Prefer to listen? Click play for AI narration

On 8 July 2026 the European Data Protection Board (EDPB) announced its draft Guidelines 02/2026 on anonymisation, an update to the 2014 opinion that businesses have relied on for years. Public comments are open until 30 October 2026. The subject sounds technical, but it decides something every organisation depends on: the point at which data stops being personal data and the GDPR stops applying to it.

If you share analytics with partners, publish statistics, keep “anonymised” customer exports, or train and fine-tune AI on customer data, this draft changes how confidently you can use the word “anonymous”.

What the EDPB actually published

The draft follows the Court of Justice's ruling in EDPS v SRB (C-413/23 P, 4 September 2025), which held that pseudonymised data is not automatically personal data for every recipient. The same dataset can be personal data in one organisation's hands and anonymous in another's. The EDPB's guidelines turn that principle into a working method, and they are candid that the answer “may vary from one entity to another”.

The EDPB announced them together with separate guidelines on web scraping for generative AI, both open for comment until the same 30 October date. We covered the scraping side in our article on GDPR and AI training data. This article is about the other half: when data, or a model, can honestly be called anonymous.

3
Criteria to pass: no isolation, no linkage, no inference
2
Ways to run the test: contextual or simplified
30 Oct
Consultation deadline, 2026
2014
Year of the opinion this draft updates

“Anonymous” now depends on who holds the data

Under the draft, data is anonymous if it does not relate to an identified or identifiable person. A person is identifiable if they can be distinguished from others in a specific context using means reasonably likely to be used, judged from the perspective of the “relevant entity” and all objective factors. Three consequences stand out in the law-firm analyses published since July:

The EDPB also offers two ways to run the assessment. The contextual approach looks at what each relevant entity could actually do. The simplified approach ignores those differences. It is more convenient and gives more confidence, but it can treat data as not anonymous even where it would be anonymous for some entities. Ashurst reports that the EDPB suggests starting with the simplified approach and switching to the contextual one when you need a more precise answer.

The three-part test

The EDPB's framework uses three criteria. If all three are met, the data can safely be considered anonymous. If one fails, that does not make the data personal automatically, but it means more analysis is required.

Zero risk is not the standard. Law-firm summaries describe the test as whether the chance of distinguishing a person is insignificant in practice. Ashurst adds a point that catches many businesses out: the test looks at capability, not motivation, so “nobody would bother” is not a defence.

Where AI changes the answer

Commentators note that the draft acknowledges AI, and agentic AI in particular, is reducing the cost of re-identification. A dataset that is anonymous today may not stay anonymous. That has three practical effects:

If you fine-tune a model on customer conversations, or feed support tickets into a tool that “learns”, do not assume the output is anonymous because names were removed. Our piece on why an AI chatbot isn't anonymising anything shows how quickly that assumption fails.

What doesn't go away when data is anonymised

There is one piece of reassurance. Ashurst notes that organisations which have already assessed datasets as anonymous under the 2014 opinion do not have to reassess them purely because of this draft.

📋
GDPRGard Toolkit
An “anonymous” claim needs paperwork behind it

Editable DPA pack, SAR response toolkit, and Article 30 RoPA register: the records that show what data you hold, why you hold it and how you assessed it. €39–€59 each or €99 for all three.

Get the Templates →

A practical checklist before 30 October

  1. List every dataset you call anonymous. Exports, shared statistics, dashboards, machine-learning training sets, test data.
  2. Name the relevant entities. Who could get the data: the recipient, their partners, your own staff, an attacker? What else could each of them combine it with?
  3. Run the three tests and write down the result. Isolation, linkage, inference. If you are unsure, start with the more conservative simplified approach.
  4. Back every contract clause with a technical measure. A no-re-identification promise on its own will not carry the claim.
  5. Test AI outputs instead of declaring them anonymous. If you fine-tune on customer data, check for extraction and regurgitation, keep the results, and cover it in your DPIA.
  6. Set a re-check date and consider commenting. Put a review in the calendar, and if this affects your sector, submit feedback through the EDPB's public consultation page before 30 October. Trade associations are the usual route for smaller businesses.

Remember that this is a draft. The final text may change, and nothing here adds obligations beyond what the GDPR and the Court's case law already require. What it does is show how regulators will read a claim of anonymity.

The bottom line

The direction is clear even while the details are open. Anonymity is not a stamp you apply once. It is a conclusion you reach for a particular holder of the data, test against three criteria, document, and revisit as technology improves. Organisations that can show that work will be in a far stronger position than those that simply write “anonymous” on the file.

Book a free consultation with GDPRGard → and we will help you review which of your datasets and AI tools really qualify.

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance — verify current obligations with your legal adviser.