Anonieme data is geen eindstatus meer na EDPB-Guidelines 02/2026
De EDPB-Guidelines 02/2026 maken herleidbaarheid na anonimisering een toetsbare, doorlopende norm. Wat betekent dat voor hoog-trust dataverwerking?
Je moet anonimisering van gevoelige data voortaan behandelen als een voortdurende risicobeoordeling, niet als een eenmalige technische handeling. Dat betekent: documenteer welke heridentificatierisico's per dataset nog openstaan, welke maatregelen die sluiten, en hoe vaak je die inschatting herziet.
An analysis of 24 August 2026 of herleidbaarheid na anonimisering als voortdurende norm argues that anonymisation is no longer a permanent state but a testable, dynamic obligation that must be reassessed as re-identification techniques and auxiliary data evolve. The European Data Protection Board adopted Guidelines 02/2026 on Anonymisation on 7 July 2026, replacing the earlier WP29 opinion with a detailed framework that treats residual re-identification risk as an explicit, measurable standard rather than a theoretical edge case. In our assessment, this shift moves the burden from one-time technical validation to continuous governance: you must now demonstrate that your anonymisation decisions remain sound as the threat landscape changes, and you must be able to show your working each time you conclude a dataset is safe to process as non-personal data.
Hoe bepaal je of data werkelijk anoniem is?
The EDPB framework begins with a two-question test: does the data relate to an identifiable natural person, and can that person be identified? Identifiability is not judged as an abstract average but from the perspective of different relevant entities with varying re-identification capabilities and resources. The same dataset may be anonymous in one context and personal data in another, depending on which linkable sources and techniques a party can reasonably access.
Beyond that threshold lie three cumulative criteria. No Record Isolation means you cannot isolate a unique record that leads back to one person. No Linkage means records cannot be matched with other datasets to identify an individual. No Inference means you cannot derive new properties about a person from the data. All three must hold simultaneously. In practice, they form a re-identification stress test: if you can still isolate, link, or infer, then re-identifiability has not disappeared.
Welke heridentificatierisico's moet je blijven monitoren?
- Record isolation via direct identifiers — names, ID numbers, contact details that directly name or locate a person.
- Linkage with external datasets — combination of indirect identifiers with publicly available auxiliary data to match records to individuals.
- Inference from demographic or behavioural patterns — derivation of new sensitive attributes from statistical or machine-learning analysis of the anonymised set.
- Improved re-identification methods — evolution of techniques, algorithms and computational power that increase the feasibility of attacks not previously practical.
- Growth of auxiliary data — expansion of reference datasets, public registries, or commercial data brokers that create new linkage opportunities.
- Scope creep in data holders — addition of new parties with access to the dataset, each bringing different re-identification capabilities and incentives.
Welke concrete controles moet je per workflow kunnen aantonen?
- Document the entity mapping — list all direct and indirect identifiers in the dataset and justify why each is necessary for your use case.
- Conduct a re-identification risk assessment against the three criteria — analyse which isolation, linkage and inference routes remain open for each relevant adversary class.
- Record the anonymisation measures applied — specify which perturbation, recoding, suppression or other technical controls you deployed and why each addresses a specific route.
- Define and document reassessment triggers — state which changes in threat landscape, auxiliary data availability, or inference capability will prompt you to re-evaluate the anonymisation decision.
- Establish a review schedule — set explicit dates or conditions on which you will revisit the risk assessment, and document each review outcome.
Wat verandert voor AI-workflows op anonieme data?
When you deploy AI on datasets you have classified as anonymous, the question shifts from whether the data is truly anonymous to whether your processing pipeline preserves that status. You must make visible which verification steps, corrections and data sources flow through each workflow, so that those steps are available for inspection. This is not a guarantee of correctness and does not eliminate hallucinations or model drift. It is a way to show per workflow which datasets you treat as anonymous, which trade-offs preceded that decision, and when a dataset must be reclassified as personal data in governance, audits and incident response because re-identification risk has risen.
The professional and legal judgment remains yours and your data protection officer's. The EDPB Guidelines 02/2026 make clear that judgment is never final: you must keep testing re-identifiability.
Hoe zorg je dat je anonimisering onder controle blijft?
Treat anonymisation as a hypothesis you verify, not a state you declare once. For each dataset, record which re-identification routes still exist — linkage with external sources, new inference methods, expansion of demographic auxiliary data — which technical and organisational measures actually close those routes, and how often you will revisit the assessment. When you process data with AI, ensure that the workflow makes visible which verification steps, corrections and sources have been used, so that those steps are available for inspection by auditors and supervisors. Document the scenario analysis you have performed for each dataset. If significant new risks emerge, treat the dataset as personal data again, with all the consequences for data protection impact assessments and breach notification obligations.
Tooling can help you maintain records, track changes in auxiliary data availability, and flag when re-identification risk scores cross a threshold you have set. What tooling cannot do is make the final judgment about whether a given risk level is acceptable for your use case and your legal obligations. That remains a professional decision, informed by your data protection impact assessment, your risk appetite, and your understanding of the specific adversaries and inference methods relevant to your sector and your data.
Bronnen: Dit artikel is gebaseerd op berichtgeving en richtlijnen van EDPB, IAPP, NIH en Iliomadhealthdata.
Geschreven door
Elena Kovač
Volgt EU-beleid op het moment dat het van consultatie naar handhaafbare eis gaat.