Recital 29
EU GDPR

(29) In order to create incentives to apply pseudonymisation when processing personal data, measures of pseudonymisation should, whilst allowing general analysis, be possible within the same controller when that controller has taken technical and organisational measures necessary to ensure, for the processing concerned, that this Regulation is implemented, and that additional information for attributing the personal data to a specific data subject is kept separately.

The controller processing the personal data should indicate the authorised persons within the same controller.

=> Article: 4
=> Dossier: Technical And Organisational Measures, Pseudonymisation

NEW: The practical guide PrivazyPlan® explains all dataprotection obligations and helps you to be compliant. Click here!