Skip to main content
Category: Impact Assessments & Documentation

Matching or Combining Datasets

Also known as: Data Matching, Data Linking, Data Linkage, Entity Resolution
Simply put

Matching or combining datasets is the process of comparing, linking, or merging personal data drawn from two or more sources to identify records that refer to the same person or thing. It is often used for purposes such as fraud prevention, direct marketing, or building a more complete picture of an individual. Because it brings together information from different places, it can create new insights about people that were not apparent from any single source.

Formal definition

Matching or combining datasets refers to processing operations that compare, link, or merge personal data obtained from multiple sources to determine or establish that records relate to the same data subject or entity (sometimes described as entity resolution or record linkage). Under the UK GDPR framework, the ICO lists 'data matching', combining, comparing or matching personal data obtained from multiple sources, within its examples of processing likely to result in a high risk to individuals; where a controller intends to carry out such processing, a Data Protection Impact Assessment (DPIA) is required under this guidance rather than merely being a discretionary consideration. Controllers should note that the ICO's high-risk list operates alongside the general criteria for identifying high-risk processing, and that the position under the EU GDPR is informed by national supervisory authority lists and EDPB guidance, which may diverge; readers should verify the applicable high-risk lists and current guidance for their jurisdiction. Independently of the DPIA question, combining datasets must have a valid Article 6 lawful basis (and, where special category data is involved, an additional Article 9 condition), and can raise purpose limitation and further-processing compatibility considerations that require separate assessment.

Why it matters

Matching or combining datasets is powerful precisely because it produces information that did not exist in any single source. Linking records that refer to the same person across separate systems can reveal patterns, correlations, and inferences that individuals never disclosed and may not anticipate, which is why the process carries distinct privacy risks beyond those of the underlying datasets. These risks include re-identification of data that seemed low-risk in isolation, use of data for purposes incompatible with why it was originally collected, and the construction of detailed profiles used for decisions affecting individuals.

For these reasons, the UK ICO includes 'data matching', described as combining, comparing or matching personal data obtained from multiple sources, within its examples of processing likely to result in a high risk to individuals. Under the ICO's guidance, where a controller intends to carry out this type of processing, a Data Protection Impact Assessment (DPIA) is required rather than merely being a discretionary or optional step. Controllers should treat this as a mandatory starting point under the UK framework and not as a factor to weigh at their own discretion.

The DPIA obligation is separate from, and additional to, the requirement to establish a valid lawful basis. Combining datasets still needs an Article 6 lawful basis, and, where special category data is involved, an additional Article 9 condition. It also frequently raises purpose limitation and further-processing compatibility questions, because data assembled for one purpose may be repurposed when linked. The position under the EU GDPR is shaped by national supervisory authority high-risk lists and EDPB guidance, which may diverge from the ICO's approach, so readers should verify the applicable high-risk lists and current guidance for their jurisdiction against the official text.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams need to identify data matching activities early, because the ICO's guidance treats this category as high-risk processing requiring a DPIA under the UK framework. They should ensure the DPIA is completed before processing starts, that a valid Article 6 lawful basis (and any necessary Article 9 condition) is documented, and that purpose limitation and compatibility of further processing are assessed. Where operations span jurisdictions, they should check the relevant EU supervisory authority high-risk lists and current EDPB guidance, which may differ.
Engineers and Data Teams
Those building or operating matching, linkage, or entity-resolution systems should surface planned combining of datasets to privacy and legal colleagues so that the required assessment happens before deployment. Design choices, such as the identifiers used, the accuracy of probabilistic matching, and controls to limit re-identification and repurposing, feed directly into the DPIA and any supplementary safeguards.
Privacy and Data Protection Lawyers
Advisers should distinguish the mandatory DPIA obligation for this processing category under ICO guidance from the separate requirement to establish a lawful basis, and should advise clients that combining datasets can raise distinct purpose limitation and further-processing compatibility questions. They should also flag that the UK position and EU national positions may diverge, and that high-risk lists and guidance evolve, so advice should be checked against the current official text for the applicable jurisdiction.
Business and Product Owners
Teams pursuing purposes such as fraud prevention, direct marketing, or building a more complete view of customers should understand that linking datasets is treated as high-risk processing and requires assessment before it proceeds. Building in time for a DPIA and lawful-basis analysis at the planning stage helps avoid delays and reduces the risk of assembling profiles in ways that are incompatible with the original collection purpose.

Inside Matching or Combining Datasets

Data matching
The processing operation of combining, comparing, or matching personal data obtained from multiple sources. Under the UK ICO's guidance ('Examples of processing likely to result in high risk'), data matching is listed as a category of processing that requires a Data Protection Impact Assessment (DPIA). Practitioners should verify this against the current ICO guidance, as regulator lists and interpretations may be updated.
Source datasets
The two or more distinct collections of personal data brought together in a matching or combining operation. Each source may have its own original purpose and Article 6 lawful basis, and the compatibility of the new combined use with those original purposes must be assessed.
Purpose and purpose limitation
Combining datasets often creates a new processing purpose distinct from the purposes for which each dataset was originally collected. This engages the purpose limitation principle and, where the new purpose differs, may require a compatibility assessment or, in some cases, a separate lawful basis.
Lawful basis
Each matching or combining operation must rest on an appropriate Article 6 basis (for example consent, contract, legal obligation, vital interests, public task, or legitimate interests). Consent is not the universal basis. Where the datasets contain special category data, an additional Article 9 condition is required.
DPIA requirement
Because data matching appears on the UK ICO's list of processing likely to result in high risk, a DPIA (Data Protection Impact Assessment) is required for this category of processing under the UK GDPR. The DPIA should be completed before the processing begins and should assess the necessity, proportionality, and risks to individuals, together with mitigating measures.
Re-identification and increased data richness
Combining datasets can increase the identifiability of individuals and the sensitivity of the resulting profile, even where individual source datasets were less revealing. This heightened risk is a key reason the processing is treated as high risk.
Transparency to data subjects
Where data is combined for a new purpose, individuals generally need to be informed, subject to the transparency obligations and any applicable exemptions. The information provided at original collection may no longer be sufficient for the combined use.

Common questions

Answers to the questions practitioners most commonly ask about Matching or Combining Datasets.

Is a DPIA optional when we match or combine datasets from multiple sources?
Not in the way this is sometimes assumed. The UK ICO includes data matching, combining, comparing or matching personal data obtained from multiple sources, in its published list of processing likely to result in high risk, which means a DPIA is required for this category of processing under UK GDPR. Rather than treating a DPIA as a discretionary judgment call for such operations, practitioners should start from the position that one is expected and document their reasoning carefully. You should verify the current ICO list and any equivalent guidance from the relevant EU supervisory authority, as national regulators may frame their high-risk lists differently.
Does combining datasets always require fresh consent from the individuals concerned?
No. Consent is only one of the Article 6 lawful bases, and matching or combining datasets does not automatically require it. The appropriate basis depends on the purpose and context and could, subject to assessment, be legitimate interests, contract, legal obligation, public task, or another basis. Where the combined data reveals or includes special category data under Article 9, an additional Article 9 condition must also be satisfied. Treating consent as a universal requirement is a common misconception; the correct basis should be identified and documented for the specific processing.
How should we approach purpose limitation when linking datasets originally collected separately?
Combining datasets can introduce new purposes beyond those for which the source data was originally collected. You should assess whether the intended matching is compatible with the original purposes, and where it is not, identify a lawful basis for the new purpose and consider transparency obligations to the individuals affected. Documenting this compatibility analysis, alongside any DPIA, helps evidence accountability. The boundary of what counts as a compatible further purpose can involve judgment, so record your reasoning against the specific facts.
What should a DPIA for a data matching project typically cover?
For matching or combining operations, a DPIA generally documents the nature, scope, context and purposes of the processing, the datasets and sources involved, the lawful basis and any Article 9 condition, the risks to individuals arising from linkage (such as re-identification, profiling, or inaccurate matches), and the measures proposed to mitigate those risks. Because this processing falls within the high-risk category, completing and retaining the DPIA before processing begins is expected. Consult your supervisory authority where residual high risk remains after mitigation, as prior consultation may be required.
If we anonymise the output of a matching exercise, does the GDPR still apply?
The GDPR applies to personal data and generally does not govern data that is genuinely anonymous. However, the matching process itself typically involves personal data at the point of combination, so the Regulation applies to that stage. Whether an output is truly anonymous, rather than pseudonymised, requires assessment against the means reasonably likely to be used to re-identify individuals, a threshold that can be difficult to meet where rich linked datasets are involved. Where re-identification remains reasonably possible, the data should be treated as personal data.
How do we handle accuracy risks when matching records across sources?
Matching can produce false positives or false negatives, and errors can propagate across the combined dataset in ways that affect individuals. As part of your assessment you should consider measures to test and monitor match quality, address the consequences of incorrect matches, and support individuals' rights, including rectification. Documenting these accuracy safeguards within the DPIA supports accountability. The appropriate level of assurance depends on the impact of an incorrect match on the individuals concerned.

Common misconceptions

A DPIA is optional for data matching as long as the organisation judges the risk to be low.
Data matching (combining, comparing, or matching personal data from multiple sources) appears on the UK ICO's list of processing likely to result in high risk, meaning a DPIA is required for this category of processing under the UK GDPR. Practitioners should not treat the DPIA as a discretionary factor for this activity and should verify the position against the current ICO guidance.
If each source dataset was lawfully collected, the combined dataset is automatically lawful to use.
Combining datasets frequently creates a new purpose that differs from the original purposes of collection. This may require a compatibility assessment and, in some cases, a distinct lawful basis. The lawfulness of the original collection does not by itself validate the combined processing.
Matching datasets always requires consent from the individuals.
Consent is only one of the Article 6 lawful bases. Depending on context, another basis such as legitimate interests, public task, or legal obligation may apply. Where special category data is involved, an additional Article 9 condition is also needed. The appropriate basis is determined by the specifics of the processing, not by a default consent requirement.

Best practices

Complete a DPIA before beginning any data matching operation, treating it as required for this category of high-risk processing under the UK ICO's guidance, and verify the current ICO list to confirm the position.
Identify and document a valid Article 6 lawful basis for the combined processing, and where special category data is involved, also document the applicable Article 9 condition.
Assess whether the combined purpose is compatible with the original purposes for which each source dataset was collected, and document the outcome of that purpose limitation analysis.
Evaluate re-identification and increased data-richness risks created by combining the datasets, and record proportionate mitigating measures in the DPIA.
Review and, where necessary, update transparency information so that data subjects are appropriately informed of the combined use, subject to any applicable exemptions.
Keep the DPIA and associated records under review, updating them if the sources, purposes, or risk profile of the matching operation change.