Skip to main content

Finepost · Notes · Law

pseudonymisation

noun · Pseudonymisierung

Pseudonymisation is the Pseudonymisierung of Art. 4 Nr. 5 DSGVO, and the word decides whether the regulation applies: for everyone able to reach the key, pseudonymised data remain personenbezogene Daten under the full GDPR, only true Anonymisierung leads out of it. A translation that slides between pseudonymisiert and anonymisiert rewrites the scope of the law, in either direction.

Which translation, when

Legaldefinitionthe mechanism: Art. 4 Nr. 5 DSGVO defines Pseudonymisierung as processing personal data so that they can no longer be attributed to a specific data subject without the use of additional information, that additional information kept separately and under technical and organisational measures; the classic form replaces the name with an ID whose key sits in a separately protected file, and encryption works as pseudonymisation in substance for as long as a key allows the text to be read back.
bleibt in der Verordnungthe legal switch: for the pseudonymising controller and everyone able to reach the key, pseudonymised data remain personenbezogene Daten under the full regulation, Erwägungsgrund 26 DSGVO, and the European court reads the label as relative, the same set may count as anonymous for a keyless recipient on the measure of the means reasonably likely to be used, EuGH C-413/23 P; only genuine anonymisation, irreversible on that measure, leads out of the GDPR for good, so in the controller’s own text anonymisiert for pseudonymised declares the regulation inapplicable to data the law keeps inside, and the reverse rendering pulls anonymous material back under duties it does not carry.
Schutzmaßnahme, kein Ausstiegthe function: the regulation treats Pseudonymisierung as a risk-reducing safeguard, named in data protection by design, Art. 25 DSGVO, and in security of processing, Art. 32 Abs. 1 lit. a DSGVO, and Erwägungsgrund 28 assigns it exactly that role, lowering risks and helping compliance without excluding other measures; a text selling pseudonymisation as the exit from data protection has confused the safeguard with the Anonymisierung it is not.

Why

Pseudonymisation translates as Pseudonymisierung, and the pair is stable because the German word is the defined term of Art. 4 Nr. 5 DSGVO: processing personal data so that attribution to a specific person is possible only with additional information, which must be kept separately and protected by technical and organisational measures. The weight of the entry lies not in the word but in its neighbour. German drafting, and machine output with it, treats pseudonymisiert and anonymisiert as near-synonyms of careful data handling, and the regulation treats them as opposites in legal effect: for the controller who holds or can reach the key, pseudonymised data remain personenbezogene Daten and carry the full apparatus of the GDPR, legal basis, data subject rights, security duties, and the European court holds the data are never anonymous for the pseudonymising controller himself, while the label is relative for a keyless recipient, EuGH C-413/23 P; anonymous information, no longer relating to an identifiable person on the measure of all means reasonably likely to be used, falls outside the regulation altogether, Erwägungsgrund 26 DSGVO, and the drafting voice of a privacy text is the controller, for whom the strict rule governs. The direction of the mistake decides who is harmed: anonymisiert written for pseudonymised strips protections the law commands, pseudonymisiert written for truly anonymous material invents duties the law does not impose. The function completes the picture: the regulation names Pseudonymisierung as a safeguard, in data protection by design, Art. 25 DSGVO, and in security of processing, Art. 32 Abs. 1 lit. a DSGVO, with Erwägungsgrund 28 assigning it the role of lowering risk and supporting compliance, expressly without excluding other measures. It is a way of processing safely inside the GDPR, never a doorway out of it. So the safe rendering keeps the two German words strictly apart, asks of every anonymisiert whether the re-identification key truly no longer exists, and lets Pseudonymisierung claim only what it is, a protective technique under the regulation.

Typical mistakes

  • Pseudonymisiert and anonymisiert carry opposite legal outcomes, inside and outside the GDPR, so treating them as style variants rewrites the scope of the law.
  • A dataset with a separately kept re-identification key is pseudonymised, not anonymised, so anonymisierte Daten is the wrong label wherever a key survives.
  • Pseudonymisierung is a safeguard under Art. 25 and Art. 32 DSGVO, not an exemption, so presenting it as the way out of data protection duties misstates its function.

What matters

A data-sharing or research clause promising anonymised data: the translation should ask whether a re-identification key survives, write pseudonymisiert where it does, and keep the full GDPR apparatus attached, because only true Anonymisierung leads out of the regulation.

Authority

  1. Art. 4 Nr. 5 DSGVO
  2. Erwägungsgrund 26 DSGVO
  3. EuGH, Urt. v. 4.9.2025, C-413/23 P

What the machine misses

Machine output renders pseudonymisation as Pseudonymisierung reliably in isolation, but in running text it slides between pseudonymisiert and anonymisiert as if they were style variants; the two words carry opposite legal outcomes, pseudonymised data remain inside the GDPR while anonymous data fall outside it, so the slide silently rewrites whether the regulation applies at all.

See what the machine does with this clause →

Examples

pseudonymised datapseudonymisierte Daten
to pseudonymise the recordsdie Datensätze pseudonymisieren
the additional information is kept separatelydie zusätzlichen Informationen werden gesondert aufbewahrt
anonymised beyond re-identificationüber die Re-Identifizierung hinaus anonymisiert
Checked 30 Jul 2026 finepost.co.uk/notes/pseudonymisation