Tokenisation
In a data security context, tokenisation is the process of replacing a sensitive piece of data with a non-sensitive stand-in value called a token, so that the original data is not exposed where the token is used. For example, a payment card number can be replaced with a substitute number stored on a phone or watch instead of the real card details. The term is also used more broadly in finance to describe creating a digital representation, or token, of an asset such as a share, bond, or currency that can be recorded and traded, which is a distinct concept from data-security tokenisation.
Tokenisation, as applied to data security, is the substitution of a sensitive data element with a non-sensitive equivalent (the token), which typically has no exploitable meaning or value on its own outside the system that maps tokens back to the underlying data. In payment applications, this involves replacing a primary account number with a stand-in value that is stored on the device rather than the original card number. A separate but related usage in finance describes tokenisation as recording ownership of, or exposure to, an asset as a digital token, often on a blockchain or distributed ledger, enabling those tokens to be programmed, traded, and settled. Note that the evidence provided defines the technique in general and financial terms and does not address how tokenisation is assessed under data protection law; whether tokenised data constitutes personal data, pseudonymised data, or anonymised data is context-dependent and should be assessed separately against the applicable legal framework and current regulatory guidance.
Why it matters
Tokenisation is a widely used data security technique that lets organisations reduce their exposure to sensitive data by replacing it with a stand-in value that has no exploitable meaning on its own outside the system that maps it back to the original. In payment contexts, for example, a card number can be replaced by a substitute number stored on a phone or watch rather than the real card details, so the underlying data is not present where the token is used. This approach is relevant to any organisation seeking to limit where high-risk data such as payment card numbers is stored, processed, or transmitted.
From a data protection standpoint, it is important not to assume a particular legal characterisation of tokenised data. The evidence here defines the technique in general and financial terms and does not address how tokenisation is treated under data protection law. Whether tokenised data amounts to personal data, pseudonymised data, or anonymised data is context-dependent and turns on factors such as who holds the mapping between tokens and original values and how readily re-identification is possible. That assessment should be carried out separately against the applicable legal framework and current regulatory guidance, rather than treated as settled by the use of tokenisation alone.
A further point of care is terminology. The word tokenisation is also used in finance to describe creating a digital representation, or token, of an asset such as a share, bond, or currency, often recorded on a blockchain or distributed ledger. This financial usage is a distinct concept from data-security tokenisation, and conflating the two can cause confusion in compliance and technical documentation. Practitioners should confirm which meaning is intended in any given context.
Who it's relevant to
Inside Tokenisation
Common questions
Answers to the questions practitioners most commonly ask about Tokenisation.