Glossary A–ZLetter P
Pseudonymisation
Pseudonymisation means processing personal data in such a way that it can no longer be attributed to a specific person without additional information kept separately.
A typical example is replacing a name with an identifier. The GDPR defines the term in Article 4(5).
Around screens, pseudonymisation occurs in queue management systems, for example, which show a waiting number instead of the name, while the link to the person is held only at reception. Analyses of devices, accounts or entrants in a prize draw can also be carried out with identifiers instead of names. Whoever carries out the analysis then sees only the identifier.
The key point: pseudonymised data remains personal data, and the GDPR continues to apply. Pseudonymisation reduces the risk but does not replace a legal basis or a deletion period. Its protection depends on the mapping table being kept separately and securely. A common misconception is to regard an identifier or a numerical value on its own as anonymous. This glossary is not legal advice.