Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Pseudonymized data under GDPR: where the compliance line shifts


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: The CJEU has clarified that pseudonymized data is not automatically outside GDPR scope, because identifiability depends on the specific recipient’s realistic ability to re-identify individuals, according to Securiti’s analysis of EDPS v SRB. That makes data-sharing assessments, transparency notices, and recipient-specific risk evaluation central to privacy governance.

NHIMG editorial — based on content published by Securiti: When Does Pseudonymized Data Constitute Personal Data Under GDPR? (EDPS v SRB)

By the numbers:

Questions worth separating out

Q: How should organisations assess whether pseudonymized data is still personal data under GDPR?

A: Start by asking who will receive the data, what other information they already hold, and whether they can realistically re-identify the person using means reasonably likely to be available.

Q: Why do pseudonymized datasets still create privacy obligations after sharing?

A: Because pseudonymization reduces identifiability but does not necessarily remove it.

Q: What do privacy teams get wrong about pseudonymization and transparency notices?

A: Many teams assume notices can be fixed later after data is anonymized or shared.

Practitioner guidance

  • Review pseudonymization by recipient context Document what auxiliary data each recipient holds, what re-identification paths exist, and whether those paths are reasonably likely to succeed.
  • Update collection-stage transparency notices Ensure notices describe third-party disclosure before transfer occurs, especially where the controller can identify the person at collection.
  • Classify opinion and feedback content as personal data Treat survey responses, stakeholder comments, and employee feedback as personal data even after names are removed.

What's in the full article

Securiti's full article covers the legal reasoning and implementation detail this post intentionally leaves for the source:

  • Step-by-step discussion of the CJEU reasoning on personal opinions as personal data and how that affects privacy assessments
  • Detailed explanation of the recipient-specific identifiability test and the role of Recital 26 in practice
  • Operational implications for transparency obligations at collection time under Article 15 and related disclosure duties
  • Context on how the ruling interacts with the EDPB pseudonymization guidance and the Digital Omnibus proposal

👉 Read Securiti's analysis of when pseudonymized data constitutes personal data under GDPR →

Pseudonymized data under GDPR: where the compliance line shifts?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16618
 

Pseudonymization relativity is now the controlling concept. The decisive issue is no longer whether data has been stripped of direct identifiers, but whether a particular recipient can realistically re-identify the subject. That creates a governance model in which the same dataset can move between personal-data and non-personal-data treatment depending on context, access, and auxiliary information. Privacy teams should treat recipient-specific identifiability as a standing classification requirement, not a one-time legal label.

A question worth separating out:

Q: Who is accountable when pseudonymized data is shared with a third party?

A: The controller remains accountable for deciding whether the data is identifiable at collection and whether the disclosure notice is complete. Third-party recipients may also carry obligations, but they do not erase the controller’s duty to assess identifiability and inform data subjects up front.

👉 Read our full editorial: When pseudonymized data still counts as personal data under GDPR



   
ReplyQuote
Share: