EDPB Unveils New EU Guidelines on Data Anonymization and AI Privacy

Abeerah Hashim  - Security Expert
Last updated: August 4, 2026
Share
EDPB Unveils New EU Guidelines on Data Anonymization and AI Privacy
  • The EDPB just rolled out a new framework for figuring out when data counts as truly anonymous. This draft ditches the old guidance and brings in a more practical approach, one that matches up with the privacy challenges we see now with AI and the latest EU court decisions.
  • Now, organizations have to look at anonymity based on who actually controls the data.  Whether information is considered personal data may differ between entities depending on whether they can realistically identify someone.
  • The new draft raises the bar for businesses using anonymized data sets. Gone are the days of checking a few boxes and moving on, companies really have to dig into the risks of someone piecing identities back together, especially with AI and all the commercial data services making it so much easier to connect the dots.

The European Data Protection Board just rolled out draft guidelines that could really change the way organizations across Europe figure out if their data is actually anonymous or not.

The watchdog adopted this new draft, referred to as Guidelines 02/2026 on Anonymisation, on July 7. It replaces the previous guidance issued in 2014. This update comes after years of legal battles, court judgements, and the explosive growth of AI tech.

People are also more worried than ever that so-called anonymous data isn’t really anonymous; it can often lead right back to actual individuals. Right now, the public can weigh in on the new draft; the consultation is open until October 30, 2026.

For all businesses that use anonymous data in their research, analysis, AI technology development, or healthcare or public services, this guidance may have a great impact on their privacy risk assessment.

One of the biggest changes is the EDPB’s view that anonymity depends on who is looking at the data. The same dataset might be personal for one organisation and anonymous for another. This depends on who is looking at it and what tools they have.

The EDPB builds on the recent SRB (Single Resolution Board) court case. That judgment clarified that whether data qualifies as personal data can depend on the recipient’s ability to identify someone, rather than a universal standard. The new guidance builds directly on that decision.

Instead of assuming that information is either anonymous or not, the guidelines say organizations should first identify every relevant party that could access the dataset. They must then determine whether each of those parties could realistically identify an individual using information available to them.

A key point concerns data processors. The guidelines say processors must assess data from their controller’s viewpoint. If the data is personal for the controller, it’s personal for the processor too. This prevents controllers from avoiding GDPR duties by outsourcing work.

The EDPB also clarifies that companies need a legal basis to anonymise data. This applies under Article 6 of the GDPR. Special rules apply for sensitive data under Article 9(2).

Considerations for the likelihood of re-identification

The guidelines clarify the test for means “reasonably likely to be used” for re-identification. Companies must consider objective factors. These include the data’s properties, available technology, and costs.

The guidelines warn about legal barriers to identification. A legal prohibition may not always prevent re-identification. Cybercriminals might ignore the law. Contractual bans on re-identification are not as strong as legal prohibitions.

Companies cannot assume recipients won’t try to re-identify people. The guidelines say motivation is hard to prove and can change. The EDPB also stresses that specialists and third-party services can make re-identification easier.

Two ways to assess anonymity

The EDPB outlines two assessment methods. The contextual approach looks at what specific entities can do. It considers their capabilities and resources.

The simplified approach is more general. It assumes anyone could try to re-identify individuals. This approach leads to a higher standard. It may be too strict in some cases.

Companies can combine both methods. They might start with the simplified test. If it flags a risk, they can move to a more detailed contextual analysis.

The three criteria test

At the heart of the guidelines are three technical criteria. All three must be met for data to be considered anonymous.

The first is ‘no record isolation.’ This means no unique combination of attributes singles out one person. Take, for example, a dataset might contain enough information to identify an employee. The more specific the info, the easier it is to single someone out.

The second is ‘linkage’. This means that you can’t tie these records to other information about the same person. If you can, you’ve lost anonymity.  A company might remove obvious identifiers from customer data. But if a public database contains matching information, the data is not truly anonymous.

Thirdly, ‘no inference.’ This means the data doesn’t allow specific conclusions about an individual. Modern AI systems can infer sensitive information. The guidelines warn about membership inference attacks that can reveal if someone’s data was used in training.

Anonymity is not forever

The rules make it clear: anonymity doesn’t last forever. Tech keeps moving, and what’s anonymous today could become identifiable with tomorrow’s breakthroughs, especially as AI and machine learning get smarter.

So companies need to check their data practices often, not just once and done. What was anonymous two years ago may no longer be safe today. The EDPB recommends revisiting assessments periodically.

The new guidelines provide a more practical framework than before. They give companies clear tools to assess anonymity. But they also demand careful documentation and regular review.

These guidelines are part of a wider push by EU regulators to strengthen data protection across the board, with platforms like TikTok now under scrutiny over their privacy and data processing practices

Share this article

About the Author

Abeerah Hashim

Abeerah Hashim

Security Expert

Abeerah is a passionate technology blogger and cybersecurity enthusiast. She yearns to know everything about the latest technology developments. Specifically, she’s crazy about the three C’s; computing, cybersecurity, and communication. When she is not writing, she’s reading about the tech world.

More from Abeerah Hashim

Comments

No comments.