ICO issues code of practice on anonymising personal data
New guidelines aim to help businesses and public bodies comply with data protection legislation, while aiding 'the open data agenda'.


The Information Commissioner's Office (ICO) has issued a new code of practice on the anonymisation of personal data to help firms avoid breaching the Data Protection Act (DPA).
The decision to publish the guidelines was announced on 31 May 2012, when the Office undertook a consultation on the matter.
Steve Wood, head of policy at the ICO told IT Pro at the time: "There is a push to open up more datasets and some of that will be based on personal data in its raw form, so there are some issues where public bodies are concerned about how they disclose that data without identifying the people involved."
In his prologue to the code of practice, Christopher Graham, the Information Commissioner, said his office "has been a strong supporter of the open data agenda and has played its part in ensuring that all sorts of valuable data has been made available through the Freedom of Information Act 2000."
However, over the past 12 years, concerns over making data relating to private individuals publicly available have grown, Graham claims.
There are significant legal restrictions when it comes to dealing with data that is deemed personal'
"Finding out about the performance of a public authority, for example, inevitably involves finding out about the performance of its staff.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"We want openness, but we want privacy too. That is why the subject matter of this code of practice anonymisation is so important," Graham added.
Bridget Treacy, who leads the UK privacy and information management practice at law firm Hunton & Williams, welcomed the publication of the code of practice.
Organisations are seeking to use data in innovative ways but there are significant legal restrictions when it comes to dealing with data that is deemed personal'," she said.
However, Treacy added, if personal data has been rendered truly anonymous and the subject is in no way identifiable, the legal restrictions on publicly disclosing it no longer apply.
"Ensuring that data is properly anonymised, and not just masked can be very difficult to achieve in practice," said Treacy.
"Organisations often are uncertain about the legal basis for the anonymisation process itself, and whether [it] might constitute personal data. The code deals with both of these issues."

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse
News The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data
By Emma Woollacott
-
“You must do better”: Information Commissioner John Edwards calls on firms to beef up support for data breach victims
News Companies need to treat victims with swift, practical action, according to the ICO
By Emma Woollacott
-
LinkedIn backtracks on AI training rules after user backlash
News UK-based LinkedIn users will now get the same protections as those elsewhere in Europe
By Emma Woollacott
-
UK's data protection watchdog deepens cooperation with National Crime Agency
News The two bodies want to improve the support given to organizations experiencing cyber attacks and ransomware recovery
By Emma Woollacott
-
ICO slams Electoral Commission over security failures
News The Electoral Commission has been reprimanded for poor security practices, including a failure to install security updates and weak password policies
By Emma Woollacott
-
Disgruntled ex-employees are using ‘weaponized’ data subject access requests to pester firms
News Some disgruntled staff are using DSARs as a means to pressure former employers into a financial settlement
By Emma Woollacott
-
ICO reprimands Coventry school over repeated data protection failures
News The ICO said the academy trust failed to follow previous guidance, which caused a serious data breach
By Emma Woollacott
-
ICO dishes out fine to HelloFresh for marketing spam campaign
News HelloFresh failed to offer proper opt-outs, the ICO said, and customers weren’t warned their data would be used for months after they cancelled
By Emma Woollacott