Entrance and European flags at the European Commission's Berlaymont building in Brussels
GDPRRemoved the names? Check what the remaining data reveals.
The European Commission's Berlaymont building, Brussels.Image: © European UnionCC BY 4.0Image fitted for layout; headline added by Securelay. Editorial context, not endorsement.
Primary source EDPB: Guidelines 02/2026 public consultation and feedback datesPrimary source EDPB: Guidelines 02/2026, version 1.0 adopted for public consultation

A consultation, not a new regulation

The EDPB adopted version 1.0 of Guidelines 02/2026 on Anonymisation for public consultation on 7 July 2026. As checked on 7 September, its consultation page lists a feedback period ending on 30 October 2026. The draft is not a new GDPR regulation. Its status matters when writing policies or answering a customer questionnaire.

Look beyond the obvious identifiers

The draft considers anonymity from the perspective of relevant entities and the means reasonably likely to identify someone. Its framework examines record isolation, linkage and inference. In practical terms, removing a name is only the beginning: other attributes, linked records and what a recipient can reasonably access may still matter.

An example to discuss with your privacy team

Imagine a synthetic recruitment dataset that contains no names but includes exact job histories, a small town and a rare professional qualification. Before calling it anonymous, ask whether public information could connect those details to someone. Removing direct identifiers and proving anonymity are different exercises. This example is an engineering review prompt, not a legal conclusion about a real dataset.

Make the release decision reviewable

Our suggested release checklist records the intended recipient, purpose, retained fields, supporting information available to that recipient, tests performed and who accepted the remaining risk. Consider whether the task can use fewer fields, less precise values or aggregated results. Revisit the assessment when you change the recipient, add a data source or change the use.

Use precise language for protected references

Securelay's redaction and tokenisation controls can reduce exposure on integrated routes. A protected reference is not, by itself, proof of anonymous data. Where values can be restored through a governed mapping, describe the implemented protection accurately and assess the remaining data. Keep the legal anonymity assessment separate from evidence that a configured transformation ran.

Put the control on the data path.Discuss an architecture review