24/06/2026
New article published:
Pseudonymization After SRB/Deloitte, Part 2: Re-Identification Is Now an Engineering Test
The article looks at why pseudonymization and de-identification can no longer be treated as legal labels alone.
The real question is whether re-identification is reasonably likely, considering the data, the recipient, auxiliary datasets, available technology, cost, time, controls, and the lifetime of the data.
I cover:
SRB/Deloitte and recipient-specific identifiability
CNIL’s recent IQVIA decision in France
LLM deanonymization and why unstructured text is risky
why free-text data can remain identifying after redaction
quantum computing as a future risk to cryptographic separation
what a defensible de-identification evidence pack should include
Main point:
Pseudonymization is a control. It is not a conclusion.
Read the full article and practical guidelines to apply the engineering test: https://aesirx.io/blog/aesirx/pseudonymization-after-srb-deloitte-part-2-re-identification-is-now-an-engineering-test
Pseudonymization is not anonymity. Learn how SRB/Deloitte, CNIL/IQVIA, GDPR Recital 26, LLMs, and quantum risk turn re-identification into an engineering test.