Anonymization, pseudonymization, redaction, masking: the differences
Anonymization removes personal data for good, while pseudonymization replaces it with a placeholder that a separate mapping can reverse. Redaction deletes a value from a text, and masking hides part of it. Only pseudonymization keeps a way back, and it is what piighost does by default.
The examples below start from the same sentence, "Patrick lives in Paris."
Four terms
- Anonymization
- Personal data turned into information that no longer relates to an identifiable person, by anyone, with any means reasonably likely to be used. It is irreversible. Replacing Patrick is not enough on its own if the rest of the text still points to him, as in "the mayor who resigned in March".
- Pseudonymization
- The value is replaced, and the information that links it back is kept separately. Patrick becomes <<PERSON:1>>, and a mapping kept apart turns <<PERSON:1>> back into Patrick. It is reversible for whoever holds the mapping.
- Redaction
- The value is deleted or replaced by a fixed marker, as with a black bar on paper. Patrick becomes <<REDACT>>, and every other name becomes the same marker. Nothing records what was there, so it cannot be restored.
- Masking
- Part of the value is hidden and the rest stays visible. Patrick becomes P******. A fragment leaks, and two values with the same first letter and length look the same, so it cannot be restored either.
- Tokenization
- The value is replaced by a token, and a vault keeps the link between the two. It is a form of pseudonymization under another name. A
piighostplaceholder is a token in this sense.
Summary
| Term | Patrick becomes | Reversible | Under the GDPR |
|---|---|---|---|
| Anonymization | nothing that leads back to him | no | outside the regulation (recital 26) |
| Pseudonymization | <<PERSON:1>>, mapping kept apart | yes, with the mapping | still personal data (article 4(5), recital 26) |
| Redaction | <<REDACT>> | no | not defined, personal data while the person stays identifiable |
| Masking | P****** | no | not defined, personal data while the person stays identifiable |
| Tokenization | a token, link kept in a vault | yes, with the vault | a form of pseudonymization |
Redaction and masking reach anonymization only when nothing left in the data, the context included, identifies the person.
What the GDPR says
The GDPR defines pseudonymization and leaves anonymous information out of its scope.
- Article 4(5) defines pseudonymization as processing personal data "in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately" and protected by technical and organisational measures.
- Recital 26 states that pseudonymized data which could be attributed to a person with additional information "should be considered to be information on an identifiable natural person". The same recital says the principles of data protection "should therefore not apply to anonymous information".
The EDPB guidelines, the case law and what they mean for a deployment are on the Compliance page.
What piighost does
By default, piighost pseudonymizes. Each value becomes a placeholder such as <<PERSON:1>>, and the conversation memory keeps the mapping that restores Patrick in the reply. For you, the controller holding that mapping, the de-identified text stays personal data.
A redacting or masking placeholder factory used without a memory keeps no mapping, so the text moves toward anonymization. Whether it is truly anonymous still depends on what the rest of the text reveals. See Placeholder factories for which factories are reversible.
In a privacy notice or a DPIA, call the default processing pseudonymization, its legal name.
See also
- Compliance: the GDPR and HIPAA in detail, with the EDPB guidelines and the case law.
- Glossary: the other terms of these pages.
- How piighost compares: which tools restore values and which only mask them.