Anonymised Data Explained: Methods, Benefits and Reidentification Risks

Removing a name does not always make a dataset anonymous. Other details can reconnect records to people, which makes technique, context and re-identification risk essential.

In this guide

Removing names from a spreadsheet does not automatically make the people inside it anonymous. Dates, locations, job titles, rare conditions and purchasing patterns can still identify someone when they are combined with other information.

Effective anonymisation is a deliberate process of reducing that identification risk while preserving enough useful detail for analysis, research or controlled sharing. It can create substantial business and public value. It also demands careful testing, documented decisions and an honest view of what the transformed data can still reveal.

IdentifiableA person can be recognised directly or through linked information.
PseudonymisedIdentifiers are replaced, but additional information can reconnect the data to a person.
AnonymisedPeople are no longer identifiable using means reasonably likely to be used.
Protected exchangeThe file remains controlled while it moves between authorised parties.

Anonymisation succeeds when the remaining information cannot reasonably be used to single out or reconnect a person.

The practical threshold
The legal lineAnonymous and pseudonymous data

The difference changes how the information must be governed

The ICO describes anonymisation as turning personal data into information from which people are no longer identifiable. Properly anonymous information falls outside the UK GDPR, although other duties, contracts and confidentiality rules may still apply. The act of creating it remains a personal-data processing operation and therefore needs a lawful purpose and appropriate controls.

Pseudonymisation sits on the other side of that line. Names or account numbers may be replaced with codes, while a separate key allows authorised people to reconnect the records. This can reduce exposure and support data minimisation, but the result remains personal data because re-identification is still possible with the additional information.

The European Data Protection Board's July 2026 draft anonymisation guidelines add a useful current point: anonymity may need to be assessed from the perspective of each party for whom the data is intended to be anonymous. The draft is open for consultation, so organisations should treat it as developing guidance rather than a final settled position.

A familiar trapHashing an email address, masking a postcode or deleting a name may reduce direct identification. None of those actions proves that the complete dataset is anonymous. The surrounding attributes and available external data still matter.

Technique selectorDifferent methods solve different problems

Anonymisation usually combines several transformations

Suppression, masking and tokenisation

Direct identifiers can be deleted, partly hidden or replaced with tokens. These are useful first steps and can be enough for tightly controlled pseudonymous processing. Rare combinations of remaining details may still identify a person, so removal alone is rarely a complete assessment.

Business valueUseful data with lower exposure

The benefits are strongest when the purpose is clear

Potential benefits

More responsible data use

  • Share trends and research without disclosing unnecessary identities.
  • Create safer datasets for analytics, testing and product development.
  • Reduce the impact of an accidental disclosure or unauthorised access.
  • Retain useful statistical information after personal-data retention ends, where appropriate.
Persistent challenges

Risk does not disappear automatically

  • External datasets can make linkage and re-identification easier.
  • Aggressive transformation can remove the detail needed for the task.
  • New technology and new data sources can change the risk over time.
  • Legal status can be misclassified when governance relies on a tool label.

NIST describes de-identification as a family of techniques rather than one universal method. Its guidance recommends deciding the intended sharing model, measuring disclosure risk and testing whether the transformed data can be re-identified. That is a useful discipline outside government as well. A dataset published openly needs a different threshold from one accessed by a small, contracted research team inside a protected environment.

Governance pathFive decisions before release

Treat anonymisation as a maintained control

01

Define

State the purpose, audience and minimum detail needed.

02

Map

Find direct identifiers, quasi-identifiers and likely external linkages.

03

Transform

Combine techniques that fit the data and intended use.

04

Test

Measure re-identification risk and check that the output remains useful.

05

Review

Reassess the release when data, recipients or available technology change.

Controls around the data still matter

Anonymisation can be combined with access restrictions, contractual limits, secure environments, logging and monitoring. These organisational controls are especially important where full anonymisation would destroy the value of the information or where the dataset remains pseudonymous.

MX and ASRAn additional file-protection method

Anonymising a dataset and protecting a file exchange are related, but distinct

My MX Data is a secure B2B file-exchange platform for organisations that need control when sensitive information moves between customers, suppliers and partners. After this first reference, MX provides the shorthand.

Relevant MX Enterprise configurations can use ASR, which stands for Anonymise, Shard and Restore. The process transforms the data, separates it into protected shards and restores the file for an authorised recipient. No single readable file is retained in one place through that process.

The visual below is useful because it shows the three ASR stages without presenting the method as another name for encryption.

Diagram showing the ASR process: Anonymise, Shard and Restore

ASR protects the exchange pathway

ASR works alongside AES-256 encryption, named-recipient access, multi-factor authentication and audit records. The word "Anonymise" in ASR should not be treated as an automatic legal conclusion that a business dataset has become anonymous information under UK GDPR.

For sensitive B2B transfers, MX can combine this additional method with expiry settings and a traceable activity record. Organisations can explore the wider approach through MX's encrypted business file-sharing controls.

A sound operating ruleUse the least identifiable data that still supports the task, then apply access and exchange controls that match the remaining risk. Anonymisation, encryption and identity management solve different parts of the problem.

SourcesCurrent privacy guidance

Further reading

Protect sensitive information throughout the exchange

Test named-recipient access, ASR, expiry settings and a complete activity record with a real customer, supplier or project workflow.

Michael Byrne
Written by

Michael Byrne

I'm a dynamic professional with extensive experience in project and business management across automotive, construction, and aerospace sectors. Currently, as Head of Digital at Majenta, I lead transformative projects, focusing on maintaining and enhancing MX as a high-performance file sharing platform. My role involves strategic project delivery and aligning digital initiatives with core business values. I excel in stakeholder management, problem-solving, and fostering strategic partnerships. Passionate about continuous learning, I thrive in high-pressure environments and enjoy contributing to MX's market presence through innovative solutions and robust project execution.

Anonymisation Data Security & Privacy
MYMXDATA

Give sensitive files a clearer, more defensible route.

Start a seven-day trial with named-user access, detailed audit trails, unlimited file sizes and the patented ASR methodology.