The Privacy Partnership Podcast with Robert Bateman
This week, Robert Bateman breaks down the newly adopted EDPB Guidelines 02/2026 on Anonymisation. Dragging the ancient 2014 Working Party 29 framework into the age of generative AI and EU data spaces, these new rules are dense, highly technical, and will undoubtedly complicate your compliance programmes. Robert explores the new concept of "relative anonymity," explains the rebranded technical criteria, and discusses why making your data anonymous might actually trigger a 72-hour data breach notification down the line. In this episode, we cover: Relative Anonymity: What the EDPS v SRB case means for controllers, and how data can be anonymous to a recipient but still constitute personal data for the sender. The Assessment Gauntlet: Navigating the "contextual" vs. "simplified" approaches (and why the EDPB expects you to evaluate the capabilities of cybercriminals and foreign spies). The New Technical Criteria: A look at the replacement tests for anonymity: No Record Isolation, No Linkage, and No Inference. The AI Threat: How "membership inference" attacks against AI training data are raising the bar for the No Inference test. The Processing Trap: Why the sheer act of running an anonymisation algorithm is a processing activity requiring its own Article 6 (and potentially Article 9) legal basis. The Expiry Date on Anonymity: How a completely unrelated security incident on the other side of the internet can instantly turn your anonymous dataset back into personal data.
50 episodes
Comments
0Be the first to comment
Sign up now and become a member of the The Privacy Partnership Podcast with Robert Bateman community!