Pseudonymisation

Pseudonymisation replaces the data that directly identifies a person with a substitute identifier, so that they can no longer be recognised without information kept separately.

What the GDPR says

Article 4 of the GDPR defines it as processing that makes data no longer attributable to a person "without the use of additional information", provided that information is kept separately and protected. It is a recommended security measure, not a box to tick.

The confusion to avoid: this is not anonymisation

Pseudonymised data remains personal data, and therefore stays fully subject to the GDPR — including data subject rights. Anonymised data, on the other hand, no longer allows anyone to be re-identified by any reasonable means, and falls outside the regulation. The difference is one of kind, not of degree: a pseudonymous identifier can be cross-referenced, an anonymous aggregate cannot.

In audience measurement

This is the distinction that decides consent exemption. The French regulator requires measurement to produce "anonymous statistical data": a tool that pseudonymises a visitor and follows them from one visit to the next through that identifier stays within the scope of consent. That is why exempt solutions limit the lifetime of their identifiers and rule out cross-site correlation.