Anonymisation is about re-identification risk
Anonymous is not a property of a dataset on its own. It depends on what else exists in the world.
A dataset that cannot identify anyone today may be trivially re-identifiable once combined with something published next year. So the honest question is not "have we removed identifiers" but "how much effort would re-identification take, by whom, with what other data". That framing also explains why the answer can change without the data changing.
More on Privacy engineering
- Differential privacy limits one person's influenceOne person cannot move the needle
- Consent interfaces can undermine genuine choiceBoth answers, very different distances
- Purpose limitation prevents silent mission creepThe pipe was laid for one thing
- Privacy by design moves decisions earlierA line on the plan, or a hole in the wall
- A privacy notice does not create permissionTelling is not asking
- Data subject rights depend on finding the dataThe right ends where the index does
