Anonymisation
Data & TrackingAlso: Data Anonymisation · Anonymised Data
Quick definition
Anonymisation is the process of removing or altering personal information so a specific individual can no longer be identified, even by combining the data with other sources. Once data is genuinely anonymised, it typically falls outside privacy regulations because there's no person left to protect.
How it varies across Australia
Most Australian businesses claim their analytics data is anonymised when it's actually only pseudonymised. The gap between the two matters more as privacy enforcement tightens. Businesses that genuinely understand the distinction tend to score higher on data and tracking maturity generally.
See data and tracking maturity across Australian industries →What it actually means
Anonymisation is the one-way door of data privacy. Once you've properly anonymised a dataset, there's no key, no lookup table and no combination of other data sources that gets you back to the individual. That's the entire point, and it's also why real anonymisation is harder than most marketing teams think.
Most businesses confuse anonymisation with pseudonymisation. Pseudonymisation replaces a name with a token, an ID, a hashed email. It looks anonymous but it isn't, because someone with the mapping table (or enough patience) can reverse it. Genuine anonymisation removes that possibility entirely, usually by aggregating data, adding statistical noise, or stripping so many identifying variables that reconstruction becomes practically impossible.
This distinction sits underneath most of your consent, cookie and CRM decisions. First-party data that's merely pseudonymised is still personal information under privacy law, even if you call it anonymous in your privacy policy. Attribution models, retention-rate analysis and segmentation all typically run on pseudonymised data, not anonymised data, because true anonymisation destroys the individual-level detail those tools need to function.
If you can still re-identify someone with a bit of effort, you haven't anonymised the data. You've just made your privacy problem harder to spot.
How it shows up
Anonymisation shows up wherever a business decides how much identity to strip before analysis or storage. Aggregated analytics reports that show '12% of visitors from Melbourne converted' rather than listing individuals are anonymised. A GA4 report grouping users by cohort without exposing individual-level identifiers leans toward anonymised, provided the underlying data can't be re-joined to a user ID elsewhere in your stack.
It also shows up in data-sharing agreements, where a business insists a dataset is anonymised to avoid consent obligations, and in audits, where a regulator or a careful data team discovers that supposedly anonymised data can, in fact, be re-identified.
The Australian context
The Privacy Act 1988 treats anonymised information as outside its scope entirely, which is a strong incentive for businesses to label data anonymised even when it isn't. The Office of the Australian Information Commissioner (OAIC) has been explicit that anonymisation requires the information to be incapable of re-identification, not just difficult to re-identify. With the Privacy Act amendments tightening enforcement and penalties, the cost of mislabelling pseudonymised data as anonymised is rising. Businesses relying on first-party data strategies to survive cookie deprecation need to get this distinction right before they lean on it as a compliance shortcut.
Where people get this wrong
Anonymisation vs Pseudonymisation
| Anonymisation | Pseudonymisation | |
|---|---|---|
| Reversible? | No, permanently de-identified | Yes, with the right key or mapping |
| Covered by privacy law | Generally no | Generally yes, still personal information |
| Usefulness for analytics | Limited, individual detail is lost | High, individual-level tracking still possible |
| Common example | Aggregated cohort reporting | Hashed email or customer ID |
Related terms
Common questions
Is anonymised data still covered by the Privacy Act?
No. Once information is genuinely anonymised so no individual can be reasonably identified, it falls outside the definition of personal information under the Privacy Act. The catch is that most data labelled anonymised is actually only pseudonymised, and that stays covered.
Can anonymised data ever be re-identified?
If it truly can be, it wasn't properly anonymised in the first place. Genuine anonymisation is meant to be irreversible. Data that can be re-identified by joining it with another dataset is pseudonymised, regardless of what it's labelled.
Does anonymising data hurt my analytics or attribution?
Usually, yes. Attribution and cohort analysis rely on tracking behaviour at the individual or session level, which anonymisation removes. Most marketing stacks run on pseudonymised data for this reason, keeping enough detail for analysis while still limiting exposure.
What's the safest way to anonymise customer data?
Aggregate rather than individualise, strip or generalise identifying variables like exact birthdates and postcodes, add statistical noise where precision isn't needed, and test whether the result can be re-joined against any other dataset you hold. If it can, it isn't anonymised yet.
Debrief
Get the next one
No spam. No fluff. Just the next article, straight to your inbox.
Keep exploring
About New Rebellion
New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.
How we think →