The legal limits of pseudonymisation under the GDPR

23-09-2025 At first glance, the distinction between pseudonymisation and anonymisation seems minor: both techniques affect the traceability of (personal) data. However, this distinction has major legal consequences. Anonymised data falls outside the scope of the GDPR, while pseudonymous data often still falls within its scope. How do these techniques relate to each other? And what does that mean in practice for your organisation?

In this blog, I discuss these questions on the basis of a recent, influential ruling by the Court of Justice of the European Union (hereinafter: the Court) of 4 September 2025 in the case of EDPS v. SRB. This ruling has important consequences for the responsibilities and obligations of organisations involved in the processing of pseudonymised data.

Why does this ruling matter?

This ruling is of great importance because the Court clarifies that pseudonymised data does not always have to be considered personal data, at least not for every party. Whether data qualifies as personal data depends on the context and the resources available to the recipient. Until recently, there was a great deal of uncertainty about this issue. Some organisations, including various supervisory authorities, took an objective approach, whereby data is considered personal data as soon as there is a theoretical possibility of identifying a person based on that data, regardless of whether the recipient actually has the means to do so.

However, the Court explicitly opts for a relative (contextual) approach. At the same time, the Court emphasises that the original controller remains bound by the GDPR obligations, such as the obligation to provide information. The Court's approach offers controllers more leeway when sharing pseudonymised data, but also requires careful analysis of who has access to which data and what measures have been taken to prevent re-identification.

What was at stake in this case?

The Single Resolution Board (SRB), a European institution responsible for handling bank failures, collected feedback from shareholders and creditors (data subjects) and shared this information in pseudonymised form with Deloitte for analysis. The data subjects were not informed of this. According to the European Data Protection Supervisor (EDPS), the European data protection supervisory authority, this was a breach of the information obligation, because the pseudonymised data still constituted personal data. This obligation means that the SRB, as the controller, must inform the data subject, among other things, to whom his or her personal data is being disclosed.

The General Court had previously taken a more nuanced view and overturned the EDPS's decision: for Deloitte, the data may not have been personal data because it did not have access to the underlying database and therefore could not re-identify the data subjects. According to the General Court, the assessment must be made from the perspective of the recipient of the data. The General Court also ruled that an opinion is only personal data if it can be directly linked to a person. According to the General Court, the EDPS had not made this assessment. The EDPS disagreed with this interpretation and lodged an appeal with the Court.

What does the Court say?

The Court comes to three important conclusions:

1. Personal opinions are personal data

The Court ruled that personal opinions or views can in themselves constitute personal data because they are directly linked to the author. According to the Court, personal opinions or views are an expression of a person's thoughts and are necessarily closely linked to that person. It is therefore not necessary to examine the purpose or effect of the feedback from the data subjects.

2. Relative approach confirmed

As indicated above, the Court confirms the relative approach to personal data: pseudonymised data is not automatically personal data for every party. The Court states that this classification is related to the identifiability of the data. According to the Court, this requires a contextual assessment, taking into account the means available to a party to identify a person. In practice, this means that pseudonymised data may qualify as personal data for one party, while this may not be the case for another party.

For example, the Court does classify the pseudonymised data for the SRB as personal data, because the SRB has additional information at its disposal to identify the data subject. According to the Court, this does not apply to Deloitte, because Deloitte cannot reverse the pseudonymisation and does not have additional data with which to link pseudonymised data to a data subject.

3. The information obligation applies from the moment of data collection

Finally, the Court ruled that the information obligation applies at the moment of data collection and from the perspective of the collecting party. In this case, the SRB should have reported at the time of collection that Deloitte would receive the pseudonymised data, regardless of whether Deloitte could identify the individuals.

What does this mean for your organisation?

The ruling emphasises that organisations must always be clear at the time of collecting personal data about which parties will have access to this data, even when it is shared in pseudonymised form. Whether data is considered personal data depends on the recipient and their ability to trace the data back to a natural person.

It is therefore essential to put in place not only technical but also organisational safeguards to prevent pseudonymisation from being reversed. This will minimise legal risks and ensure better compliance with GDPR obligations.

Boris Kruse Legal Consultant

Would you like to be sure that your organisation is applying pseudonymisation correctly and acting in accordance with the GDPR?

We would be happy to think along with you. Feel free to contact us.

Our services orContact