Pseudonymized personal data: How should the records be classified for GDPR purposes?
Retained linkability makes the records pseudonymized personal data, not anonymous data, under the EU GDPR.
The question
A travel-support provider subject to the EU GDPR replaces traveler names with random customer codes before sending records to its analytics team. The provider retains the lookup table and can reconnect records to individuals. How should the records be classified for GDPR purposes?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Encrypted data because the codes conceal the original valuesEncryption may be a security technique, but it does not answer whether the provider can still link the records to identifiable people.
- Aggregated data because each traveler has a distinct codeDistinct codes preserve record-level linkage; they do not combine individuals into statistical groups or remove identifiability.
- Pseudonymized personal data ✓The retained lookup table preserves a means of linking records to travelers, so the data remains personal data in pseudonymized form under the GDPR.
- Anonymized data after direct identifiers are removedRemoving names is insufficient because the retained lookup table provides a means of reconnecting records to individuals.
The trap
Ask whether the organization retains a realistic means of reconnecting records with individuals. How to remember it
Retained linkability makes the records pseudonymized personal data, not anonymous data, under the EU GDPR.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Collect only data necessary for the recommendation purpose: Which distinction is decisive before collection? →
- The authority is controller and provider processor under: Which role allocation follows actual purposes and →
- Use an Article 28 processor agreement: Which control reflects the provider’s role? →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.