ICO published the next chapter of the Anonymisation guidance draft : Anonymisation, pseudonymisation and privacy enhancing technologies guidance

How to ensure anonymisation is effective?

The ICO is calling for views on its updated draft guidance on anonymisation, pseudonymisation and privacy enhancing technologies. ICO are sharing their thinking in stages to ensure they gather as much feedback as possible to help refine and improve the final guidance, which will carry out a formal consultation.

In the first chapter ‘Introduction to Anonymisation’ it is outlined the legal, policy and governance issues around the application of anonymisation in the context of data protection law. .

The second chapter ‘Identifiability’ focuses on how to assess anonymisation in the context of identifiability. ICO explores the concept of a spectrum of identifiability, data sharing scenarios, the motivated intruder and reasonably likely tests as well as guidance on managing re-identification risk. These key principles set out views on effective anonymisation.

ICO will continue to publish draft chapters for comment at regular intervals. As outlined the next chapters to follow will include:

  • Guidance on pseudonymisation techniques and best practices;
  • Accountability and governance requirements in the context of anonymisation and pseudonymisation, including data protection by design and DPIAs;
  • Anonymisation and research – how anonymisation and pseudonymisation apply in the context of research;
  • Guidance on privacy enhancing technologies (PETs) and their role in safe data sharing;
  • Technological solutions – exploring possible options and best practices for implementation; and
  • Data sharing options and case studies – supporting organisations to choose the right data sharing measures in a number of contexts including sharing between different organisations and open data release. Developed with key stakeholders, our case studies will demonstrate best practice.

About the Author

Zlatko Delev

Head of Commercial & Country Manager

Zlatko Delev is Head of Commercial and Country Manager at GDPRLocal, where he leads the company’s commercial strategy and market presence. He brings international experience across sales, marketing, and customer success, along with a legal background from his studies at Iustinianus Primus Law School in Skopje, Macedonia.

Zlatko sits at the front line of GDPRLocal’s client relationships, guiding organisations through the first stages of their compliance journey and helping them understand where they stand and where they need to go on GDPR, information security, and the emerging landscape of AI regulation. His role bridges commercial strategy with practical data protection knowledge, ensuring clients get clear, actionable direction from their very first conversation with GDPRLocal.

Alongside his commercial focus, Zlatko has trained extensively in project management and organisational leadership, including risk management, stakeholder communication, agile methodology, and digital marketing, a broad skill set that supports his structured, delivery-focused approach to growing GDPRLocal’s business internationally.