Removing names from a spreadsheet does not automatically make the people inside it anonymous. Dates, locations, job titles, rare conditions and purchasing patterns can still identify someone when they are combined with other information.
Effective anonymisation is a deliberate process of reducing that identification risk while preserving enough useful detail for analysis, research or controlled sharing. It can create substantial business and public value. It also demands careful testing, documented decisions and an honest view of what the transformed data can still reveal.
Anonymisation succeeds when the remaining information cannot reasonably be used to single out or reconnect a person.
The practical thresholdThe difference changes how the information must be governed
The ICO describes anonymisation as turning personal data into information from which people are no longer identifiable. Properly anonymous information falls outside the UK GDPR, although other duties, contracts and confidentiality rules may still apply. The act of creating it remains a personal-data processing operation and therefore needs a lawful purpose and appropriate controls.
Pseudonymisation sits on the other side of that line. Names or account numbers may be replaced with codes, while a separate key allows authorised people to reconnect the records. This can reduce exposure and support data minimisation, but the result remains personal data because re-identification is still possible with the additional information.
The European Data Protection Board's July 2026 draft anonymisation guidelines add a useful current point: anonymity may need to be assessed from the perspective of each party for whom the data is intended to be anonymous. The draft is open for consultation, so organisations should treat it as developing guidance rather than a final settled position.
A familiar trapHashing an email address, masking a postcode or deleting a name may reduce direct identification. None of those actions proves that the complete dataset is anonymous. The surrounding attributes and available external data still matter.
Anonymisation usually combines several transformations
Suppression, masking and tokenisation
Direct identifiers can be deleted, partly hidden or replaced with tokens. These are useful first steps and can be enough for tightly controlled pseudonymous processing. Rare combinations of remaining details may still identify a person, so removal alone is rarely a complete assessment.
Grouping detail into broader categories
Exact ages can become age bands, precise locations can become regions and individual dates can become months or quarters. Generalisation reduces the chance of singling someone out, although each broader category also removes analytical precision.
Adding controlled uncertainty
Noise, swapping and perturbation change values while preserving useful patterns across a larger dataset. Differential privacy goes further by providing a mathematical way to quantify privacy loss. Poorly chosen parameters can still produce weak privacy or unusable results.
Generating representative artificial records
Synthetic data is produced from a model rather than released as a direct copy of the source records. It can support testing and analysis, but the model must be checked for memorisation, disclosure and distorted representation of important groups.
The benefits are strongest when the purpose is clear
More responsible data use
- Share trends and research without disclosing unnecessary identities.
- Create safer datasets for analytics, testing and product development.
- Reduce the impact of an accidental disclosure or unauthorised access.
- Retain useful statistical information after personal-data retention ends, where appropriate.
Risk does not disappear automatically
- External datasets can make linkage and re-identification easier.
- Aggressive transformation can remove the detail needed for the task.
- New technology and new data sources can change the risk over time.
- Legal status can be misclassified when governance relies on a tool label.
NIST describes de-identification as a family of techniques rather than one universal method. Its guidance recommends deciding the intended sharing model, measuring disclosure risk and testing whether the transformed data can be re-identified. That is a useful discipline outside government as well. A dataset published openly needs a different threshold from one accessed by a small, contracted research team inside a protected environment.
Treat anonymisation as a maintained control
Define
State the purpose, audience and minimum detail needed.
Map
Find direct identifiers, quasi-identifiers and likely external linkages.
Transform
Combine techniques that fit the data and intended use.
Test
Measure re-identification risk and check that the output remains useful.
Review
Reassess the release when data, recipients or available technology change.
Controls around the data still matter
Anonymisation can be combined with access restrictions, contractual limits, secure environments, logging and monitoring. These organisational controls are especially important where full anonymisation would destroy the value of the information or where the dataset remains pseudonymous.
Anonymising a dataset and protecting a file exchange are related, but distinct
My MX Data is a secure B2B file-exchange platform for organisations that need control when sensitive information moves between customers, suppliers and partners. After this first reference, MX provides the shorthand.
Relevant MX Enterprise configurations can use ASR, which stands for Anonymise, Shard and Restore. The process transforms the data, separates it into protected shards and restores the file for an authorised recipient. No single readable file is retained in one place through that process.
The visual below is useful because it shows the three ASR stages without presenting the method as another name for encryption.
ASR protects the exchange pathway
ASR works alongside AES-256 encryption, named-recipient access, multi-factor authentication and audit records. The word "Anonymise" in ASR should not be treated as an automatic legal conclusion that a business dataset has become anonymous information under UK GDPR.
For sensitive B2B transfers, MX can combine this additional method with expiry settings and a traceable activity record. Organisations can explore the wider approach through MX's encrypted business file-sharing controls.
A sound operating ruleUse the least identifiable data that still supports the task, then apply access and exchange controls that match the remaining risk. Anonymisation, encryption and identity management solve different parts of the problem.
Further reading
- ICO introduction to anonymisation
- ICO guidance on effective anonymisation
- EDPB Guidelines 02/2026 on Anonymisation, public consultation version
- NIST SP 800-188 on de-identification techniques and governance
- NIST guidance on differential privacy guarantees
- My MX Data guide to ASR and advanced exchange controls