Data & identity · also called HEM, hashed email address
Hashed email
A hashed email is an email address transformed by a one-way cryptographic function, usually SHA-256, into a fixed string used to match users across systems without sharing the plain address.
If two companies both know someone's email, they can each hash it and compare the results: the same email always produces the same hash, but the hash cannot simply be reversed into the address. That makes hashed emails the most common key for matching audiences between advertisers, publishers and platforms.
To match correctly, emails must be normalised first, for example lowercased and with spaces removed, then hashed with the agreed algorithm, typically SHA-256. Hashed emails underpin customer-list uploads to social platforms, conversions APIs, clean rooms and identifiers like Unified ID 2.0 and RampID.
The big misconception is that hashing makes data anonymous. It does not. Anyone holding a list of emails can hash them and match, so a hashed email is still pseudonymous data and personal data under GDPR; US regulators including the FTC have said hashing does not make data anonymous. Hashed emails are also persistent and portable, which is why ID bridging and cross-context tracking concerns attach to them.
Think of it like this
A hashed email is like a fingerprint of your email address: it cannot tell a stranger your address, but anyone who has your address can check if it matches.
An example
"[email protected] " is normalised to "[email protected]" and hashed to a 64-character SHA-256 string; a retailer and a publisher each hash their lists and find 1.1 million matching strings.
Related terms
Unified ID 2.0 (UID2)
Unified ID 2.0 (UID2) is an open-source advertising identifier, originally developed by The Trade Desk, generated from a user's hashed and salted email address or phone number with their consent.
Pseudonymous data
Pseudonymous data is personal data where direct identifiers are replaced with a code, such as a hashed email or random ID, so it cannot identify someone without additional information kept separately.
Deterministic matching
Deterministic matching links identifiers to the same person using definite, shared information, such as the same login email or phone number, rather than statistical inference.
Data clean room
A data clean room is a secure environment where companies combine and analyse their customer data together, getting aggregated insights or audiences without exposing each other's raw personal data.
PII (personally identifiable information)
PII (personally identifiable information) is information that identifies, or can be used to identify, a specific person, such as a name, email, phone number or government ID number.
Sources: Unified ID 2.0, GDPR Article 4: definitions