every time data is reused.
The better settlement is to treat anonymisation as an auditable legal pathway. The public release of granular health, location, or behavioural data should remain subject to a high bar. Controlled-access research environments should be assessed differently from open publication. Internal analytics should be treated differently from external sharing. AI models and synthetic datasets need specific tests for memorisation, regurgitation, membership inference and individual-level leakage. Processor relationships should remain within the scope of the GDPR, where the controller can identify the individuals. Still, processors that are technically unable to identify data subjects should benefit from proportionate operational treatment, provided that technical separation, contractual restrictions, monitoring, and auditing are real.
This would not dilute the rights floor. It would make the rights floor administrable. A controller should be able to point to recognised anonymisation methods, documented re-identification testing, access controls, key separation, deletion or segregation of source data, and independent audit, and receive a rebuttable presumption that the output is anonymous for defined recipients and purposes. A controlled research environment should not be treated as legally equivalent to public release. A synthetic dataset should not be assumed anonymous simply because it is synthetic, but nor should it be treated as personal data merely because it was generated from personal data if meaningful individual-level inference is not reasonably likely. These are not deregulatory moves. They are the institutional machinery needed to make anonymisation real.
The EDPB has therefore done something important, but incomplete. It has accepted contextual anonymisation, resisted the idea that uniqueness alone decides the question, preserved the distinction between population-level learning and individual-level leakage, and drawn an anti-evasion boundary around processor relationships. Those are substantial gains. But it has also produced a framework that remains difficult to apply, heavily contextual, cautious about governance controls and uncertain over time. The document should be welcomed as a doctrinal correction and criticised as an instrument of implementation.
That is the first Omnibus lesson. Europe does not need to choose between privacy and data use here. Proper anonymisation is privacy-enhancing because sometimes the best way to reduce the risks of personal data processing is to stop processing it altogether. But that only works if anonymisation is a credible, testable and institutionally supported route from personal data to non-personal data. The EDPB has opened that route. The Omnibus should make it usable.
Source notes
[1] EDPB Guidelines 03/2026 on web scraping in the context of generative AI state that legitimate interest is often used by private entities for scraping for generative AI training, while requiring the three-part Article 6(1)(f) test and allowing mitigating measures in the balancing exercise; the same executive summary also identifies minimisation measures such as synthetic data, precise collection criteria, filtering, source exclusions, anonymisation and pseudonymisation.
[2] EDPB Guidelines 02/2026 on Anonymisation, pp. 16–17, explaining that technical analysis must consider the state of the art and that, given the range of datasets, techniques and future developments, assessments will often require case-by-case analysis.
[3] EDPB Guidelines 02/2026, executive summary and pp. 5–7, stating that anonymity may vary from one entity to another and should be assessed from the relevant entity’s perspective.
[4] EDPB Guidelines 02/2026, p. 7, discussing EDPS v SRB and explaining why the transparency obligation concerning recipients was assessed from the controller’s perspective at the time of collection.
[5] EDPB Guidelines 02/2026, pp. 6–7 and 26–28, explaining “for whom is the data intended to be anonymous?” and the contextual assessment of relevant entities, access and means reasonably likely to be used.
[6] EDPB Guidelines 02/2026, pp. 9–11, defining identification as distinguishing a person within a given context in a way that permits different treatment, and explaining that the likelihood of identification need not be zero but must be insignificant in reality.
[7] EDPB Guidelines 02/2026, p. 18, setting out No Record Isolation, No Linkage and No Inference, and stating that violation of a criterion does not necessarily mean the information is personal data.
[8] EDPB Guidelines 02/2026, p. 21, defining the No Inference criterion and the requirement that an inference be specific and meaningful.
[9] EDPB Guidelines 02/2026, p. 23, giving the bank-loan example and explaining that a risk inference about a new applicant who was not in the historical dataset does not make the historical dataset fail the No Inference criterion.
[10] EDPB Guidelines 02/2026, pp. 25–26, explaining that AI models and synthetic data may permit specific inferences through querying or prompting, and that special-purpose AI agents may be used for sophisticated re-identification techniques.
[11] EDPB Guidelines 02/2026, pp. 7–8, stating that where an entity processes information on behalf of another, the assessment uses the controlling entity’s perspective.
[12] EDPB Guidelines 02/2026, p. 8, describing the processor position as a teleological application of GDPR to prevent controllers from avoiding protections by outsourcing.
[13] EDPB Guidelines 02/2026, p. 8, Examples 3 and 4, contrasting an e-commerce retailer using an agency as processor with a hospital sending excerpts to an independent research institute.
[14] EDPB Guidelines 02/2026, pp. 25–26, identifying factors relevant to re-identification effectiveness, including aggregation, dimensionality, resolution, diversity, additional information and sufficient confidence to distinguish and treat individuals differently.
[15] EDPB Guidelines 02/2026, pp. 12–13, listing possible relevant entities such as rogue employees, investigative journalists, law enforcement and intelligence agencies, unethical companies and cybercriminals, while noting that not all perspectives must be considered systematically in every case.
[16] EDPB Guidelines 02/2026, pp. 14–15, stating that contractual prohibitions are not prohibitions by law and should complement technical measures, while being reliable, verifiable and enforceable.
[17] EDPB Guidelines 02/2026, p. 15, stating that re-identification risk typically increases over time and recommending periodic reassessment where possible and appropriate.
[18] European Commission, Digital Omnibus press material, describing the proposal as simplifying existing rules on AI, cybersecurity and data.
[19] The Innovation Mandate lecture deck, slides 1–6, frames the core argument as high-rights digital governance with accountable supervisory discretion, not deregulation, and notes that guidance on anonymisation, legitimate interests, AI training data, or sandbox participation may be more operationally decisive than the Regulation’s text.
[20] EDPB Guidelines 02/2026, pp. 15–16, explaining GDPR compliance in the anonymisation process, transparency, documentation and the warning against misleading labels such as “anonymous,” “de-identified” or “de-personalised” where individuals remain identifiable.






