2 ms·
It seems to me this counts only as pseudonymisation and not anonymization. While the hash is not directly readable, it's still reversible with additional inform
by Erwin 8y ago
It seems to me this counts only as pseudonymisation and not anonymization. While the hash is not directly readable, it's still reversible with additional information (such as a large list of email addresses and knowledge of the hashing algorithm).
One of the GDPR notes says:
> [p]ersonal data which have undergone pseudonymization, which could be attributed to a natural person by the use of additional information, should be considered to be information on an identifiable natural person”
Consider that you are running some kind of controversial/embarassing site of sexual/political/other sensitive nature. You keep a hashes of people who once were users but unsubscribed or something like that.
If that database is leaked, a user could re-hash list of political figures, celebrities or just some big list of well known email addresses and with this information find out they were users of this sensitive site.
So to me it seems that pseudoanymized/hashed emails still count as PII and have to be treated as such.