Pith. sign in

REVIEW 3 major objections 5 minor 95 references

Anonymity-washing

T0 review · 3 major / 5 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read Anonymity-washing is a systemic privacy failure: conflicting rules, outdated technical advice, and weak training keep pseudonymized data being presented as anonymous.

desk verdict A useful label and a competent synthesis, but the systemic claim overreaches a small, unsystematic sample; the qualitative argument holds. read the letter →

arxiv 2505.18627 v2 pith:GPKAV7MT submitted 2025-05-24 cs.CR cs.DB

classification cs.CRcs.DB
keywords anonymity-washinganonymizationpseudonymizationdataprotectionregulationGDPRre-identificationriskprivacy-washingpractitionerguidance
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Anonymity-washing, as defined in this paper, is the misrepresentation of the anonymity level of 'sanitized' personal data: data are presented as anonymous when they are only pseudonymized, weakly transformed, or still re-identifiable. The paper claims this is not an isolated bad-actor problem but a systemic one, produced by the combination of conflicting legal interpretations of anonymization, technical guidelines that are either legally vague or mathematically inaccessible, and practitioner training that omits modern methods. It supports that claim by reviewing EU and international regulations, court decisions, data-protection-authority websites, statistical agencies' documentation, and academic coverage, finding a pervasive lack of coherent support for practitioners. A sympathetic reader would care because, if the claim is right, many organizations are treating personal data as outside data-protection law while individuals' privacy expectations are systematically overstated.

What carries the argument

The central object is anonymity-washing itself, defined as the misrepresentation of the anonymity level of sanitized personal data, a specialized form of privacy-washing. The argument is carried by a documented gap analysis: it takes the GDPR's risk-based anonymization standard (Recital 26, operationalized through the WP29 Opinion 5/2014 criteria of singling out, linkability, and inference, and the EDPB's subsequent pseudonymization and AI-model guidance) and holds it against what regulators, guidelines, statistical agencies, and court decisions actually tell practitioners. That comparison produces the paper's main result: no coherent, accessible, technically accurate support exists, so the recurring misuse of pseudonymization and obsolete methods is the expected outcome, not an anomaly.

What would settle it

A large, representative survey of data controllers across many jurisdictions that could reliably state whether their data is anonymized or pseudonymized, pass the reasonable-means test, and point to up-to-date technical guidance they actually use would contradict the paper's central claim.

Watch

Extended reading notes

Core claim

The central discovery is the identification of anonymity-washing as a distinct and pervasive privacy concern, and the demonstration that its enabling conditions are structural rather than accidental. The paper shows that under the GDPR, anonymized data falls outside the regulation while pseudonymized data remains inside, yet the line between the two is drawn inconsistently: the WP29 Opinion 5/2014 prescribes a strict, zero-risk reading, while subsequent court decisions such as Breyer and SRB vs EDPS apply a risk-based 'reasonable means' test that can treat pseudonymized data as anonymous when the re-identification key is inaccessible. National authorities likewise disagree, with some demanding impossibility of re-identification and others accepting a remote risk. On top of this, the technical guidance available to practitioners is either too elementary or too advanced, and court cases like IAB Europe and CEGEDIM SANTE show companies and institutions routinely confusing pseudonymization with anonymization. The paper concludes that this incoherence sustains anonymity-washing, and that the remedy lies in education, updated practical guidance, and cooperation between regulators, researchers, and industry.

Load-bearing premise

The whole systemic diagnosis rests on the assumption that the handful of EU authorities, court decisions, guidelines, and technical documents reviewed is representative of global anonymization practice, so that the observed gaps indicate a structural failure rather than isolated cases.

Editorial extensions

If this is right

  • If anonymity-washing is systemic, many datasets currently treated as anonymous are still personal data, meaning their processing may lack a lawful basis under the GDPR and equivalent laws.
  • Regulators updating anonymization guidance will have to reconcile the zero-risk wording of WP29 Opinion 5/2014 with the risk-based standards in Recital 26 and recent case law, or the confusion the paper documents will persist.
  • Practitioner training would need to be rebuilt around threat modeling and modern techniques such as differential privacy, replacing reliance on k-anonymity and l-diversity as default answers.
  • Technical documentation for anonymization would need to be written for engineers and data scientists rather than for policymakers, since the current legalistic or highly mathematical materials are the ones practitioners cannot use.
  • Courts and authorities may increasingly treat claims of anonymity as enforceable consumer-protection representations, as the FTC's position on hashing already suggests.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A testable extension the paper leaves implicit is to audit privacy policies at scale: compare every 'anonymized' claim against the actual transformation applied, and measure how often the data are merely pseudonymized or hashed.
  • The paper's logic suggests that the release of the EDPB's long-awaited anonymization guidelines is itself a natural experiment: if the guidelines appear and familiar confusion persists, then lack of guidance is not the sole driver; if confusion drops sharply, the paper's diagnosis is confirmed.
  • The same enabling conditions likely apply to AI models: because models trained on personal data are not automatically anonymous, 'anonymized model' claims are a foreseeable sphere of anonymity-washing that the paper's recommendations would also cover.
  • The paper's framing implies that detecting anonymity-washing will usually require expert or regulatory intervention, since data subjects cannot readily check whether a dataset is truly anonymous before a breach occurs.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper introduces the concept of "anonymity-washing" -- the misrepresentation of the anonymity level of sanitized personal data -- and argues that it is a critical privacy concern enabled by inconsistent regulatory interpretations, outdated technical guidance, and gaps in practitioner education. The authors synthesize legal and technical literature, review selected EU and non-EU guidelines and case law, and conclude that practitioners lack coherent support, leading to persistent misuse of pseudonymization and obsolete anonymization techniques. They recommend targeted education, clearer guidance, and closer regulator-researcher-industry cooperation.

Significance. The paper makes a useful conceptual contribution by naming and framing anonymity-washing as a distinct phenomenon within the broader privacy-washing discourse. Its strength lies in the breadth of sources it assembles -- ISO standards, EU and national DPA guidance, court decisions, and technical documentation -- and in its effort to connect legal ambiguity with technical practice. The case-law discussion, in particular, is detailed and generally accurate. If the empirical claims were properly supported, the paper would be a valuable resource for privacy researchers, DPAs, and practitioners seeking to understand and close the gap between legal expectations and technical implementation. The paper does not present machine-checked proofs or parameter-free derivations, but such methods are not required for this type of policy-oriented analysis. The main weakness is that the evidence base for the systemic "lack of coherent support" claim is a small, non-random, convenience sample, which limits the generality of the conclusions as currently stated.

major comments (3)
  1. [Section 4.2] The paper repeatedly refers to a "systematic review" of national and international resources, but the review described in Section 4.2 lacks a reproducible protocol: there is no search strategy, inclusion criteria, coding scheme, or sampling logic. The five EU DPAs are introduced as "the most active" without defining "active" or justifying the cutoff, and the non-EU resources (ICO, UKAN, PDPC, INSEE, books) appear to be an ad hoc convenience sample. On this basis, the claim that "most guidelines are often hard to find" and the broader conclusion of a "lack of coherent support for practitioners" generalize beyond what the data can support. Please either replace the term "systematic review" with a more modest description and explicitly scope the conclusions to the reviewed resources, or conduct a genuinely systematic audit with a stated methodology.
  2. [Section 5] The case-law selection is described as "the most representative and recent cases" with no criteria for representativeness or recency, and no attempt to enumerate or sample the population of relevant decisions. The paper's conclusion that there is "persistent misuse" of pseudonymization and obsolete techniques implies recurrence and prevalence, but the evidence presented consists of a handful of illustrative cases (CEGEDIM, IAB Europe, SRB, and a few others). These cases demonstrate that the phenomenon exists, but they cannot measure how widespread or persistent it is. Please either provide a more systematic case census (e.g., all published DPA decisions involving anonymization claims in a defined period) or soften the "persistent" claim to something like "as illustrated by the cases discussed."
  3. [Section 2.2 and Section 5.3] The definition of anonymity-washing is internally inconsistent regarding intentionality. Section 2.2 defines it as "misrepresentation" and discusses the manipulative aspect, noting that the term "washing" implies intentional action. Yet Section 5.3 concludes that "anonymity-washing may not be a deliberate practice," citing the CEGEDIM case as an illustration of unintentional confusion. This ambiguity matters because the paper's normative claim that anonymity-washing is a "critical privacy concern" and a form of deceptive practice depends on whether the concept includes merely negligent or mistaken claims. Please sharpen the definition: either restrict the term to intentional misrepresentation and treat unintentional confusion as a separate category, or explicitly define it to include misleading claims regardless of intent, and adjust the discussion accordingly.
minor comments (5)
  1. [References] Reference [52] contains an obvious typo: "7 March 20246" should read "7 March 2024."
  2. [Section 3.1] The sentence discussing Sénéchal's critique contains an unclosed parenthesis and a grammatical fragment: "(for example, the general-purpose AI models [46] and the ones posing systemic risks. This is problematic since anonymization is difficult to implement..." Please rephrase to close the parenthesis and make the sentence complete.
  3. [Section 5.2] The phrase "privacy washing practices" appears where the paper's subject is "anonymity-washing"; unless the broader term is intended, this looks like a typo and should be corrected.
  4. [Section 4.2] The criticism that some ICO examples are "oversimplified or technically wrong" is asserted with only a footnote reference to a "case study on differentially private mixed noise addition" but no explanation of the alleged error. Please either provide the specific technical issue or soften the claim.
  5. [Throughout] The paper uses both "EUCJ" and "Court of Justice" to refer to the Court of Justice of the European Union; please standardize the abbreviation and spelling (e.g., "CJEU" or "Court of Justice") for consistency.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the paper introduces a conceptual term and applies it to external legal and technical sources without fitting parameters or deriving predictions from its own definition.

full rationale

This is a conceptual and legal-review paper, not a technical derivation. It introduces 'anonymity-washing' by analogy to the independently defined notion of 'privacy-washing' (Cirucci, reference [21]), and then surveys external regulatory texts, DPA guidelines, court decisions, and technical resources. There are no equations, no fitted parameters, and no quantity is predicted from a quantity that is itself defined in terms of the prediction. The central claim that ambiguous guidance, outdated techniques, and educational gaps enable anonymity-washing is supported by cited external materials (e.g., GDPR Recital 26, WP29 Opinion 5/2014, EDPB guidelines, CNIL, ICO, DPC, and court cases such as CEGEDIM SANTE). The case selection is explicitly described as 'the most representative and recent cases, but these are not exhaustive,' and the DPA website review is presented as a review rather than a statistical sample. The representativeness concern raised in the skeptic headline is a question of evidence strength and external validity, not circularity: the paper does not use its own concept to prove its own conclusion by construction. The only mild conceptual feature is that the authors define anonymity-washing and then identify examples that fit that definition, which is normal concept application rather than circular derivation. No load-bearing self-citation chain is present: the authors do not rely on their own prior work to justify the central premise. Therefore the appropriate circularity score is 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 1 invented entities

The paper introduces no free parameters and no technical derivations. Its central claims rest on domain assumptions about the GDPR standard, the obsolescence of classical anonymization methods, and the reliability of the sources reviewed. The only invented entity is the conceptual label 'anonymity-washing'.

assumptions (3)
  • domain assumption The GDPR Recital 26 'reasonable means' test is the appropriate benchmark for judging whether data are anonymous.
    Used throughout Sections 3 and 5 as the main standard for evaluating anonymization adequacy. If a different standard (e.g., zero-risk) were adopted, many conclusions about guidance inconsistency would shift.
  • domain assumption k-anonymity and l-diversity are obsolete and fail against modern re-identification attacks.
    Repeatedly assumed (e.g., citing [56]) rather than demonstrated in this paper. The premise underlies the claim that outdated methods persist and contribute to anonymity-washing.
  • domain assumption The legal cases, DPA decisions, and guidelines cited are accurate and correctly interpreted by the authors.
    Throughout the paper the authors rely on their own reading of legal documents and secondary reports without providing primary-source verification for each case.
invented entities (1)
  • 'Anonymity-washing' concept
    purpose: To name and unify the phenomenon of misrepresenting the anonymity level of personal data as a subset of privacy-washing.
    The concept is a classification label, not a measurable entity. Real-world cases (FTC, Garante, IAB Europe) illustrate it, but the label itself provides no independent falsifiable handle.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Anonymity-washing." pith.science (2026). https://pith.science/paper/GPKAV7MT

@misc{pith2026250518627,
  author       = {Pith},
  title        = {Pith review of: Anonymity-washing},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/GPKAV7MT}},
  note         = {Machine review of arXiv:2505.18627}
}
read the original abstract

Anonymization is a foundational principle of data privacy regulation, yet its practical application remains riddled with ambiguity and inconsistency. This paper introduces the concept of anonymity-washing -- the misrepresentation of the anonymity level of ``sanitized'' personal data -- as a critical privacy concern. While both legal and technical critiques of anonymization exist, they tend to address isolated aspects of the problem. In contrast, this paper offers a comprehensive overview of the conditions that enable anonymity-washing. It synthesizes fragmented legal interpretations, technical misunderstandings, and outdated regulatory guidance and complements them with a systematic review of national and international resources, including legal cases, data protection authority guidelines, and technical documentation. Our findings reveal a lack of coherent support for practitioners, contributing to the persistent misuse of pseudonymization and obsolete anonymization techniques. We conclude by recommending targeted education, clearer technical guidance, and closer cooperation between regulators, researchers, and industry to bridge the gap between legal norms and technical reality.

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

95 extracted references · 79 canonical work pages

  1. [1]

    In: VLDB

    Aggarwal, Charu C: On k-anonymity and the curse of dimensionality. In: VLDB. vol. 5, pp. 901–909 (2005)

  2. [2]

    Journal of Law and the Biosciences 12(1), 1 (2025)

    Aliki, E., Marietjie, B., Dusty-Lee, D., Beverley, T., Carmel, S., Don- rich, T.: ‘Potato potahto’? Disentangling de-identification, anonymisation, and pseudonymisation for health research in Africa. Journal of Law and the Biosciences 12(1), 1 (2025)

  3. [3]

    ACM TechBriefs (2024)

    Altman, M., Aloni, C., Nissim, K.: ACM TechBrief: Data Privacy Protection. ACM TechBriefs (2024)

  4. [4]

    ANPD: Agenda Regulatoria 2025-2026 (2025),https://www.gov.br/anpd/pt-br/ assuntos/noticias/anpd-publica-agenda-regulatoria-2025-2026

  5. [5]

    Article 26 Data Protection Working Party: Opinion 05/2014 on Anonymisation Techniques (2014)

  6. [6]

    Article 29 Data Protection Working Party: Opinion on the concept of personal data (2007)

  7. [7]

    Atsumi & Sakai Co.: A Guide to Data Protection in Japan (2020), https: //www.aplawjapan.com/archives/pdf/data-protection-202009 .pdf Anonymity-washing 21

  8. [8]

    Ayyamperumal,S.G.,Ge,L.:CurrentstateofLLMRisksandAIGuardrails(2024), https://arxiv.org/abs/2406.12934

Show all 95 references
  1. [9]

    BfDI: Die Anonymisierung im Datenschutzrecht (2022), https:// www.bfdi.bund.de/SharedDocs/Downloads/DE/DokumenteBfDI/Reden_Gastbeitr% C3%A4ge/2022/Anonymisierung-im-DS-recht .pdf?__blob=publicationFile&v=2

  2. [10]

    BfDI: Aktuelle Fragestellungen des Datenschutzes (2023), https:// www.bfdi.bund.de/SharedDocs/Downloads/DE/DokumenteBfDI/Reden_Gastbeitr% C3%A4ge/2023/eco-Kompetenzgruppe.pdf?__blob=publicationFile&v=2

  3. [12]

    Smart Cities

    BfDI: Arbeitspapier zum Thema “Smart Cities”’ (2023), https: //www.bfdi.bund.de/SharedDocs/Downloads/DE/Berlin-Group/20230608_WP- Smart-Cities.pdf?__blob=publicationFile&v=2

  4. [13]

    BfDI: Datenschutz durch Technik – Chancen und Grenzen von Anonymisierung, Pseudonymisierung und PETs (2024), https://www.bfdi.bund.de/SharedDocs/ Downloads/DE/DokumenteBfDI/Reden_Gastbeitr%C3%A4ge/2024/Datenschutz- durch-Technik-BvD .pdf?__blob=publicationFile&v=1

  5. [14]

    BfDI: Datennutzung vs. Datenschutz – Veranstaltung zum Europäischen Datenschutztag (2025), https://www.bfdi.bund.de/SharedDocs/Downloads/ DE/DokumenteBfDI/Reden_Gastbeitr%C3%A4ge/2025/Rede-Eu-Akademie- Informationsfreiheit-Datenschutz.pdf?__blob=publicationFile&v=2

  6. [15]

    Simon and Schuster (2022)

    Bhajaria, Nishant: Data Privacy: A runbook for engineers. Simon and Schuster (2022)

  7. [16]

    Brazil: Lei Geral de Proteção de Dados Pessoais (Redação dada pela Lei nº 13.853, de 2019) (LGPD) (2019)

  8. [17]

    Konsultationsverfahren des BfDI10 (2020)

    Burkert, C., Federrath, H., Marx, M., Schwarz, M.: Positionspapier zur Anonymisierung unter der DSGVO unter Besonderer Berücksichtigung der TK- Branche. Konsultationsverfahren des BfDI10 (2020)

  9. [18]

    Burt, A., Stalla-Bourdillon, S., Rossi, A.: A guide to the EU’s unclear anonymization standards (2021), https://iapp.org/news/a/a-guide-to-the- eus-unclear-anonymization-standards/

  10. [19]

    CCPA: California Consumer Privacy Act (CCPA) (2020)

  11. [20]

    Journal of Medical Internet Research21(5), e13484 (2019)

    Chevrier, R., Foufi, V., Gaudet-Blavignac, C., Robert, A., Lovis, C.: Use and un- derstanding of anonymization and de-identification in the biomedical literature: scoping review. Journal of Medical Internet Research21(5), e13484 (2019)

  12. [21]

    Privacy-washing

    Cirucci,A.M.:Oversharingthesupersafestuff:“Privacy-washing”’inAppleiPhone and Google Pixel commercials. First Monday (2024)

  13. [22]

    CNIL: L’anonymisation des données, un traitement clé pour l’open data (2019), https://www.cnil.fr/fr/lanonymisation-des-donnees-un-traitement-cle- pour-lopen-data

  14. [23]

    CNIL: L’anonymisation de données personnelles (2020),https://www.cnil.fr/fr/ technologies/lanonymisation-de-donnees-personnelles

  15. [24]

    CNIL: Recherche scientifique (hors santé): enjeux et avantages de l’anonymisation et de la pseudonymisation (2022), https://www.cnil.fr/fr/recherche- scientifique-hors-sante-enjeux-et-avantages-de-lanonymisation-et- de-la-pseudonymisation

  16. [25]

    Proceedings of the National Academy of Sciences117(15), 8344–8352 (2020)

    Cohen, A., Nissim, K.: Towards formalizing the GDPR’s notion of singling out. Proceedings of the National Academy of Sciences117(15), 8344–8352 (2020)

  17. [26]

    Lestyán et al

    Commission nationale de l’informatique et des libertés CNIL: Délibération SAN- 2024-013 (5 September 2024) 22 Sz. Lestyán et al

  18. [27]

    Proceedings of the VLDB Endowment 3(1-2), 1045–1056 (2010)

    Cormode, G., Srivastava, D., Li, N., Li, T.: Minimizing minimality and maximizing utility: analyzing method-based attacks on anonymized data. Proceedings of the VLDB Endowment 3(1-2), 1045–1056 (2010)

  19. [28]

    O’Reilly (2011)

    Craig, Terence and Ludloff, Mary E: Privacy and big data: the players, regulators, and stakeholders. O’Reilly (2011)

  20. [29]

    Data Security Council of India: Balancing Privacy and Innovation: Anonymisation Standards for Indian Data (2023)

  21. [30]

    Scientific Reports3(1), 1376 (2013)

    De Montjoye, Y.A., Hidalgo, C.A., Verleysen, M., Blondel, V.D.: Unique in the crowd: The privacy bounds of human mobility. Scientific Reports3(1), 1376 (2013)

  22. [31]

    Unique in the shoppingmall:Onthereidentifiabilityofcreditcardmetadata

    De Montjoye, Y.A., Pentland, A.S.: Response to Comment on “Unique in the shoppingmall:Onthereidentifiabilityofcreditcardmetadata”.Science 351(6279), 1274–1274 (2016)

  23. [32]

    Djiriguian, J., Missègue, N., Ricroch, L.: Diffuser une base anonymisée : utopie ou réalitée? Journées de méthodologie statistique de l’Insee (2022), https://journees-methodologie-statistique .insee.net/wp-content/ uploads/2022/S11_4_ACTE_MISSEGUE_JMS2022.pdf

  24. [33]

    DPC: Data Protection: The Basics (2019), https://dataprotection.ie/sites/ default/files/uploads/2019-07/190710%20Data%20Protection%20Basics.pdf

  25. [34]

    DPC: Guidance on Anonymisation and Pseudonymisation (2019), https://www.dataprotection.ie/sites/default/files/uploads/2022-04/ Anonymisation%20and%20Pseudonymisation%20-%20latest%20April%202022.pdf

  26. [35]

    EDPB and AEPD: 10 misunderstandings related to anonymisation (2021)

  27. [36]

    International Data Privacy Law 5(1), 73–87 (2015)

    El Emam, K., Alvarez, C.: A critical appraisal of the Article 29 Working Party Opinion 05/2014 on data anonymization techniques. International Data Privacy Law 5(1), 73–87 (2015)

  28. [37]

    Elliot, M., Mackey, E., O’Hara, K.: The Anonymisation Decision-Making Frame- work 2nd Edition: European Practitioners’ Guide (2020)

  29. [38]

    EU-USA: Privacy Shield Framework (2016), https://eur-lex.europa.eu/eli/ dec_impl/2016/1250/oj/eng

  30. [39]

    European Commission EC: Directive 95/46/EC of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data, OJ L 281 (1995)

  31. [40]

    European Commission EC: Communication from the Commission to the European Parliament and the Council, Guidance on the Regulation on a framework for the free flow of non-personal data in the European Union, COM/2019/250 final (2019)

  32. [41]

    European Commission EC: Communication from the Commission to the Euro- pean Parliament and the Council – two years of application of the General Data Protection Regulation, COM/2020/264 (2020)

  33. [42]

    European Commission EC: Communication from the Commission to the European Parliement and the CouncilL - Second Report on the application of the General Data Protection Regulation,COM/2024/357 (2024)

  34. [43]

    European Data Protection Board EDPB: Opinion 28/2024 on certain data protec- tion aspects related to the processing of personal data in the context of AI models (2024)

  35. [44]

    EuropeanDataProtectionBoardEDPB:GuidelinesonPseudonymisation-version for public consultation (2025)

  36. [45]

    European Parliament, Council of the European Union: Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) (2016), https:// data.europa.eu/eli/reg/2016/679/oj Anonymity-washing 23

  37. [46]

    European Parliament and of the Council: Regulation (EU) 2024/1689 of the Eu- ropean Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/85...

  38. [47]

    39–98, art 15 (1) d (23 October 2018)

    European Parliament and of the Council: Regulation (EU) 2018/1725 on the pro- tection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) ...

  39. [48]

    European Parliament, Directorate – General for Internal Policies, Policy Depart- ment Economic and Scientific Policy: Industry, Research and Energy, Data Flows- Future Scenarios, in-depth Analysis for the ITRE Committee (2017)

  40. [49]

    European Union Court of Justice EUCJ: Judgment of the Court (Grand Cham- ber): Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems (16 July 2020)

  41. [50]

    European Union Court of Justice EUCJ: Breyer, Case C-582/14 (19 October 2016)

  42. [51]

    (7 March 2024)

    European Union Court of Justice EUCJ: GOC vs European Commission, Case C-479/22 P. (7 March 2024)

  43. [52]

    (7 March 20246)

    European Union Court of Justice EUCJ: IAB Europe, Case C-604/22. (7 March 20246)

  44. [53]

    European Union Court of Justice EUCJ: Gesamtverband Autoteile-Handel (Accès aux informations sur les véhicules), case C-319/22 (9 Novembre 2023)

  45. [54]

    European Union General Court EUGC: SRB vs EDPS, Case T-557/20 (26 April 2023)

  46. [55]

    Federal Trade Commission: Protecting Consumer Privacy in an Era of Rapid Change, Recommendations for businesses and policymakers, FTC Report (2012), https://www.ftc.gov/sites/default/files/documents/reports/ federal-trade-commission-report-protecting-consumer-privacy-era- rapi...

  47. [56]

    Sci- ence Advances10(29), eadn7053 (2024)

    Gadotti, A., Rocher, L., Houssiau, F., Creţu, A.M., De Montjoye, Y.A.: Anonymization: The imperfect science of using data while preserving privacy. Sci- ence Advances10(29), eadn7053 (2024)

  48. [57]

    National Institute of Standard and Technology (2015)

    Garfinkel, Simson L: De-Identification of Personal Information. National Institute of Standard and Technology (2015)

  49. [58]

    GPDP: Provvedimento [10090499] (13 November 2024)

  50. [59]

    GPDP: GUIDA ALL’APPLICAZIONE DEL REGOLAMENTO EU- ROPEO IN MATERIA DI PROTEZIONE DEI DATI PERSONALI (2023), https://www.garanteprivacy.it/documents/10160/0/Guida+all+ applicazione+del+Regolamento+UE+2016+679.pdf/2281f960-a7b2-4c53-a3f1- ad7578f8761d?version=2.0

  51. [60]

    ICO: Anonymisation: managing data protection risk code of practice (2019)

  52. [61]

    ICO: (Draft) Anonymisation, pseudonymisation and privacy enhancing technologies guidance (2022), https://ico.org.uk/about-the-ico/ico- and-stakeholder-consultations/ico-call-for-views-anonymisation- pseudonymisation-and-privacy-enhancing-technologies-guidance/

  53. [62]

    Lestyán et al

    ICO: Privacy-enhancing technologies (PETs) (2023), https://ico.org.uk/for- organisations/uk-gdpr-guidance-and-resources/data-sharing/privacy- enhancing-technologies/ 24 Sz. Lestyán et al

  54. [63]

    INSEE: Risque de ré-identification : deux questions pratiques relatives au critère de la l-diversité (2019),https://www.insee.fr/fr/information/4277545

  55. [64]

    INSEE: Guide du Secret Statistique (2024), https://www.insee.fr/fr/ information/1300624

  56. [65]

    INSEE: Les méthodes perturbatives d’anonymisation des données indi- viduelles (2024), https://www.insee.fr/fr/statistiques/fichier/4277545/1- SMS_secret_24_juin_2019.pdf

  57. [66]

    57 of 2003) (Last version Act No

    Japan: Act on the Protection of Personal Information (Act No. 57 of 2003) (Last version Act No. 37 of 2021) (2003),https://www.japaneselawtranslation.go.jp/ en/laws/view/4241/en

  58. [67]

    O’Reilly (2023)

    Jarmul, Katharine: Practical data privacy. O’Reilly (2023)

  59. [68]

    Health Informatics Meets eHealth pp

    Langarizadeh, M., Orooji, A., Sheikhtaheri, A.: Effectiveness of anonymization methods in preserving patients’ privacy: a systematic literature review. Health Informatics Meets eHealth pp. 80–87 (2018)

  60. [69]

    Tsul Legal Report5, 25 (2024)

    Mamanazarov, Sardor: De-identification and anonymization: legal and technical approaches. Tsul Legal Report5, 25 (2024)

  61. [70]

    Maxime Bergeat (INSEE): La question de la confidentialité des données individu- elles (2016), https://www.insee.fr/fr/statistiques/2535625

  62. [71]

    Journées de méthodologie statistique de l’Insee (2022)

    Michael Levi-Valensin: Gestion du secret pour la diffusion grand public de cubes multidimensionnels: une expérimentation au SSM agricultiure. Journées de méthodologie statistique de l’Insee (2022)

  63. [72]

    Government Information Quarterly40, 101805 (2023)

    Moon-Ho Joo and Hun-Yeong Kwon: Comparison of personal information de- identification policies and laws within the EU, the US, Japan, and South Korea. Government Information Quarterly40, 101805 (2023)

  64. [73]

    White Paper (2014)

    Narayanan, A., Felten, E.W.: No silver bullet: De-identification still doesn’t work. White Paper (2014)

  65. [74]

    May21, 2019 (2019)

    Narayanan, Arvind and Shmatikov, Vitaly: Robust de-anonymization of large sparse datasets: a decade later. May21, 2019 (2019)

  66. [75]

    Statistique et société2(4), 53–60 (2014)

    Nguyen, B.: Techniques d’anonymisation. Statistique et société2(4), 53–60 (2014)

  67. [76]

    arXiv preprint arXiv:2001.02650 (2020)

    Nguyen, B., Castelluccia, C.: Techniques d’anonymisation tabulaire: concepts et mise en oeuvre. arXiv preprint arXiv:2001.02650 (2020)

  68. [77]

    In: Privacy in context

    Nissenbaum, Helen: Privacy in context: Technology, policy, and the integrity of social life. In: Privacy in context. Stanford University Press (2009)

  69. [78]

    OECD: Cross-border data flows, Policy sub-issue (2022),https://www.oecd.org/ en/topics/cross-border-data-flows .html

  70. [79]

    UCLA Law Review57, 1701 (2009)

    Ohm, Paul: Broken promises of privacy: Responding to the surprising failure of anonymization. UCLA Law Review57, 1701 (2009)

  71. [80]

    PDPC: Guide to Basic Anonymisation (2022)

  72. [81]

    Personal Information Protection Commission Secretariat: Anonymously Pro- cessed Information - Towards Balanced Promotion of Personal Data Uti- lization and Consumer Trust (2017), https://www.ppc.go.jp/files/pdf/ The_PPC_Secretariat_Report_on_Anonymously_Processed_Information.pdf

  73. [82]

    President’s Council of Advisors on Science and Technology, White House: Big data and Privacy: A technological perspective (2014)

  74. [83]

    Québec: Regulation respecting the anonymization of personal information (2024)

  75. [84]

    Rubinstein, I.S., Hartzog, W.: Anonymization and risk. Wash. L. Rev.91, 703 (2016)

  76. [85]

    John Wiley & Sons (2019)

    Sharma, Sanjay: Data privacy and GDPR Handbook. John Wiley & Sons (2019)

  77. [86]

    Nature Computational Science2(4), 208–210 (2022) Anonymity-washing 25

    Stadler, Theresa and Troncoso, Carmela: Why the search for a privacy-preserving data sharing mechanism is failing. Nature Computational Science2(4), 208–210 (2022) Anonymity-washing 25

  78. [87]

    Stalla-Bourdillon, S., Burt, A.: The definition of ’anonymization’ is changing in the EU: Here’s what that means (2023),https://iapp.org/news/a/the-definition- of-anonymization-is-changing-in-the-eu-heres-what-that-means

  79. [88]

    Stalla-Bourdillon, S.: Identifiability, as a Data Risk: Is a Uniform Approach to Anonymisation About to Emerge in the EU? Available at SSRN (2025)

  80. [89]

    personal data-false debate: an EU perspective on anonymization, pseudonymization and personal data

    Stalla-Bourdillon, S., Knight, A.: Anonymous data v. personal data-false debate: an EU perspective on anonymization, pseudonymization and personal data. Wis. Int’l LJ 34, 284 (2016)

  81. [90]

    Addison-Wesley Professional (2019)

    Stallings, William: Information privacy engineering and privacy by design: Under- standing privacy threats, technology, and regulations based on standards and best practices. Addison-Wesley Professional (2019)

  82. [91]

    Wallace: What Does Anonymization mean? DataSHIELD and the Need for Consensus on Anonymization Terminology

    Susan E. Wallace: What Does Anonymization mean? DataSHIELD and the Need for Consensus on Anonymization Terminology. Biopreservation and Biobanking 14(3), 224 (2016)

  83. [92]

    Sénéchal, J.: Publication de l’avis de l’EDPB du 17 décembre 2024 sur le traitement des données personnelles dans le contexte des mod- èles d’IA: prémices d’une mutation profonde du RGPD? (2024), https: //www.dalloz-actualite.fr/flash/publication-de-l-avis-de-l-edpb-du- 17-dec...

  84. [93]

    USA: Health Insurance Portability and Accountability Act (1996)

  85. [94]

    Weitzenboeck, E.M., Lison, P., Cyndecka, M., Langford, M.: The GDPR and un- structured data: is anonymization possible? International Data Privacy Law12(3), 184–206 (2022)

  86. [95]

    Wolff, J., Lehr, W., Yoo, C.S.: Lessons from GDPR for AI Policymaking. Va. JL & Tech.27, 1 (2023)

  87. [96]

    Wood,A.,Altman,M.,Bembenek,A.,Bun,M.,Gaboardi,M.,Honaker,J.,Nissim, K., O’Brien, D.R., Steinke, T., Vadhan, S.: Differential privacy: A primer for a non- technical audience. Vand. J. Ent. & Tech. L.21, 209 (2018)

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.