
The EDPB just published guidelines that redefine when data qualifies as anonymous — and the answer now depends on who holds it.
On 8 July, the European Data Protection Board adopted new guidelines on anonymisation, incorporating the Court of Justice ruling in C-413/23 P (EDPS v SRB). The core shift: anonymity is no longer a property of the data. It is a property of the relationship between the data and the entity processing it.
The guidelines introduce a three-criteria test. For data to qualify as anonymous, an organisation must demonstrate that the data cannot be used to: isolate an individual record, link records across datasets, or infer information about an identifiable person. All three criteria must be met simultaneously.
More significantly, the EDPB introduces two assessment approaches. The contextual approach recognises that different entities have different re-identification capabilities — data that is anonymous in the hands of one organisation may not be anonymous in the hands of another. The simplified approach applies a uniform standard regardless of entity capability, treating data as personal if any reasonably foreseeable means of re-identification exist.
The guidelines also address web scraping for generative AI training — confirming that scraping publicly available personal data does not make that data anonymous by default. Public availability is not anonymity.
What this means for your compliance team:
→ If your organisation classifies any dataset as “anonymous,” you must now validate that classification against the three-criteria test: no isolation, no linkage, no inference. Previous assessments may no longer hold.
→ Anonymity is entity-specific. Data you receive from a partner as “anonymised” may not be anonymous in your hands — particularly if you hold supplementary datasets that enable re-identification.
→ AI training pipelines that rely on scraped web data cannot claim anonymisation simply because the data was publicly accessible. Legal basis must be established independently.
→ The guidelines are open for public consultation until 30 October 2026. Compliance teams should review and submit feedback — these will become the operational standard across all 27 EU member states.
At S8fe.ai, we help organisations audit their data classification frameworks against evolving regulatory standards — because the difference between “anonymised” and “pseudonymised” is the difference between no GDPR obligations and full GDPR compliance.
“Anonymous” is not a label you apply. It is a conclusion you must prove — and the test just changed.
Source: https://www.edpb.europa.eu/news/edpb-sheds-light-on-anonymisation-and-web-scraping-for-generative-ai-and-adopts-final-version_en
