The UK Information Commissioner’s Office (ICO) has launched a public consultation on new draft guidance. The document addresses anonymisation and pseudonymisation for research, archiving, and statistical purposes. The consultation period will remain open until 19 October 2026.
Target Audience and Regulatory Scope
This draft guidance is particularly relevant for universities, healthcare organizations, and technology providers. Furthermore, the ICO explains how to apply data minimisation principles within modern research environments. In addition, the text clarifies how organizations should approach the new safeguards introduced under the Data (Use and Access) Act 2025 (DUAA).
Mandatory Safeguards and Governance Frameworks
The DUAA requires organizations to implement effective technical and organizational measures for data minimisation. Consequently, identifiability risks must be assessed and managed throughout the entire research lifecycle. To assist with compliance, the ICO highlights the “Five Safes” governance framework. Therefore, adopting this framework helps organizations demonstrate appropriate safety controls across people, projects, settings, data, and outputs.
Limitations of TREs and Synthetic Data
Trusted research environments (TREs), trusted third parties (TTPs), and synthetic data effectively reduce privacy risks. However, these tools do not automatically render data anonymous. In fact, synthetic datasets generated from real personal data can still pose re-identification risks. As a result, organizations must evaluate access models carefully depending on who receives the dataset.
Challenges with Unstructured Datasets
Standard de-identification methods often fail when applied to unstructured formats. Indeed, speech recordings, video feeds, images, and sensor data frequently contain embedded personal attributes. This issue is especially critical for AI developers training models on large sets of clinical notes or behavioral logs. Thus, data minimisation must be embedded into the design stage of every project.
Recommended Immediate Actions
Although the guidance is currently in draft form, organizations should review their practices today. First, research teams need to audit existing DPIAs, access controls, and data-sharing agreements. Second, if identifiable data is required for a project, organizations must clearly justify why anonymised or pseudonymised options are not suitable.