De-identified data in North America: California, US states and Québec
What “deidentified” means under California’s CCPA and Virginia law, what Québec’s Law 25 adds, and what to do before sending a document there.
Masking a document does not make it “deidentified” in North America. In California and Virginia, the business holding the data must also promise publicly not to re-identify it and bind its recipients by contract. In Québec, removing direct identifiers such as names only makes information “de-identified”, which is still personal information.
This guide is for European teams who exchange documents with the United States or Québec. It is dated October 2026, and it is information, not legal advice.
What does “deidentified” mean under California’s CCPA?
The California Consumer Privacy Act (CCPA) defines “deidentified” in Civil Code section 1798.140(m). The text published by the California Privacy Protection Agency, in the version effective 1 January 2026, opens like this:
“Deidentified” means information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer provided that the business that possesses the information:
- takes reasonable measures so the information cannot be tied to a consumer or household;
- publicly commits not to re-identify it, except to test its own process;
- contractually obligates every recipient to follow the same rules.
So the test looks at the holder, not only at the file. Say Claire Exemple, a paralegal in Lyon, sends a perfectly masked contract to a client in San Diego. If that client has made no public promise not to re-identify the data, the file is not deidentified. If all three conditions are met, subdivision (v)(3) takes it out of “personal information”.
Subdivision (aa) defines “pseudonymize”: data that cannot be tied to a consumer without extra information kept separately. The law does not exclude it from personal information. Names replaced by codes, with the key stored elsewhere, are pseudonymized, not deidentified.
Do other US state privacy laws use the same test?
Virginia’s Consumer Data Protection Act follows the same model. Its section 59.1-575 defines “de-identified data” as data that cannot reasonably be linked to an identified or identifiable person. Section 59.1-581 gives the holder three similar duties. It adds a fourth: whoever discloses such data must check that recipients keep their contract promises.

Both laws have thresholds on revenue or data volume, so a small partner may fall outside them. We checked only these two states, and wording varies. So read the law that covers your partner. US health records follow a separate federal rule, HIPAA, covered in its own article.
How does Québec’s Law 25 define anonymized information?
“Law 25” is the short name of the Act to modernize legislative provisions as regards the protection of personal information (2021, chapter 25). It amended Québec’s Act respecting the protection of personal information in the private sector (chapter P-39.1). Since 22 September 2023, section 23 of that Act says:
information concerning a natural person is anonymized if it is, at all times, reasonably foreseeable in the circumstances that it irreversibly no longer allows the person to be identified directly or indirectly.
Section 12 sets a lower level, “de-identified”: information that no longer identifies the person directly. It stays personal information, and the business must limit the risk of re-identification. Québec’s privacy authority, the Commission d’accès à l’information (CAI), gives examples: removing names, addresses and social insurance numbers.
What does the anonymization regulation require?
The « Règlement sur l’anonymisation des renseignements personnels » (Regulation respecting the anonymization of personal information) was published on 15 May 2024. It took effect fifteen days later, on 30 May 2024, and its register duty on 1 January 2025. A business that anonymizes personal information must:
- set the purposes first (section 3);
- work under a competent supervisor (section 4);
- remove direct identifiers, then analyse re-identification risks (section 5);
- apply recognized techniques and security measures (section 6);
- show that the remaining risk is very low, though not necessarily zero (section 7);
- reassess regularly as technology advances (section 8);
- record all of this in a register (section 9).
The analysis looks in particular at three criteria: individualization (singling a person out), correlation (linking data sets about one person) and inference (deducing personal information from other data). According to France’s CNIL, European data protection authorities use the same three criteria.
What does federal Canadian law say?
Canada’s federal private-sector law, the Personal Information Protection and Electronic Documents Act (PIPEDA), never defines anonymization. Clause 4.5.3 of its Schedule 1 just says that information no longer needed should be destroyed, erased or made anonymous. The version current to 21 September 2026 still says so. Careful: its French text says « dépersonnaliser » here, while Québec uses « dépersonnalisé » for mere de-identification.
Reform is slow. The Privacy Commissioner of Canada reports that Bill C-27 died with the prorogation of Parliament in January 2025. Bill C-36, introduced on 15 June 2026, would define anonymizing as an irreversible change with no reasonably foreseeable risk of identification. As the Library of Parliament noted in July 2026, it has no force until passed.
How do these rules compare side by side?
| Jurisdiction | Term and source | Test | Duties beyond masking | For a document |
|---|---|---|---|---|
| California | “Deidentified”, Civil Code 1798.140(m) | Cannot reasonably be linked to a consumer | Reasonable measures, public promise, contracts with recipients | Masking is step one. The holder does the rest |
| Virginia | “De-identified data”, Code 59.1-575 and 59.1-581 | Cannot reasonably be linked to an identifiable person | Three similar duties, plus oversight of recipients | Same as California |
| Québec, anonymized | Section 23 of P-39.1 and the 2024 regulation | Irreversibly no longer identifies anyone | Purposes, competent supervisor, risk analysis, review, register | Hard to reach for one document |
| Québec, de-identified | Section 12 of P-39.1 | No longer identifies the person directly | Reasonable measures against re-identification | Where a masked file usually lands. Still personal information |
| Canada, federal | PIPEDA, no definition. Bill C-36 is not law | Information about an identifiable individual | None specific today | Treat it as personal information |
What should an EU business do before sending a document?
The GDPR still applies to you when you send the file. The European Commission recognizes Canada for commercial organizations, and the United States only for companies in the EU-US Data Privacy Framework.
- Send only what the recipient needs.
- Mask direct identifiers: names, emails, phone numbers, Social Security or social insurance numbers, account numbers, signatures.
- Check what the recipient can combine: a job title, a date and a small town can point to one person.
- When a US partner sends you deidentified data, expect to promise by contract not to re-identify it.
- Before sending you personal information, a Québec business must run a privacy impact assessment and sign a written agreement (section 17 of P-39.1, as the CAI explains).
On an American document, ONYRI Sanitize uses its US formats. It finds Social Security numbers (never-issued ranges are skipped), EINs, ZIP codes, US phone numbers and street addresses. It also finds passport and bank routing numbers, and driver’s license and account numbers only next to their label. Canada is not among its countries, so mask a Social Insurance Number by hand. No tool makes the commitments or signs the contracts for you.
These rules move. Check the current text before relying on one. Then ask your data protection officer, a lawyer in your partner’s state or province, or the CAI.
Frequently asked questions
Is a masked PDF automatically deidentified under the CCPA?
No. The holder must also take reasonable measures, publicly commit not to re-identify the data and bind its recipients by contract. Masking covers only part of the first condition.
In Québec, is a document without names anonymized?
Usually not. At best it is de-identified under section 12, which stays personal information. Anonymization needs the full process of the 2024 regulation, including a risk analysis and a register.
Does federal Canadian law define anonymized data?
Not today. PIPEDA mentions making information anonymous without defining it. Bill C-36 would define it, but a bill has no force until it is passed and comes into force.
Is a file deidentified in California anonymous under the GDPR?
Not automatically. Recital 26 of the GDPR asks whether anyone could still identify the person by means reasonably likely to be used. Check the file against that test too.
Sources & references
- California Consumer Privacy Act of 2018, statute text effective 1 January 2026 (Civil Code section 1798.140)California Privacy Protection Agency
- Code of Virginia section 59.1-575, Definitions (Consumer Data Protection Act)Virginia General Assembly
- Code of Virginia section 59.1-576, Scope; exemptions (Consumer Data Protection Act)Virginia General Assembly
- Code of Virginia section 59.1-581, Processing de-identified data; exemptionsVirginia General Assembly
- Bill 64 (2021, chapter 25), An Act to modernize legislative provisions as regards the protection of personal informationQuébec Official Publisher
- Regulation respecting the anonymization of personal information, O.C. 783-2024, Gazette officielle du Québec, 15 May 2024Publications du Québec
- Conservation et destruction des renseignements personnels: anonymisation et dépersonnalisation (in French)Commission d’accès à l’information du Québec
- Principaux changements apportés par la Loi 25 (in French)Commission d’accès à l’information du Québec
- Personal Information Protection and Electronic Documents Act, full text (current to 21 September 2026)Justice Laws Website, Government of Canada
- Loi sur la protection des renseignements personnels et les documents électroniques, texte complet (in French)Justice Laws Website, Government of Canada
- 2024-2025 Annual Report to Parliament on the Privacy Act and PIPEDAOffice of the Privacy Commissioner of Canada
- Legislative Summary of Bill C-36, preliminary version, 6 July 2026Library of Parliament
- Adequacy decisionsEuropean Commission
- L’anonymisation de données personnelles (in French)CNIL
- GDPR Recital 26, Not applicable to anonymous datagdpr-info.eu
- 45 CFR 164.514, Other requirements relating to uses and disclosures of protected health informationLegal Information Institute, Cornell Law School