
Anonymized EEG data may not be as anonymous as it appears. Even when names, account details, and other identifying information are removed, EEG recordings can contain stable patterns unique to individuals. Machine-learning systems can use these person-specific features, sometimes described as “brainprints,” to distinguish one person from another and potentially reconnect de-identified neural data with the person it came from.
Standard de-identification methods may need to evolve so EEG device companies can safely and ethically share data for R&D without creating new risks to patients’ or users’ privacy. A team at Germany’s Fraunhofer-Gesellschaft has taken on this challenge, developing methods that reduce identifying information in EEG while preserving its value for research. Dr. Insa Wolf spoke with Neurofounders about her team’s work to develop non-identifiable EEG.
Data privacy in neurotechnology is becoming a hot topic in policy debates. And for good reason. Neural data can encode some of the most sensitive information about a person’s brain that a consumer device can collect. One of the defining questions for how privacy in neurotechnology is governed is whether neural data can also reveal who someone is.
Consumer privacy laws are designed to protect personal information from being collected or used in ways that people have not consented to. These protections often apply to data that can be connected to a person’s identity. For companies to use data more broadly, they may therefore need to disconnect it from the person it came from. This process is known as de-identification.
EEG data has traditionally been de-identified by unlinking recordings from personal information such as names, addresses, and specific user accounts. Properly de-identified data can then be used more broadly for purposes such as algorithm development, secondary research, and data sharing, depending on the applicable privacy rules.
But neural data presents an additional challenge. Researchers testing whether EEG recordings themselves contain identifying information have found that they can reveal brainprints.
Brainprints are signatures that are unique to individual users, similar to how DNA, voice recordings, and photographs can be traced back to individual people. On its own, a DNA sample cannot tell you who someone is. But the unique sequence it carries can allow you to find a matching identity when compared with genetic databases, some of which are publicly available. As it turns out, EEG data can also be re-identified when compared or combined with other datasets.
While claims of ‘mind reading’ are ambitious, at least for now, current EEG devices can more accurately be seen as ‘health reading’ technologies. They can measure or infer stress, emotional states, sleep quality, and patterns associated with mental health and neurological disorders, among other indicators of brain health.
Like voiceprints derived from audio recordings, brainprints create the possibility of linking data back to individuals. With EEG, that creates an additional privacy risk because the same recordings may also contain sensitive information about a person’s health or mental state. If leaked or re-identified, this information could potentially be misused , for example by revealing indications of an underlying mental health condition.
To preserve privacy beyond simply removing metadata, differential privacy and related methods can be used to make individuals harder to identify from datasets. These approaches often involve adding noise or otherwise reducing the amount of identifying information that can be extracted from the data.
But stronger privacy protections can also reduce the usefulness of the data for studying health and wellness. “There is no simple switch that removes only identity information while preserving every possible future use of the data,” says Dr. Insa Wolf, Head of Mobile Neurotechnologies at the Fraunhofer Institute for Digital Media Technology (IDMT) in Germany.

Dr. Insa Wolf leads a research team at IDMT developing mobile EEG systems for everyday use. Her team recently investigated ways to address the privacy-utility tradeoff by generating non-identifiable EEG that reduces identifying information while preserving the data’s usefulness for medical research.
“Our machine learning-based method takes an EEG recording, creates a compact internal representation of it, and reconstructs a modified, synthetic version of the signal,” says Wolf. “We train the system with two goals: to reduce the information that allows a machine learning model to match the EEG to a particular person, while preserving information needed for a defined scientific purpose—in our case, sleep-stage analysis.”
Wolf compares her team’s ‘transformer’ method to an audio editor that keeps the words in a recording understandable while making the speaker harder to recognize. In their study, the transformed EEG data made individual identification substantially more difficult while retaining 90 percent accuracy in sleep-stage classification.

Wolf reminds consumers that while an EEG headset cannot read private thoughts, it can still generate sensitive biometric data and should not be treated as a harmless gadget. “Consumers should ask whether raw EEG data leave the device, whether they are linked to an account, who can access them, how long they are retained, and whether they can be deleted.”
A 2024 report by the Neurorights Foundation found that most consumer neurotechnology companies allowed some form of data sharing with third parties, while fewer than half gave users the right to delete their data.
As researchers learn more about the identifying features contained in EEG, Wolf argues that device companies should assess re-identification risks using realistic threat models rather than relying on conventional de-identification alone. “Companies should treat EEG as potentially personal and sensitive data from the outset. Privacy should be built into products through data minimization, local processing where possible, encryption, strict access controls, meaningful consent, limited retention periods and regular independent testing of re-identification risks.”
[LLMs were used to generate the header image of this article]