Deidentification: Anonymous vs Pseudonymous and Identifiers
Last reviewed:
When data cannot be traced to a person, privacy law no longer applies. Anonymization removes identifiability; pseudonymization masks identity with a unique identifier. EU law treats pseudonymized data as personal under the GDPR, but anonymized data falls outside it. Identifiers range from strong identifiers to quasi-identifiers.
Privacy laws apply to personal data; when data can no longer be traced to a person, they no longer apply. Anonymization removes identifiability, while pseudonymization masks identity behind a unique identifier (e.g. 'Patient 13579'). EU law treats pseudonymized information as personal data under the GDPR, in contrast to anonymized data, which falls outside the GDPR.
| Identifier | Example / nature |
|---|---|
| Strong identifier | Social Security or passport number; clearly identifying |
| Weak identifier | Must be combined with other information to identify |
| Quasi-identifier | Date of birth - over 25,000 cells (366 days x 80+ years) make it highly identifying when combined with external knowledge |
FTC Chair Ramirez (2016): data is personally identifiable when it can be reasonably linked to a particular person, computer, or device - including persistent identifiers like device IDs, MAC addresses, static IPs, and loyalty card numbers. Linked data already ties to identity; linkable data could be tied to it.
Key terms - quick answers
What is “Anonymization”?
What is “Pseudonymization”?
What is “Deidentified”?
What is “Strong identifier”?
Keep going - free
Every study note on this site is free. So are these: