Pseudonymous Data
What is Pseudonymous Data?
Personal data that cannot be attributed to a specific individual without the use of additional information kept separately and securely.
Terms that appear alongside pseudonymous data
Each of these is named in at least one of the same controls as pseudonymous data. The number is how many controls name both.
- de identification 6 shared controls
- pseudonymisation 3 shared controls
- attestation 3 shared controls
- state privacy laws 3 shared controls
- gdpr 3 shared controls
- encryption 2 shared controls
- integrity 2 shared controls
- glba 2 shared controls
Frameworks that govern pseudonymous data
What the standards actually require on pseudonymous data
Requirements naming pseudonymous data across 6 standards, quoted from the control text.
A controller in possession of de-identified data must take measures to prevent re-identification, publicly commit to maintaining de-identification, and contractually obligate recipients to comply; rights do not apply to de-identified data.
COPA-1307-DEIDENT · De-identified and Pseudonymous Data →Controllers in possession of de-identified data must take reasonable measures to prevent re-identification, publicly commit to maintaining de-identification, and contractually bind recipients; rights do not apply to de-identified/pseudonymous data.
CTDPA-42-521-DEIDENT · De-identified and Pseudonymous Data →If data is de-identified, the controller must take reasonable measures to ensure the data cannot be re-associated with an individual, publicly commit to processing it only in de-identified form, and contractually obligate recipients to comply with the same res...
TDPSA-541-101-DEID · De-identified and Pseudonymous Data →The obligations of consumer rights (access, correction, deletion, portability, opt out) do not apply to pseudonymous data when the controller is able to demonstrate that information necessary to identify the consumer is kept separately and subject to effective...
VCDPA-59-1-581-PSEUDONYMOUS · Pseudonymous Data Carve Out →Per Iowa Code 715D.5-7 ICDPA imposes heightened obligations for sensitive data + children + de-identification. Unique among US state privacy laws Iowa CDPA requires NOTICE + OPT-OUT for sensitive data processing rather than OPT-IN CONSENT (other states VCDPA/C...
ICDPA-SensitiveData-Notice-OptOut-NotConsent-Children-COPPA-Alignment-De-Identification · Iowa CDPA Sensitive Data + Notice + Opt-Out (NOT Consent unlike VCDPA) + Children Under 13 + COPPA Alignment + De-Identification Standards + Heightened Risk Awareness →Per IC 24-15-4-5 and IC 24-15-4-10 plus the separate Indiana Personal Information Disclosure Statute IC 24-4.9 (Indiana data breach notification law) controllers and processors must implement security + breach response + and records discipline.
INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation · Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification →Questions people ask about pseudonymous data
What is Pseudonymous Data?
Why is Pseudonymous Data important for compliance?
Which compliance frameworks address Pseudonymous Data?
Where can I learn more about Pseudonymous Data?
See how Pseudonymous Data applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.