Skip to main content
Praxikon

Guideline

Guidelines 01/2025 on Pseudonymisation

Date
Status
adopted
Body
European Data Protection Board (EDPB)
Reference
Guidelines 01/2025, versie voor publieke consultatie

What it is about

The EDPB explains what pseudonymisation is, that pseudonymised data remain personal data and how pseudonymisation helps with security, data protection by design and the balancing test for legitimate interest. The annex contains ten worked examples. Adopted on 16 January 2025 as a version for consultation (consultation from 17 January to 14 March 2025). On 15 September 2026 the EDPB site shows no final version.

What this means in practice

You must keep the key or additional information separately and securely and record who can access it. Pseudonymisation is a measure you can rely on in a DPIA and a balancing test, but the GDPR continues to apply in full. In processing agreements you can agree that the processor only receives pseudonymised data.

The GDPR articles concerned

Source: EDPB public consultation pagechecked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

The counterpart in the other law

Case law8 of 13

Guidelines8 of 13

Enforcement and fines8 of 10

Legislation in motion6 of 10