
Author:
Sharon Heys, Head of Legislation and Due Diligence, SAIL Databank
Those working in the field of data governance will be all too familiar with the dilemma of whether anonymisation of personal data can actually be delivered. If achieved it is the perfect position for data controllers giving them a ‘free pass’ in relation to the obligations that come from processing personal data under UK laws.
If a controller claims to have achieved anonymisation, its data is free from the legal constraints of the Data Protection Act and the UK GDPR. Anonymisation is the ‘utopia state’ for those of us who operate in the world of privacy protecting Trusted Research Environments (TRE’s).
The reality, all too often however, is that no matter how long or protracted the discussions around methodologies, or how complex the governance employed, there is a long-held reluctance to accept that data anonymisation has been achieved. This often proves a sticking point, especially when dealing with big data for academic and scientific research and data acquisitions for TREs. Given the implications for the data, in some respects perhaps we should not be surprised. Anonymised data can in theory be sent anywhere, or given to anyone, without consequence.

Given the aim of the current labour government, to achieve a data driven economy using AI to drive growth, responding to this dilemma should surely be a higher priority. We need data at scale to flow to realise these gallant objectives.
The UK ICO which has over the years been the author of much comprehensive and accessible guidance, is currently in the process of updating and amending its longstanding ‘Code: Anonymisation: managing data protection risk code of practice’ which was first produced in November of 2012. Its new code which is currently being redrafted following consultation and in line with the introduction of the Data (Use and Access) Bill, is helpful and seeks to bring pragmatic guidance to this issue in line with developments in technology. The current date for publication is Spring 2025.
The draft code offers hope to practitioners who have grappled with the issue of anonymisation for years. The guidance contains a really helpful flowchart, which categorises data into ‘Truly Anonymised’ and ‘Effectively Anonymised’, stating that current data protection law does not apply to either use case.
The guidance clarifies that data controllers should consider whether an individual is ‘likely to be identifiable’ taking into account the controls and balances of a TRE in association with the following criteria for assessing the likelihood of reidentification risk:
- motivation;
- competence needed;
- cost and time required;
- the available technologies; and
- legal gateways and likelihood of their use.
If the TRE can show that after the application of its controls, reidentification is unlikely, the data can be considered effectively anonymised according to the ICO.
So is the new guidance a magic bullet? Will this stop the endless discussion about anonymisation? Will we still have discussion about the application of the ’Anonymisation Decision Making Framework’ or will data controllers rest easy, accepting that their data can be used for public good, without the fear of repercussions?
Much in the world of data processing is dependent on trust and reputation. Both are hard won and easily lost and it is therefore easy to understand the reticence of those being asked to hand over their data for research. The Code is going to need to hit hard if it is to have real effect.
Whilst SAIL sincerely hopes that the new guidance will help to alleviate confusion and instil trust, reservations remain. Not about the guidance itself, but in relation to whether we can persuade data controllers to accept that a well governed TRE does indeed provide the clear counter to the factors set out by the ICO, that facilitate effective anonymisation. What further steps can be taken by TRE’s we ask, we are all accredited, certified and audited beyond measure.
How indeed to provide comfort to nervous data controllers? There is no badge for effective anonymisation. Perhaps it is time that we considered one, or would this simply end up as more red tape with little benefit? This debate will undoubtedly continue, but we think it needs to be moved up the agenda if we are to reap the benefits from the potential linkages at scale that could deliver real change to the country.
We are really interested to hear your views on this debate.
Leave a Reply
You must be logged in to post a comment.