EU institutions data protection regulation · Regulation (EU) 2018/1725
Article 30a
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 1 part · 2 Council drafts · 0 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to EU institutions data protection regulationThe wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Article in June Presidency compromise · 18 June Council text
Comparison basis: Existing law (23 October 2018) compared with June Presidency compromise · 18 June (18 June 2026)
Article 30a
is added: 30a - Application of pseudonymisation and identification of a natural person
- 1.
Controllers and processors may apply pseudonymisation in order to reduce the risks to the data subjects concerned and to comply with their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. To determine whether a natural person is identifiable, including through personal data having undergone pseudonymisation, account shall be taken of all the means reasonably likely to be used, such as singling out or online identifiers, either by the controller or by another person to identify the natural person directly or indirectly.
- 2.
The application of pseudonymisation to personal data may, depending on the circumstances of the case and provided that appropriate technical and organisational measures are put in place and are such as to prevent the data in question from being attributed to the data subject, effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable.
- 3.
Paragraphs 1 and 2 are without prejudice to other provisions and obligations applicable to the controller, including under Chapter IV and V of this Regulation. The provision set out in paragraph 2 shall not apply to processors.
- 4.
The European Data Protection Board shall issue an opinion, in accordance with Article 64(2) of the Regulation (EU) 2016/679, addressing the application of pseudonymisation and anonymisation, including the related circumstances and technical and organisational measures referred to paragraph 2.
Article 30a
June Presidency compromise · 18 June
Article 30a is added: 30a - Application of pseudonymisation and identification of a natural person
Controllers and processors may apply pseudonymisation in order to reduce the risks to the data subjects concerned and to comply with their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. To determine whether a natural person is identifiable, including through personal data having undergone pseudonymisation, account shall be taken of all the means reasonably likely to be used, such as singling out or online identifiers, either by the controller or by another person to identify the natural person directly or indirectly.
The application of pseudonymisation to personal data may, depending on the circumstances of the case and provided that appropriate technical and organisational measures are put in place and are such as to prevent the data in question from being attributed to the data subject, effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable.
Paragraphs 1 and 2 are without prejudice to other provisions and obligations applicable to the controller, including under Chapter IV and V of this Regulation. The provision set out in paragraph 2 shall not apply to processors.
The European Data Protection Board shall issue an opinion, in accordance with Article 64(2) of the Regulation (EU) 2016/679, addressing the application of pseudonymisation and anonymisation, including the related circumstances and technical and organisational measures referred to paragraph 2.
Article in September Presidency compromise Council text
Comparison basis: Existing law (23 October 2018) compared with September Presidency compromise (3 September 2026)
Article 30a
- Application of pseudonymisation and identification of a natural person
- 1.
Controllers and processors may apply pseudonymisation in order to reduce the risks to the data subjects concerned and to comply with their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information.
- 2.
Pseudonymised data shall not be considered personal data for a person if that person is unable to identify the natural person to whom the data relates, unless paragraph 5 applies.
- 3.
To determine whether a natural person is identifiable, including through personal data having undergone pseudonymisation, account shall be taken of all the means reasonably likely to be used, either by the controller or by another person to identify the natural person directly or indirectly. A natural person is not identifiable where the likelihood of identification is insignificant in practice.
- 4.
Where a processor processes personal data on behalf of a controller, that information shall be considered personal data for the processor, and the processor continues to be subject to the obligations applicable under this Regulation.
- 5.
Where a person other than the controller discloses, transmits or otherwise makes such data available to a third party and, in light of all relevant circumstances, the third party possesses or can obtain means reasonably likely to enable the data subject to be identified, both the transmission of the data to this third party and the subsequent processing of the data by this third party is processing of personal data.
- 6.
The European Data Protection Board shall issue an opinion, in accordance with Article 64(2) of Regulation (EU) 2016/679, addressing the application of pseudonymisation and anonymisation, including the related technical and organisational measures.
Article 30a
September Presidency compromise
Council wording reconstructed for this provision from the official operation
Article 30a - Application of pseudonymisation and identification of a natural person (1) Controllers and processors may apply pseudonymisation in order to reduce the risks to the data subjects concerned and to comply with their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. (2) Pseudonymised data shall not be considered personal data for a person if that person is unable to identify the natural person to whom the data relates, unless paragraph 5 applies. (3) To determine whether a natural person is identifiable, including through personal data having undergone pseudonymisation, account shall be taken of all the means reasonably likely to be used, either by the controller or by another person to identify the natural person directly or indirectly. A natural person is not identifiable where the likelihood of identification is insignificant in practice. (4) Where a processor processes personal data on behalf of a controller, that information shall be considered personal data for the processor, and the processor continues to be subject to the obligations applicable under this Regulation. (5) Where a person other than the controller discloses, transmits or otherwise makes such data available to a third party and, in light of all relevant circumstances, the third party possesses or can obtain means reasonably likely to enable the data subject to be identified, both the transmission of the data to this third party and the subsequent processing of the data by this third party is processing of personal data. (6) The European Data Protection Board shall issue an opinion, in accordance with Article 64(2) of Regulation (EU) 2016/679, addressing the application of pseudonymisation and anonymisation, including the related technical and organisational measures.
Official source passage and amending instruction
(6b) The following Article 30a is added: ‘Article 30a - Application of pseudonymisation and identification of a natural person (1) Controllers and processors may apply pseudonymisation in order to reduce the risks to the data subjects concerned and to comply with their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. (2) Pseudonymised data shall not be considered personal data for a person if that person is unable to identify the natural person to whom the data relates, unless paragraph 5 applies. (3) To determine whether a natural person is identifiable, including through personal data having undergone pseudonymisation, account shall be taken of all the means reasonably likely to be used, either by the controller or by another person to identify the natural person directly or indirectly. A natural person is not identifiable where the likelihood of identification is insignificant in practice. (4) Where a processor processes personal data on behalf of a controller, that information shall be considered personal data for the processor, and the processor continues to be subject to the obligations applicable under this Regulation. (5) Where a person other than the controller discloses, transmits or otherwise makes such data available to a third party and, in light of all relevant circumstances, the third party possesses or can obtain means reasonably likely to enable the data subject to be identified, both the transmission of the data to this third party and the subsequent processing of the data by this third party is processing of personal data. (6) The European Data Protection Board shall issue an opinion, in accordance with Article 64(2) of Regulation (EU) 2016/679, addressing the application of pseudonymisation and anonymisation, including the related technical and organisational measures.’
Article 30a 2 Council drafts
Article 30a
18 June 2026 · June Presidency compromise · 18 June
Article 30a is added: 30a - Application of pseudonymisation and identification of a natural person
Controllers and processors may apply pseudonymisation in order to reduce the risks to the data subjects concerned and to comply with their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. To determine whether a natural person is identifiable, including through personal data having undergone pseudonymisation, account shall be taken of all the means reasonably likely to be used, such as singling out or online identifiers, either by the controller or by another person to identify the natural person directly or indirectly.
The application of pseudonymisation to personal data may, depending on the circumstances of the case and provided that appropriate technical and organisational measures are put in place and are such as to prevent the data in question from being attributed to the data subject, effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable.
Paragraphs 1 and 2 are without prejudice to other provisions and obligations applicable to the controller, including under Chapter IV and V of this Regulation. The provision set out in paragraph 2 shall not apply to processors.
The European Data Protection Board shall issue an opinion, in accordance with Article 64(2) of the Regulation (EU) 2016/679, addressing the application of pseudonymisation and anonymisation, including the related circumstances and technical and organisational measures referred to paragraph 2.
Article 30a
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
Article 30a - Application of pseudonymisation and identification of a natural person (1) Controllers and processors may apply pseudonymisation in order to reduce the risks to the data subjects concerned and to comply with their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. (2) Pseudonymised data shall not be considered personal data for a person if that person is unable to identify the natural person to whom the data relates, unless paragraph 5 applies. (3) To determine whether a natural person is identifiable, including through personal data having undergone pseudonymisation, account shall be taken of all the means reasonably likely to be used, either by the controller or by another person to identify the natural person directly or indirectly. A natural person is not identifiable where the likelihood of identification is insignificant in practice. (4) Where a processor processes personal data on behalf of a controller, that information shall be considered personal data for the processor, and the processor continues to be subject to the obligations applicable under this Regulation. (5) Where a person other than the controller discloses, transmits or otherwise makes such data available to a third party and, in light of all relevant circumstances, the third party possesses or can obtain means reasonably likely to enable the data subject to be identified, both the transmission of the data to this third party and the subsequent processing of the data by this third party is processing of personal data. (6) The European Data Protection Board shall issue an opinion, in accordance with Article 64(2) of Regulation (EU) 2016/679, addressing the application of pseudonymisation and anonymisation, including the related technical and organisational measures.
Official source passage and amending instruction
(6b) The following Article 30a is added: ‘Article 30a - Application of pseudonymisation and identification of a natural person (1) Controllers and processors may apply pseudonymisation in order to reduce the risks to the data subjects concerned and to comply with their obligations under this Regulation, in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. (2) Pseudonymised data shall not be considered personal data for a person if that person is unable to identify the natural person to whom the data relates, unless paragraph 5 applies. (3) To determine whether a natural person is identifiable, including through personal data having undergone pseudonymisation, account shall be taken of all the means reasonably likely to be used, either by the controller or by another person to identify the natural person directly or indirectly. A natural person is not identifiable where the likelihood of identification is insignificant in practice. (4) Where a processor processes personal data on behalf of a controller, that information shall be considered personal data for the processor, and the processor continues to be subject to the obligations applicable under this Regulation. (5) Where a person other than the controller discloses, transmits or otherwise makes such data available to a third party and, in light of all relevant circumstances, the third party possesses or can obtain means reasonably likely to enable the data subject to be identified, both the transmission of the data to this third party and the subsequent processing of the data by this third party is processing of personal data. (6) The European Data Protection Board shall issue an opinion, in accordance with Article 64(2) of Regulation (EU) 2016/679, addressing the application of pseudonymisation and anonymisation, including the related technical and organisational measures.’
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
No Parliament amendment is mapped to these tracked parts.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 30a
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded