GDPR-compliant anonymization

GDPR-compliant anonymization — when is data truly protected?

Companies are regularly faced with the question of whether redacting or anonymizing data is sufficient to comply with GDPR. This page explains when data is considered anonymous, what requirements the GDPR imposes and where errors often occur in practice.

Anonymize texts and documents

What does GDPR-compliant anonymization involve?

The GDPR addresses the question of whether data is linked to data protection law are subject, not to the type of processing, but to whether there is a personal connection.

The decisive factor is whether a natural person is identified or identifiable based on the available information. Decisive for this is Recital 26 GDPR, which requires objective consideration: It is not the intention of the person responsible that is decisive, but whether identification would be realistically possible.

When is data considered anonymous?

According to Recital 26 of the GDPR, data are only considered anonymous if the identification of the data subject is no longer possible, taking into account all means that are “reasonably likely to be used” by the controller or by another person.

What matters is not only direct identification, but also any form of indirect re-identification through additional knowledge, data linkage, or technical means. If re-identification cannot be practically ruled out, the data remain personal data within the meaning of the GDPR.

Grafik zeigt den Prozess der Anonymisierung, bei dem personenbezogene Daten so verarbeitet werden, dass sie als anonym gelten

Anonymize or redact — what is the difference?

In practice, these terms are often equated, although they must be assessed differently from a legal point of view.

Redact

Optical redaction and its limits

Redaction visually obscures content, but often allows the original data to be retained in the document. Recovery is often possible without technical removal.

• PDF text can be copied
• Layers are retained in metadata
• Hidden content can still be read

Anonymization

Technical anonymization

GDPR-compliant anonymization removes or technically changes data in such a way that conclusions can no longer be drawn about people — even with additional knowledge.

• Content is removed or irreversibly changed
• Metadata is cleaned
• Review based on defined criteria

Typical mistakes when redacting and anonymizing

Many data protection breaches do not result from intent, but from incomplete or faulty procedures.

Documents

Incomplete redaction

Content is only visually covered, but is technically retained in the document. As a result, they can be reconstructed and made visible again, for example by copying, exporting or analysis tools.

Metadata

Remaining metadata

Author names, version histories, or comments may still contain personal information, even if the visible text has been redacted. This metadata is often retained in the document and allows conclusions to be drawn about people involved or internal processes, unless removed.

Context

Contextual re-identification

Combinations of time, location, or project data can make it possible to re-identify people.

Grafik zeigt einen Kreislauf von Faktoren wie große Datenmengen, langfristige Archivierung und Weitergabe, bei denen automatisierte Anonymisierung sinnvoll ist

When is redaction insufficient?

Redacting data may be sufficient in individual cases, but not in the following scenarios.

1. Transfer to third parties or external recipients

As soon as documents are transmitted to external bodies, the anonymization must be technically reliable. Optical blackening is usually not enough.

2. Processing larger amounts of data

With larger amounts of data, the risk of indirect identification increases. This requires clear rules and automatic procedures.

3. Long-term archiving

When documents are archived or kept for audits, personal data must be permanently removed. Subsequent access must not allow any inferences to be drawn.

GDPR-compliant anonymization — the next step

Explore further aspects or check which formats and scenarios are relevant for your company. We are happy to provide you with an individual evaluation.

Further information:

Document types & formats

Overview of formats, risks and appropriate anonymization channels.

Risks of false anonymization

Overview of typical risks of incorrect anonymization.

Further steps

Would you like to learn more about use cases, document types or the use of Project A? Get in touch with us — we will give you individual advice and show you the appropriate next steps.

Receive an offer
When you go to “Accept all” click, you agree to the storage of cookies on your device to improve navigation and support our marketing efforts. For more information, see our privacy policy.

Publications

Experiences, insights and more

Career portal

Vacancies

Project A

Anonymize texts and files

RESA

Transferring data to your SAP system