Reasonably Likely Means of Identification
This is a test used to decide whether a person can be identified from data, and therefore whether that data counts as personal data. Instead of asking if identification is theoretically possible, it asks whether identification is realistically likely using methods that could reasonably be used. If the only ways to identify someone are far-fetched or remote, the data may fall outside this threshold, though this always depends on the specific circumstances.
A concept used when assessing identifiability of a natural person, drawn from Recital 26 of the GDPR, which states that account should be taken of all the means reasonably likely to be used to identify an individual, whether directly or indirectly, including techniques such as singling out. It sets a risk-based rather than an absolute standard: rather than considering every conceivable method, the assessment weighs the means that could realistically be deployed, taking into account factors such as available technology, cost, and effort. In practice, the assessment is contextual and forward-looking, and ICO guidance treats it as central to determining whether data has been effectively anonymised or remains personal data (including pseudonymised data that can still be attributed to an individual). Note that Recital 26 is interpretive rather than an operative article, that the threshold of 'reasonably likely' is qualitative and subject to assessment on the facts, and that regulator guidance and case law on where the boundary lies continue to evolve; practitioners should verify the current position against official sources.
Why it matters
The 'reasonably likely means of identification' test sits at the heart of one of the most consequential decisions in data protection: whether a given dataset is personal data at all. If identification is reasonably likely, the data falls within the scope of the GDPR and the full range of obligations, from lawful basis to data subject rights, applies. If the only routes to identification are far-fetched or remote, the data may fall outside that threshold and, where genuinely anonymised, sit outside the Regulation. Because the entire compliance perimeter can turn on this assessment, getting it wrong in either direction carries real risk: treating personal data as anonymous can leave individuals unprotected and organisations exposed, while over-classifying anonymous data can impose unnecessary obligations.
The test also matters because it is deliberately risk-based rather than absolute. Recital 26 of the GDPR directs assessors to consider all the means reasonably likely to be used, including techniques such as singling out, taking into account factors like available technology, cost, and effort. This means the analysis is not a one-off checkbox but a contextual and forward-looking judgement that can shift as technology and re-identification techniques evolve. What was reasonably difficult to identify at one point may become straightforward later, so an assessment made today may not hold indefinitely.
Because the standard is qualitative and applied on the facts, there is recognised uncertainty about precisely where the boundary lies. Recital 26 is interpretive rather than an operative article, and regulator guidance and case law continue to develop. Practitioners should therefore treat any identifiability determination as provisional, document their reasoning, and revisit it against the current official position rather than assuming a past conclusion remains valid.
Who it's relevant to
Inside Reasonably Likely Means of Identification
Common questions
Answers to the questions practitioners most commonly ask about Reasonably Likely Means of Identification.