Pseudonymisation: not anonymity, just a mask
Pseudonymisation under GDPR means data cannot be linked to a person without extra info, but it is not anonymous if re-identification remains possible.
Écouter cette page (bêta)
Pseudonymisation replaces identifying details like names with codes or tokens, so the data alone cannot pinpoint an individual. The key contrast is with anonymisation: anonymised data is stripped of all identifiers permanently, making re-identification impossible, whereas pseudonymised data still holds a hidden link. Under GDPR Article 4(5), pseudonymisation reduces risk but does not remove the data from the regulation's scope—it remains personal data because the original identity can be reconstructed with additional information held separately.
To spot the difference in an exam, remember that pseudonymisation is reversible by design, while anonymisation is irreversible. A common trick is to look for phrases like 'without additional information' in the question—if re-identification is possible with extra data, it is pseudonymisation, not anonymity. Another hint: pseudonymisation is often used for research or analytics because it lowers risk, but controllers must still protect the separate key. If a scenario mentions 'hashing' or 'encryption' of personal data, that is typically pseudonymisation, not full anonymisation.
A quick mental test: if the data controller keeps a separate mapping table or key to re-link codes to individuals, it is pseudonymisation. For the exam, link the word 'pseudo' (false) to 'mask'—the data wears a mask but can be unmasked. Contrast this with 'anonymous' (no name), where no mask exists. This distinction often appears in questions about GDPR compliance, so always check whether re-identification is still feasible.
What is pseudonymisation under GDPR?
Processing personal data so it cannot be attributed to a person without additional information.