In July, the European Data Protection Board (EDPB) published its draft Guidelines on Anonymisation for public consultation. A consistent position at European level has long been awaited, as the last guidelines on this subject date back to 2014.
Relative anonymity
The central concept of the guidelines is that anonymity is relative. The same dataset may be personal data in the hands of one party and anonymous in the hands of another. Whether a person is identifiable is assessed from the perspective of each relevant party. These may be data controllers or, for example, recipients such as data processors. In each scenario, account is taken of the means reasonably likely to be used. If the likelihood of re-identification is ‘insignificant in practice’, the data may be regarded as anonymous.
Special case: data processors
With these guidelines, the EDPB introduces a controversial point into the debate. Data processors are not to be assessed in isolation like other parties, but rather from the perspective of the data controller. Presumably, the EDPB wishes to prevent data controllers from circumventing their GDPR obligations by outsourcing data processing to a data processor. It also points out that contractual prohibitions on re-identification cannot replace technical safeguards and that a general presumption of legal compliance is rebuttable if there are specific risks of unlawful re-identification.
Assessment approaches
The guidance offers two assessment approaches for evaluating data processing.
- Contextual approach: Identifies individual actors and assesses their actual re-identification capabilities.
- Simplified approach: Disregards specific differences between actors and applies a uniform, conservative standard. This approach is ideal when the capabilities of the recipients cannot be reliably determined.
Data controllers are not required to choose one approach exclusively. A hybrid approach, in which a simplified analysis is first carried out to assess theoretical re-identification, followed by a context-based analysis if a more precise assessment is required, is expressly encouraged.
Three criteria test
In principle, three criteria must be assessed for both approaches. Data can only be considered anonymous if all criteria are met.
- No Record Isolation: There is no unique combination of attribute values that relate to a single individual.
- No Linkage: The data does not contain an individual’s record which could be linked to another record which (a) also relates to that same individual, and (b) comes from a different dataset.
- No Inference: No specific and meaningful inference can be drawn from the given dataset to identify an individual.
The EDPB expressly warns that conclusions drawn from AI models and synthetic datasets may breach the ‘No Inference’ criterion. Data is generally only considered anonymous if all three anonymity criteria, including ‘No Inference’, are met simultaneously. This serves as a warning to organisations that mistakenly regard such results as inherently anonymous.
Despite the complexity, it can be noted that the guidelines are practice-oriented, but are stricter than previous practice in several areas. We would be happy to assist you in applying the new assessment approache.