Skip to content
Fundamentals8 min read

Anonymization glossary: key terms in English, French and German

About 30 anonymization terms in English, French and German, with the official GDPR wording in each language and the false friends to avoid.

By Alexis de ONYRI

This glossary gives about 30 data protection terms in English, French and German, grouped by theme. For every term in the GDPR, it uses the official wording of each language version. Keep it open when a French colleague writes occultation, a German one writes Schwärzung, and you wonder whether they mean redaction.

What are the core data protection terms in three languages?

Each table starts with English, then French and German. Terms marked as not defined in the GDPR come from guidance or standards. This glossary spells anonymization with a z, but the regulation's English text writes pseudonymisation with an s.

A wooden card catalogue with one drawer pulled out and filled with index cards, in front of a grey concrete wall
Each term gets its own entry in each language, filed like a card in a catalogue.Photo: Tima Miroshnichenko, Pexels
EnglishFrançaisDeutschPlain meaning
personal datadonnées à caractère personnelpersonenbezogene DatenAny information about a person who is identified or can be identified (Article 4).
identifieridentifiantKennungA detail that points to a person: name, ID number, location data, online identifier.
quasi-identifierquasi-identifiantQuasi-IdentifikatorDetails that identify someone only in combination, such as birth date plus postcode. Not defined in the GDPR.
special categories of personal datacatégories particulières de données à caractère personnelbesondere Kategorien personenbezogener DatenThe Article 9 list: racial or ethnic origin, political opinions, religious or philosophical beliefs, union membership, genetic, biometric and health data, sex life, sexual orientation.
anonymizationanonymisationAnonymisierungA process that aims to make data anonymous. When nobody can identify the person by means reasonably likely to be used, the GDPR stops applying (Recital 26).
pseudonymizationpseudonymisationPseudonymisierungProcessing so that data cannot be tied to a person without extra information kept apart. Still personal data.
re-identificationréidentificationReidentifizierungWorking out again who is behind data meant to hide them. Not defined in the GDPR.
data minimizationminimisation des donnéesDatenminimierungKeeping only data that is adequate, relevant and limited to what the purpose needs (Article 5(1)(c)).
Core concepts

The GDPR defines pseudonymization in Article 4(5) but never defines anonymization. Recital 26 only says that anonymous information, informations anonymes in French and anonyme Informationen in German, falls outside the rules. The German federal authority BfDI adds, in its 2020 position paper, that pseudonymized data stays personal data.

What are the main techniques for hiding data called?

These words describe what you do to the data, not the legal result. The last six rows are based on the Article 29 Working Party's Opinion 05/2014, available in all three languages. It does not list redaction or masking as techniques, so their words come from authorities' practice.

EnglishFrançaisDeutschPlain meaning
redactioncaviardage, occultationSchwärzungRemoving chosen passages from a copy of a document so the reader cannot see them.
maskingmasquageMaskierungHiding a value with a bar, stars or a label. Often a synonym of redaction.
tokenizationtokenisationTokenisierungSwapping a value for a substitute such as a label. The Working Party lists it as pseudonymization.
hashinghachageHashing (Hashfunktion)A one-way, fixed-size code. Known inputs, such as ID numbers, can still be tried one by one.
encryptionchiffrementVerschlüsselungScrambling data with a key. Whoever holds the key can read the original again.
generalizationgénéralisationGeneralisierungMaking a detail less precise: a region instead of a city, a month instead of a week.
aggregationagrégationAggregationGrouping single records into totals or ranges so no one person stands out.
k-anonymityk-anonymatk-AnonymitätEach combination of quasi-identifiers is shared by at least k records, so a person hides in a group.
Techniques

Which words describe what hides inside a document file?

These terms have no official wording in the GDPR. They come from everyday use and from guidance by authorities and software makers. The French and German words below are the usual ones.

EnglishFrançaisDeutschPlain meaning
metadatamétadonnéesMetadatenDetails stored in the file itself: author, dates, software used.
text layercouche de texteTextebeneThe real, selectable text inside a PDF. A scan has none, so OCR must read it.
OCR (optical character recognition)reconnaissance optique de caractères (OCR)Texterkennung (OCR)Software that reads the letters in an image and turns them into text.
flatteningaplatissementflach rendernIn redaction, rebuilding each page as an image, so the text layer and anything under a bar are gone.
annotationannotationKommentar, AnmerkungA note or drawing added on the page. It can carry names even when the text is masked.
tracked changessuivi des modificationsnachverfolgte ÄnderungenEdits a Word file records, with the deleted text and who made them.
Document terms

Microsoft's Document Inspector looks for comments, tracked-change marks, document properties with personal information and hidden text. Lower Saxony's data protection authority says to check metadata such as the author. The ICO warns that pasting a PDF with black rectangles into a text editor can reveal the covered text. Its guidance is dated 31 July 2025.

What are the GDPR roles and procedures called in French and German?

This is where the official wording matters most. Every term below is copied from the matching language version of the regulation. The article numbers help you find the full text.

EnglishFrançaisDeutschPlain meaning
data subjectpersonne concernéebetroffene PersonThe person the data is about (Article 4(1)).
controllerresponsable du traitementVerantwortlicherWhoever decides why and how personal data is processed, alone or with others (Article 4(7)).
processorsous-traitantAuftragsverarbeiterWhoever processes personal data on behalf of the controller (Article 4(8)).
data protection officerdélégué à la protection des donnéesDatenschutzbeauftragterThe person an organisation designates for data protection, in the cases of Article 37.
data protection impact assessmentanalyse d'impact relative à la protection des donnéesDatenschutz-FolgenabschätzungA risk review before processing that is likely to carry a high risk for people (Article 35).
right of accessdroit d'accès de la personne concernéeAuskunftsrecht der betroffenen PersonA person's right to confirmation that their data is processed, and to access it (Article 15).
personal data breachviolation de données à caractère personnelVerletzung des Schutzes personenbezogener DatenA security breach that destroys, loses, alters or exposes personal data, by accident or unlawfully (Article 4(12)).
supervisory authorityautorité de contrôleAufsichtsbehördeThe public body that oversees data protection, such as the CNIL in France or the BfDI in Germany.
Roles and procedures

In the UK, people say subject access request. The ICO uses that phrase, but Article 15 is titled right of access by the data subject. The BfDI writes Auskunftsersuchen for the request itself, and the CNIL speaks of a demande de droit d'accès. In formal writing, use the title of the article.

Which terms look alike but mean different things?

These are the traps that cause misunderstandings between teams. Each one rests on an authority's own wording.

  • Sensitive data. The CNIL uses donnée sensible for the special categories of Article 9, such as health, religion or union membership. Bank details and addresses are not on that list, even if they feel sensitive. The regulation itself says special categories.
  • Anonymization. It is often used for any masking. Yet the CNIL writes that anonymisation must not be confused with pseudonymisation, and the BfDI warns against assuming too quickly that anonymization is sufficient.
  • Redaction. One gesture, several words. The French Ministry of Justice says occultation for names removed from published court decisions. The CNIL says masquer for third parties in an access reply. The BfDI says schwärzen. NIST notes that redaction sometimes means plain removal of information in government. Lower Saxony's authority calls it a technical and organisational measure under Article 32.
  • Hashing. The word sounds irreversible, so people call hashed data anonymous. The Working Party warns that when the possible inputs are known, such as national ID numbers, you can hash them all and compare. Hashing is a pseudonymization technique.
  • Controller and processor. In daily speech, a responsable or Verantwortlicher is anyone in charge, and a sous-traitant is any subcontractor. In the GDPR, they are roles defined in Article 4.

How do you use these words in a real document workflow?

Name the result, not only the gesture. Write redacted when you removed passages. Write pseudonymized when labels can be linked back. Write anonymized only when the reasonable means test of Recital 26 is met. One short vocabulary line in your procedure saves long email threads between teams.

  1. Decide which legal result you need: anonymous, pseudonymized or simply redacted.
  2. Use the official term of the recipient's language for roles and rights, such as Verantwortlicher or responsable du traitement.
  3. Check the hidden parts: metadata, annotations, tracked changes and the text layer.
  4. Mask indirect identifiers too, such as a rare job title or a date, not only names.
  5. Keep the original, and treat the masked copy as personal data if labels can be linked back.
  6. Ask your data protection officer, or the authority of your country, when one word decides a legal duty.

ONYRI Sanitize, a tool that runs in your browser, uses two of these terms. Its Black marker mode is redaction with a flattened export, so masked text is removed, not covered. Its Token mode, on the Pro plan, replaces each value with a label such as [NAME1]. That is pseudonymization, so the document stays personal data. Detection is not exhaustive, so review the preview.

This glossary is information, not legal advice. A contract or a national law can use other words, and a lawyer or your data protection officer can confirm which term applies. The wording was checked in October 2026.

Frequently asked questions

What is the difference between anonymization and pseudonymization?

Anonymization is a process. When it works, nobody can identify the person by any means reasonably likely to be used, so the GDPR no longer applies (Recital 26). Pseudonymization is a process too, but extra information kept apart can still link the data to a person (Article 4(5)). So it stays personal data.

What is redaction called in French and German?

In French, people say caviardage, and official texts such as the Ministry of Justice's page on court decisions say occultation. In German, the word is Schwärzung, and the BfDI uses the verb schwärzen. None of these words is a legal status.

Is a hashed or tokenized value anonymous?

Not by itself. The Working Party lists both among pseudonymization techniques. Anyone who can try all likely inputs of a hash, such as every ID number, can find the original. NIST adds that pseudonymization can be reversed if someone keeps a table linking pseudonyms to identities.

How was the official wording checked?

The English and German GDPR terms were checked on public reproductions of the regulation, and the French terms on the CNIL website, in October 2026. Terms outside the GDPR have no official wording. For techniques we relied on the Working Party's opinion in three languages. For document terms we used the usual words.

Who can confirm the right term for my case?

Your data protection officer, if you have one, or a lawyer. You can also ask the authority of your country. That means the CNIL in France, the BfDI or your state authority in Germany, and the ICO in the UK. The right term can change a legal duty, so do not guess.

Sources & references

  1. GDPR Article 4: Definitions (English text)gdpr-info.eu (text of Regulation (EU) 2016/679)
  2. GDPR Article 5: Principles relating to processing of personal datagdpr-info.eu (text of Regulation (EU) 2016/679)
  3. GDPR Article 9: Processing of special categories of personal datagdpr-info.eu (text of Regulation (EU) 2016/679)
  4. GDPR Article 15: Right of access by the data subjectgdpr-info.eu (text of Regulation (EU) 2016/679)
  5. GDPR Article 35: Data protection impact assessmentgdpr-info.eu (text of Regulation (EU) 2016/679)
  6. GDPR Article 37: Designation of the data protection officergdpr-info.eu (text of Regulation (EU) 2016/679)
  7. GDPR Recital 26: Not applicable to anonymous datagdpr-info.eu (text of Regulation (EU) 2016/679)
  8. Opinion 05/2014 on Anonymisation Techniques (WP216), adopted 10 April 2014Article 29 Data Protection Working Party
  9. NIST IR 8053: De-Identification of Personal Information (October 2015)National Institute of Standards and Technology (NIST)
  10. How do we avoid an accidental breach when redacting information? (guidance dated 31 July 2025, under review)Information Commissioner's Office (ICO)
  11. Remove hidden data and personal information by inspecting documents, presentations, or workbooksMicrosoft Support
  12. L'anonymisation de données personnelles (19 May 2020, in French)CNIL
  13. Donnée sensible (in French)CNIL
  14. Professionnels : comment répondre à une demande de droit d'accès ? (in French)CNIL
  15. Open data des décisions de justice (in French)Ministère de la Justice
  16. Positionspapier zur Anonymisierung unter der DSGVO (29 June 2020, in German)Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
  17. Das Recht auf Auskunft (Art. 15 DSGVO) (in German)Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
  18. Hinweise zum Schwärzen von Dokumenten (July 2025, in German)Der Landesbeauftragte für den Datenschutz Niedersachsen
  19. GDPR, French text with the recitals (in French)CNIL
  20. GDPR, German text (in German)dsgvo-gesetz.de (Text der Verordnung (EU) 2016/679)

Mask a document without uploading it

ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.