Anonymised data is no longer an end state after EDPB Guidelines 02/2026
The EDPB Guidelines 02/2026 make re-identifiability after anonymisation a testable, ongoing standard. What does that mean for high-trust data processing?
You must now treat anonymisation as an ongoing, testable standard rather than a one-time technical fix. Every dataset you classify as anonymous requires documented re-identifiability assessment, periodic recalibration, and a clear record of which isolation, linkage and inference routes remain open.
The prompt is an analysis of 24 August 2026 of the re-identifiability standard now embedded in anonymisation guidance, which argues that anonymisation is no longer a permanent property but a dynamic risk hypothesis that must be reassessed as attack methods and auxiliary data evolve. The European Data Protection Board adopted Guidelines 02/2026 on 7 July 2026, replacing earlier guidance and making re-identification risk an explicitly testable criterion rather than a theoretical consideration. In our assessment, this development means you cannot treat a dataset as safely anonymous once and move on; you must build recalibration into your governance and incident response workflows, and document the reasoning that supports each classification decision.
What does the new anonymisation standard actually require?
The Guidelines 02/2026 establish a two-part threshold: data is anonymous only if a natural person cannot be identified from it, and that identifiability is assessed not in the abstract but from the perspective of various relevant entities with differing technical means and access to auxiliary data. The same dataset can be anonymous in one context and personal data in another, depending on which linkable sources and re-identification techniques are reasonably available to a given party.
Anonymisation itself must satisfy three cumulative criteria. The data must not allow isolation of a unique record traceable to one person. It must not be linkable to other datasets in a way that identifies an individual. And no new attributes about a person may be derived from it. Only when all three are satisfied does the data count as anonymous. In practice, these form a re-identifiability stress test: if you can still isolate, link or infer, the anonymisation has not succeeded.
Which failure modes does the new standard address?
- Record isolation — a unique record can be singled out and traced back to an identifiable individual.
- Linkage to external data — records can be matched with other datasets to re-identify a person.
- Inference of new attributes — characteristics about a person can be derived that were not explicitly present in the original data.
- Expansion of auxiliary data — new external datasets become available that increase re-identification risk over time.
- Evolution of attack methods — improved techniques for re-identification emerge after anonymisation was performed.
Why is anonymisation no longer a permanent state?
The EDPB states explicitly that the chance of re-identification generally increases as inference methods improve and auxiliary data grow. A dataset treated as anonymous today can become personal data again tomorrow, as soon as the re-identification chance is no longer negligible. This is not a theoretical risk: research on publicly available health datasets demonstrates how re-identification risk can be expressed quantitatively and tied to concrete access decisions. Controllers must therefore recalibrate their risk assessment whenever the set of relevant entities, attack means or available auxiliary datasets changes.
This dynamic requirement means you cannot treat anonymisation as a completed project. You must establish trigger points for reassessment — when new inference techniques emerge, when your organisation gains access to additional data sources, when the regulatory environment shifts, or when a significant period has elapsed since the last review.
What concrete controls must you be able to demonstrate?
- Document the entity mapping — identify and record all direct and indirect identifiers present in or derivable from the dataset before anonymisation is applied.
- Perform and record the re-identifiability risk assessment — analyse the dataset against the three criteria (isolation, linkage, inference) and document which routes to re-identification remain open.
- Select and document the anonymisation measures — record which technical and organisational measures (perturbation, recoding, suppression, access controls) are applied to close each identified route.
- Establish recalibration triggers and schedule — define the conditions and intervals under which the anonymisation assessment will be reviewed and updated.
- Maintain the audit trail — keep records of each assessment, the reasoning behind each classification decision, and the dates on which recalibration occurred.
How does this change your handling of AI workflows on classified data?
For those deploying AI on data you have classified as anonymous, the question shifts from a binary classification to continuous visibility and documentation. You must be able to show not just that data is anonymised, but what analysis underlies that claim, which specific measures close which re-identification routes, and when you last decided the risk remained acceptable. This is particularly important because AI systems can amplify re-identification risk through inference, memorisation and pattern extraction.
Tooling can make visible, per workflow, which verification steps and corrections have been applied, and which data sources have been used. That supports review and oversight, but it is not a guarantee of correctness and does not remove the possibility of errors or hallucinations. The professional final judgement — including the legal qualification of whether data is truly anonymous — remains with you and your data protection officer. The Guidelines 02/2026 make clear that this assessment is never finished: re-identifiability must be tested continually, and your governance must reflect that.
Sources: This article draws on reporting and guidance from EDPB, IAPP, NIH and Iliomadhealthdata.
Written by
Elena Kovač
Follows EU policy as it turns from consultation into enforceable requirement.