A brand hashes customer email addresses before uploading them to an ad platform for matching and claims the data are anonymous so GDPR no longer applies. Is that claim sound?
Select an answer to reveal the explanation.
Short Explanation
Hashing an email so an ad platform can still find the same person is camouflage, not a disappearing act. If you can single someone out or match them back, GDPR still cares. Call it pseudonymisation at best—not a free anonymity pass.
Full Explanation
GDPR distinguishes anonymisation (information that does not relate to an identified or identifiable person) from pseudonymisation. Hashed emails uploaded for advertising match-rates are ordinarily still linked to individuals via the platform's matching capability and thus remain personal data. Controllers remain responsible for lawful basis, transparency, and security; merely hashing before transfer does not remove GDPR applicability.