Why Encryption Alone Is Not Enough Under GDPR

2. September 2026

Many organisations view encryption as a comprehensive solution for privacy compliance. While encryption is an essential security control, relying solely on it can leave compliance gaps if other core requirements of the General Data Protection Regulation (GDPR) are overlooked.

Here is why encryption and anonymization can complement each other as part of a balanced data protection strategy.

What Are the Legal Requirements Under GDPR?

Encryption is a vital security tool for protecting data against unauthorized access. However, a common compliance oversight is conflating Article 32 (Security of Processing) with Article 6 (Lawfulness of Processing).

Under the GDPR, encryption does not answer the fundamental prerequisite: Do you have a lawful basis to process this personal data in the first place?

Core Principle: Encrypting personal data for which you lack a lawful basis does not make the processing lawful.

Complementary Requirements: Articles 5, 6, 25, and 32

Articles 5, 6, 25, and 32 of the GDPR impose distinct, complementary requirements rather than a single hierarchy:

  • Article 6 (Lawfulness): Requires a valid legal basis for processing personal data.
  • Article 5 (Data Minimization & Principles): Requires that personal data be adequate, relevant, and limited to what is necessary for the specified purpose.
  • Article 25 (Data Protection by Design & Default): Mandates appropriate technical and organizational measures to integrate privacy principles into data processing.
  • Article 32 (Security of Processing): Directs organizations to implement security controls, such as encryption, appropriate to the risk.

The GDPR does not contain a general rule requiring organizations to adopt whichever technically available solution is the “most privacy-preserving,” nor does anonymization inherently “win” over encryption. Instead, the regulation mandates appropriate measures based on the state of the art, implementation costs, the nature, scope, context, and risk of processing.

Encryption and anonymization address different challenges:

  • Encryption is essential for safeguarding data that must remain identifiable to fulfill its legitimate purpose.
  • Anonymization supports data minimization when keeping data in an identifiable form is no longer necessary or proportionate.

Bridging the Technical Feasibility Gap

Historically, organizations argued that anonymization was impractical for complex datasets, such as high-frequency sensor data or video footage.

With the advancement of modern technology,such as Brighter AI’s visual anonymization technology, effective visual anonymization has become increasingly practical and accessible across many use cases. As technology matures, claiming that visual anonymization is technically impossible becomes less viable before regulatory authorities.

However, anonymization is not automatically required in every case. Organizations must evaluate whether identifiable data remains necessary for their purpose, and whether anonymization is feasible, effective, and proportionate in their specific circumstances.

Understanding Data Outside the Scope of GDPR

Genuinely anonymous information falls outside the scope of the GDPR because it no longer relates to an identified or identifiable natural person. Where data is truly anonymized, organizations benefit from reduced compliance friction:

  • Data Subject Access Requests (DSARs): Since individuals cannot be identified, DSAR obligations generally do not apply.
  • Breach Notifications: Genuinely anonymous information is not subject to personal data breach reporting mandates.

Important Caveats:

  • Re-identification Risks: Redacting faces and licence plates does not necessarily mean that an entire video or dataset is anonymous. Other contextual details—such as exact locations, timestamps, distinctive clothing, movement patterns, audio, or metadata—may still permit re-identification. Using an anonymization tool does not automatically grant a full exemption from the GDPR.
  • Broader Regulatory and Commercial Boundaries: Falling outside the GDPR does not mean data can be used without restrictions. Organizations must still navigate contractual obligations, confidentiality agreements, intellectual property rights, AI regulation (such as the EU AI Act), and sector-specific legal framework obligations.

Responsibilities for Controllers and Processors

Organizations in data-heavy sectors such as automotive, manufacturing, and public infrastructure, frequently operate with complex data pipelines.

Controllers and processors each have responsibilities under the GDPR. The controller remains responsible for determining whether the processing is lawful and whether the personal data are limited to what is necessary, while processors have direct obligations within their own areas of responsibility. Relying on encryption without evaluating data minimization principles or assessing whether personal identification is genuinely necessary creates avoidable regulatory exposure.

The Bottom Line

Encryption and anonymization are complementary components of a robust compliance framework:

  • Encryption protects personal data from unauthorized access while maintaining the dataset’s utility when identification is required.
  • Anonymisation can reduce identification risks and support data minimisation where retaining identifiable information is no longer necessary for the intended purpose.

Encryption remains an essential security measure. Considering encryption and anonymisation together can support a more comprehensive GDPR compliance strategy by addressing both security and the continuing necessity of identifiable data.

Marina Mitrashov
Marketing Lead