HomeKnowledge HubWeekly Guidance Watch › The Anonymisation Decision-Making Framework (2nd Edition)

Practitioner framework · surfaced resource

The Anonymisation Decision-Making Framework (2nd Edition)

UK Anonymisation Network · University of ManchesterFramework — first published 2016, 2nd edition 2020

Someone asks whether a dataset can go out as anonymous. Most guidance will tell you what the test is. Much less of it takes you through the decision itself — in an order you can repeat, and a form you can evidence afterwards. That is what the ADF is for — ten components, a set of templates, and a way of thinking that treats anonymity as a property of the data and the environment they sit in, rather than a technique you apply to a spreadsheet. It is the most complete openly published process of its kind we have found.

Published by
UK Anonymisation Network (UKAN), University of Manchester. Authors: Mark Elliot, Elaine Mackey and Kieron O’Hara. UKAN is a not-for-profit; per the joint ICO–UKAN statement the ICO initiated the network and seed-funded it from 2012–2014, the two organisations are independent, and they meet at least twice a year to share good practice. UKAN also offers consultancy, clinics and training on a paid basis; we link to the framework, which is published openly. We have no relationship with UKAN and this is not an endorsement in either direction.
Type
Practitioner framework and book — first published 2016; current 2nd edition published 2020, roughly 120 pages. The full book’s licence was changed to CC BY 4.0 on 29 January 2024. Accompanied by a short Overview, a European Legal Context summary (both still under the earlier CC BY-NC-ND licence), a Data Situation Evaluation Template, a Data Features Template, a Data Situation Evaluation Tool (spreadsheet), and companion notes on the DIS method, disclosure scenarios, standard key variables and differential privacy.
Jurisdiction
UK-authored, GDPR-framed; the legal commentary is written against the GDPR and the DPA 2018 and reads across to the UK GDPR in substantially the same terms. Written in 2020 — it predates the ICO’s anonymisation and pseudonymisation guidance (28 March 2025), the CJEU’s judgment in EDPS v SRB (4 September 2025) and the EDPB’s draft Guidelines 02/2026 on Anonymisation (adopted for consultation 7 July 2026). Take the method from here; take the legal test from the ICO.
Primary audience
Anyone who has to decide whether data can be released, shared or published as anonymous — DPOs, data-sharing and information-governance leads, research and analytics teams, public-sector data custodians.
Topic tags
anonymisation · pseudonymisation · identifiability · disclosure risk · data sharing and reuse · DPIA · re-identification
Availability
Free download from ukanon.net — book, summaries, templates and tools. No registration.

Why it matters

The organising idea is what the authors call the data situation — the data together with their environment — and what follows from it is the useful part: anonymity is not a property a dataset carries around with it, so the same file can be personal data in one environment and not in another. That is why the framework asks you to map four elements of every environment the data pass through (agents, other data, governance, infrastructure) before it asks you to touch the data at all. It is also, the authors argue, how Recital 26’s “means reasonably likely to be used” is best assessed. The reasoning runs parallel to the approach the Court of Justice took in EDPS v SRB (Case C-413/23 P, judgment of 4 September 2025), where identifiability was assessed from the position of the recipient and by reference to the means reasonably likely to be available to it — an EU judgment, so persuasive rather than binding here, and the ICO’s anonymisation and pseudonymisation guidance remains the operative UK test.

The framework’s second commitment is functional anonymisation: useful data cannot carry zero re-identification risk, so the work is to bring residual risk down to negligible and then manage it, rather than to claim it away. This is defensible risk management, not a safe harbour.

The ten components follow from those two ideas. Components 1–6, the Data Situation Audit, establish what you are actually trying to do, where the data flow, what you are responsible for, what the data are, who the stakeholders are, and whether the residual risk is negligible. Two points in that section are easy to lose sight of and the guide is helpful on both: provenance does not stop being your concern because you sit downstream of collection, and controllership does not depend on holding the personal data yourself. Component 7 is the technical layer — intruder testing, data-analytical risk assessment, comparative data situation analysis; controls on the data such as suppression and noise addition, or controls on the environment such as access and licensing, or a confidentiality model such as k-anonymity or differential privacy — applied proportionately and looped with component 6 until the risk is negligible. Components 8–10 cover the ground that is easiest to leave until last: maintain stakeholder trust, plan for what you will do if re-identification or disclosure does occur (breach management, notification, review and communication — Arts. 33 and 34, where the data in question are personal data), and monitor a data situation that will not hold still.

Two things worth carrying in before you start. Anonymisation is itself processing of personal data: it needs a lawful basis under Art. 6, a purpose-limitation assessment under Art. 5(1)(b), and an Art. 9 condition where special category data are in scope. And releasing an anonymised extract does not end your obligations over the source dataset or any keys you retain — the framework is explicit that data which are functionally anonymous for a recipient remain the controller’s responsibility upstream.

With those in place, the commercial case runs both ways. Data that can be defensibly released as anonymous sits outside the regime and can be shared, published or reused without the consent, transparency and rights machinery that would otherwise attach — real value, and value that unnecessary caution leaves on the table. Data that cannot should not go out, and the audit is what tells you which you are holding while the decision is still reversible. Either way what you are left with is evidence — a documented data situation, a risk assessment proportionate to the risk, and a monitoring policy — which maps closely onto the accountability record Art. 5(2) requires, and which the authors say plainly can form a key part of a DPIA under Art. 35.

One caution to carry into it, and one thing that has moved since it was written. The legal commentary dates from 2020, so treat the ICO’s anonymisation and pseudonymisation guidance as the UK yardstick. And on 7 July 2026 the EDPB adopted draft Guidelines 02/2026 on Anonymisation for public consultation, open until 30 October 2026 — the first update to the Article 29 Working Party’s Opinion 05/2014 on anonymisation techniques, and, as EU guidance, not binding in the UK. The draft sets out a test built on three criteria — no record isolation, no linkage, no inference. Meet all three and the information may be regarded as anonymous; fall short on one and further analysis may be required. The criteria are assessed either through a contextualised approach, entity by entity against the means each is reasonably likely to use, or through a deliberately cautious simplified approach that disregards those differences (the EDPB is clear that the simplified approach “is not an alternative legal standard”, only a voluntary shift from false positives to false negatives). Read alongside the ADF, the two are close relatives arriving from opposite directions: the EDPB reasons down from Recital 26 and EDPS v SRB, the ADF reasons up from disclosure-control practice, and both land on identifiability as something you assess per entity and per environment rather than once for the dataset. What the draft does not set out is an order of operations. It is candid about its own limits — assessments “will often require a case-by-case analysis and may require considerations not fully covered by this document” — and that is where a framework like the ADF earns its place. Worth noting too: the draft says controllers should ensure adequate documentation of the anonymisation processing and retain it after completion (para. 41). A Data Situation Audit is one reasonable way to produce it.

If 120 pages is more than the question in front of you warrants, there is a shorter way in. The Guide to Getting Started with Anonymisation, published in June 2025 by the Asia Pacific Privacy Authorities technology working group — nine authorities including the Office of the Privacy Commissioner of Canada, Japan’s PPC, Korea’s PIPC, Singapore’s PDPC and Hong Kong’s PCPD — sets out a five-step method anchored to ISO/IEC 27559, with ISO/IEC 20889 for the taxonomy of techniques, and a worked case study. Its scope is structured, non-complex datasets, so it will not carry a hard release decision on its own; but it is a good deal quicker to read, and it gets you to the point where the ADF is worth opening. It is listed in our Key Publications & Reports directory.

Read alongside the EDPB’s Guidelines 01/2025 on Pseudonymisation, which set out the law on the distinction this framework depends on, and the EDPB DPIA template and AEPD risk management and DPIA guide from issue #4, which are where a Data Situation Audit most naturally lands.

A Weekly Guidance Watch resource entry, curated by VulaPri. We summarise and link to the original; we do not reproduce or host it. Suggest a correction.