pseudonymisation
noun · Pseudonymisierung
Pseudonymisation is the Pseudonymisierung of Art. 4 Nr. 5 DSGVO, and the word decides whether the regulation applies: for everyone able to reach the key, pseudonymised data remain personenbezogene Daten under the full GDPR, only true Anonymisierung leads out of it. A translation that slides between pseudonymisiert and anonymisiert rewrites the scope of the law, in either direction.
Which translation, when
Why
Pseudonymisation translates as Pseudonymisierung, and the pair is stable because the German word is the defined term of Art. 4 Nr. 5 DSGVO: processing personal data so that attribution to a specific person is possible only with additional information, which must be kept separately and protected by technical and organisational measures. The weight of the entry lies not in the word but in its neighbour. German drafting, and machine output with it, treats pseudonymisiert and anonymisiert as near-synonyms of careful data handling, and the regulation treats them as opposites in legal effect: for the controller who holds or can reach the key, pseudonymised data remain personenbezogene Daten and carry the full apparatus of the GDPR, legal basis, data subject rights, security duties, and the European court holds the data are never anonymous for the pseudonymising controller himself, while the label is relative for a keyless recipient, EuGH C-413/23 P; anonymous information, no longer relating to an identifiable person on the measure of all means reasonably likely to be used, falls outside the regulation altogether, Erwägungsgrund 26 DSGVO, and the drafting voice of a privacy text is the controller, for whom the strict rule governs. The direction of the mistake decides who is harmed: anonymisiert written for pseudonymised strips protections the law commands, pseudonymisiert written for truly anonymous material invents duties the law does not impose. The function completes the picture: the regulation names Pseudonymisierung as a safeguard, in data protection by design, Art. 25 DSGVO, and in security of processing, Art. 32 Abs. 1 lit. a DSGVO, with Erwägungsgrund 28 assigning it the role of lowering risk and supporting compliance, expressly without excluding other measures. It is a way of processing safely inside the GDPR, never a doorway out of it. So the safe rendering keeps the two German words strictly apart, asks of every anonymisiert whether the re-identification key truly no longer exists, and lets Pseudonymisierung claim only what it is, a protective technique under the regulation.
Typical mistakes
- Pseudonymisiert and anonymisiert carry opposite legal outcomes, inside and outside the GDPR, so treating them as style variants rewrites the scope of the law.
- A dataset with a separately kept re-identification key is pseudonymised, not anonymised, so anonymisierte Daten is the wrong label wherever a key survives.
- Pseudonymisierung is a safeguard under Art. 25 and Art. 32 DSGVO, not an exemption, so presenting it as the way out of data protection duties misstates its function.
What matters
A data-sharing or research clause promising anonymised data: the translation should ask whether a re-identification key survives, write pseudonymisiert where it does, and keep the full GDPR apparatus attached, because only true Anonymisierung leads out of the regulation.
What the machine misses
Machine output renders pseudonymisation as Pseudonymisierung reliably in isolation, but in running text it slides between pseudonymisiert and anonymisiert as if they were style variants; the two words carry opposite legal outcomes, pseudonymised data remain inside the GDPR while anonymous data fall outside it, so the slide silently rewrites whether the regulation applies at all.
Examples
| pseudonymised data | pseudonymisierte Daten |
| to pseudonymise the records | die Datensätze pseudonymisieren |
| the additional information is kept separately | die zusätzlichen Informationen werden gesondert aufbewahrt |
| anonymised beyond re-identification | über die Re-Identifizierung hinaus anonymisiert |