Perkins Coie·PRIVACY / DATA SECURITY

EDPB Releases Draft GDPR Anonymisation Guidelines

The European Data Protection Board has published much-anticipated draft guidelines on data anonymisation, introducing a new framework for assessing when data falls outside the GDPR's scope.

The European Data Protection Board (EDPB) has released significant draft guidelines clarifying the standard for data anonymisation under the GDPR, a key threshold for determining when data processing falls outside the regulation's scope. The guidance, which updates a 2014 opinion, is open for public consultation until October 2026. For sophisticated counsel, the draft offers a more flexible, context-based approach. It clarifies that a dataset may be considered anonymous for a recipient who lacks the means to re-identify individuals, even if the disclosing controller retains that ability. This could facilitate data sharing for research and analytics. However, the guidelines also raise the compliance bar, requiring an assessment of re-identification risk from the perspective of potential adversaries, such as cybercriminals, and asserting that contractual prohibitions against re-identification are insufficient on their own. Organizations should review their data-sharing agreements and anonymisation techniques against the EDPB’s proposed new framework, particularly the criteria of record isolation, linkage, and inference, and monitor feedback during the consultation period as technology like AI continues to make re-identification easier.

gdpredpbdata-anonymisationdata-privacyeu
Read the original firm alert → Friday, September 11, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.