GDPR
EDPB Releases Draft Guidelines on Data Anonymisation Under GDPR
The European Data Protection Board has issued updated draft guidance detailing the technical and legal criteria required to achieve true anonymisation under GDPR in the age of AI and big data.
The European Data Protection Board (EDPB) has adopted draft Guidelines on Anonymisation for public consultation, delivering updated guidance on when personal data can legally be considered anonymous under the General Data Protection Regulation (GDPR). This draft supersedes the longstanding 2014 guidance from the Article 29 Working Party, updating regulatory standards to reflect the realities of artificial intelligence, interconnected data spaces, and recent rulings by the Court of Justice of the European Union (CJEU).
The Evolution of Anonymisation and Re-identification Risks
Achieving true anonymisation under the GDPR means data must be altered in such a way that the data subject can no longer be identified by any means reasonably likely to be used, either by the controller or any third party. If individuals remain singlable, linkable, or inferable—even when combined with external datasets—the data remains pseudonymous and within the scope of GDPR obligations.
The EDPB emphasizes that technological advancements, especially advanced machine learning models and high-dimensional analytics, significantly heighten the probability of re-identification. As a result, basic data masking or removal of direct identifiers (such as names and email addresses) no longer suffices. Instead, controllers must demonstrate rigorous technical assessments demonstrating that the risk of re-identification has been reduced to a negligible threshold across the entire lifecycle of the data.
Recommended Actions for Data and Security Architects
Organizations utilizing machine learning models, analytics platforms, or cross-border data repositories should adapt their data sanitization strategies:
- Re-evaluate Traditional Anonymisation Pipelines: Reassess datasets previously classified as anonymous against modern re-identification techniques, paying special attention to location data and behavioral biometrics.
- Adopt Advanced Privacy-Enhancing Technologies (PETs): Implement mathematical and cryptographic techniques such as differential privacy, k-anonymity, or homomorphic transformation where large datasets are leveraged for AI model training.
- Establish Continuous Re-identification Risk Auditing: Conduct periodic vulnerability stress tests to determine if novel external datasets could facilitate the re-identification of sanitized records.
แหล่งที่มา: Privacy Matters (DLA Piper) เผยแพร่ครั้งแรก: Thu, 13 Aug 2026 13:20:13 +0000 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: Privacy Matters (DLA Piper)
เผยแพร่ครั้งแรก: Thu, 13 Aug 2026 13:20:13 +0000
บทความต้นฉบับ: https://privacymatters.dlapiper.com/2026/08/eu-edpb-publishes-draft-guidelines-on-anonymisation/
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
