Pseudonymisation & Anonymisation as Tools for Managing Data Protection Risk
Pseudonymisation and anonymisation are two of the most frequent techniques used in modern data protection and privacy management. Yet, we find that organisations sometimes apply both concepts incorrectly. In this update, we explain the key differences, practical applications, and why understanding these concepts is critical for compliance with data protection laws.
Understanding Pseudonymisation under the Nigeria Data Protection Act
Pseudonymisation involves processing personal data so that it cannot be directly attributed to a specific individual without additional information. Typically, this means replacing identifiers, like names, phone numbers, or email addresses, with a code, token, or other pseudonym.
For example, in a database of customer records, "John" Smith ight become "cu_7ys_". The original data can only be restored if a secure mapping table or key is available. The main benefits of pseudonymisation include:
Reduced risk in case of data breaches: Even if attackers gain access to the pseudonymised dataset, they cannot easily link the information back to individuals without the separate key.
Regulatory compliance: Laws like the NDPA encourage pseudonymisation as a privacy-enhancing technique, demonstrating that organisations take reasonable steps to protect personal data.
Operational utility: Pseudonymised data can still be used for analytics, research, and internal reporting while limiting exposure of sensitive identifiers.
However, pseudonymised data remains personal data under the law because it can potentially be re-identified. Under the NDPA, organisations must still implement strict access controls, encryption, and audit procedures to maintain compliance.
Understanding Anonymisation under the Nigeria Data Protection Act
Anonymisation, in contrast, is the process of irreversibly removing or altering personal identifiers so that individuals cannot be identified by any means. Unlike pseudonymisation, anonymised data is considered no longer personal data under the NDPA. A practical example would be removing names, phone numbers, and email addresses from a dataset and aggregating information so that it’s impossible to link a record back to a specific individual. Anonymisation will be a great compliance strategy where the objective is to share fully anonymised datasets with researchers, partners, or the public without exposing individual privacy. The key limitation is that anonymisation can reduce the utility of personal data. Once identifiers are removed irreversibly, certain operations like personalised outreach or detailed auditing become impossible.
Key Considerations
For organisations looking to demonstrate accountability, reduce risk, and build trust with customers, employees, and regulators alike, pseudonymising or anonymising personal data is a prudent compliance strategy.
Confusing pseudonymisation with anonymisation or applying them incorrectly, can have serious consequences, including regulatory fines under NDPA and other data protection laws.

Olu A.
LL.B. (UNILAG), B.L. (Nigeria), LL.M. (UNILAG), LL.M. (Reading, U.K.)
Olu is a Partner in the Firm’s Transactions & Policy Practice. Admitted as a Barrister & Solicitor of the Supreme Court of Nigeria in 2009, he has spent over a decade advising clients on high-value transactions and policy matters at some of Nigeria’s leading law firms.
olu@balogunharold.com
Kunle A.
LL.B. (UNILAG), B.L. (Nigeria), LL.M. (UNILAG), Barrister & Solicitor (Manitoba)
Kunle is a Partner in the Firm’s Transactions & Policy Practice. Admitted as a Barrister & Solicitor of the Supreme Court of Nigeria in 2009, he has spent over a decade advising clients on high-value transactions and policy matters at some of Nigeria’s leading law firms.
k.adewale@balogunharold.comRelated Articles
Dario Amodei's "Pacing the Frontier": Some Anti-Trust Law Limitations
If competing AI companies were to agree to limit or slow the development, deployment, or release of increasingly capable AI systems, such arrangements would raise significant competition law concerns. We discuss some of the primary legal considerations below.
Automated Decision-Making Under the NDPA: Navigating the Line Between Automation and Regulation
The rapid integration of artificial intelligence, algorithms, and automated workflows across corporate operations raises a critical compliance question under the Nigeria Data Protection Act 2023 (NDPA): When does standard corporate automation trigger Section 37 regulation?
FCCPC’s Conditional Approval for MTN/IHS Acquisition - Some Key Commercial Considerations
Will a plain 30% equity sell-down to local investors actually address the competition concern created by MTN’s continued control of IHS, post the MTN-IHS Acquisition?
Nigeria’s FCCPC Launches Digital Markets Probe: Key Considerations for Global Tech and AI General Counsels
Nigeria recently launched a digital markets inquiry with a focus on dominant digital platforms like global technology platforms and Generative Artificial Intelligence (AI).