Anonymized is being used so heavily in every article.
I'll try again, anonymized would assume you can't discover the origin device. You literally have to for this to work. That means somewhere device id = anonymized id. You can change the anonymous id every five minutes but it still has to be in a table somewhere that said id at this time belongs to device id. That's the only way you are notified.
In advertising that's anonymized and what everyone keeps touting you don't need to store device id = advertising id anywhere. The data never has to make it back to the origin device because you just want the data.
Do you see the difference? Somewhere there is a record that has to keep track of the device. You are trusting this joint rushed operation has safeguards in place that someone won't be able to access that data. In the advertising world that data literally isn't there so its safe.
"You literally have to for this to work" ... no, you're incorrect. Read the spec and come back.