Skip to content
Literature · International Data Privacy Law EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

GDPR bypass by design? Transient processing of data under the GDPR

Damian George, Kento Reutimann, Aurelia Tamò-Larrieux — International Data Privacy Law

Damian George, Kento Reutimann, Aurelia Tamò-Larrieux — International Data Privacy Law

International Data Privacy Law
DOI

How it connects

Full text

In search of privacy-friendly facial detection and autonomous driving software, data controllers are discovering that processing data merely transiently might not only be in compliance with the data minimization principle, but also exclude their activities from the General Data Protection Regulation (GDPR) altogether. The argument can be made that since transient data does not allow for re-identification it is not personal data in a legal sense. However, effect-oriented or output-based interpretations of the notion ‘personal data’ have been proposed, which in turn could lead transient data processing technologies to fall within the scope of the GDPR. An effect-oriented interpretation of the regulation would ensure that in cases where transient data...