Ch.10 Protecting Personal Data and Privacy Trap 204 words

Pseudonymised ≠ anonymous: the GDPR re-ID trap

Pseudonymised data stays personal data because re-identification is possible with extra info; the exam trap is treating it as anonymous.

Audio

Listen to this page (beta)

Subtitles

Pseudonymisation replaces direct identifiers (like names) with codes, but the original data still exists elsewhere. That means someone with the key—or with access to other datasets—can link the code back to a real person. Truly anonymous data, by contrast, cannot be linked to an individual by any means, even with extra information. The GDPR sets a high bar for anonymity: if re-identification is possible in practice, the data is still personal.

In multiple-choice questions, watch for options that claim pseudonymised data is exempt from GDPR. That is almost always wrong. Another trick: if a scenario says 'the key was deleted', ask whether the data could still be re-identified via other sources (e.g. location logs or purchase history). If yes, it is not anonymous. A useful elimination move is to check whether the data controller retains any ability to re-link—if they do, it is pseudonymised, not anonymous.

To test yourself, imagine a dataset where names are replaced with random IDs, but the IDs are stored in a separate file. Ask: 'Can the IDs be matched back to names using that file?' If yes, it is pseudonymised and still personal data. A quick memory anchor: pseudonymised = reversible with a key; anonymous = irreversible by design.

Related flashcard

Why is pseudonymised data still personal data?

Because re-identification may be possible with additional information.

Back to flashcard View all flashcards