Privacy & regulation · also called Pseudonymised data, pseudonymisation
Pseudonymous data
Pseudonymous data is personal data where direct identifiers are replaced with a code, such as a hashed email or random ID, so it cannot identify someone without additional information kept separately.
Pseudonymisation swaps obvious identifiers for stand-ins. Instead of "Priya Sharma, [email protected]", a system stores "user 8f3a9c". Much advertising data works this way: cookie IDs, advertising IDs, hashed emails, Unified ID 2.0 tokens and RampIDs.
GDPR defines pseudonymisation in Article 4(5) and treats it as a good security measure, but pseudonymous data generally remains personal data, because it can be linked back to a person by someone holding the key or by combining it with other data. EU case law has suggested the answer can depend on whether a particular recipient can realistically re-identify the person. Anonymous data, by contrast, is data from which no one can reasonably identify an individual, and it falls outside GDPR.
The common mistake in ad tech is to treat pseudonymous as anonymous. A persistent ID that follows someone across sites, even without a name, enables profiling and is regulated under GDPR, CCPA / CPRA and DPDP. Pseudonymisation reduces risk; it does not remove obligations.
Think of it like this
Pseudonymous data is like a coat-check ticket: the attendant does not need your name, but the ticket still leads straight back to your coat.
An example
An ad platform stores campaign logs keyed by random IDs. Because it also holds a table linking those IDs to logged-in accounts, the logs remain personal data under GDPR.
Related terms
PII (personally identifiable information)
PII (personally identifiable information) is information that identifies, or can be used to identify, a specific person, such as a name, email, phone number or government ID number.
Hashed email
A hashed email is an email address transformed by a one-way cryptographic function, usually SHA-256, into a fixed string used to match users across systems without sharing the plain address.
GDPR
The GDPR (General Data Protection Regulation) is the European Union's data protection law, applying since May 2018, which governs how organisations collect and use personal data about people in the EU.
Unified ID 2.0 (UID2)
Unified ID 2.0 (UID2) is an open-source advertising identifier, originally developed by The Trade Desk, generated from a user's hashed and salted email address or phone number with their consent.
Data minimization
Data minimization is the privacy principle that organisations should collect and keep only the personal data that is adequate, relevant and necessary for a specific, stated purpose.
Sources: GDPR Article 4: definitions, GDPR full text (gdpr-info.eu)