Anonymisation

Data & Tracking

Also: Data Anonymisation · Anonymised Data

What it doesStrips data of identity, permanently
Not the same asPseudonymisation
Why it mattersAnonymised data sits outside privacy law
Trade-offLess useful the more you strip

Quick definition

Anonymisation is the process of removing or altering personal information so a specific individual can no longer be identified, even by combining the data with other sources. Once data is genuinely anonymised, it typically falls outside privacy regulations because there's no person left to protect.

How it varies across Australia

Most Australian businesses claim their analytics data is anonymised when it's actually only pseudonymised. The gap between the two matters more as privacy enforcement tightens. Businesses that genuinely understand the distinction tend to score higher on data and tracking maturity generally.

See data and tracking maturity across Australian industries

What it actually means

Anonymisation is the one-way door of data privacy. Once you've properly anonymised a dataset, there's no key, no lookup table and no combination of other data sources that gets you back to the individual. That's the entire point, and it's also why real anonymisation is harder than most marketing teams think.

Most businesses confuse anonymisation with pseudonymisation. Pseudonymisation replaces a name with a token, an ID, a hashed email. It looks anonymous but it isn't, because someone with the mapping table (or enough patience) can reverse it. Genuine anonymisation removes that possibility entirely, usually by aggregating data, adding statistical noise, or stripping so many identifying variables that reconstruction becomes practically impossible.

This distinction sits underneath most of your consent, cookie and CRM decisions. First-party data that's merely pseudonymised is still personal information under privacy law, even if you call it anonymous in your privacy policy. Attribution models, retention-rate analysis and segmentation all typically run on pseudonymised data, not anonymised data, because true anonymisation destroys the individual-level detail those tools need to function.

If you can still re-identify someone with a bit of effort, you haven't anonymised the data. You've just made your privacy problem harder to spot.

How it shows up

Anonymisation shows up wherever a business decides how much identity to strip before analysis or storage. Aggregated analytics reports that show '12% of visitors from Melbourne converted' rather than listing individuals are anonymised. A GA4 report grouping users by cohort without exposing individual-level identifiers leans toward anonymised, provided the underlying data can't be re-joined to a user ID elsewhere in your stack.

It also shows up in data-sharing agreements, where a business insists a dataset is anonymised to avoid consent obligations, and in audits, where a regulator or a careful data team discovers that supposedly anonymised data can, in fact, be re-identified.

The Australian context

The Privacy Act 1988 treats anonymised information as outside its scope entirely, which is a strong incentive for businesses to label data anonymised even when it isn't. The Office of the Australian Information Commissioner (OAIC) has been explicit that anonymisation requires the information to be incapable of re-identification, not just difficult to re-identify. With the Privacy Act amendments tightening enforcement and penalties, the cost of mislabelling pseudonymised data as anonymised is rising. Businesses relying on first-party data strategies to survive cookie deprecation need to get this distinction right before they lean on it as a compliance shortcut.

Where people get this wrong

Calling hashed email addresses anonymised.A hashed email is deterministic and reversible against a known list. It's pseudonymised, not anonymised, and it's still personal information under privacy law.
Assuming aggregation alone guarantees anonymity.Small sample sizes in aggregated reports can still allow re-identification. A segment of one or two people isn't anonymous just because it's presented as a percentage.
Treating anonymisation as a one-time technical step.Anonymisation can be undone by combining datasets later. A dataset that's anonymous in isolation may not stay that way once it's merged with other sources, so the assessment has to account for what else exists.

Anonymisation vs Pseudonymisation

AnonymisationPseudonymisation
Reversible?No, permanently de-identifiedYes, with the right key or mapping
Covered by privacy lawGenerally noGenerally yes, still personal information
Usefulness for analyticsLimited, individual detail is lostHigh, individual-level tracking still possible
Common exampleAggregated cohort reportingHashed email or customer ID

Related terms

Common questions

Is anonymised data still covered by the Privacy Act?

No. Once information is genuinely anonymised so no individual can be reasonably identified, it falls outside the definition of personal information under the Privacy Act. The catch is that most data labelled anonymised is actually only pseudonymised, and that stays covered.

Can anonymised data ever be re-identified?

If it truly can be, it wasn't properly anonymised in the first place. Genuine anonymisation is meant to be irreversible. Data that can be re-identified by joining it with another dataset is pseudonymised, regardless of what it's labelled.

Does anonymising data hurt my analytics or attribution?

Usually, yes. Attribution and cohort analysis rely on tracking behaviour at the individual or session level, which anonymisation removes. Most marketing stacks run on pseudonymised data for this reason, keeping enough detail for analysis while still limiting exposure.

What's the safest way to anonymise customer data?

Aggregate rather than individualise, strip or generalise identifying variables like exact birthdates and postcodes, add statistical noise where precision isn't needed, and test whether the result can be re-joined against any other dataset you hold. If it can, it isn't anonymised yet.

Debrief

Get the next one

No spam. No fluff. Just the next article, straight to your inbox.

Keep exploring

About New Rebellion

New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.

How we think →