Aug 02, 2026 · 8 min read
EDPB's New Test: Is Your Tracking ID Really Anonymous?
Draft Guidelines 02/2026, adopted 7 July 2026, retire the Article 29 Working Party's 2014 opinion and replace it with three gates every dataset must clear. Consultation closes 30 October.
Twelve years is a long time in data protection. The last time European regulators wrote down what "anonymous" actually means, the Article 29 Working Party issued Opinion 05/2014 — two years before GDPR applied, long before generative models made re-identification cheap. On 7 July 2026 the European Data Protection Board retired it. The replacement is harder on outcomes and contains a three part test that a great many "anonymous analytics" claims will not survive. The per recipient identifier inside a marketing tracking pixel is one of them.
Key Takeaways
- The EDPB adopted Draft Guidelines 02/2026 on Anonymisation, Version 1.0 on 7 July 2026, superseding the Article 29 Working Party's Opinion 05/2014.
- Public consultation on the draft closes on 30 October 2026.
- Data counts as anonymous only if it clears all three criteria at once: no isolation of individual records, no linkability to other datasets, and no inference about a specific person.
- The Court of Justice's September 2025 judgment in EDPS v SRB (C-413/23 P) held that pseudonymised data is not automatically personal data for every recipient, and the EDPB has built that relative view into the guidelines.
- Anonymisation is itself processing, so it needs an Article 6 legal basis, written evidence that it worked, and periodic reassessment.
What Do Guidelines 02/2026 Actually Change?
They swap a catalogue of anonymisation techniques for a structured test answered per organisation rather than per dataset. Opinion 05/2014 graded methods — k-anonymity, l-diversity, noise addition — against a risk grid. The 2026 draft asks a question and expects you to show your working.
The question has two steps. Does the data relate to a natural person, by content, purpose or effect? If it does, is that person identified or identifiable, judged by the "means reasonably likely to be used"? Say no to either and GDPR does not apply. Say yes to both and everything downstream follows: legal basis, subject access, breach notification.
Sidley's Data Matters attributes the rewrite to four pressures at once — accumulated CJEU case law, new instruments including the EU Data Act and the European data spaces framework, advances in AI, and better re-identification techniques. Source: datamatters.sidley.com. EDPB Chair Anu Talus called the result a "significant milestone in clarifying the notion of anonymous data." Source: edpb.europa.eu.
Who Is the "Relevant Entity", and Why Does It Matter?
The relevant entity is whoever holds the data at the moment you ask the question, and the answer can legitimately differ between holders. One file can be personal data in your hands and anonymous in a recipient's.
That comes straight from the CJEU. In EDPS v SRB (C-413/23 P), decided in September 2025, the Court held that pseudonymised data may not be classified as personal data in all cases and for every recipient. Freshfields reads the draft guidelines as adopting exactly this relative approach as their foundation. Source: freshfields.com.
Read what the ruling did not say, because it is being oversold. SRB did not declare pseudonymised data anonymous. It made identifiability a question you answer about a specific recipient with specific means — narrower and more demanding. The guidelines then close the obvious loophole: where a processor handles data on a controller's behalf, the controller's perspective governs, so the data stays personal for the processor even if the processor alone could not identify anyone. That disposes of the most popular vendor defence in email marketing — "we only ever see an opaque token."
Contextual or Simplified: Which Approach Should You Use?
Start simplified, then move to contextual only where the simplified verdict is unworkably strict — the sequence the EDPB itself suggests. The two approaches differ in one variable: whether you may notice that organisations have unequal resources.
- Simplified approach. Disregard capability differences and assume every entity is equally equipped. Cheap to run, conservative in outcome, easy to defend in an audit.
- Contextual approach. Assess each entity's actual technical capability. A two person nonprofit is not held to a data broker's standard. More accurate, considerably more work.
Simplified is both cheaper and stricter, so anything clearing it needs no further argument. Contextual is where a regulator will look hardest, because it is the approach you reach for when the simplified answer was inconvenient. The IAPP frames the pairing as a genuine strategic choice rather than a formality. Source: iapp.org.
What Are the Three Criteria for Anonymous Data?
Isolation, linkability and inference — and all three must be defeated, in both the simplified and the contextual approach, before data can be presumed anonymous.
- No record isolation. Nobody can single out the records relating to one individual with sufficient precision.
- No linkability. Records cannot be joined to another dataset carrying matching identifiers.
- No inference. Nothing meaningful can be deduced about a specific individual, whether from the records or from aggregate statistics built on them.
The word doing the work is cumulative. In 2014 these read as risks to be scored and balanced, where two strong controls could offset one weak one. In the 2026 draft they are gates. Fail one and the dataset is personal data, however well it does on the other two.
Do Email Tracking Identifiers Pass the Test?
No, and not narrowly — a per recipient tracking pixel fails all three criteria by design. To be clear about whose claim this is: the guidelines are general and say nothing about tracking pixels. Applying the test to them is my analysis, not the EDPB's finding.
The mechanism makes the analysis short. A tracking pixel is an image tag pointing at a URL carrying a unique token for one recipient. When your mail client fetches it, the sender's server writes a row: token, timestamp, IP address, user agent. Run that row through the three gates.
- Isolation. The token's entire purpose is to isolate one recipient from the rest of the send. It fails this gate by construction, not by accident.
- Linkability. The token resolves to a row in the mailing list, and that row holds an email address. The join is a foreign key.
- Inference. Open time, open count, device, approximate location, and the reading pattern across a campaign are all deductions about a specific named subscriber.
Three failures out of three. "Anonymous open rate analytics" describes the dashboard, not the log the dashboard is computed from — and the guidelines assess the data, not the report. This is not an isolated position. Italy's Garante and France's CNIL reached consent obligations for open tracking from a different direction entirely, through ePrivacy terminal access rules rather than the definition of personal data. See our coverage of the Garante's Provision No. 284 on tracking pixels and the CNIL's recommendation and its compliance deadline. Two independent legal routes converging on one conclusion is usually a sign the conclusion is durable. The rethink is not confined to Europe either: China's TC260 is redrawing when consent can be skipped entirely in its national personal information standard.
What This Means for Your Inbox
If you receive marketing email in Europe, the practical effect is that the "it's just anonymous analytics" line gets much harder for a sender to hold. Under the new framework the open log is personal data about you, which drags along the whole apparatus: a lawful basis, a place in the privacy notice, an answer when you file a subject access request, and a retention period that ends.
It also puts pressure on a common architecture. Many senders outsource open tracking to an email service provider and treat the provider's hashed token as a firewall between themselves and personal data. The controller perspective rule removes that firewall — the provider processes on the sender's behalf, so the sender's ability to resolve the token is what counts. The EDPB's coordinated enforcement work on email transparency already probes whether senders disclose this tracking at all; the anonymisation guidelines remove one of the last excuses for not disclosing it.
None of this changes what happens on your end. Your mail client still fetches remote images unless you stop it. Regulation sets what senders owe you; it does not intercept the request.
What Should You Do Before 30 October?
Four things, in order. The first is uncomfortable because it usually produces a longer list than expected.
- Inventory every dataset you currently label anonymous. For each, name the relevant entity holding it and record which approach you used. An unlabelled assessment is one you cannot defend.
- Re-run the three criteria as gates. Anything that previously passed on a balance of risk needs retesting under a cumulative standard. Expect analytics exports and marketing engagement logs to be the first casualties.
- Decode one real tracking URL from your own sends. Pull the pixel URL from a production email and check whether the token resolves to a subscriber record. If it does, that log is personal data and belongs in your Article 30 record.
- Give anonymisation itself a legal basis, documentation and a review date. The guidelines treat it as processing and expect periodic reassessment, particularly after a security incident, since re-identification risk only rises over time.
Then consider filing a consultation response on the EDPB's public consultation page. The version that emerges will govern anonymisation claims for years — the last one lasted twelve.
While you are inventorying, note where those logs physically sit. The same Board has also asked the Commission to reassess the EU-U.S. Data Privacy Framework, and if a tracking log is personal data, the transfer basis carrying it to a US vendor matters just as much as the anonymisation claim.
The Bottom Line
Most commentary on Guidelines 02/2026 reads the SRB inheritance as a loosening — proof that pseudonymised data can escape GDPR. The opposite reading is at least as defensible. Making identifiability relative to a named entity does not lower the bar; it multiplies the number of times you have to clear it, once per entity, with documentation each time. And for email the arithmetic is not close: an identifier built to distinguish one recipient from every other recipient cannot honestly be called anonymous under a test whose first gate is "you cannot distinguish one recipient."