Perkins Coie·PRIVACY / DATA SECURITY

EDPB Issues Draft Guidance on GDPR Data Anonymisation

The European Data Protection Board has released awaited draft guidelines on data anonymisation, introducing a new perspective-based test that could reshape how organizations share and use data under the GDPR.

The European Data Protection Board (EDPB) has published long-awaited draft guidelines on data anonymisation under the GDPR, aiming to create a clearer standard following a key 2025 Court of Justice of the EU ruling. The guidance establishes a new framework centered on whether an individual is identifiable by any "means reasonably likely to be used" from the perspective of each "relevant entity." This approach allows for a dataset to be considered anonymous for a recipient even if the disclosing controller retains the ability to re-identify individuals, potentially easing data sharing for analytics and research. However, the guidelines broaden the risk assessment to include adversarial actors like cybercriminals and clarify that contractual "no re-identification" clauses are not a substitute for robust technical measures. The EDPB also confirms that anonymisation itself is a form of data processing that requires a lawful basis. The consultation on these significant draft rules is open until October 2026, and firms should begin evaluating their existing data strategies against this new framework while awaiting the final version.

edpbgdpranonymisationdata-privacycjeuicoeuuk
Read the original firm alert → Saturday, September 12, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.