What is Irreversibility of Anonymization?

Irreversibility of anonymization - definition

Irreversibility of anonymization is the property of a process that prevents a person from being identified again from the anonymized output, using means reasonably likely to be available. In image and video processing, it concerns whether blurred faces, masked license plates, and related metadata can still be connected to an identifiable individual.

Under the European Union (EU) General Data Protection Regulation (GDPR), data are anonymous only if the individual is no longer identifiable. Recital 26 requires an assessment of all means reasonably likely to be used for identification, including available technology, cost, time, and technological developments. If re-identification remains reasonably likely, the footage remains personal data and the GDPR continues to apply.

Irreversibility is therefore not the same as applying a visible blur effect. A face can be visually obscured while the video remains identifiable through clothing, location, vehicle characteristics, movement patterns, audio, timestamps, camera identifiers, or access to an unblurred original file.

Why irreversibility determines the status of image and video data

The GDPR distinguishes anonymization from pseudonymization. Pseudonymized data can be linked back to a person using additional information. Anonymous data cannot reasonably be linked back. This distinction affects whether footage is regulated as personal data.

Processing result

Can a person reasonably be identified again?

Typical GDPR status

 

Original video with a blurred display copy

Yes, if the organization retains the original file

Personal data

Video with encrypted originals and a separate decryption key

Yes, for a party with access to the key

Personal data, often pseudonymized

Destructively blurred video without accessible originals, identifiers, or practical linkage data

Potentially no, subject to a contextual assessment

May be anonymous data

Footage with faces blurred but unique location and time data retained

Possibly, depending on available external information

Usually requires further assessment

A controller cannot establish anonymity by relying only on the mathematical or visual properties of a blur filter. The assessment must include the entire processing environment. This includes who holds the original footage, who can access mask coordinates, whether a video can be linked to another camera source, and whether public or internal data could identify a person.

Irreversibility in face and license plate blurring

Face blurring and license plate blurring are commonly used to reduce identifiability in recorded footage. Their effectiveness depends on detection quality, mask coverage, temporal consistency, and the removal or protection of original source material.

For video anonymization, a privacy review should assess the following technical conditions:

  • Detection coverage: faces and license plates must be detected across all relevant frames, including partial views, profile views, motion blur, occlusion, and changes in lighting.
  • Mask persistence: the blur mask must remain aligned with the face or license plate throughout movement. A mask that briefly slips can expose identifying information.
  • Blur strength and mask area: the mask must obscure sufficient visual detail. Pixelation, mosaic effects, and Gaussian blur can have different residual-information risks.
  • Original-file handling: retaining an unblurred copy makes the process reversible for parties with access to that copy.
  • Metadata minimization: timestamps, precise geolocation, camera names, vehicle identifiers, and audio may enable indirect identification.
  • External data linkage: a blurred person may still be identifiable when footage is combined with access-control records, schedules, social media posts, or another camera angle.

Gallio PRO automatically detects and blurs faces and license plates in image and video files. It does not perform real-time anonymization or video stream anonymization. It also does not automatically detect logos, tattoos, name badges, documents, or content displayed on monitors. These elements may require manual masking in the built-in editor when they create an identification risk.

Key metrics for assessing anonymization quality

Irreversibility is a legal and contextual conclusion, but technical metrics provide evidence for that conclusion. Detection metrics should be measured on representative footage, including the camera angles, lighting conditions, compression settings, and movement patterns used in the actual processing environment.

Metric

Formula or measurement

Why it matters

 

Recall

TP / (TP + FN)

Measures the proportion of faces or license plates correctly detected.

False negative rate

FN / (TP + FN)

Measures the proportion of relevant objects left unmasked.

Precision

TP / (TP + FP)

Measures whether applied masks correspond to actual faces or license plates.

Track coverage

Masked frames / frames in which the object is visible

Measures whether protection persists across a video sequence.

Residual identifiability testing

Controlled attempts to identify subjects from processed output

Tests risks created by context, metadata, and external data sources.

There is no GDPR-approved minimum blur radius, pixel block size, or single recall threshold that automatically makes video anonymous. A technical setting may reduce direct recognition while leaving indirect identification possible. The appropriate test is whether identification remains reasonably likely in the specific processing context.

Limitations and practical controls

Anonymization should be designed as a process rather than as a single filter. A defensible workflow combines automated detection, manual quality review where risk justifies it, secure source-file management, and documented testing.

  1. Define the intended disclosure and the likely recipients of the processed footage.
  2. Identify direct identifiers, including faces and license plates.
  3. Identify indirect identifiers, such as audio, location, uniforms, vehicle markings, and event context.
  4. Apply face blurring and license plate blurring across all relevant frames.
  5. Review missed detections, partial masks, and scene-specific identifying details.
  6. Restrict, delete, or separately protect original unblurred footage.
  7. Document the threat model, test method, residual risks, and retention decisions.

Standards and references

The GDPR does not prescribe one technical anonymization method. It requires a contextual assessment of identifiability. The following sources provide the primary legal framework and widely used technical terminology.

Source

Relevance

 

Regulation (EU) 2016/679, Article 4 and Recital 26

Defines personal data and sets the EU test for whether identification is reasonably likely.

Article 29 Working Party, Opinion 05/2014 on Anonymisation Techniques, 2014

Explains singling out, linkability, and inference as key anonymization risks.

ISO/IEC 20889:2018

Provides terminology and classification concepts for privacy-enhancing data de-identification techniques.

National Institute of Standards and Technology, NISTIR 8053, 2015

Describes de-identification concepts, risk assessment, and the limits of data transformation methods.

US equivalent

The United States has no general federal equivalent to the GDPR test for anonymous image and video data. Relevant rules are sectoral and state-specific. For example, the Health Insurance Portability and Accountability Act (HIPAA) provides de-identification standards for protected health information at 45 CFR 164.514, while the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), defines deidentified information in California Civil Code Section 1798.140(m).

Neither framework creates a universal rule that blur effects alone make footage anonymous. Organizations should assess whether the footage remains reasonably linkable to a person under the applicable law, contractual terms, court order, public-records rule, or internal privacy policy.