Pseudonymisation vs anonymisation: the difference, and when to use which
The short answer. Pseudonymisation replaces personal data with placeholders while a key exists that can restore the originals. Anonymisation removes that link for good: no key, no way back. Legally the difference is large: pseudonymised data remains personal data under GDPR, truly anonymised data falls outside it. Practically: choose pseudonymisation when you work with AI and want to translate the answer back, anonymisation when the link must be gone forever.
The difference in one table
| Pseudonymisation | Anonymisation | |
|---|---|---|
| What happens | Values become consistent placeholders | Values are removed or generalised |
| Reversible | Yes, with the key | No, for anyone |
| GDPR status | Remains personal data (Art. 4(5)) | Outside GDPR (Recital 26), if truly irreversible |
| Recognised as | Security measure (Art. 32) | Definitive solution |
| Typical use | AI work, analysis, internal reuse | Publication, archive, external sharing |
| At ShareSafe.ai | You get the Identity Key, we store nothing | No key is created |
The trap: "anonymised" data that isn't
GDPR sets the bar high: nobody should reasonably be able to re-identify the person, including by combining other sources. Much of what gets called "anonymised" in practice is not:
- initials instead of names (J.d.V. from a named small town is identifiable);
- removing the name but keeping role, company and date;
- black bars with the text still underneath;
- a replacement table sitting in someone's mailbox. That is pseudonymisation with a badly managed key, the worst of both worlds.
Be honest in your own documentation about which of the two you are doing. That is exactly how ShareSafe.ai names it: pseudonymise with the key in your hands, or anonymise with no key at all.
When to choose which
Choose pseudonymise when:
- you are giving the document to ChatGPT, Claude or another AI and want to translate the answer back to real names;
- you analyse internally but need the link later;
- you need consistency: [NAME_01] must stay the same person throughout the document.
Choose anonymise when:
- the document goes outside: publication, sample case, training material, benchmark;
- your retention obligation has ended but you want to keep the content;
- you want certainty that even you can no longer make the link.
How it works at ShareSafe.ai
- Drop your file into the tool and pick your mode.
- Check the before and after view; add anything detection missed.
- Download the safe file. In pseudonymise mode you also get the Identity Key; we keep no copy, so if you lose it, the way back is closed for us too.
FAQ
- Does pseudonymised data stay under GDPR?
- Yes, as long as a key exists somewhere that can restore the link. But GDPR explicitly names pseudonymisation as an appropriate safeguard. What you send to an AI vendor then contains no directly identifying data.
- Is anonymisation always better?
- No, it is more final, not better. For AI work pseudonymisation is usually more useful: the AI's answer only becomes usable once you can translate the placeholders back.
- Who can access my Identity Key?
- Only you. The key is generated during your session and delivered to you. ShareSafe.ai keeps no copy.
- Can an anonymised document become identifiable again later?
- In theory that risk exists when a lot of context remains. That is why anonymisation also generalises indirect identifiers, and why the review step stays part of the method.
ShareSafe.ai is part of VaultLM. Raw files stay in the EU. Minimal retention. You hold the key. Try it with your own document →