-
Not us :)
Though I can speak of the joys of mapping identifiers back and forth endlessly.
The first layer is external id to internal id... but then you realise that internal services class other services as external and start to realise there's a delicate chain of id swapping (and auditing and enforcement) that is pervasive. It's also fragile, because if you try and circumvent the chain, the id you possess is meaningless.
GDPR... how many organisations are going to be in breach of this in 2018? My guess is 'most'.
https://blog.varonis.com/eu-gdpr-spotlight-pseudonymization-as-an-alternative-to-encryption/