Pseudonymised data is still personal data; only information that cannot be related to an identifiable person leaves the regulation's scope.
Why it matters when the plan changes
Suppliers describe data as anonymised when they mean pseudonymised, and the difference decides whether every obligation still applies. The regulation defines pseudonymisation as data that cannot be attributed to a person without additional information held separately, which is why the key, not the label, decides the category. A leadership team of eight with names removed is not anonymous, because the combination of role, tenure and result identifies each person to anyone who knows the team. Most organisational datasets are small enough for that to be true.
The tension is that real anonymisation destroys much of what makes organisational data useful. The individual-level detail that identifies people is the same detail that carries the signal. Recital 26 draws the line at data that no longer relates to an identifiable person at all; short of that line, the safeguard sits inside the regulation rather than outside it. The honest position reserves the word anonymous for aggregates that have genuinely lost the individual.
In practice
A supplier's deck says all benchmark data is anonymised. Asked how, the answer is that names and email addresses were removed. Each record still carries company, function, level, country and a full assessment profile. In a company with one finance director in Denmark, that record is that person, and the benchmark is personal data being processed for a purpose nobody was told about.
Evidence
Pseudonymisation means processing so that data can no longer be attributed to a specific person without additional, separately kept information.
Article 4, General Data Protection Regulation (2016)The principles of data protection do not apply to anonymous information that does not relate to an identifiable person.
Recital 26, General Data Protection Regulation (2016)
What it cannot tell you
The distinction tells you whether the regulation applies; it does not tell you whether identification is actually likely in practice, or how small a population must be before pseudonymisation fails as a safeguard. It offers a legal threshold, not a technical guarantee, and a dataset can pass the test on paper while remaining identifiable to anyone who already knows the group.
Questions
Because the key exists. Article 4 of the GDPR (2016) defines pseudonymisation as processing that prevents attribution only with additional information kept separately, not processing that removes it entirely. The regulation looks at whether identification is possible by any means reasonably likely to be used, not at whether the current holder has the key.
Recital 26 of the GDPR (2016) states that data protection principles do not apply to anonymous information that does not relate to an identifiable person. For small populations such as a leadership team, reaching that point usually requires aggregation to a level where individual patterns are no longer visible at all.
Almost never. Role, function, level, country and tenure identify most senior people inside their own organisation, and an assessment profile is itself distinctive enough to do the same. Removing direct identifiers produces pseudonymised data, which still carries every obligation the original record did.
Because it ends the conversation. Anonymous data needs no basis, no notice and no retention limit, so calling data anonymous removes every difficult question at once. Regulators and works councils know this, which is why the word invites scrutiny rather than deflecting it.
Real, and recognised. It limits who can see identities in day-to-day processing and reduces the harm of a breach, and the regulation names it as an appropriate security measure. Its value is as protection inside the rules, not as a route around them.