Irreversibility of anonymization - definition
Irreversibility of anonymization is the property of a process that prevents a person from being identified again from the anonymized output, using means reasonably likely to be available. In image and video processing, it concerns whether blurred faces, masked license plates, and related metadata can still be connected to an identifiable individual.
Under the European Union (EU) General Data Protection Regulation (GDPR), data are anonymous only if the individual is no longer identifiable. Recital 26 requires an assessment of all means reasonably likely to be used for identification, including available technology, cost, time, and technological developments. If re-identification remains reasonably likely, the footage remains personal data and the GDPR continues to apply.
Irreversibility is therefore not the same as applying a visible blur effect. A face can be visually obscured while the video remains identifiable through clothing, location, vehicle characteristics, movement patterns, audio, timestamps, camera identifiers, or access to an unblurred original file.
Why irreversibility determines the status of image and video data
The GDPR distinguishes anonymization from pseudonymization. Pseudonymized data can be linked back to a person using additional information. Anonymous data cannot reasonably be linked back. This distinction affects whether footage is regulated as personal data.
Processing result | Can a person reasonably be identified again? | Typical GDPR status
|
|---|---|---|
Original video with a blurred display copy | Yes, if the organization retains the original file | Personal data |
Video with encrypted originals and a separate decryption key | Yes, for a party with access to the key | Personal data, often pseudonymized |
Destructively blurred video without accessible originals, identifiers, or practical linkage data | Potentially no, subject to a contextual assessment | May be anonymous data |
Footage with faces blurred but unique location and time data retained | Possibly, depending on available external information | Usually requires further assessment |
A controller cannot establish anonymity by relying only on the mathematical or visual properties of a blur filter. The assessment must include the entire processing environment. This includes who holds the original footage, who can access mask coordinates, whether a video can be linked to another camera source, and whether public or internal data could identify a person.
Irreversibility in face and license plate blurring
Face blurring and license plate blurring are commonly used to reduce identifiability in recorded footage. Their effectiveness depends on detection quality, mask coverage, temporal consistency, and the removal or protection of original source material.
For video anonymization, a privacy review should assess the following technical conditions:
- Detection coverage: faces and license plates must be detected across all relevant frames, including partial views, profile views, motion blur, occlusion, and changes in lighting.
- Mask persistence: the blur mask must remain aligned with the face or license plate throughout movement. A mask that briefly slips can expose identifying information.
- Blur strength and mask area: the mask must obscure sufficient visual detail. Pixelation, mosaic effects, and Gaussian blur can have different residual-information risks.
- Original-file handling: retaining an unblurred copy makes the process reversible for parties with access to that copy.
- Metadata minimization: timestamps, precise geolocation, camera names, vehicle identifiers, and audio may enable indirect identification.
- External data linkage: a blurred person may still be identifiable when footage is combined with access-control records, schedules, social media posts, or another camera angle.
Gallio PRO automatically detects and blurs faces and license plates in image and video files. It does not perform real-time anonymization or video stream anonymization. It also does not automatically detect logos, tattoos, name badges, documents, or content displayed on monitors. These elements may require manual masking in the built-in editor when they create an identification risk.
Key metrics for assessing anonymization quality
Irreversibility is a legal and contextual conclusion, but technical metrics provide evidence for that conclusion. Detection metrics should be measured on representative footage, including the camera angles, lighting conditions, compression settings, and movement patterns used in the actual processing environment.
Metric | Formula or measurement | Why it matters
|
|---|---|---|
Recall | TP / (TP + FN) | Measures the proportion of faces or license plates correctly detected. |
False negative rate | FN / (TP + FN) | Measures the proportion of relevant objects left unmasked. |
Precision | TP / (TP + FP) | Measures whether applied masks correspond to actual faces or license plates. |
Track coverage | Masked frames / frames in which the object is visible | Measures whether protection persists across a video sequence. |
Residual identifiability testing | Controlled attempts to identify subjects from processed output | Tests risks created by context, metadata, and external data sources. |
There is no GDPR-approved minimum blur radius, pixel block size, or single recall threshold that automatically makes video anonymous. A technical setting may reduce direct recognition while leaving indirect identification possible. The appropriate test is whether identification remains reasonably likely in the specific processing context.
Limitations and practical controls
Anonymization should be designed as a process rather than as a single filter. A defensible workflow combines automated detection, manual quality review where risk justifies it, secure source-file management, and documented testing.
- Define the intended disclosure and the likely recipients of the processed footage.
- Identify direct identifiers, including faces and license plates.
- Identify indirect identifiers, such as audio, location, uniforms, vehicle markings, and event context.
- Apply face blurring and license plate blurring across all relevant frames.
- Review missed detections, partial masks, and scene-specific identifying details.
- Restrict, delete, or separately protect original unblurred footage.
- Document the threat model, test method, residual risks, and retention decisions.
Standards and references
The GDPR does not prescribe one technical anonymization method. It requires a contextual assessment of identifiability. The following sources provide the primary legal framework and widely used technical terminology.
Source | Relevance
|
|---|---|
Defines personal data and sets the EU test for whether identification is reasonably likely. | |
Article 29 Working Party, Opinion 05/2014 on Anonymisation Techniques, 2014 | Explains singling out, linkability, and inference as key anonymization risks. |
Provides terminology and classification concepts for privacy-enhancing data de-identification techniques. | |
National Institute of Standards and Technology, NISTIR 8053, 2015 | Describes de-identification concepts, risk assessment, and the limits of data transformation methods. |
US equivalent
The United States has no general federal equivalent to the GDPR test for anonymous image and video data. Relevant rules are sectoral and state-specific. For example, the Health Insurance Portability and Accountability Act (HIPAA) provides de-identification standards for protected health information at 45 CFR 164.514, while the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), defines deidentified information in California Civil Code Section 1798.140(m).
Neither framework creates a universal rule that blur effects alone make footage anonymous. Organizations should assess whether the footage remains reasonably linkable to a person under the applicable law, contractual terms, court order, public-records rule, or internal privacy policy.