Pseudonymisation
Replacing direct identifiers such as names or account numbers with artificial keys, while keeping the information needed to re-identify individuals separately and under additional controls. Under UK GDPR, pseudonymised data is still personal data.
Why it matters
Pseudonymisation lets analysts and data scientists work with individual-level records without seeing who the individuals are. It reduces the impact of a breach and supports role-based access, because only a small group can hold the re-identification key.
It is a risk-reduction measure, not an exemption. Organisations still need a lawful basis, security controls and a DPIA where appropriate, and should test whether combinations of remaining fields could identify people.
In practice
For example, a UK clinical research team might replace patient identifiers with study IDs before loading records into its analytics environment. The mapping table sits in a separate, tightly controlled store used only when a clinician needs to follow up an individual result.
Where Rodan fits
Rodan builds pseudonymisation into analytics and AI pipelines delivered through Data and Analytics Engineering, with key management and access separated from the analytical environment.

