Glossary

Pseudonymisation

Processing data so it can no longer be attributed to a person without additional information kept separately: a risk-reduction measure, not an exit from data protection law.

Defined in
GDPR Article 4(5)
Still personal data
Yes
Used here for
The visitor key on consent records

Pseudonymous is not anonymous

Anonymous data falls outside data protection law because no one can re-identify it. Pseudonymous data stays inside, because someone with the additional information can. The GDPR encourages pseudonymisation as a safeguard (Article 25 names it in the privacy-by-design provision) while keeping the data in scope.

Calling pseudonymous data anonymous in a privacy notice is a common and material error. It tells people their data is outside the regime when it is not.

How it is used here

A consent record is keyed on a pseudonymous visitor key rather than a name or email. That avoids direct identifiers, but the key still links decisions and can support singling out or re-association, so the record remains personal data. Retention is bounded by plan rather than indefinite.

Common questions

Can I keep pseudonymous records forever?

Storage limitation still applies, because the data remains personal data. Keep records long enough to answer a challenge to a decision you relied on, and no longer.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.