Anonymization
Irreversibly processing personal data so that no one can be identified from it by any means reasonably likely to be used, which places the result outside the scope of the GDPR.
Anonymisation transforms personal data so that the people it describes can no longer be identified, either directly or by combining it with other information. GDPR Recital 26 sets the test: identifiability is judged against all the means reasonably likely to be used, taking account of cost, time and the technology available, and information that passes the test is anonymous and falls outside the regulation. Techniques commonly used include removing identifiers, generalising values (an age band in place of a birth date), aggregating records and adding statistical noise.
The distinction candidates commonly blur is with pseudonymisation. Pseudonymised data replaces identifiers with a code or token, but someone still holds the means to reverse it, so Recital 26 treats it as personal data. Anonymisation is meant to leave no route back that is reasonably likely to be used. Anonymisation is also harder than it looks: removing names is rarely enough, because quasi-identifiers such as postcode, birth date and gender can be linked with another data set to re-identify individuals.
Exam relevance: a scenario is likely to turn on reversibility. If anyone holding extra information can link the data back to a person, it is pseudonymised rather than anonymised, and data protection obligations still apply. Candidates are also expected to recognise anonymisation as a strong form of data minimization for analytics and testing.