Tue 15 Sep 2026

Anonymisation, pseudonymisation and research: Information Commissioner's Office's new draft guidance

The Information Commissioner's Office (ICO) has published new draft guidance on the use of anonymisation and pseudonymisation in research. The guidance is not yet finalised and is open to consultation until 19 October 2026.

While the guidance applies across sectors, it is particularly relevant for pharmaceutical companies, biotech organisations, digital health providers, healthcare researchers and AI developers operating within the life sciences sector.

Start with anonymisation wherever possible

Researchers and controllers must first consider whether data can be anonymised before processing personal data for research purposes. Personal data should only be used where anonymisation would prevent the research objective from being achieved.

Pseudonymisation is expected when anonymisation is not possible

Where anonymisation would undermine the research, the ICO expects pseudonymisation to be used as a key safeguard and data minimisation measure. However, because pseudonymised data remains personal data, UK GDPR continues to apply and so organisations should anonymise at the earliest opportunity.

Data minimisation is the key compliance obligation

For life sciences organisations, the guidance reflects a growing regulatory expectation that data minimisation should be embedded into research design from the outset. Research protocols, data access arrangements and governance frameworks should be developed on the basis of collecting and retaining only the information necessary to achieve a clearly defined scientific objective.

Risk assessment

Organisations should consider the risk that individuals could be identified from the information being used or shared. This assessment should take into account the nature of the data, who will have access to it, what other information they may already hold, how the data will be shared or made available and the methods that could reasonably be used to re-identify someone. Tools such as the "whose hands" assessment and the motivated intruder test can be useful for evaluating risk. When carrying out research using personal data, it is also important to clearly identify those responsible for the data at each stage of the process and understand the role that each organisation or individual plays. This helps ensure that data is handled appropriately and that responsibilities for compliance are clearly defined from the outset.

Safeguarding

No single safeguard is likely to be sufficient on its own. As such, organisations should apply a combination of measures to protect personal information and reduce the risk of identification. These may include embedding data protection principles into the design of projects from the beginning, implementing appropriate security controls, using Trusted Research Environments (TREs) or Trusted Third Parties (TTPs) and adopting Privacy Enhancing Technologies (PETs). Organisations should also have clear governance and accountability arrangements in place to support the safe and responsible use of data for research purposes. If you are releasing anonymised data, then you must consider your release model, for example the risks that come with public release as opposed to release to a defined group through a secure environment.

Summary

The ICO's draft guidance signals a more sophisticated and risk-based approach to research governance. Organisations operating in life sciences should view anonymisation, pseudonymisation, TREs, privacy-enhancing technologies and documented identifiability assessments as increasingly important components of responsible research and innovation. Given the draft status of the guidance, a degree of "watching brief" is appropriate. Read more on the ICO's draft guidance here.

This article was co-authored by Legal Administrator at MFMac Selina Paton.

Make an Enquiry

From our offices we serve the whole of Scotland, as well as clients around the world with interests in Scotland. Please complete the form below, and a member of our team will be in touch shortly.

Are you contacting us as an individual or business? *


Are you an existing client? *


How would you like us to contact you?


Morton Fraser MacRoberts LLP will use the information you provide to contact you about your inquiry. The information is confidential. For more information on our privacy practices please see our Privacy Notice