Anonymisation and Pseudonymisation: Why the Difference Matters
1st July 2026
A recent French case is a useful reminder that just calling data anonymised does not make it so. On 26 May 2026, the CNIL fined IQVIA Operations France €5 million for failings in two health data warehouses holding records on tens of millions of French residents. IQVIA argued the data was anonymous; the CNIL found it was pseudonymised, and therefore still personal data, and therefore still squarely within the scope of the GDPR. The decision echoes a Conseil d’État ruling earlier in 2026 against the Cegedim group on the same point. For UK businesses, the message is identical: the line between anonymisation and pseudonymisation is not a label you apply but a standard you have to meet.
The difference
Pseudonymisation, defined in Article 4(5) of the UK GDPR, is the process of replacing identifying information with codes or references, keeping the key separately and securely. Done well, it is a powerful security measure. But the data remains personal data, and the UK GDPR still applies in full.
Anonymisation goes further. The ICO’s guidance on anonymisation explains that anonymised data is information from which a person cannot be identified, either on its own or when combined with other reasonably available information. Once data is genuinely anonymous, data protection law no longer applies. The bar is high: the ICO uses a ‘motivated intruder’ test, asking whether a reasonably competent person with no special knowledge could re-identify someone from the data set. The IQVIA decision is the latest reminder that aggregation and code-replacement do not, on their own, pass this test.
Obfuscating the name and address are not enough!
One of the key failings that led to Cegedim Group’s difficulties with the CNIL was its narrow focus on the record identifier. It assumed that replacing the patient’s name and address with a URN was enough to make the record pseudonymised, without considering the information contained within the record itself. In reality, the records still included extensive detail such as age, gender, medical history, prescriptions, sick leave, vaccinations, medicines purchased, and the exact dates and times of medical appointments or pharmacy visits. They also included the names of treating physicians, who could easily be traced.
Why this matters for retention
The storage limitation principle at Article 5(1)(e) means you cannot keep personal data indefinitely. You have two practical routes if you want to keep something long-term:
- Delete the data when its original purpose ends.
- Anonymise it properly, after which the UK GDPR no longer applies.
Pseudonymisation, on its own, does not buy you indefinite retention. Pseudonymised data remains personal data and is still subject to retention rules, lawful basis requirements, and data subject rights. The pay-off from pseudonymisation is in day-to-day risk reduction, not in escaping the obligations of holding the data.
The research exemption
The UK GDPR provides limited derogations for archiving in the public interest, scientific or historical research, and statistical purposes, where appropriate safeguards are in place. Pseudonymisation is the principal safeguard mentioned. In this narrow context, processing can continue for longer than its original purpose and some rights such as erasure may be restricted. The exemption is not a blanket research carve-out: you still have to demonstrate the public interest, the necessity, and the safeguards.
Pseudonymisation as a security measure
Even where genuine anonymisation is not appropriate, pseudonymisation is worth doing. Article 32 of the UK GDPR names pseudonymisation among the technical measures organisations should consider, alongside encryption. The benefit is concrete: if an attacker takes a pseudonymised data set without the key, the harm is materially reduced. That can also affect whether the resulting breach is reportable. Pseudonymisation does not let you off the GDPR hook, but it can significantly improve your security posture.
How Griffin House Consultancy Can Help
Getting anonymisation right is technically demanding, and the IQVIA decision shows that getting it wrong is expensive. We help organisations assess whether their data is genuinely anonymised, design effective pseudonymisation schemes, build the safeguards required for research processing, and document the decisions in a way that stands up to scrutiny. Get in touch with us at Griffin House Consultancy, or call us on 01673 885533, and one of our team will be happy to talk it through.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.