AI Vocabulary
Anonymise or pseudonymise: which of the two protects privilege?
Anonymisation is irreversible: individuals can no longer be identified, by anyone, ever. Pseudonymisation replaces identifying elements with substitutes and keeps the means of reversing the process. In legal work it is always pseudonymisation, since the final deliverable must carry the real names.
The difference, and why it is not cosmetic
Genuinely anonymised data falls outside European data protection law: there is no longer personal data. Pseudonymised data remains fully within it, with every obligation that attaches.
The criterion is reversibility. If a table exists anywhere allowing identities to be restored, the data is pseudonymised, however robust the process.
Why legal work cannot anonymise
Because an instrument must name the parties. A clause, an opinion, a set of submissions serve no purpose if they cannot be restored to nominative form.
The process is therefore necessarily: substitute before processing, process, then restore. A provider describing that as anonymisation is describing its own system inaccurately, and the imprecision is worth noting — it usually heralds others.
What determines the value of the process
A single question: where is the correspondence table held, and who holds the key that reads it?
If the table is encrypted and the key stays with you, a third party obtaining the processed data obtains a legal structure without knowing whom it concerns. The leak exists and its content is heavily degraded.
If the table sits in the same place as the data and is accessible to the same people, the process adds a step without adding a barrier.
What to ask a provider
Four questions, whose answers should be written and signed by someone who binds the company.
Which elements are substituted: names of individuals only, or also companies, addresses, amounts, dates? Scope varies widely between arrangements.
Where is substitution performed: at your end before any transmission, or at the provider's after receipt? In the second case, identifying data has already left your infrastructure.
Where is the correspondence table held, and under what encryption? And who holds the key, distinguishing who holds it technically from who is entitled to it contractually.
One last point worth checking: what becomes of the table once processing is complete? An arrangement that keeps it indefinitely gradually rebuilds a mapping between your matters and your clients, which is exactly what substitution was meant to prevent.
What it does not solve
Privilege and professional secrecy do not attach solely to identities. A transaction described with its figures, its sector and its timetable may remain recognisable to someone in the market, with no names at all.
Pseudonymisation therefore sharply reduces exposure without eliminating it. That is how it should be presented: a risk-reduction measure, not a guarantee of impossibility.
It dispenses with none of the other obligations: records, information to data subjects, and retention periods apply identically to pseudonymised data.
Why it matters to a lawyer
Because this is the point where a serious provider distinguishes itself from an approximate one in a single sentence. Ask whether it anonymises or pseudonymises; if the answer is anonymises without hesitation, ask how the real names are restored in the final deliverable.
The answer to that contradiction will tell you more than 30 pages of documentation.