Personal Data & Pseudonymization: What Changed in the Last 15 Months?

General View

Concepts and what they truly represent have always mattered to me. Because once you genuinely understand a concept, you gain the ability to structure meaning, connect ideas, and ultimately shape how a message is received.

But what happens when the concepts themselves start to shift?

This is precisely where the discussion around Personal Data and Pseudonymization stands today. Over the past 15 months, these notions have been tested, stretched, and, in some cases, fundamentally reinterpreted.

🧭 EDPB Pseudonymization Guidelines – January 2025

The European Data Protection Board (EDPB), in its guidelines on Pseudonymization, adopts a precautionary approach to the notion of Personal Data. It presents Pseudonymization as a key safeguard under the GDPR, one that can effectively reduce risks to Data subjects and support compliance with core principles such as Data minimization, security, and Data protection by design and by default.

According to the guidelines, Pseudonymized Data remains Personal Data wherever the possibility exists that it could be attributed to a natural person using additional information, considering the means reasonably likely to be used not only by the controller but also by other actors.

This interpretation implies that even where a recipient of Pseudonymized Data does not have access to the additional information required for re-identification -and may not realistically be able to obtain it- the Data may still be considered personal from that recipient’s perspective. In doing so, the EDPB promotes a risk-based reading of the GDPR, where the threshold for identifiability is set deliberately high.

⚖️ EDPS v SRB Decision – September 2025

The SRB judgment of the Court of Justice of the European Union (CJEU) marks a significant development in the ongoing debate on Pseudonymization and the scope of Personal Data. Building on its earlier case law, the CJEU has explicitly rejected an absolute understanding of Personal Data and confirmed instead its relative nature. In doing so, it has established that the same Dataset may be considered Personal Data for one actor, while not qualifying as such for another, depending on their ability to identify the Data subject.

More specifically, the CJEU has held that Pseudonymized Data shared with a recipient does not necessarily constitute Personal Data from that recipient’s perspective. This is the case where the recipient is not in a position -legally or practically- to re-identify individuals, and where effective technical and organizational measures prevent such re-identification, including through access to additional information or other reasonably available means. In contrast, for the initial controller who retains the additional information enabling identification, the Data remains Personal.

Pseudonymization is thus recognized not only as a risk mitigation tool, but also as a factor that may influence the legal qualification of Data. While it does not automatically render Data anonymous, it can, under specific conditions, place certain processing activities outside the scope of Data protection law—thereby drawing clearer limits to the concept of Personal Data.

💬 EDPB Stakeholders Event on Anonymization and Pseudonymization – December 2025

Following the EDPS v SRB decision, a stakeholder event was organized to reflect on its implications for Anonymization and Pseudonymization under EU Data Protection law. The decision marked an important development as mentioned above.

Together with several colleagues from our company, we had the opportunity to participate in this event and engage directly in discussions on some of the most pressing practical challenges. In particular, the exchanges focused on how identifiability should be assessed when Data are shared with third parties, and how the classification of Data may evolve depending on the recipient’s actual ability to re-identify individuals.

These discussions once again confirmed that the distinction between Anonymous and Personal Data is far from static. For complex Data environments, these developments carry significant implications, particularly in the context of Data sharing and cross-border transfers.

🏛️ Implementation at National Level: Decision From French Conseil d’État – February 2026

In its February 2026 decision, the French Conseil d’État provided further clarification on the assessment of identifiability in the context of Pseudonymized Data. The case arose from enforcement actions by the CNIL against several entities belonging to the same corporate group (Cegedim), which were subject to different administrative fines in relation to the use of large-scale Health Data sets.

Aligning with the case law of the CJEU, the Court emphasized that the qualification of Data as Personal cannot be determined in the abstract but must be assessed considering the concrete means available to the actor processing the Data.

In particular, the Conseil d’État underlined that the mere theoretical possibility of re-identification is not sufficient; rather, the analysis must consider whether re-identification is realistically achievable, considering legal, technical, and organizational constraints.

In the case at hand, the Conseil d’État applied this reasoning and found that, despite the use of Pseudonymized codes, theDataset included detailed information such as age, gender, medical conditions, prescribed and purchased medications, as well as temporal Data (including exact dates and sometimes times), indirect identifiers relating to Healthcare professionals (including ADELI and RPPS identifiers), as well as regional information.

The Court held that the combination of these elements made it possible to reconstruct care pathways and individualize Data subjects and noted that some of these identifiers could be linked to identified professionals through publicly accessible sources. It further relied on the CNIL’s findings that re-identification could be achieved with limited time and resources using commonly available tools.

The decision also highlights the importance of a contextual and operational approach to Data classification. Where a recipient does not have access to additional information enabling identification, and cannot reasonably obtain such information, the Data may fall outside the scope of Personal Data for that recipient. At the same time, the case illustrates the limits of this reasoning in complex Data ecosystems, particularly where multiple entities within the same group may indirectly contribute to re-identification risks, or when or additional Datasets are accessible allowing individualization. In doing so, the Conseil d’État reinforces the emerging trend towards a relative understanding of Personal Data, while confirming that context and robust safeguards, both technical and organizational, remain essential to ensure that this qualification is justified in practice.

📌 Conclusion

Taken together, each of these developments has contributed, in its own way, to reshaping the understanding of Personal Data within the GDPR framework. The EDPB guidelines have reinforced a precautionary and risk-oriented approach, maintaining a deliberately high threshold for identifiability. The CJEU, through the SRB judgment, has introduced a decisive shift by explicitly recognizing the relative nature of Personal Data. This position has been further echoed in stakeholder discussions and subsequently reflected at the national level by the French Conseil d’État, which has grounded the assessment of identifiability in concrete, operational realities.

These developments are not merely interpretative nuances; they signal a deeper evolution in the very nature of Personal Data. They challenge the idea of Personal Data as a fixed and uniform category and instead point towards a more contextual and actor-dependent understanding. The qualification of Data increasingly depends on factors such as access to additional information, the legal and practical ability to re-identify individuals, and the effectiveness of technical and organizational safeguards. In this context, Pseudonymization emerges not only as a tool for risk mitigation, but as a mechanism capable of influencing how the boundaries of Personal Data are defined in practice.

At MyData-TRUST, we closely monitor these developments and analyze their practical implications for Data sharing, cross-border transfers, and compliance strategies to ensure that our clients navigate these evolving boundaries with clarity and confidence.

Author: Alperen Yilmaz

📎 Sources:

· EDPB Guidelines 01/2025 on Pseudonymization: https://www.edpb.europa.eu/system/files/2025-01/edpb_guidelines_202501_pseudonymisation_en.pdf

· SRB Decision: https://infocuria.curia.europa.eu/tabs/document?source=document&docid=303863&doclang=EN

· Report on stakeholder event on Anonymization and Pseudonymization of 12 December 2025: https://www.edpb.europa.eu/our-work-tools/our-documents/other/report-stakeholder-event-anonymisation-and-pseudonymisation-12_en

· Jurisprudence of French Conseil d’Etat: https://www.conseil-etat.fr/fr/arianeweb/CE/decision/2026-02-13/498628

Prev post
Next post
Powered by MyData-TRUST

Want to subscribe to our newsletter ?

Name(Required)
Privacy(Required)