Skip to main content
Category: Data Classification & Identifiers

Singling Out

Simply put

Singling out generally refers to the ability to pick out or isolate one individual from a larger group, distinguishing that person from others. In a data context, it describes when information can be used to separate one person's records from everyone else's, even without knowing that person's name.

Formal definition

In general usage, to single out means to select one member from a group and treat or distinguish them differently from the rest. Note: the evidence provided consists only of general-language dictionary sources and does not include GDPR, regulatory, or data protection guidance defining 'singling out' as a technical identifiability or anonymisation criterion. In privacy practice, 'singling out' is a recognised concept used when assessing whether data relates to an identifiable person, but a precise, authoritative definition in that context cannot be stated from the evidence supplied and should be verified against current official regulatory guidance.

Why it matters

Singling out matters in privacy practice because identifiability is not limited to knowing a person's name. If a dataset allows one individual's records to be isolated and distinguished from everyone else's, that dataset may still relate to an identifiable person even where direct identifiers have been removed. This has direct consequences for whether information is treated as personal data and therefore falls within the scope of data protection law, or whether it can be regarded as genuinely anonymous and outside that scope.

Because the boundary between pseudonymised and anonymised data drives obligations across a compliance program, the concept of singling out is frequently invoked when assessing anonymisation, aggregation, and re-identification risk. However, the evidence supplied here consists only of general-language dictionary sources and does not include GDPR text or regulatory guidance. Readers should therefore treat the privacy-specific application of 'singling out' as a recognised concept whose precise, authoritative formulation must be verified against current official guidance rather than relied on from a general definition.

Who it's relevant to

Data Protection Officers and Compliance Leads
Those assessing whether datasets constitute personal data, are pseudonymised, or can be treated as anonymous need to understand that the ability to isolate one individual from a group can be relevant to identifiability, independent of whether a name is known. The precise weight given to singling out in that assessment should be verified against current official guidance.
Engineers and Data Scientists
Teams designing aggregation, de-identification, or anonymisation pipelines should consider whether their outputs still permit one person's records to be distinguished from others, as this may affect whether the resulting data is in scope. The applicable technical thresholds are not established by the evidence here and should be confirmed against authoritative guidance.
Privacy and Data Protection Lawyers
When advising on the scope of data protection obligations, lawyers may encounter singling out as a concept bearing on identifiability. Because a precise, authoritative privacy-specific definition cannot be stated from the general-language sources supplied, its legal significance should be grounded in the current official regulatory text and guidance, noting that regulator interpretations can diverge.

Inside Singling Out

Concept of Singling Out
The possibility of distinguishing or isolating some or all records identifying an individual within a dataset, even without knowing that person's name. It is generally treated as one of the criteria for assessing whether data remains identifiable rather than truly anonymous.
Relationship to Identifiability
Singling out is typically considered alongside linkability and inference as a means by which an individual may be identified directly or indirectly. Where singling out remains possible, the data will generally still qualify as personal data within scope of the GDPR.
Origin in Guidance
The framing of singling out as a re-identification risk derives principally from regulatory guidance and opinions on anonymisation and pseudonymisation rather than from an express definition in the text of the Regulation. Practitioners should verify the current guidance, as regulator positions can evolve.
Distinction from Anonymisation
If a dataset still permits singling out of an individual, it is generally not regarded as anonymous and therefore does not fall outside the material scope of the GDPR. Truly anonymous data, by contrast, is generally outside scope.
Contextual and Risk-Based Assessment
Whether singling out is possible depends on the dataset, the means reasonably likely to be used, and surrounding context. It is subject to assessment rather than a fixed determination, and conclusions can change as techniques and available auxiliary data change.

Common questions

Answers to the questions practitioners most commonly ask about Singling Out.

Does removing direct identifiers like names and email addresses mean a dataset is no longer capable of singling out individuals?
Not necessarily. Singling out refers to the possibility of isolating some or all records identifying an individual within a dataset, and this can remain possible even after direct identifiers are removed. A combination of remaining attributes, or a sufficiently unique record, may still allow a single person to be distinguished from others. Because singling out is one of the risks assessed when determining whether data is truly anonymous, the removal of names alone generally does not resolve it. The position depends on the specific dataset and the context of possible re-identification, and should be assessed rather than assumed.
Is singling out the same thing as identifying a person by name?
No. Singling out does not require knowing a person's name or any conventional identifier. It concerns whether records relating to one individual can be isolated or distinguished from those of others, even if that person is never named. This is why singling out is treated as a distinct risk vector: an individual can be singled out within a dataset while remaining nominally 'unnamed'. Identification in the broader sense, and singling out specifically, are related but not identical concepts, and the assessment turns on the practical means reasonably likely to be used.
How should singling out be considered when assessing whether data qualifies as anonymous?
Singling out is typically evaluated as one of several risks alongside linkability and inference when testing whether data has been rendered anonymous. In most cases the assessment asks whether, taking account of the means reasonably likely to be used, an individual could still be isolated within the dataset. If singling out remains reasonably possible, the data will generally continue to be treated as personal data rather than anonymous. The conclusion is context-dependent and should be documented as part of the anonymisation assessment. This reflects regulatory guidance rather than a single defined article, so readers should verify against current official sources.
What techniques are commonly used to reduce the risk of singling out?
Approaches often considered include aggregation, generalisation of granular values, suppression of rare or unique records, and adding noise, among other statistical disclosure control methods. The suitability of any technique depends on the dataset, the utility required, and the residual risk that remains after application. No single technique reliably eliminates singling out in all circumstances, so measures are typically combined and calibrated to the specific context. The effectiveness of a chosen approach should be tested rather than presumed.
Should a Data Protection Impact Assessment address singling out risk?
Where a processing operation is likely to result in a high risk to individuals and a Data Protection Impact Assessment is being conducted, singling out can be a relevant risk to document and mitigate, particularly for datasets intended to be shared, published, or used for analytics. Whether a DPIA is required in a given case depends on the nature of the processing and the applicable criteria. Even outside a formal DPIA, considering singling out as part of a broader re-identification risk analysis is generally good practice, subject to assessment of the specific circumstances.
How should residual singling out risk be documented and reviewed over time?
It is generally advisable to record the assessment methodology, the assumptions about means reasonably likely to be used, the mitigations applied, and the residual risk concluded. Because the means available to isolate individuals can change as external data, tools, and techniques evolve, an assessment made at one point may not remain valid indefinitely. Periodic review is therefore typically recommended, especially before releasing or re-releasing data. The appropriate frequency and depth of review depend on the sensitivity of the data and the context, and should be determined on a case-by-case basis.

Common misconceptions

Singling out requires knowing the individual's name or direct identifiers.
Singling out concerns the ability to isolate or distinguish a record relating to an individual within a dataset. It can be possible even where no name or obvious identifier is present, which is why it is treated as an indirect identifiability risk.
Removing direct identifiers makes a dataset anonymous and out of scope.
Where singling out (or linkability or inference) generally remains possible, the data is typically still considered identifiable and thus within scope of the GDPR. Such data is more often pseudonymised than anonymised, subject to assessment.
Singling out is a defined legal test set out expressly in the GDPR articles.
The criterion derives principally from regulatory guidance and opinions on anonymisation rather than an express statutory definition. Its application can vary, and readers should confirm the current position against official guidance.

Best practices

Assess singling out alongside linkability and inference when evaluating whether a dataset is genuinely anonymous or merely pseudonymised, and document the reasoning.
Base the assessment on the means reasonably likely to be used to isolate an individual, taking into account available auxiliary data and evolving techniques rather than a one-off snapshot.
Do not treat the removal of direct identifiers as sufficient to render data anonymous; test whether individual records can still be distinguished.
Verify conclusions against current regulator guidance on anonymisation and pseudonymisation, noting that positions may differ between authorities and can change over time.
Re-evaluate anonymisation claims periodically, since new datasets or methods can make previously infeasible singling out possible.
Where singling out remains possible, treat the data as personal data within scope and apply the applicable GDPR obligations accordingly.