Blog

Anonymised data is no longer an end state after EDPB Guidelines 02/2026

The EDPB Guidelines 02/2026 make re-identifiability after anonymisation a testable, ongoing standard. What does that mean for high-trust data processing?

· Victor Angelier

On 7 July 2026 the European Data Protection Board adopted the Guidelines 02/2026 on Anonymisation. This retires the old WP29 opinion and introduces a detailed framework in which the risk of re-identifiability after anonymisation is no longer a theoretical side note, but an explicitly testable standard. The core: a dataset is only anonymous if the chance of re-identification is negligible and remains so, and that assessment must be made anew over time.

What exactly changes

The guidelines begin with a two-question test, as the IAPP analysis explains: does the data relate to a natural person, and is that person identifiable? Identifiability is not assessed as an abstract average, but from the perspective of various relevant entities with differing means for re-identification. The same dataset can be anonymous in one context and not in another, depending on which linkable sources and techniques are reasonably available to a party.

After this comes the core: three cumulative criteria that anonymisation must satisfy. No Record Isolation: it must not be possible to isolate a unique record that traces back to one person. No Linkage: records must not be linkable to other datasets so as to identify an individual. No Inference: no new attributes about a person may be derived. Only when all three are satisfied does the data count as anonymous. In practice they together form a re-identifiability stress test: if you can still isolate, link or infer, then the re-identifiability has not disappeared.

Anonymity is a hypothesis, not an end state

The most far-reaching point is the dynamic. The EDPB states explicitly that the chance of re-identification generally increases as inference methods improve and auxiliary data grow. The analysis "Anonymous" Is Not a Permanent Status sums it up aptly: anonymous is not a permanent property. Datasets treated as anonymous today can become personal data again tomorrow, as soon as the re-identification chance is no longer insignificant. Controllers must therefore recalibrate their risk assessment whenever the set of relevant entities, attack means or available auxiliary sets changes.

That anonymisation is not a one-off technical act is also evident from research. An academic study on re-identification risk scores in publicly available health datasets shows how you can express the risk quantitatively on a scale of 0 to 1, and tie that to concrete decisions about access regimes. Re-identification proceeds via direct and indirect identifiers; there is no universal notion of utility, so organisations must pragmatically weigh which indirect identifiers are really needed and which mainly raise the re-identifiability risk. Reducing residual risk is done through perturbation, recoding and suppression.

From standard to practice in high-trust domains

How this becomes operational can be seen in the clinical research world. The practical analysis on the EDPB guidelines and clinical trial data describes a concrete method: first an entity mapping of all direct and indirect identifiers, then an explicit Re-identification Risk Assessment along the three criteria, followed by choosing and documenting measures, and finally recorded recalibration moments. Sponsors and CROs must document per dataset which scenarios have been analysed. In the event of significant new risks, a dataset must be treated as personal data again, with all the consequences for DPIAs and data breach notification obligations.

The common thread through all these sources: professionals working with sensitive information must treat anonymisation as a verifiable risk hypothesis. Recording per dataset which re-identifiability routes are still open — linkage with external sources, new inference methods, expansion of demographic auxiliary data — which technical and organisational measures actually close those routes, and how often the assessment is revised.

What this means for AI workflows

For those deploying AI on data classified as anonymous, the question shifts towards visibility and documentation. Not just: is this data anonymised?, but: what analysis underlies it, which measures close which routes, and when did we decide the risk had risen again?

In that context IamVera.ai can be positioned as a verification layer, not as a party that anonymises itself. Vera can make visible, per AI workflow, which verification steps, corrections and sources have been carried out, so that these are available for inspection. That supports review and oversight; it is no guarantee of correctness and it does not remove the possibility of hallucinations. The Semantic Privacy Shield is designed to replace sensitive document values with synthetic, session-only equivalents on EU infrastructure before AI processing; the AI chain analyses the synthetic version and the original values can be restored locally. The architecture is designed so that only anonymised content is sent onward, and the workflow is fail-closed: if the privacy check fails, the document is not sent onward.

That is emphatically not a promise of flawless anonymisation or completed GDPR compliance. It is a way to make visible, per workflow, which datasets count as anonymous, which considerations preceded that, and when a dataset — given the dynamics of re-identifiability — must be treated as personal data again in governance, audits and incident response. The professional final judgement — including the legal qualification — remains with the user and their DPO. The EDPB Guidelines 02/2026 above all make clear that this assessment is never finished: re-identifiability must be tested continually.

← All articles