
Pseudonymization reduces the risk of re-identification and can support an AITD, but it never exempts the exporter from the obligations of Chapter V of the GDPR. Since the CJEU ruling of September 4, 2025, everything has been based on a precise question: does the recipient have, yes or no, reasonable means to re-identify the person concerned? Without solid technical and contractual proof of this impossibility, pseudonymization remains a risk reduction tool, not a legal blank check.
In brief:
>
- Pseudonymization reinforces the security of transfers by reducing the risk of reidentification, but does not exempt the exporter from complying with the GDPR.
- The CJEU of September 4, 2025 introduced a contextual assessment, where pseudonymized data can be considered non-personal if the recipient cannot reasonably re-identify it.
- Companies must document precisely who holds the re-identification key, where it is stored and under what jurisdiction, in their impact assessment (AITD).
- Pseudonymization must be accompanied by contractual, technical and organizational guarantees, such as encryption and data separation, to be recognized as an effective measure.
- The re-identification evaluation process must be based on a precise analysis of the local legal framework, the recipient's means, and must produce concrete evidence to demonstrate the reasonable impossibility of re-identification.
Table of contents
- What are the legal mechanisms for transferring data outside the EU?
- What is the legal status of pseudonymization after recent case law?
- How to integrate pseudonymization into the impact analysis of transfers?
- What technical and organizational measures reduce the risk of re-identification?
- What pseudonymization really changes in daily practice
- How Safe-Doc facilitates pseudonymization before a transfer outside the EU
- Where to find texts and reference guides
- Sources
What are the legal mechanisms for transferring data outside the EU?
Chapter V of the GDPR establishes a simple principle: Article 44 prohibits by default any transfer of personal data to a third country, unless one of the tools provided for by the text applies. The objective is not to block international flows, but to guarantee that the level of protection remains equivalent once the data leaves the European Economic Area, as CNIL points out.
Three families of tools structure the practice:
- The adequacy decision: when the European Commission recognizes that a country offers a comparable level of protection, the transfer can be carried out without additional formality or AITD.
- The guarantees of Article 46: revised standard contractual clauses (CCT), binding corporate rules (BCR) or negotiated ad hoc clauses. Each requires documenting the preliminary analysis and following the models published by European Commission.
- Exemptions from article 49: explicit consent, execution of a contract, public interest. They assume a strict necessity test and should only be used in one-off situations, never as a structural basis for a recurring flow.
In practice, certain French companies which transfer data to countries without an adequacy decision often rely on CCTs. It is precisely in this case that pseudonymization comes into play, because it reinforces a contractual guarantee which, alone, is not always sufficient to neutralize the risk of access by foreign authorities.
What is the legal status of pseudonymization after recent case law?
Article 4(5) of the GDPR defines pseudonymization as processing which makes personal data not attributable to an identified person without the use of additional information, kept separately and protected by technical and organizational measures. This definition clearly distinguishes it from anonymization, which makes reidentification irreversibly impossible and takes the data outside the scope of the GDPR. Pseudonymized data remains personal data as long as reidentification remains possible for someone, somewhere.
What the judgment of September 4, 2025 changes: the CJEU has introduced a contextual approach and no longer absolute. The same pseudonymized data can be qualified as personal for the exporter, who holds the reidentification key, and non-personal for the recipient, if he has no reasonable means of accessing it. It was the C-413/23 judgment which established this principle.
This reading concretely changes the way of reasoning. The data controller must now assess the status of the data from the point of view of each actor in the chain, and no longer in a uniform manner. The Court also recalls that the obligation to inform the persons concerned arises at the time of collection, regardless of the subsequent fate of the data.
Three operational consequences arise from this:
- The processing register must reflect this distinction in status between exporter and recipient, rather than a single “pseudonymized” box.
- Information notices must cover transfer outside the EU upon collection, even if the data is pseudonymized before sending.
- The residual risk of re-identification must be documented, not simply stated.
The EDPB recommendations finally specify the conditions for pseudonymization to be recognized as an effective complementary measure: strict separation of information allowing reidentification, reasonable impossibility for the authorities of the third country to access it, and contractual guarantees which formally prohibit any attempt at reidentification by the recipient.
How to integrate pseudonymization into the impact analysis of transfers?

The Impact Analysis of Data Transfers becomes mandatory as soon as a transfer is based on an article 46 tool and no adequacy decision covers the recipient country. It involves both the European exporter and the non-EU importer, who must provide information on their own legal framework and their actual data access practices.
The CNIL practical guide offers a four-step method that most compliance teams can follow without extensive legal expertise:
1. Mapping the flow: identify precisely which categories of data are leaving the EU, to which country, and via which transfer tool.
2. Assess the local legal framework: check whether the legislation of the recipient country allows disproportionate access by public authorities.
3. Test the re-identification capacity: determine whether the recipient, taking into account his technical means and his access to the keys, could reasonably re-identify a person.
4. Document additional measures: list what fills the gap between the local level of protection and that required by the GDPR.
Pro tip: never treat pseudonymization as a checkbox in AITD. Document precisely who holds the key, where it is stored, and under what jurisdiction, because this is exactly what the EDPB and, now, the CJEU look at first.
The deliverables expected at the end of the process are concrete: a dated and versioned AITD report, a mitigation plan listing the technical and organizational measures adopted, annotated contracts specifying non-reidentification clauses, and the results of audits or penetration tests demonstrating that the guarantees hold in practice and not just on paper.

What technical and organizational measures reduce the risk of re-identification?
Effective pseudonymization does not rely on an algorithm, but on the overall architecture that surrounds it. Here are the points that the EDPB recommendations and the CNIL guides consider to be structuring in the face of an inspection.
On a technical level, three reflexes systematically recur in solid files: the encryption of correspondence tables, the physical or logical separation between pseudonymized data and the information allowing their reidentification, and the storage of cryptographic keys exclusively within the European Economic Area. Salted hashing, combined with regular key rotation, seriously complicates any attempt at cross-referenced re-identification.

On the governance side, the logic of least privilege is essential: only people with a real operational need access additional information. Detailed logging of these accesses, a documented key management policy, and regular intrusion tests form the basis expected by a regulator or an external auditor.
The contractual clauses with the importer must go beyond the standard CCTs: explicit prohibition of any attempt at re-identification, right of audit for the exporter, and obligation of immediate notification in the event of a violation affecting pseudonymized information. For health or biometric data, these guarantees must be reinforced, because the level of sensitivity requires greater protection than that of simple commercial data.
- Encryption of correspondence tables and strict separation of datasets.
- Key storage in Europe, with scheduled rotation and salted hashing.
- Limited access, logged, and subject to periodic audit.
- Specific contractual clauses prohibiting re-identification by the importer.
Pro tip: for documents handled on a daily basis by your legal or financial teams, the pseudonymization of GDPR documents deserves to be handled before the transfer, not as a last minute step before export.
What pseudonymization really changes in daily practice
Most compliance files that we come across treat pseudonymization as a technical formality, whereas it is above all a question of proof. What the CJEU judgment of September 2025 clarified is that a company can no longer simply assert that its data is pseudonymized: it must demonstrate, with supporting documents, that the recipient has no reasonable means of accessing it.
At Safe-Doc, this requirement is directly linked to our product approach. The absence of storage of processed documents and the strict separation of correspondence keys facilitate the demonstration of this impossibility of reidentification, whether for exchanges with subcontractors outside the EEA or to secure uses of generative AI in the face of Shadow AI. But no technical tool, even robust, replaces the contract and the audit evidence that must accompany it.
- Jacques
How Safe-Doc facilitates pseudonymization before a transfer outside the EU
Documenting a convincing AITD involves proving, not just asserting, that the recipient cannot re-identify your data. Safe-Doc processes your documents in real time without ever storing them, automatically detects more than 90 types of sensitive data, and generates a mapping export that allows you to restore the original data only on your side.

Concretely, this covers situations that compliance teams encounter every week: preparing a data room for a merger-acquisition operation, exchanging contracts with a subcontractor established outside the EEA, or securing the use of ChatGPT and Claude by your employees without exposing identifying information. Each processing generates an auditability report in PDF format, exactly the type of proof that an AITD or a CNIL control requires. Legal departments and DPOs who wish to integrate these controls into their processes can discover the DPO support offered by Safe-Doc and test the platform on a real use case before integrating it into their international transfer flows.
Where to find texts and reference guides
To go further on the legal and technical aspects discussed here, several official sources remain essential to build a solid compliance file.
- The CNIL AITD guide details the complete method of impact analysis of transfers.
- The EDPB recommendations 01/2020 specify the technical conditions for recognized pseudonymization as a complementary measure.
- The EDPB guide for SMEs summarizes the obligations for structures with limited legal resources.
- The European Commission standard contractual clauses models serve as a contractual basis for any transfer based on article 46.
- For companies structuring an international presence, a domiciliation solution like Adryo can complete this reflection on cross-border flows.
This article constitutes general information and is not a substitute for advice from a qualified attorney. Consult a qualified legal professional regarding your individual case before acting on this content.
Sources
- CNIL - European regulation: data protection
- EDPB - Recommendations 01/2020 (pseudonymization) - 2025 update
- Deshoulieres Avocats - Pseudonymization and personal data: what the CJEU ruling of September 4, 2025 changes
- European Commission - Standard contractual clauses (SCC)