Deidentified & Pseudonymous Data Under the SECURE Data Act — Rules & Exemptions

Why Deidentification Matters

One of the most practically important questions for any data-intensive business is: if we strip out the identifying information, does the SECURE Data Act still apply?

The answer depends on whether the data qualifies as genuinely deidentified or merely pseudonymized — and the bill treats these two categories differently.


Deidentified Data

Definition

Deidentified data is data that cannot reasonably be linked to an identified or identifiable individual or a device linked to an individual.

Is It Covered by the Act?

No — deidentified data is outside the scope of the SECURE Data Act. Consumer rights (access, deletion, correction, etc.) do not apply to it.

But There Are Obligations

Controllers in possession of deidentified data must:

  1. Take reasonable measures to ensure the data cannot be re-associated with an individual
  2. Publicly commit to maintaining and using the data without attempting to re-identify it
  3. Contractually obligate any recipient of the data to comply with the same requirements

Controllers must also monitor compliance with those contractual commitments and take appropriate action if a recipient breaches them.

What Companies Are NOT Required to Do

  • Re-identify deidentified data to respond to consumer requests
  • Maintain data in identifiable form if they’ve chosen to deidentify it

Pseudonymous Data

Definition

Pseudonymous data is personal data that cannot be attributed to a specific individual without the use of additional information — where that additional information is kept separately and protected with appropriate technical and administrative measures.

Think: a database of user behavior records keyed to a random ID, where the ID-to-identity mapping is stored in a completely separate, secured system.

Is It Covered by the Act?

Pseudonymous data is still personal data under the Act — because re-identification is possible, just harder. However, consumer rights requests do not apply to pseudonymous data if the controller can demonstrate that:

  1. The identifying information is kept separately
  2. Appropriate measures are in place to prevent attribution
  3. The controller does not use the data to recognize or respond to the specific consumer
  4. The controller does not sell the data to other controllers

The Practical Difference

DeidentifiedPseudonymous
Can be re-identified?No (by definition)Yes (with additional data)
Covered by the Act?NoYes (but limited rights apply)
Consumer rights apply?NoOnly in limited circumstances
Public commitment required?YesNo
Contractual obligations on recipients?YesNo

Frequently Asked Questions

Our analytics data uses hashed user IDs. Is that deidentified or pseudonymous? Almost certainly pseudonymous — because the hash could be reversed or matched if someone had access to both datasets. True deidentification typically requires more aggressive techniques like k-anonymity, differential privacy, or data aggregation that prevents any individual from being singled out.

If we deidentify data, do we need to delete it in response to a consumer’s deletion request? No. The bill does not require you to re-identify deidentified data in order to comply with a deletion request. You are deemed compliant if you retain a record of the deletion request and ensure the data stays deidentified.