Anonymization, pseudonymization, redaction: what is the difference?
Three words, three different results. What the GDPR says, why a label like [NAME1] is pseudonymization, where redaction fits, and a decision table.
Anonymized data can no longer be linked to a person by anyone using reasonable means, so the GDPR stops applying. Pseudonymized data can be linked back with extra information, such as a key or the original file, so it stays personal data for whoever holds that information. Redaction is not a legal category: it means masking passages in a document, and the result can be either.
What does the GDPR say about anonymization and pseudonymization?
The GDPR defines only pseudonymization. Under Article 4(5), it means processing personal data so that it can no longer be attributed to a specific person without additional information, kept separately and protected by technical and organisational measures.
Anonymization is not defined in the articles. Recital 26 draws the line: pseudonymized data that could be attributed to a person with additional information concerns an identifiable person. You weigh all the means reasonably likely to be used, by the controller or by anyone else, taking into account cost, time and available technology.
The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. (GDPR, Recital 26)
So truly anonymous information falls outside the GDPR, and pseudonymized data does not. In the UK, the ICO agrees: pseudonymisation reduces risk and improves security, but it does not take personal data outside the law. As of September 2026, the ICO notes that this guidance is under review after the Data (Use and Access) Act.
Why is replacing a name with a label pseudonymization?
Take a complaint letter about an employee, Jane Example. You replace her name everywhere with [NAME1], her email with [EMAIL1] and a colleague's name with [NAME2]. The text stays readable, and you can still follow who did what. That is the point of consistent labels, and it is exactly why this is pseudonymization.
The Article 29 Working Party, the EDPB's predecessor, explains why in Opinion 05/2014. Pseudonymization replaces one attribute with another: a useful security measure, but not a method of anonymization. The opinion tests each technique against three risks.
- Singling out: can you isolate what concerns one person? With [NAME1], yes: every sentence about her carries the same label.
- Linkability: can you link records about the same person, here or in another file? A shared label does exactly that.
- Inference: can you deduce something about her with significant probability? Her job, her team and the incident date may be enough.
On 4 September 2025, in EDPS v SRB (C-413/23 P), the EU Court of Justice added a nuance. The case concerned EU bodies, but the Court reads the concept of personal data as in the GDPR. Pseudonymized data is not personal data in all cases and for every person. For a recipient with no reasonable means of re-identification, it may not be. For the party holding the additional information, such as you with your original, it stays personal.
What is redaction, and where does it fit?
Redaction is an operation on one document. You mask passages in it: a name, an account number, a signature, a face in a photo. The classic form is the black bar. The word describes what you do to the page, not the legal status of what is left.
That status depends on the result. Black out the names in a contract but leave the address, job title and dates, and the people usually stay identifiable. Replacing values with labels is also redaction, and it produces a pseudonymized document.
Which one do you need for your document?
| Technique | Reversible? | Still personal data? | Typical use |
|---|---|---|---|
| Black bars, applied properly | Not the shared copy | Usually, if the rest points to a person | Sending a contract or payslip to someone who needs only part of it |
| Labels such as [NAME1] (pseudonymization) | Yes, with the key or the original | Yes for you. For a recipient, it depends on their means | Sharing a case file with an expert, a translator or an AI tool |
| Anonymization | No | No, once truly achieved | Publishing statistics or open data |
| Removing names only | Often, by cross-checking details | Yes, in most cases | A first step, never enough alone |
- 1List who will see the document and what they must read.
- 2Mark direct identifiers: names, emails, phone numbers, addresses, ID and account numbers, signatures, photos.
- 3Mark indirect identifiers: job titles, rare dates, places, small teams, unusual facts.
- 4Use black bars if the reader does not need the content, and labels if they must follow who is who. For a public file, aim for anonymization.
- 5Export a flattened copy without metadata, paste its text into an editor and search for a masked name.
- 6Reread it as a stranger would. If you can tell who it is, mask more or treat the file as personal data.
I removed the names. Is my document anonymous?
Almost never. The ICO says a person can be identifiable even if you do not know their name, and that simply removing direct identifiers is not enough. Picture a disciplinary report without the name Jane Example. It still says: the only night-shift pharmacist at the Springfield site, hired in March 2019. Any colleague knows who it is.
The ICO suggests the motivated intruder test: could a reasonably competent person, using the internet, libraries and public documents, identify someone? If so, the file is not anonymous. The ICO also warns of the mosaic or jigsaw effect: details that seem harmless alone can identify someone once combined.
What should you do in practice?
Use the right word: say masked, redacted or pseudonymized, and say anonymized only when it truly is. Then keep treating the file as personal data: few recipients, a secure channel, deletion when the job is done. Always work on a copy.
Dedicated redaction software, a PDF editor's redaction feature or a browser-based tool can do the masking. ONYRI Sanitize is a browser-based tool: detection and masking run in your browser, and the file is not uploaded. It offers black bars, or labels such as [NAME1] on the Pro plan, and always exports a flattened PDF or image. Detection is not exhaustive, so review each item before downloading. Masking reduces exposure. It does not, by itself, make a document anonymous.
Frequently asked questions
- Is pseudonymized data still personal data?
- Yes, for anyone who holds the additional information, such as the key or the original. Recital 26 says so, as do the EDPB's draft guidelines on pseudonymisation of January 2025. Since the Court of Justice ruling of September 2025, the data may not be personal for a recipient with no reasonable means of re-identification. That is assessed case by case.
- If I delete the key or the original, does the data become anonymous?
- Not automatically. Opinion 05/2014 says that as long as the key or the original data are available, the possibility of identifying the person is not eliminated. And deleting them is not enough, because other details can still point to the person. The opinion calls for extra steps, such as removing and generalising attributes.
- Which technique fits before pasting a document into an AI tool?
- Consistent labels usually work best: the model can still follow who did what. But the labelled text is still personal data for you, since you hold the original. Check indirect identifiers too, and follow your organization's rules on AI tools.
Sources & references
- Regulation (EU) 2016/679 (GDPR), Article 4(5) and Recital 26 — EUR-Lex
- Opinion 05/2014 on Anonymisation Techniques (WP216), adopted 10 April 2014 — Article 29 Data Protection Working Party
- Anonymisation guidance: Pseudonymisation — Information Commissioner's Office (ICO)
- Anonymisation guidance: How do we ensure anonymisation is effective? — Information Commissioner's Office (ICO)
- Disclosing documents to the public securely: how do we avoid an accidental breach when redacting information? (31 July 2025) — Information Commissioner's Office (ICO)
- Judgment of 4 September 2025, EDPS v SRB, C-413/23 P — Court of Justice of the European Union (EUR-Lex)
- EDPB adopts pseudonymisation guidelines (17 January 2025, draft for public consultation) — European Data Protection Board
Mask a document without uploading it
ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.