Pseudonymisation
What is Pseudonymisation?
The processing of personal data in such a manner that it can no longer be attributed to a specific data subject without the use of additional information. Unlike anonymisation, pseudonymised data is still considered personal data under GDPR.
Terms that appear alongside pseudonymisation
Each of these is named in at least one of the same controls as pseudonymisation. The number is how many controls name both.
- encryption 37 shared controls
- gdpr 32 shared controls
- confidentiality 25 shared controls
- data protection 23 shared controls
- integrity 19 shared controls
- anonymisation 17 shared controls
- availability 17 shared controls
- breach notification 17 shared controls
Frameworks that govern pseudonymisation
What the standards actually require on pseudonymisation
Requirements naming pseudonymisation across 6 standards, quoted from the control text.
Standard 7 per Section 35 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in a manner that ensures appropriate security including protection against unauthorised or unlawful processing + accidental loss + destruction or...
JM-DPA2020-Standard7-Security-Sec35-Appropriate-Technical-Organisational-Confidentiality-Integrity-Availability-Resilience · Jamaica DPA 2020 Standard 7 - Security + Section 35 + Appropriate Technical and Organisational Measures + Confidentiality + Integrity + Availability + Resilience + Encryption + Pseudonymisation + Risk-Based Security →Pseudonymisation (GDPR Art.4(5)) processes personal data in a way that the data can no longer be attributed to a specific data subject without additional information kept separately and subject to technical and organisational measures.
ENISA-DPE-3.2 · Pseudonymisation →Articles 39 + 46 of UU PDP establish security + breach notification obligations. Article 39: Personal Data Controller shall protect personal data processed through implementation of appropriate technical + organisational + and physical security measures + comm...
IDPdp-Security-BreachNotification-72Hour-Art39-Art46-Encryption-Pseudonymisation-Records-IR · Indonesia PDP Article 39 + Article 46 + Reasonable Security + Encryption + Pseudonymisation + Personal Data Breach Notification 3x24 Hours (72 Hours) to DPA + Data Subjects + IR Plan + Records →Apply pseudonymisation as a default safeguard for research data where the purpose can be achieved without identifiers, with key separation and access controls.
RDCOC-PSE-01 · Pseudonymisation Standards →Per IC 24-15-4-5 and IC 24-15-4-10 plus the separate Indiana Personal Information Disclosure Statute IC 24-4.9 (Indiana data breach notification law) controllers and processors must implement security + breach response + and records discipline.
INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation · Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification →Per Iowa Code 715D.5-1 and Iowa Personal Information Security Breach Notification Law (Iowa Code 715C separate statute) controllers and processors must implement security + breach response + records discipline.
ICDPA-Security-ReasonablePractices-Breach-Notification-Iowa-Code-715C-Records-Encryption-Pseudonymisation · Iowa CDPA Security + Reasonable Practices + Iowa Personal Information Security Breach Notification Law (Iowa Code 715C) + Records + Encryption + Pseudonymisation →Questions people ask about pseudonymisation
What is Pseudonymisation?
Why is Pseudonymisation important for compliance?
Which compliance frameworks address Pseudonymisation?
Where can I learn more about Pseudonymisation?
See how Pseudonymisation applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.