PDPL Guide No. 13 – Is pseudonymized data considered personal data?

The Implementing Regulation to the PDPL provides for a definition of the “pseudonymization”:

Article 1 (7) of Implementing Regulation to the PDPL

Conversion of the main identifiers that indicate the identity of the Data Subject into codes that make it difficult to directly identify them without using additional data or information. The pseudonymized data or additional information should be kept separately, and appropriate technical and administrative controls should be implemented to ensure that they are not specifically linked to the data subject>s identity.

Pseudonymization is a technique that replaces or removes data in a dataset that directly identifies an individual. Pseudonymized data is still considered personal data and acts as an effective data security measure. Pseudonymization involves masking identifying data, for example by replacing directly identifying data (such as names) with a unique identifier. Such an identifier can no longer be attributed to a particular individual without the use of additional data.

Pseudonymization is a data protection and security-enhancing measure that assists with risk mitigation. It is used in a number of areas, for example, clinical trials and medical research, financial sector, etc.

Example | Pseudonymization | Banking services

A bank wants to provide special offers to its customers. The offers depend on the customers’ volume of transactions.

The bank took the following steps.

1. It separated the names of customers from their transactions into two separate databases:

• the first database contains names of the customers;

• the second database contains the volumes of their transactions;

• the names of the customers were replaced with symbols in the second database.

2. These two separate databases were provided to two separate teams in the bank for analysis.

3. Each team held its own passwords to the database. One team could not access the database of the other team.

Therefore, the bank pseudonymized the data of its customers.

In this case, the data on volumes of transactions will be considered personal data. This is because:

• it will be possible to link volumes of transactions to particular customers, if both databases are combined;

• both databases are kept within the same bank and the bank has a real possibility to combine such databases when required.

Example | Pseudonymization | Educational sector

A university maintains a database with data of its students. In this database, each student has his/ her own unique ID number.

When undertaking their exams, students are required to specify in the exam papers their ID number only. When the exam board reviews the exam papers, the exam board can only see the ID number of each student. The exam board does not know the name of the student who took the exam. The exam board does not have access to the database where the ID numbers are matched with the names of the students.

Therefore, the university in this case pseudonymized the names of the students.

The ID numbers of students will still be considered as personal data. This is because the university may match in its database the ID numbers with names of the students.

Scroll to Top