[nonimo]
EN
Download

Is pseudonymised data personal data? An Irish answer for AI

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Is pseudonymised data personal data? For the firm that did the pseudonymising, yes, and it stays yours to answer for. For the company on the other end, the Court of Justice said on 4 September 2025 that it depends, and it set two conditions that a paragraph of client prose rarely meets. Everything below is about the second half of that answer.

It matters because the question is no longer academic in an Irish office. People take a passage from a file, replace the client’s name and numbers, and put what is left into a chatbot. What they have made, in the language of the GDPR and of the Data Protection Commission, is pseudonymised data. The label on it decides which obligations travel with the text.

Two related questions are covered elsewhere. If you want a checklist for stripping an Irish document before it goes, PPS number and Eircode included, that is in our PPSN guide. If you want the three words compared across legal systems, that is in the guide to deidentified, pseudonymised and anonymised. This one is about the word pseudonymised itself, and what the courts have done to it since 2019.

Is pseudonymised data personal data? For you, yes. For the provider, it depends

The Regulation’s own answer is in Recital 26: data that has been pseudonymised, but can be linked back to someone with extra information, “should be considered to be information on an identifiable natural person”. It is easy to read that as a flat rule: once personal, always personal, for everybody.

The Court of Justice has now read it more carefully. In EDPS v SRB it held that pseudonymised data must not be regarded as personal data “in all cases and for every person”, because pseudonymisation may, depending on the circumstances, stop people other than the controller from identifying anyone.

Two readers of the same text

You, holding the original file and the key, are reading personal data. A recipient without either may be reading something that is not personal data for them, but only if the measures you took actually stop them from working out who it is.

In an office the first reader is the firm, and the second is whichever provider the text goes to: the company behind ChatGPT, Google, Microsoft or Anthropic. The judgment is about how far the second reader’s position can differ from yours. It says very little that comforts the first.

Why the Court’s answer governs here

The case was decided under Regulation 2018/1725, which binds the EU institutions rather than private firms. The Court dealt with that directly: at paragraph 52 it said the concept of personal data in that Regulation and in Article 4(1) of the GDPR must be interpreted in the same way. In Ireland, as in every member state, the Court of Justice has the final word on what the GDPR means.

That is the difference between Dublin and London on this point. Since Brexit a British court may have regard to a judgment like this one; an Irish court and the DPC work inside it. Anything written in Ireland about pseudonymisation before September 2025 now needs to be read with the judgment beside it.

The GDPR’s definition, and where the word turns up in Irish law

The definition sits in Article 4(5). Data is pseudonymised when it has been processed in a way that stops it being linked to a particular individual unless extra information is used, and that extra information is held apart and protected by technical and organisational measures. It has three parts, and each of them matters.

The first is the additional information: the key, the lookup table, or simply the original document. The second is that it is kept apart. The third is that it is guarded. Take away any of the three and what you have is not pseudonymisation in the legal sense. It is a copy of the file with some words changed.

The additional information

The key, the lookup table, or simply the original document.

Kept apart

Held separately from the text that was pseudonymised.

Guarded

Protected by technical and organisational measures.

The three parts of pseudonymisation under Article 4(5) of the GDPR. Without all three, it is not pseudonymisation in the legal sense

Six articles and two sections

Seven of the recitals mention it too, which is more attention than most readers expect. Most of those mentions treat it as a safeguard that counts in your favour, not as something that takes the data outside the Regulation.

wherewhat it does there
Article 4(5)defines the term
Article 6(4)(e)a safeguard when judging a new purpose
Article 25(1)an example of data protection by design
Article 32(1)(a)a security measure, beside encryption
Article 89(1)a safeguard for research and statistics
DPA 2018, s. 36(1)(e)(iv)a suitable and specific measure
DPA 2018, s. 69the definition for Part 5, law enforcement

The sixth article, 40(2)(d), lets industry codes of conduct spell out how to pseudonymise. The Irish Act changes nothing in the meaning of the word.

Two recitals name the risk rather than the remedy. Recitals 75 and 85 both list “unauthorised reversal of pseudonymisation” among the kinds of damage a breach can cause. The Regulation assumed from the start that someone might put the names back. If that happens to a file of yours, the question becomes whether you must report it as a breach, which our guide on client data in ChatGPT works through.

What the DPC wrote in 2019, and why it now needs a second reading

The DPC’s guidance note, which covers both techniques, is dated June 2019. Its list of key points is unambiguous, and for an office it is still the right place to start.

Pseudonymised data remains personal data.

The note goes further. It says pseudonymisation “only provides a limited protection for the identity of data subjects in many cases as it still allows identification using indirect means”, and that where a pseudonym is used “it is often possible to identify the data subject by analysing the underlying or related data”. For prose, that second sentence carries the weight.

What the note gets right that the judgment confirms

Read against SRB, the DPC’s position still holds, because it is written from the viewpoint of the organisation that did the work, which is precisely the viewpoint the Court says stays personal. The judgment adds a second viewpoint the note never needed to address: the recipient’s.

The note also warns about a quieter risk. If a pseudonym is reused, it says, it permits the linking together of different records relating to the same individual. A firm that calls the same client “Client A” in every prompt for a month is building exactly that link, with the provider holding every piece; at Google, chats picked for human review are kept for three years.

Where the dates now sit

The copy on the Commission’s site is still the June 2019 text, and it is worth seeing how much has happened around it.

The dates that changed the answer on pseudonymised data Timeline from the DPC note of June 2019 to the close of the EDPB consultation on 30 October 2026. June 2019 DPC note 16 Jan 2025 EDPB 01/2025 pseudonymisation 4 Sep 2025 EDPS v SRB 7 Jul 2026 EDPB 02/2026 anonymisation 30 Oct 2026 consultation closes
Pseudonymised data in Irish practice: the DPC note, the two EDPB texts and the judgment. Sources listed at the end

Two European texts and one judgment have come out since the note was written, and neither of the EDPB texts is final. For now a careful Irish firm reads all four together, and where they differ, follows the stricter one for its own obligations.

EDPS v SRB: the two conditions in paragraph 77

The facts are ordinary enough to recognise. After the resolution of Banco Popular Español, the Single Resolution Board collected comments from shareholders and creditors, replaced their identities with codes, and sent the comments to Deloitte for valuation work. The European Data Protection Supervisor found that the people should have been told Deloitte would receive their comments. The case went to the Court of Justice on appeal.

The First Chamber gave judgment on 4 September 2025. It set aside the General Court’s judgment and sent the case back, but on the way it said a great deal about pseudonymised data.

Paragraph 76: the firm with the key

The Court first described the SRB’s own position, and it reads like a description of any office.

“as is usually the case for controllers who have pseudonymised data, the SRB does, in the present case, have additional information enabling the comments transmitted to Deloitte to be attributed to the data subject”

For the organisation that did the substitution, the data stays personal. The word “usually” matters there: the Court expects the pseudonymising party to hold the key, because it normally does. Our guide to the three words reads the paragraph the same way.

Paragraph 77: what the recipient needs

Then the recipient. The measures may mean the comments are not personal for Deloitte, but only on two conditions, and both must hold.

The two conditions of paragraph 77: when pseudonymised data may stop being personal for the recipient The firm keeps the key and reads personal data. The recipient reads data that may not be personal, only if it cannot lift the measures and cannot identify anyone by matching other data. Your firm holds the original file and the key personal data paragraph 76 text only The provider 1. cannot lift the measures 2. cannot identify anyone by matching other data both, or it is personal paragraphs 77 and 85
EDPS v SRB, C-413/23 P, 4 September 2025: one text, two readers, and what the second one needs

First, the recipient must not be in a position to lift the measures during any processing under its control. Second, the measures must in fact prevent it from attributing the text to the person by any other means, including by checking it against other information. The first is about the key. The second is about everything else in the text.

The Court then closed the obvious escape. Where you cannot exclude that a third party has means reasonably allowing it to attribute the data, such as checking it against other data at its disposal, the person must be regarded as identifiable for that transfer and for any later processing by that third party.

What the Court did not say

It did not say the recipient’s view settles everything. The General Court had held that the Supervisor, when checking the duty to inform, should have looked at the comments from Deloitte’s point of view, and paragraph 115 calls that an error of law.

At paragraphs 111 and 112 it said something that applies directly to any office: the duty to tell people who will receive their data is assessed when the data is collected and from the controller’s point of view, whatever the recipient can or cannot see later.

Is pseudonymised data personal data once it reaches ChatGPT?

Apply the two conditions to a passage someone actually puts into a chatbot and they give very different answers. The first is about architecture and you can meet it. The second is about language, and client prose usually breaks it.

If the substitution happens on your own machine and the table linking each label to a real value stays there, the provider has nothing to reverse. That is a design choice, and it is available today. It is also the only part of the test that a tool can settle for you.

The second condition: what the sentence still says

A paragraph from a client file is not a spreadsheet of codes. It carries a role, a town, an employer, a sequence of dates and a sum of money, and none of those is an identifier until they sit together. The Court referred at paragraph 81 to its own earlier ruling on a press release that named nobody but let the public identify a person by combining it with material on the internet.

Now picture who is on the receiving end. The provider holds an enormous amount of other data, some of it public and some of it from its own users. Under paragraph 85, you do not have to prove it will match the text against other data. It is enough that you cannot rule it out. For most client prose, you cannot.

  1. Does the table linking each label to a real value stay on your machine?

    YesThe provider has nothing to reverse, and the first condition is met.

    NoThe first condition fails, and the text is personal data for the provider.

  2. Can you rule out that the provider matches what is left against other data?

    YesThe second condition may be met.

    NoUnder paragraph 85, the person is identifiable for the provider too.

For most client prose, you cannot rule it out.

The two conditions of paragraph 77 of EDPS v SRB, applied to a prompt. Our reading of the judgment, not legal advice

Ireland adds its own difficulty. Many firms work in towns where the practising professionals know each other, and a masked paragraph is read against a small pool of possible people. Our guide to what the PPSN and Eircode reveal shows how few solicitors practise in some counties; the practical upshot here is that the second condition is harder to meet in Leitrim than in a large city.

Your duties do not wait for the provider’s view

Most summaries skip paragraphs 111 and 112. Whether or not the text is personal data for the provider, your obligation to tell the client who receives their data is judged from your side, at the time you collected it. The provider’s position does not relieve you of anything that was already yours. In practice, that means the AI provider is still listed among the recipients in the data protection notice sent with your terms.

What the EDPB adds: the domain, the key and the processor

Guidelines 01/2025 on pseudonymisation came from the European Data Protection Board on 16 January 2025, with feedback taken until 14 March 2025. As of 23 September 2026 the only version on its site is still the one for public consultation. It is a draft, and it predates SRB, but it contains three ideas that are useful at a desk.

The domain

The circle meant to be unable to identify anyone. Put a passage into a chatbot and the provider is inside yours.

The key

Not only the lookup table: the original file, kept as it was, is part of it too.

The processor

A provider acting on your instructions is still a processor, and still needs a contract.

Three ideas from the EDPB's draft guidelines on pseudonymisation and on anonymisation, neither of them final

The guidelines call the circle of people who are meant to be unable to identify anyone the pseudonymisation domain. The effectiveness of the whole exercise, they say, depends on choosing that domain and keeping it isolated from the information that would reverse it. When you put a passage into a chatbot, the provider is inside your domain whether you drew it or not.

Your original file is part of the key

The second idea sits in a footnote, and it bites hardest in an office. If the controller keeps the original data in the form it had before pseudonymisation, the EDPB says, those original data are also part of the additional information that has to be kept separately.

“If the controller keeps the original data in the form they had prior to pseudonymisation, those original data also constitute part of the additional information that have to be kept separately.”

In practice the key includes the matter file on the server, the email thread and the scanned letter, not only the lookup table. Keeping those apart from the pseudonymised text, and secured, is what makes the word accurate.

The provider is still a processor

The third idea comes from the newer draft, Guidelines 02/2026 on anonymisation, adopted on 7 July 2026 and open for comment until 30 October 2026. Paragraph 15 says that if an entity processes information on behalf of a controller for whom it is personal data, it should also be considered personal data for the processing entity, which should be treated as a processor.

Read with SRB, that closes a tempting argument. Even if a pseudonymised prompt were not personal data from the provider’s side, a provider acting on your instructions is still a processor, and Article 28 still requires a contract. Pseudonymising first does not make the contract optional.

What pseudonymising does buy you under the GDPR

None of this makes pseudonymisation pointless. It is one of the few measures the Regulation names repeatedly, and the EDPB lists what it can earn: support for a legitimate interests assessment under Article 6(1)(f), help in judging whether a new purpose is compatible under Article 6(4), and a contribution to design and security duties under Articles 25 and 32.

The same guidelines add an important qualification: pseudonymisation alone will normally not be a sufficient measure for either design or security. It is one layer, and the Regulation expects others around it. For health or union data held under the employment exception, the Irish Act names it as one of the suitable and specific measures, alongside access limits, training and logging.

The cleaning step has a basis too

There is a point in paragraph 23 of the EDPB text that is easy to miss and useful to know. If a controller processes personal data and applies pseudonymisation in the process, the legal basis for the processing extends to the operations needed to apply it. You do not need a separate justification for the act of replacing the names, provided the underlying use is lawful.

What it does not buy

It does not supply the lawful basis for sending the text in the first place. It does not change what the provider’s terms allow it to keep, which our guides to Anthropic’s rules and Microsoft’s four Copilots go through. And it does not remove the duty to tell clients where their information goes.

Side by side, the two lists look like this.

what pseudonymising helps withwhat it leaves untouched
a legitimate interests assessment, Article 6(1)(f)the lawful basis for sending the text
judging a new purpose, Article 6(4)what the provider’s terms let it keep
design and security duties, Articles 25 and 32the duty to tell clients where their information goes
the cleaning step itself, under the same legal basis (paragraph 23)the Article 28 contract with the provider

One paragraph, three readers: a worked example

Here is the sort of note an Irish practice asks a chatbot to tidy every day. The people, the town and the numbers are invented.

Client Áine Ó Murchú, PPSN on file, practice manager at the only dental surgery in Kilbrannagh, Co Clare, for 14 years. Dismissed on 12 May. WRC hearing listed for 3 November. Her husband runs the pharmacy on the same street. She wants the letter to the employer to be firm but not to burn bridges.

Replace the name and the PPS number with placeholders, as most people would, and the paragraph still reads: a practice manager at the only dental surgery in one small Clare town, dismissed on a stated date after 14 years, a hearing on a stated date, a husband who runs the pharmacy on the same street.

Who can tell who it is

readerholdswho is it, for them?
your firmthe file and the keythe client, by name
the AI providerthe text onlyone person in one town, findable
anyone localthe text and local knowledgeobvious at a glance

The provider fails the second condition of paragraph 77 without trying. One dental surgery in one town gives one practice manager, and since 29 July 2021 WRC hearings have been held in public, with decisions naming the parties unless the adjudication officer finds special circumstances. A published decision is exactly the kind of other data such a match needs.

What would pass

A version that meets the second condition reads differently: an employee of many years in a small professional practice, dismissed this year, a hearing pending, a letter that must stand firm while leaving the door open. It gets you the same draft from the model, and it no longer points at one person in one town. The substitution handles the numbers; the rewriting of the facts is still a person’s job.

Accountancy practices meet the same pattern in a different form: a client’s payroll query with the employer, the role and the pay date left in.

Confidentiality and privilege are a separate question

Everything above is about identifiability, which is a data protection test. A solicitor’s duty of confidence, and the client’s privilege, do not depend on whether the text is personal data at all. A paragraph can be fully pseudonymised and still disclose the client’s affairs.

The High Court has now said so in writing. Practice Direction HC 142, signed by the President of the High Court on 29 July 2026 and in operation from 1 September 2026, lists legal privilege among the known risks of generative AI tools. It also asks for a declaration on affidavits and witness statements, and what a deponent signs under it is a separate duty from this one.

“Privileged information entered into non-private GenAI Tools or systems may lose its privileged status.”

Nothing in that sentence turns on whether names were removed. It turns on where the information went. For a firm, that means the pseudonymisation question and the privilege question get separate answers, and our page for solicitors sets out what the Law Society’s guidance asks on top.

What Nonimo does, and why we call it pseudonymisation

Nonimo runs on the computer in front of you. You select a passage, press one key, and the identifiers it finds are replaced with placeholders before the text goes to ChatGPT, Claude or Copilot. When the reply arrives, the originals are restored. The table that links each placeholder to its value stays on your machine.

That last sentence is why we use the word we use, and why our page for Irish firms uses it too. The substitution can be undone on purpose, since the answer is useless otherwise. Under the Article 4(5) definition, that is pseudonymisation, and the text stays personal data for you. In the language of SRB, the design is aimed at the first condition of paragraph 77: the provider never receives the key.

Nonimo covering the PPS number, date of birth and IBAN in an invented Irish affidavit
The Mac app, version 0.2.8, with an invented affidavit: PPS number, date of birth and IBAN replaced. The Windows app works the same way

In the version available today, 0.2.8, that covers PPS numbers, Eircodes, VAT numbers, names in a signature block, dates of birth, IBANs, mobile numbers and email addresses. The second condition stays with you: a dental surgery in a small town is not an identifier, and what a paragraph reveals to someone local is yours to judge.

What the app stores is on our security page: the map back to the originals is kept encrypted on your computer.

Before it goes: four questions the judgment lets you ask

SRB gives an Irish office a sharper test than “have I taken the names out”. It turns into four questions you can answer before a passage leaves the building.

  1. Who holds the key? If you do, the text is personal data for you, and every duty you had before the substitution you still have after it.
  2. Could the provider reverse it? If the lookup table or the original ever travels with the text, the first condition of paragraph 77 fails.
  3. Could someone match it against other data? Read what is left as the provider would, with the internet and the WRC’s published decisions to hand. If one person still fits, the second condition fails.
  4. What else applies anyway? The contract under Article 28, the transparency owed to the client, and privilege, none of which the word pseudonymised touches.

If the answers are you, no, no and a contract you have read, you have done what the Regulation calls pseudonymisation and done it well. That is worth doing, but it is not anonymisation, and an Irish firm now has a Court of Justice judgment to explain the difference to a client. The written rules for the office belong in an AI policy, and the Irish side of the EU AI Act belongs next to it.

Sources

Checked 23 September 2026.

Common questions

Is pseudonymised data personal data?

For the organisation that holds the key, yes, and that is nearly always the firm that did the pseudonymising. The Court of Justice said so at paragraph 76 of its SRB ruling, delivered on 4 September 2025, while adding that the same data need not be personal for a recipient who cannot reverse it. Nonimo keeps the key on your own computer, so the text you send stays personal data in your hands.

Can pseudonymised data stop being personal data for the person who receives it?

It can, but only if two conditions both hold. Paragraph 77 of the SRB judgment says the recipient must not be in a position to lift the measures, and the measures must prevent attribution even by checking it against other information. A paragraph of client prose usually fails the second. Nonimo addresses the first, because the provider never receives the key; the second depends on what the text still says.

What is the difference between pseudonymisation and anonymisation in Ireland?

Anonymised data falls outside both the GDPR and the Data Protection Act 2018; pseudonymised data can still be attributed to someone using information kept separately. The DPC's guidance note states it flatly in its key points: pseudonymised data remains personal data. Nonimo produces the second kind by design, because it has to put the real details back into the answer.

Does the DPC accept the SRB judgment?

The DPC's anonymisation note is dated June 2019, six years before the judgment, and the version on its site still carries that date. The Court of Justice has the final word on what EU data protection law means, and the European Data Protection Board already builds on SRB in its draft Guidelines 02/2026. Until the DPC updates its note, read the two together. Nonimo's own wording follows the stricter one: we call it pseudonymisation.

Do I still need a contract with the AI provider if I pseudonymise first?

Almost certainly. The EDPB's draft Guidelines 02/2026 say that an entity processing information on behalf of a controller, for whom it is personal data, should be treated as a processor, which brings Article 28 with it. Pseudonymising does not replace that contract. Nonimo reduces what the provider reads; the contract decides what the provider may do with it.

Is pseudonymised data enough to put client information into ChatGPT?

It lowers the risk; it does not settle whether you may. The GDPR lists pseudonymisation as a security and design measure in Articles 25 and 32, and the EDPB says it will normally not be a sufficient measure on its own. The lawful basis, the transparency owed to your client and the provider's terms still apply. Nonimo takes the identifiers out before anything leaves the machine.

Where does pseudonymisation appear in Irish law?

In the GDPR, which applies here directly, and twice in the Data Protection Act 2018. Section 36(1)(e)(iv) lists it among the safeguards a controller can adopt, and section 69 defines it for Part 5, the law enforcement rules. Nonimo is one practical way to apply the measure at the moment text is sent to an AI tool.

Does pseudonymising a document protect legal privilege?

No, that is a separate question. Practice Direction HC 142 from the High Court, in operation since 1 September 2026, warns that privilege can be lost when privileged material goes into a GenAI tool that is not private, however well the names were removed. Nonimo takes client identifiers out of a passage; it does not make privileged material safe to send.