Pseudonymization
Replacing direct identifiers in personal data with aliases, while the information needed to re-identify people is kept separately and protected. Under GDPR it is still personal data.
Pseudonymisation (the GDPR’s own spelling) is defined in GDPR Article 4(5) as processing personal data so that it can no longer be attributed to a specific data subject without additional information, provided that information is kept separately and protected by technical and organisational measures. In practice, names, account numbers or other direct identifiers are replaced with consistent aliases, and the lookup table or key that maps aliases back to people is held apart from the data set.
The distinction that matters is with anonymization. Pseudonymised data can be re-identified by whoever holds the additional information, so GDPR Recital 26 treats it as personal data. Data that has been properly anonymised, so that people can no longer be identified by any means reasonably likely to be used, falls outside the GDPR. The Regulation also names pseudonymisation among the measures for data protection by design (Article 25) and security of processing (Article 32). Tokenization is a common way to implement it, and data masking is a related technique that is often irreversible.
Exam relevance: a scenario may describe identifiers replaced with codes and ask whether the data is still personal data. Candidates are expected to ask whether a route back to the individual exists: where the organisation, or anyone else, can reasonably re-identify people, the data remains in scope of privacy law.