\n\n

On July 7, 2026, the European Data Protection Board (“EDPB”) adopted draft Guidelines 02/2026 on Anonymisation (“Guidelines”), updating a 2014 Opinion on Anonymization Techniques. While the EDPB maintains a cautious approach to anonymization, the new Guidelines appear to offer a more structured and practical framework for assessing whether information can be considered anonymous. The Guidelines are open for public consultation until October 30, 2026.

I. Legal Analysis of Anonymity

The Guidelines anchor anonymization in the GDPR definition of personal data: information is anonymous if it either (i) does not “relate” to an individual or (ii) does not concern an identified or identifiable individual. Importantly, and triggered by the recent SRB case (see our blog here), the EDPB stresses that the answer to these questions may vary depending on the entity assessing the data. This forms the basis for one of the Guidelines’ central themes: anonymization is often a matter of perspective.

In this context, the EDPB clarifies that, when assessing anonymity, organizations should first identify relevant entities, before considering the likelihood of each of these entities re-identifying individuals from a given dataset.

Identifying relevant entities. This will require organizations to take into account several factors, including access, control, sharing arrangements, party relationships, and whether one party acts on another’s behalf. On this point, the Guidelines consider that where an entity processes a dataset on behalf of another entity, the anonymity assessment should be conducted from the perspective of the controlling entity. As a result, processors cannot escape their GDPR obligations – if the data are personal data for the controller, they are personal data for the processor. This is striking because the SRB case related precisely to the sharing of data with a processor, although the court could not take this aspect into account in its assessment.  The EDPB also reiterates that the act of anonymizing requires a legal basis in the GDPR (and an Art. 9 derogation in case of special categories of data) if the anonymization serves a different purpose than the original one.

Considering the likelihood of re-identification. Consistent with Recital 26 GDPR, the EDPB reiterates that organizations should assess whether a relevant entity could identify individuals through means “reasonably likely to be used.” Means that are impossible, disproportionate in time, cost or effort, or legally prohibited may fall outside this test. However, the Guidelines caution that such limits may offer little protection in certain circumstances, e.g., where actors are unlikely to comply with the law, such as cybercriminals, and that contractual restrictions should not be treated as equivalent to legal prohibitions. The EDPB also suggests that re-identification may remain reasonably likely where specialist third-party services are readily available, or where an entity has a legal avenue to access additional data.

II. Technical Analysis of Anonymity

A. Contextual vs Simplified Approach

The EDPB describes two methodologies for assessing anonymization. A contextual approach considers the means available to relevant entities and the likelihood they will use them to reidentify individuals, while a “simplified approach” applies a more generalized assessment that considers the ability of anyone to re-identify individuals. When assessing anonymity, organizations may use either approach, or combine them, depending on the circumstances. However, the Guidelines caution that contextual assessments may falsely conclude that a dataset is anonymous, reflecting continued regulatory caution toward findings of anonymity.  The simplified approach, on the other hand, will result in a higher standard, but may be overly restrictive.

B. The Three Criteria

At the technical level, the Guidelines retain and further develop three familiar criteria for evaluating the effectiveness of anonymization and re-identification techniques:

  1. Record Isolation, where no unique combination of attributes relates to a single individual;
  2. Linkage, where a record cannot be linked to another record from a different dataset that relates, with certainty or high likelihood, to the same individual;
  3. Inference, where the data does not support specific and meaningful conclusions about an individual.

If all three criteria are met, the dataset may be considered anonymous. If not, additional analysis is required – including potentially under the contextual approach.

*                         *                         *

Covington’s Privacy and Cybersecurity team will continue to monitor developments related to data anonymization. If you have any questions about the issues raised in this blog, or would like to participate in the Commission’s consultation phase, please do not hesitate to contact us.