The EDPB's draft Guidelines 02/2026 on Anonymisation, released July 7, 2026, pose a practical question: when you anonymize a dataset, are you doing it for the entity that controls it today, or for everyone who might access it tomorrow?
This decision impacts whether you can share research data with partners, whether your analytics vendor processes personal data, and whether your cross-border transfers need Standard Contractual Clauses. The Guidelines describe two methodologies, contextual and simplified, and your compliance depends on choosing the right one.
The Decision You're Facing
You need to determine whether a dataset qualifies as anonymous under the General Data Protection Regulation. The EDPB's framework offers two paths:
Contextual approach: Assess anonymity based on the specific means available to identified entities who will access the data, considering their technical capabilities, legal restrictions, and realistic incentives to re-identify individuals.
Simplified approach: Apply a generalized standard that assumes any actor, including those with advanced capabilities or malicious intent, could attempt re-identification.
Your choice isn't just methodological. It defines your legal obligations. If you conclude data is anonymous under a contextual assessment but a regulator later disagrees, you've been processing personal data without a legal basis, without appropriate safeguards, and potentially without valid consent.
Key Factors That Affect Your Choice
Who accesses the data? The Guidelines emphasize identifying relevant entities before assessing anonymity. Consider access, control, sharing arrangements, and whether one party acts on another's behalf. If you're sharing data with a processor, the anonymity assessment must be conducted from your perspective as controller, the processor inherits your determination.
What means are reasonably likely? Recital 26 of the General Data Protection Regulation establishes that re-identification risk depends on means "reasonably likely to be used." The Guidelines clarify this isn't just a technical question. Means that are impossible, disproportionate in time or cost, or legally prohibited may fall outside the test. But don't lean too hard on legal restrictions: the EDPB warns that contractual prohibitions aren't equivalent to statutory ones, and actors like cybercriminals won't comply with either.
Can you meet the three criteria? Both approaches require evaluating:
- Record Isolation: No unique combination of attributes relates to a single individual.
- Linkage: Records can't be linked to other datasets identifying the same individual with certainty or high likelihood.
- Inference: The data doesn't support specific, meaningful conclusions about individuals.
If your dataset fails any criterion, you need additional controls or a different approach.
What's your risk tolerance? The EDPB warns that contextual assessments "may falsely conclude that a dataset is anonymous." The simplified approach sets a higher bar but offers more defensibility.
Path A: Choose Contextual When You Control Distribution
Use a contextual approach when:
You're sharing with a defined set of recipients. If you're providing anonymized datasets to specific research institutions under contract, assess anonymity based on their specific capabilities and constraints. Document who they are, what technical means they possess, and what legal or contractual restrictions apply.
The data stays within your organization. If your analytics team processes anonymized customer data and never shares it externally, assess anonymity from your own perspective. Consider your internal access controls, technical environment, and whether staff have access to auxiliary data that could enable re-identification.
You can enforce technical and legal barriers. The Guidelines suggest re-identification may not be reasonably likely where you've implemented both technical controls (encryption, access restrictions, audit logging) and legal prohibitions (contracts with liquidated damages, regulatory restrictions on data use). Neither alone is sufficient.
You need operational flexibility. Contextual anonymization lets you work with datasets that wouldn't pass a simplified assessment. If you're running machine learning models on health data and need quasi-identifiers for stratification, a contextual approach may be your only viable path.
Document everything. The EDPB's caution about false conclusions means you'll need to show your work: who are the relevant entities, what means do they possess, why is re-identification not reasonably likely for each entity?
Path B: Choose Simplified When Data Moves Beyond Your Control
Use a simplified approach when:
You're publishing data publicly. If you're releasing datasets on an open data portal, sharing aggregated statistics in research papers, or providing data to journalists, you can't predict who will access it or what auxiliary information they'll combine it with. Assume sophisticated actors with advanced capabilities.
Recipients have strong re-identification incentives. The Guidelines note that specialist third-party re-identification services exist. If your recipients operate in competitive intelligence, investigative journalism, or litigation support, assume they'll use them.
You're sharing across jurisdictions. Legal prohibitions vary by jurisdiction. What's illegal in the EU may be permissible elsewhere. A simplified approach doesn't rely on legal barriers that may not apply to all recipients.
You need regulatory defensibility. The simplified approach applies a higher standard, which means it's harder to meet, but easier to defend. If you're in a sector facing heightened scrutiny (health, finance, government), the additional rigor may be worth the operational constraints.
This path requires more aggressive anonymization techniques: higher k-anonymity thresholds, more generalization, stronger noise injection. You'll lose analytical utility, but you'll gain confidence that no regulator will challenge your determination.
Path C: Combine Both Approaches for Staged Processing
The Guidelines explicitly allow combining methodologies. Consider a hybrid approach when:
You process data in stages. Apply contextual anonymization for internal analytics, then apply simplified techniques before external sharing. This lets you preserve detail for internal use while ensuring external releases meet a higher bar.
You're building a data clean room. Assess anonymity contextually within the clean room environment (known parties, controlled access, technical barriers), but apply simplified standards to any outputs that leave the environment.
You're testing your assumptions. Run both assessments in parallel. If they reach different conclusions, you've identified where your contextual controls are insufficient. Either strengthen them or accept that you're processing personal data.
Summary Matrix
| Factor | Contextual Approach | Simplified Approach |
|---|---|---|
| Recipients | Defined, contractually bound | Unknown or unrestricted |
| Access controls | Strong technical and legal barriers | Limited or unenforceable |
| Re-identification incentive | Low or neutral | High (competitive, investigative) |
| Distribution | Controlled sharing | Public or cross-border |
| Regulatory risk | Moderate (EDPB cautions against false conclusions) | Lower (higher standard, more defensible) |
| Analytical utility | Higher (preserves more detail) | Lower (requires aggressive anonymization) |
| Legal basis requirement | Yes, if anonymization serves a different purpose than original processing | Yes, if anonymization serves a different purpose than original processing |
| Processor obligations | Processor inherits controller's determination | Processor inherits controller's determination |
The EDPB's consultation period runs until October 30, 2026. If your organization relies on contextual anonymization for significant data flows, consider submitting feedback. The final Guidelines will shape enforcement priorities for years to come.
Remember: both approaches require a legal basis under the General Data Protection Regulation if anonymization serves a different purpose than your original processing. And if you're processing special categories of data, you'll need an Article 9 derogation as well. Anonymization doesn't exempt you from lawful processing requirements, it changes what happens after you've processed lawfully.



