Anoni

Guide

Pseudonymization and anonymization.

The GDPR does not treat them as synonyms. Anonymization is irreversible and leaves the regulation. Pseudonymization stays reversible, so it stays personal data.

Updated 3 September 2026

Two words, two regimes.

People use them as synonyms. The GDPR does not. One of them takes data out of the regulation entirely. The other leaves it inside, governed as personal data like anything else. Treating them as the same thing means believing you are in the clear when you are not, and the mistake is almost always made in the reassuring direction.

Anonymization: irreversible, and outside the GDPR.

Data is anonymous when nobody can get back to the person. Not you, not a third party, not by cross-referencing another file. It is final. Only at that point does the data leave the scope of the regulation, which Recital 26 states plainly. The threshold is high. The established test, from the Article 29 Working Party's opinion on anonymisation techniques, is three risks: singling someone out, linking them to other records, inferring information about them. While any one of those holds, the data is not anonymous.

Pseudonymization: reversible, so still personal.

Replacing a name with a code, a token or a plausible fake is pseudonymization, defined in Article 4(5). The mapping exists somewhere, so the operation can be undone. The regulation says the consequence without hedging: in Recital 26, data that has undergone pseudonymisation and could be attributed to a person by using additional information should be considered information on an identifiable person. It reduces risk. It does not remove it.

Why the confusion is expensive.

Plenty of tools advertise « anonymize » while they pseudonymize. The difference is not semantics. Treat pseudonymized data as anonymous and you skip obligations that still apply: a lawful basis, minimisation, data subject rights, records of processing. The safe reflex is the other way round. Assume the data is still personal unless you can show real, irreversible anonymization.

The case of an online AI.

Pasting a file into a prompt transfers the data to the model provider. That is the point to hold on to. The question then becomes what actually leaves. Replace the names, the addresses, the bank details and the national identifiers before you send, and you pseudonymize at the source: the model never sees the identities. It is the safeguard the French data protection authority, the CNIL, retains in its recommendations on AI, and the one the French Bar Council retains for professional secrecy. It is not an exit from the GDPR. It is less data leaving.

What Anoni does, without overpromising.

Anoni pseudonymizes on your own machine, before anything is sent. It does not make your data « anonymous » in the regulatory sense, and it does not take you out of the GDPR. It reduces what leaves, at the source. « Anoni everywhere » makes that immediate: one shortcut pseudonymizes the text in your clipboard before you paste it into an AI. The mapping back to your real data stays in a vault encrypted with AES-256-GCM, behind your passphrase, which is what makes it reversible. Entirely local.

Questions

Is pseudonymization enough to leave the GDPR?

No. Pseudonymized data is still personal data: the mapping exists, so the operation is reversible, and Recital 26 says such data should be treated as information about an identifiable person. Only irreversible anonymization takes data out of the regulation, and its threshold is high. Pseudonymization reduces risk; it does not lift the obligations.

Is replacing a name with a token anonymization?

No, it is pseudonymization. As long as a mapping table can bring back the original name, the data is not anonymous. This is not a fine point of interpretation: it follows directly from the definition in Article 4(5) and from Recital 26.

Does Anoni really anonymize my documents?

Anoni pseudonymizes, locally: it replaces identifying data with plausible fakes, reversibly, through an encrypted vault. It does not claim to reach irreversible anonymization. Its job is to reduce what leaves your machine before an AI sees it, which is a different and more honest promise.

Is this specific to France?

The definitions are not: Article 4(5) and Recital 26 apply across the EU and the EEA, and the UK GDPR carries the same wording. What is French here is the source of two practical recommendations, the CNIL's guidance on AI and the French Bar Council's on professional secrecy. Anoni is built in France, which is why they are the ones cited.

The definitions above are those of the GDPR itself, Article 4(5) and Recital 26. The three-risk test comes from the Article 29 Working Party opinion on anonymisation techniques. See also pseudonymization compared with redaction, the GDPR frame for prompting an AI, and download Anoni to try it.