Anonymous data sounds simple: if no one can be identified, the General Data Protection Regulation ("GDPR") no longer applies. But in practice, the legal line between anonymous data and personal data is much finer than it first appears. This blog explains what it takes before data can truly fall outside the GDPR, in light of the European Data Protection Board's ("EDPB") recent guidelines on anonymisation.*
Protecting people's privacy is the main objective of the GDPR. That's why the regulation applies whenever organisations process personal data. The GDPR sets out rules and obligations to make sure individuals' rights are not put at risk.
If data is not considered personal data, it falls outside the scope of the GDPR. This means organisations don't have to comply with the GDPR's obligations, giving them more freedom to use, share and repurpose data. That freedom, however, only applies if the anonymisation is effective.
Data is anonymous when it either does not concern a person, or when that person cannot be identified from it. The next paragraphs explain what constitutes personal data, and what doesn't.
According to the GDPR, personal data is "any information relating to an identified or identifiable natural person". Recent case law from the Court of Justice of the European Union ("CJEU") confirms that whether data qualifies as personal data also depends on the perspective of the entities involved.1
Before assessing whether data has been effectively anonymised, organisations should first identify for whom the data is intended to be anonymous. This means considering all relevant entities that are likely to access, receive or have control over the data.
According to the EDPB, these relevant entities include anyone who directly or indirectly receives the data, such as the controller, a person's partner, friends or colleagues, investigative journalists, (foreign) intelligence agencies or cybercriminals.
The relationships between the entities involved should also be taken into account. Where one entity processes information on behalf of another (in other words, there is a controller-processor relationship under the GDPR), the assessment should be made from the controller's perspective.
Information relates to an individual where it is linked to that person by its content, purpose or effect. For this information to be considered personal data, the individual must be identified or identifiable using means reasonably likely to be used. The EDPB explains these two requirements in its recent guidelines, as described below.
Information can be linked to an individual in three different ways:
Identifying an individual means being able to distinguish them from others within a given context, and, as a result, being able to treat them differently. Identification can occur either directly, through the information itself, or indirectly, through other means, such as obtaining additional information or applying a decryption technique.
Identification is usually achieved through an identifier that is unique within a given context, or through a combination of attributes that together point to one particular individual. In this context, "unique" means that the information singles out one specific person. The information that can be used for identification should be assessed based on the means likely to be used by the specific entity seeking to identify the individual.
The EDPB takes a deliberately broad view of "means." It covers anything from simply reading a document, to running a web search, to deploying complex algorithms or AI-driven analysis. An entity's means can also include taking advantage of means that are available through another entity (e.g. hiring a third party).
The key question is whether, considering all objective factors relevant to the specific entity, those means are reasonably likely to be used. Relevant factors include the nature of the data, the availability of additional information, the cost and time required, available technology, and the context in which the data are released or processed. Means that are prohibited by law generally do not need to be taken into account. However, the EDPB identifies two exceptions: where the entities involved are not bound by the prohibition, or where there is sufficient evidence that the legal prohibition is not respected in practice. Contractual terms do not qualify as a legal prohibition.
Due to advances in technology and techniques for re-identification, data that was once considered anonymous can, over time, come to be regarded as personal data. It is therefore important to periodically reassess the effectiveness of the anonymisation and likelihood of re-identification.
It's important to distinguish anonymisation from pseudonymisation, as they are not the same thing. With pseudonymisation, personal data is processed in such a way that it can no longer be attributed to a specific individual without the use of additional information.2 That additional information is kept separately, but remains accessible for the specific entity. This additional information enables the pseudonymised data to be attributed back to an individual, allowing them to be identified. Therefore, the data is still considered personal: the information still relates to an individual, and that individual can still be identified. This means the GDPR continues to apply to pseudonymised data.
This differs from anonymisation. Data is only considered anonymous when it is not possible to identify a particular individual, even with the use of additional information.
Pseudonymisation is considered a security measure that makes it harder to identify a person — for example, by replacing personal data, such as a name, with a unique code. Anonymisation, by contrast, exempts organisations from the obligations of the GDPR.
Last year, the EDPB also published guidelines on pseudonymisation. These are still in draft form, though the public consultation has now closed.
These new EDPB guidelines are particularly interesting in light of the European Commission's Digital Omnibus. As discussed in one of our recent blogs, the Digital Omnibus proposes a change to the definition of personal data: whether information qualifies as personal data would depend on the specific position of the relevant entity. The EDPB has expressed concerns about this change and advised against adopting the proposed changes.
The EDPB guidelines clarify how the EDPB interprets the definition and scope of personal data. In particular, they explain which relevant entities should be considered when assessing whether data qualifies as personal data. The guidelines also emphasise that, where data is shared with a processor, the assessment should be made from the controller's perspective rather than the processor's own perspective.
This is where the EDPB's approach and the Commission's proposal diverge. The Commission's proposal states that information relating to a natural person does not automatically become personal data for another entity merely because that entity is capable of identifying the person. Unlike the EDPB, the Commission's proposal does not address the controller/processor relationship, and takes a narrower view of which entities should be considered when assessing whether data qualifies as personal data.
Considerati is curious to see how the EDPB guidelines will influence the proposed definition in the Digital Omnibus. We will monitor this closely to provide you with timely updates and practical advice. Do you have any questions in relation to anonymisation of personal data? Feel free to reach out.
It is important to note that the EDPB guidelines are still in draft form, and the consultation period runs until October 30th. Feedback can be contributed here.
Do you have any questions about the above or are you looking for strategic Legal advice? Contact Considerati, we offer specialised advice and tailored support.
Our services Contact