Skip to content

Anonymisation guidance by country: what European regulators say

Ten European regulators on anonymisation: exact titles and dates, where they agree, where they differ, and what it means for a document sent abroad.

By Alexis de ONYRI

Across the EU, one legal test decides whether a document is anonymous. Could someone identify a person with the means reasonably likely to be used? The UK and Switzerland have their own laws with a similar test. But each national authority adds practical guidance with its own emphasis. So check the guidance of the country where the document will be read.

Below are ten regulators side by side, each with one key document checked on 4 October 2026. This is information, not legal advice. Other articles cover the UK, Switzerland and national ID numbers in depth.

In the EU, the test sits in Recital 26 of the General Data Protection Regulation (GDPR), an explanatory paragraph of the law. It counts all the means reasonably likely to be used to identify someone, by the controller or anyone else, given cost, time and technology. Anonymous information falls outside the GDPR. Pseudonymised data, which extra information can link back to a person, stays personal data.

The UK and Switzerland apply their own laws, built on the same idea. The UK regulator is the Information Commissioner's Office (ICO). Switzerland's revised Federal Act on Data Protection (FADP, in German DSG) has applied since 1 September 2023. The Swiss regulator is the Federal Data Protection and Information Commissioner (FDPIC). It quotes the Federal Council's 2017 dispatch (explanatory message) on that law: count all the means reasonably likely to be used.

What does each European regulator say about anonymisation?

The documents differ in kind: guidance pages, a position paper, a decision on one complaint, a glossary entry, a checklist. Older texts stay online, so note the year.

Two plain white archive boxes stacked in soft grey light, the lower one with a black rectangular handle slot
Ten regulators, ten kinds of text: guidance pages, a position paper, one decision on a complaint.Photo: Castorly Stock, Pexels
AuthorityCountryKey document on anonymisationKey point
CNILFrance« L'anonymisation de données personnelles » (Anonymising personal data), 19 May 2020Identification impossible in practice and irreversible, or a negligible risk you can demonstrate and keep under review.
BfDIGermany (federal)„Positionspapier zur Anonymisierung unter der DSGVO unter besonderer Berücksichtigung der TK-Branche“ (position paper on anonymisation under the GDPR), 29 June 2020Anonymising needs a legal basis. Absolute anonymity is usually not required.
DSBAustriaBescheid (decision) DSB-D123.270/0009-DSB/2018, 5 December 2018Anonymising can count as erasure if no one can undo it without disproportionate effort.
APD/GBABelgium« Recherche » (Research), theme page on data used for research, undatedDeleting name and address is not always enough.
CNPDLuxembourg« Donnée anonyme » (Anonymous data), glossary, updated 25 July 2023Restates Recital 26: the GDPR does not apply to anonymous information.
APNetherlands« Datalek voorkomen bij documenten publiceren of delen » (Preventing data breaches when publishing or sharing documents), 7 April 2026Use redaction software, never black boxes over text that stays in the file, and log your decisions.
AEPD, with the EDPSSpain« 10 malentendidos relacionados con la anonimización » (10 misunderstandings related to anonymisation), April 2021After direct identifiers, look for indirect ones. Context differs by country.
GaranteItaly« Linee guida in materia di trattamento di dati personali, contenuti anche in atti e documenti amministrativi […] » (Guidelines on personal data in administrative documents on the web), 15 May 2014 (before the GDPR), part 1, section 3Initials instead of a name are not enough in documents that public bodies publish online.
FDPIC (EDÖB, PFPDT)SwitzerlandGuide to Technical and Organisational Data Protection Measures (TOM), section 5.3, 15 January 2024Irreversible, without disproportionate effort. Photos and videos need adapted techniques.
ICOUnited KingdomAnonymisation guidance, 28 March 2025, under review after the Data (Use and Access) ActBring the risk to a “sufficiently remote” level, with most care for public release.
One key document per authority, checked on 4 October 2026, with a plain English translation of each title.

Where do European regulators agree?

  • Case by case. The CNIL asks for a thorough assessment. The Spanish AEPD and the European Data Protection Supervisor (EDPS) say anonymisation is not a recipe.
  • Three risks: singling out, linkability and inference. The CNIL and the FDPIC both point to a 2014 opinion of the EU regulators' former Article 29 Working Party.
  • Context counts. Recital 26 and the CNIL count the means of “another person”, and the ICO asks who may get access.
  • Re-check over time, say the CNIL, the BfDI and the ICO.
  • Pseudonymised data stays personal data, say Recital 26, the CNIL, the BfDI, the ICO, the AEPD and the EDPS.

Where do national approaches really differ?

The differences are about emphasis, detail and legal weight, not the test itself. Four of them matter for documents.

Do you need a legal basis to anonymise?

Yes, say both the BfDI and the ICO, because anonymising alters personal data, and that is a processing. The BfDI is the most detailed. It names possible bases: consent, compatibility with the original purpose under Article 6(4) GDPR, or a legal duty to erase. Both say you must tell people about the purpose.

Can anonymising replace deletion?

In Switzerland, Article 6(4) FADP requires data to be destroyed or anonymised once no longer needed, the FDPIC notes. In Austria, a 2018 decision of the Datenschutzbehörde (DSB) accepted that anonymisation can be a means of erasure. The condition: no one can undo it without disproportionate effort. The BfDI cites that decision. The CNIL and the ICO also see anonymising as an option once a retention period ends. Same idea, different legal weight: a statute, a decision, guidance.

How high is the bar?

The wording varies. The CNIL asks for identification that is impossible in practice and irreversible, or else a negligible risk shown by a thorough assessment. The BfDI says absolute anonymity is usually not required. The ICO aims for a “sufficiently remote” risk.

Which authorities write about documents?

Most guidance targets datasets, but some looks at documents. Italy's Garante, in a 2014 text from before the GDPR, says initials instead of a name are not enough for public bodies' online documents. The FDPIC adds that photos and videos need adapted techniques.

A story from the Dutch Autoriteit Persoonsgegevens (AP) features a municipal employee whose black bars left a resident's name and address searchable. The story is based on real reports, with details changed. The AP's checklist is adapted from a July 2025 ICO guide.

How do you anonymise one document that crosses a border?

Take a fictitious case. Jane Example, an HR officer in Brussels, sends a disciplinary file to a group lawyer in Milan, who may quote it in a public report.

  1. Name the reader, the country, and whether the file could go public. For a public release, the ICO asks for a very robust approach.
  2. Read the guidance of both authorities, yours and the reader's, and follow the stricter line. Here, no initials in place of names.
  3. Mask direct identifiers, then indirect ones such as a job title, a small town or an exact date.
  4. Ask what the reader could combine the file with: public registers, the press, social media, papers they already hold.
  5. Record who masked what, when and why, as the Dutch AP recommends.

Software can take care of the first pass. With its default profile, ONYRI Sanitize recognises the document's country from its content, among 11 countries including Belgium, Italy, Germany, Switzerland and the UK. It then applies that country's formats, such as national ID numbers and postcodes. But masking direct identifiers is only step one. Whether the result is anonymous depends on context and on the recipient, and that judgement stays yours.

When the stakes are high, such as health data or a public release, ask your data protection officer (DPO) or a lawyer. They know which authority supervises you.

Will the EDPB guidelines bring national guidance together?

Possibly. The European Data Protection Board (EDPB) adopted draft Guidelines 02/2026 on anonymisation on 7 July 2026. As of October 2026, comments are open until 30 October. The draft judges anonymity from the view of each party for whom the data should be anonymous. It also says that anonymising needs a legal basis under Article 6 GDPR. Once final, it could give EU authorities a common reference.

The EDPB works under the GDPR, so the ICO and the FDPIC keep their own laws. Outside Europe, other laws apply, for example in California and Québec. Another article covers them.

Frequently asked questions

Is national anonymisation guidance legally binding?

Mostly not. Guidance shows how an authority reads the law. The binding texts are the GDPR, the UK GDPR or the Swiss FADP. The Austrian DSB's 2018 decision settled one complaint, but it shows how that authority reasons.

Which guidance applies if I send a document from France to Germany?

Both countries apply the GDPR, so the test is the same. Read the CNIL page and the BfDI paper, then follow the stricter reading. The BfDI itself says private companies are mostly supervised by state authorities, so ask your DPO which authority applies.

Are black bars in a PDF enough to anonymise it?

No. The Dutch AP warns that black rectangles can leave the text in the file, readable by copy and paste. Use redaction software and ask a colleague to check.

Sources & references

  1. Recital 26 GDPR: not applicable to anonymous datagdpr-info.eu (text of Regulation (EU) 2016/679)
  2. L'anonymisation de données personnelles, 19 May 2020 (in French)Commission nationale de l'informatique et des libertés (CNIL), France
  3. Positionspapier zur Anonymisierung unter der DSGVO unter besonderer Berücksichtigung der TK-Branche, 29 June 2020 (in German)Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI), Germany
  4. BfDI page for the position paper: date 29 June 2020 and note on who supervises companies (in German)Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI), Germany
  5. Bescheid DSB-D123.270/0009-DSB/2018 of 5 December 2018 (in German)Datenschutzbehörde (DSB), Austria, via the RIS legal information system
  6. Recherche, theme page for professionals (in French)Autorité de protection des données (APD), Belgium
  7. Glossaire : Donnée anonyme, updated 25 July 2023 (in French)Commission nationale pour la protection des données (CNPD), Luxembourg
  8. Preventing data breaches when publishing or sharing documents, last edited 7 April 2026Autoriteit Persoonsgegevens (AP), Netherlands
  9. Eva (38) thought she just needed to black out text to anonymise a document, 7 April 2026Autoriteit Persoonsgegevens (AP), Netherlands
  10. 10 misunderstandings related to anonymisation, joint paper, April 2021Agencia Española de Protección de Datos (AEPD) and European Data Protection Supervisor (EDPS)
  11. Linee guida in materia di trattamento di dati personali, contenuti anche in atti e documenti amministrativi, effettuato per finalità di pubblicità e trasparenza sul web da soggetti pubblici e da altri enti obbligati, decision no. 243 of 15 May 2014 (in Italian)Garante per la protezione dei dati personali, Italy
  12. Guide to Technical and Organisational Data Protection Measures (TOM), 15 January 2024Federal Data Protection and Information Commissioner (FDPIC), Switzerland
  13. New data protection legislation (in force since 1 September 2023)Federal Office of Justice (FOJ), Switzerland
  14. Anonymisation guidance: About this guidance (published 28 March 2025, under review)Information Commissioner's Office (ICO), UK
  15. Anonymisation guidance: Introduction to anonymisationInformation Commissioner's Office (ICO), UK
  16. Anonymisation guidance: How do we ensure anonymisation is effective?Information Commissioner's Office (ICO), UK
  17. Disclosing documents to the public securely (published 31 July 2025)Information Commissioner's Office (ICO), UK
  18. Guidelines 02/2026 on Anonymisation, public consultation until 30 October 2026European Data Protection Board (EDPB)
  19. Guidelines 02/2026 on Anonymisation, version 1.0, adopted 7 July 2026European Data Protection Board (EDPB)

Mask a document without uploading it

ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.