# Anonymization — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/anonimisering
> Sources are cited per item. Verify against the official texts before relying on them.

Irreversible removal of identifying information from data

## Overview

## Legal Framework

Anonymization is not separately defined in the GDPR, but its conceptual boundary is drawn by what falls *outside* the definition of personal data in [Article 4(1)](/laws/gdpr/art-4#par-5). Data that can no longer be linked to an identified or identifiable natural person by any reasonably likely means falls outside the Regulation's scope entirely. By contrast, [Article 4(5)](/laws/gdpr/art-4#par-5) defines *pseudonymisation* as a form of processing that still operates on personal data:

> "the personal data can no longer be attributed to a specific data subject without the use of additional information"
> — [GDPR Art. 4(5)](/laws/gdpr/art-4#par-5)

This distinction is critical: pseudonymised data remains personal data and is subject to the full GDPR, whereas genuinely anonymised data is not. The difference hinges on whether re-identification is possible, not merely whether it is difficult.

[Article 25(1)](/laws/gdpr/art-25#par-1) requires controllers to implement data-protection-by-design measures — explicitly naming pseudonymisation — while [Article 32(1)(a)](/laws/gdpr/art-32#par-1-pnt-a) lists pseudonymisation and encryption as security measures. Neither provision mentions anonymisation directly, but both reinforce that reducing identifiability is a structural obligation, not an afterthought. [Article 6(1)](/laws/gdpr/art-6) governs the lawfulness of any processing that precedes anonymisation: the legal basis must exist *before* the data is anonymised, since the anonymisation act itself constitutes processing.

## Key Developments

The CJEU in *Bundesverband der Verbraucherzentralen v Planet49* confirmed that even seemingly anonymous identifiers can constitute personal data when they can be linked to other data sets:

> "by linking that number with that data, a connection between a person to the data stored by the cookies arises if the user uses the internet, such that the collection of that data by means of cookies is a form of processing of personal data"
> — [Planet49 ¶45](/posts/51473#seg-45)

This establishes a dynamic, context-dependent threshold: data is personal if linkage is feasible, regardless of whether the controller holds the linking key. The EDPB reinforces this functional approach in its consent guidelines, treating anonymisation as the gold standard where processing can be avoided:

> "Anonymisation is the preferred solution as soon as the purpose of the research can be achieved without the processing of personal data."
> — [EDPB Guidelines 05/2020 §160](/posts/38053#seg-160)

The EDPB's breach guidelines further recognise "unauthorised reversal of pseudonymisation" as a concrete harm, underscoring that pseudonymisation alone does not remove data from the GDPR's protective perimeter. Enforcement actions — including the Italian Garante's proceedings against Character.AI and Ireland's DPC fine against Permanent TSB for insufficient technical measures — signal that regulators scrutinise whether controllers have genuinely anonymised data or merely pseudonymised it while claiming exemption.

## Status of the Debate

This topic is **contested and actively litigated**. The core tension lies in the re-identification standard: must anonymisation be irreversible in absolute terms, or is it sufficient that re-identification is not reasonably likely given available technology and effort? Courts have not yet drawn a bright line. The Planet49 ruling leans toward a broad, linkage-based conception of personal data that narrows the space for true anonymisation. Meanwhile, the EDPB has scheduled anonymisation and pseudonymisation as priority topics in its work programme and held a stakeholder event in December 2025, signalling that authoritative guidance is still forthcoming. What would resolve the open question is a CJEU ruling directly addressing whether anonymisation must withstand every theoretical re-identification attempt or only those that are reasonably likely — a question the Court has not yet answered head-on.

## Practical Guidance

- **Assess identifiability dynamically, not statically.** Document what additional information exists, who holds it, and whether linkage is reasonably likely given current technology. The Planet49 standard means that data is personal if *any* party can link it, not just the controller.
- **Distinguish pseudonymisation from anonymisation in records.** Pseudonymised data remains fully subject to the GDPR. Label datasets accurately in your processing records to avoid inadvertently claiming an exemption that does not apply.
- **Build anonymisation into design.** [Article 25(1)](/laws/gdpr/art-25#par-1) requires data-protection-by-design measures from the outset. Where a processing purpose can be achieved with anonymised data, prefer it — the EDPB treats this as the default for research contexts.
- **Secure any re-identification key separately.** [Article 32(1)(a)](/laws/gdpr/art-32#par-1-pnt-a) requires technical and organisational measures for pseudonymised data. Store linking keys under separate access controls, encryption, and authentication to prevent unauthorised reversal.
- **Establish a legal basis before anonymising.** The act of anonymising personal data is itself processing under [Article 4(2)](/laws/gdpr/art-4) and requires a lawful basis under [Article 6(1)](/laws/gdpr/art-6) before it is carried out.

## Legislation (full text of key provisions)

### Recital 28 — pseudonymisation benefits for data protection

*Source: GDPR, gdpr-rec-28-en, 2016-04-27 — https://overview.legal/posts/91571*

The application of pseudonymisation to personal data can reduce the risks to the data subjects concerned and help controllers and processors to meet their data-protection obligations. The explicit introduction of ‘pseudonymisation’ in this Regulation is not intended to preclude any other measures of data protection.

### Recital 29 — incentives for pseudonymisation within controller

*Source: GDPR, gdpr-rec-29-en, 2016-04-27 — https://overview.legal/posts/91573*

In order to create incentives to apply pseudonymisation when processing personal data, measures of pseudonymisation should, whilst allowing general analysis, be possible within the same controller when that controller has taken technical and organisational measures necessary to ensure, for the processing concerned, that this Regulation is implemented, and that additional information for attributing the personal data to a specific data subject is kept separately. The controller processing the personal data should indicate the authorised persons within the same controller.

### Recital 69 — privacy and data protection lifecycle

*Source: AI Act, aiact-rec-69-en, 2024-06-12 — https://overview.legal/posts/93820*

The right to privacy and to protection of personal data must be guaranteed throughout the entire lifecycle of the AI system. In this regard, the principles of data minimisation and data protection by design and by default, as set out in Union data protection law, are applicable when personal data are processed. Measures taken by providers to ensure compliance with those principles may include not only anonymisation and encryption, but also the use of technology that permits algorithms to be brought to the data and allows training of AI systems without the transmission between parties or copying of the raw or structured data themselves, without prejudice to the requirements on data governance provided for in this Regulation.

### Recital 75 — personal data processing risks to individuals

*Source: GDPR, gdpr-rec-75-en, 2016-04-27 — https://overview.legal/posts/91665*

The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from personal data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage; where data subjects might be deprived of their rights and freedoms or prevented from exercising control over their personal data; where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, and the processing of genetic data, data concerning health or data concerning sex life or criminal convictions and offences or related security measures; where personal aspects are evaluated, in particular analysing or predicting aspects concerning performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, in order to create or use personal profiles; where personal data of vulnerable natural persons, in particular of children, are processed; or where processing involves a large amount of personal data and affects a large number of data subjects.

### Recital 26 — personal data identifiability scope

*Source: GDPR, gdpr-rec-26-en, 2016-04-27 — https://overview.legal/posts/91567*

The principles of data protection should apply to any information concerning an identified or identifiable natural person. Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person. To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly. To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments. The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. This Regulation does not therefore concern the processing of such anonymous information, including for statistical or research purposes.

### Recital 156 — safeguards for archiving research processing

*Source: GDPR, gdpr-rec-156-en, 2016-04-27 — https://overview.legal/posts/91827*

The processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be subject to appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation. Those safeguards should ensure that technical and organisational measures are in place in order to ensure, in particular, the principle of data minimisation. The further processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is to be carried out when the controller has assessed the feasibility to fulfil those purposes by processing data which do not permit or no longer permit the identification of data subjects, provided that appropriate safeguards exist (such as, for instance, pseudonymisation of the data). Member States should provide for appropriate safeguards for the processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. Member States should be authorised to provide, under specific conditions and subject to appropriate safeguards for data subjects, specifications and derogations with regard to the information requirements and rights to rectification, to erasure, to be forgotten, to restriction of processing, to data portability, and to object when processing personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. The conditions and safeguards in question may entail specific procedures for data subjects to exercise those rights if this is appropriate in the light of the purposes sought by the specific processing along with technical and organisational measures aimed at minimising the processing of personal data in pursuance of the proportionality and necessity principles. The processing of personal data for scientific purposes should also comply with other relevant legislation such as on clinical trials.

### Recital 85 — personal data breach notification requirements

*Source: GDPR, gdpr-rec-85-en, 2016-04-27 — https://overview.legal/posts/91685*

A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons such as loss of control over their personal data or limitation of their rights, discrimination, identity theft or fraud, financial loss, unauthorised reversal of pseudonymisation, damage to reputation, loss of confidentiality of personal data protected by professional secrecy or any other significant economic or social disadvantage to the natural person concerned. Therefore, as soon as the controller becomes aware that a personal data breach has occurred, the controller should notify the personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the controller is able to demonstrate, in accordance with the accountability principle, that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where such notification cannot be achieved within 72 hours, the reasons for the delay should accompany the notification and information may be provided in phases without undue further delay.

### Recital 121 — lawful personal data processing for cybersecurity

*Source: NIS2, nis2-rec-121-en, 2022-12-14 — https://overview.legal/posts/96770*

The processing of personal data, to the extent necessary and proportionate for the purpose of ensuring security of network and information systems by essential and important entities, could be considered to be lawful on the basis that such processing complies with a legal obligation to which the controller is subject, in accordance with the requirements of Article 6(1), point (c), and Article 6(3) of Regulation (EU) 2016/679. Processing of personal data could also be necessary for legitimate interests pursued by essential and important entities, as well as providers of security technologies and services acting on behalf of those entities, pursuant to Article 6(1), point (f), of Regulation (EU) 2016/679, including where such processing is necessary for cybersecurity information-sharing arrangements or the voluntary notification of relevant information in accordance with this Directive. Measures related to the prevention, detection, identification, containment, analysis and response to incidents, measures to raise awareness in relation to specific cyber threats, exchange of information in the context of vulnerability remediation and coordinated vulnerability disclosure, the voluntary exchange of information about those incidents, and cyber threats and vulnerabilities, indicators of compromise, tactics, techniques and procedures, cybersecurity alerts and configuration tools could require the processing of certain categories of personal data, such as IP addresses, uniform resources locators (URLs), domain names, email addresses and, where they reveal personal data, time stamps. Processing of personal data by the competent authorities, the single points of contact and the CSIRTs, could constitute a legal obligation or be considered to be necessary for carrying out a task in the public interest or in the exercise of official authority vested in the controller pursuant to Article 6(1), point (c) or (e), and Article 6(3) of Regulation (EU) 2016/679, or for pursuing a legitimate interest of the essential and important entities, as referred to in Article 6(1), point (f), of that Regulation. Furthermore, national law could lay down rules allowing the competent authorities, the single points of contact and the CSIRTs, to the extent that is necessary and proportionate for the purpose of ensuring the security of network and information systems of essential and important entities, to process special categories of personal data in accordance with Article 9 of Regulation (EU) 2016/679, in particular by providing for suitable and specific measures to safeguard the fundamental rights and interests of natural persons, including technical limitations on the re-use of such data and the use of state-of-the-art security and privacy-preserving measures, such as pseudonymisation, or encryption where anonymisation may significantly affect the purpose pursued.

### Recital 61 — high-risk AI in justice and democracy

*Source: AI Act, aiact-rec-61-en, 2024-06-12 — https://overview.legal/posts/93804*

Certain AI systems intended for the administration of justice and democratic processes should be classified as high-risk, considering their potentially significant impact on democracy, the rule of law, individual freedoms as well as the right to an effective remedy and to a fair trial. In particular, to address the risks of potential biases, errors and opacity, it is appropriate to qualify as high-risk AI systems intended to be used by a judicial authority or on its behalf to assist judicial authorities in researching and interpreting facts and the law and in applying the law to a concrete set of facts. AI systems intended to be used by alternative dispute resolution bodies for those purposes should also be considered to be high-risk when the outcomes of the alternative dispute resolution proceedings produce legal effects for the parties. The use of AI tools can support the decision-making power of judges or judicial independence, but should not replace it: the final decision-making must remain a human-driven activity. The classification of AI systems as high-risk should not, however, extend to AI systems intended for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases, such as anonymisation or pseudonymisation of judicial decisions, documents or data, communication between personnel, administrative tasks.

## Case law

### NSS - 1 As 183/2023-62

*Source: Supreme Administrative Court, 2026-08-04 — https://overview.legal/posts/184683 — original: https://gdprhub.eu/index.php?title=NSS_-_1_As_183/2023-62*

Facts — OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free Access to Information, it requested information from the General Health Insurance Company of the Czech Republic concerning the treatment of patients with iron deficiency and related conditions for the period from 1 January 2010 to 31 October 2017. The request covered 183 types of diagnoses, 18 types of medical procedures, 96 DRG codes and 13 types of medications. The company stated that it wished to analyse how specific diagnoses were treated, the number of patients treated, and the frequency of related medical procedures, in order to compare clinical practice against the relevant theoretical background. The public health insurer rejected the request on the grounds that granting it would require the creation of new information. Following an appeal by the company, the Prague Municipal Court overturned the decision. The public health insurer provided then the company with five separate tables regarding the diagnoses, diagnoses in conjunction with medical procedures, the DRG codes and prescribed medications. It aggregated the parameters of the provided data as follows: five-year age groups, dates were given only at the monthly level, and healthcare providers were classified into broad geographic regions. However, it refused to add a unique random identifier which would allow linking the individual records and tables pertaining to the same patient. The public health insurer considered that providing the code would result in the disclosure of special categories of personal data. The company lodged a complaint with the Czech DPA (UOOU), which rejected it. The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4(1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case (C-582/14), according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in Case T-557/20 (SRB v. EDPS), which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety. The company filed a cassation appeal with the Supreme Administrative Court, arguing that the information had been anonymised. It alleged that the addition of a random code with no independent meaning would not alter their anonymous nature. It claimed that the Municipal Court had not explained what specific additional information could be used to identify the patients and had relied on hypothetical scenarios. The company stated that it was objectively impossible to obtain such data through other requests in a detailed and non-aggregated form. It also argued that iron deficiency was not a rare disease, but was associated with a large number of patients and various conditions and that the data had undergone both randomisation and generalisation so the risk of identification was therefore low. Finally, the company emphasized that the tables without the random identifier could not be used effectively for the intended analysis. It further argued that the DPA and the Municipal Court had not adequately balanced the right of access to information against the right to the protection of personal data. The DPA argued that the random identifier constituted personal data when considered in conjunction with the health data to which it would be linked. It stated that the concept of personal data was not limited to information that directly identifies an individual nor did it require that all necessary additional information be held by the same entity. Replacing direct identifiers with a code did not anonymise the data, but made it pseudonymised. Moreover, it argued that certain categories contained a relatively small number of records and that combining them with other data could make it possible to select and identify a specific insured person and their treatment history. It further argued that, even if identifiability was relative, it should be assessed in relation to all potential information applicants and their ability to obtain contextual information. The Supreme Administrative Court stayed the proceedings in the case pending the CJEU’s decision in Case C-413/23 P (EDPS v. SRB). After the judgment was issued, the company argued that whether the data were pseudonymised or anonymised should be assessed in relation to the specific recipient of the data and the means that it could reasonably use. It stated that it did not have any means of re-identification and that only specific and practically available cross-referencing possibilities should be taken into account. Holding — The court relied on Case C-413/23 and noted that pseudonymised data under Article 4(5) GDPR does not automatically constitute personal data in relation to every person. Therefore, it examined whether the company had lawful means that could reasonably be expected to be used to identify the patients directly or indirectly. The court found that the tables, without the random identifier, did not allow for the identification of specific insured individuals. It held that the requested random identifier would link the records from the different tables and allow for the aggregation of information on the diagnoses, medical procedures, hospitalizations, and medications for the same patient during the eight-year period. Certain combinations of these data, along with age group, gender, and region, could be unique and allow for the identification of patients using information from public sources. It pointed out that although iron deficiency was a very common diagnosis and some tables contained a very large number of entries, other categories were not sufficiently generalised. According to the court, in certain cases, such as rare diseases, unusual treatment combinations, or particularly young or old age, knowing even a few details about a person could make it possible to identify the corresponding record. The risk was not negligible, given that information about a person’s age, gender, hospitalization, diagnosis, or treatment could be available in the media or on social media. Consequently, the court held that adding the random identifier, in conjunction with the data already provided, would make the dataset personal data in relation to the company under Article 4(1) GDPR, including health data falling under Article 9 GDPR. The court clarified that classifying the information as personal data was not sufficient in itself to reject the request. It noted that the right of access to the information must also be balanced against patients’ right to privacy through an assessment of suitability, necessity and proportionality. It determined that the decision not to provide the random identifier was appropriate for the protection of privacy, because without it, it was impossible to link the tables and identify individual patients. It was also deemed necessary because the company insisted on receiving that specific code along with the existing tables and there was no other procedure that would constitute a lesser infringement of its right to information. The court also recognized the public interest in accessing information related to the operation of the healthcare system, but ruled that this did not outweigh the need to protect the detailed health data of potentially hundreds of thousands of insured individuals. It concluded that the refusal to provide the code was therefore proportionate. The Supreme Administrative Court therefore upheld the Municipal Court’s ruling, but partially corrected its reasoning regarding the relative nature of identifiability and the need to conduct a proportionality review. It dismissed the appeal.

### Judgment of the Court (First Chamber) of 4 September 2025.#European Data Protection Supervisor v Single Resolution Board.#Appeal – Protection of natural persons with regard to the processing of personal data – Procedure for granting compensation to shareholders and creditors of a banking institution following the resolution of that institution – Decision of the European Data Protection Supervisor finding that the Single Resolution Board failed to fulfil its obligations relating to the processing

*Source: Court of Justice of the European Union, C-413/23, 2025-09-04 — https://overview.legal/posts/132136 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0413*

The European Data Protection Supervisor (EDPS) appealed a General Court judgment that annulled its decision finding the Single Resolution Board (SRB) had failed to fulfil its obligations under Regulation (EU) 2018/1725 regarding the processing of personal data in a banking resolution compensation procedure. The core legal issues concerned whether pseudonymised data transmitted to a third party constitutes "personal data" under Article 3(1), the proper interpretation of "pseudonymisation" under Article 3(6), and the scope of the controller's obligation to inform data subjects under Article 15(1)(d). The Court of Justice (First Chamber) ruled on these interpretive questions in deciding whether to set aside the General Court's judgment.

### Hoge Raad - ECLI:NL:PHR:2023:935

*Source: Supreme Court of the Netherlands, ECLI:NL:PHR:2023:935, 2023-10-20 — https://overview.legal/posts/158435 — original: https://gdprhub.eu/index.php?title=Hoge_Raad_-_ECLI:NL:PHR:2023:935*

Facts — The data subject, an asset management professional, undertook an agreement with PME Investment Services. The agreement was that the data subject would take over a housing project mediated by PME, and in return PME would be awarded a fee and a minor percentage of the subsequent sale of the apartments. However, the data subject failed to uphold the agreement. As a result, on 9 May 2018, PME filed a suit against the data subject. After a first decision, on 27 January 2021, the case was brought to the attention of the Court of Appeal of Den Haag. In those proceedings, in an attempt to avoid liability, the data subject relied on the GDPR to anonymise and redact deeds which were key to the proceedings, on the basis of Article 5(1)(c) GDPR (data minimisation). In a judgment dated 4 October 2022, the Court of Appeal of Den Haag ignored the anonymised deeds and ruled in favour of PME and made a compensation order based on calculations which did not take into account the anonymised deeds. As a result, the compensation order was significantly higher than it would have been if the anonymised deeds were taken into account. On 3 January 2023, the data subject filed an appeal against the Court of Appeal's decision to the Supreme Court of the Netherlands. Holding — The Supreme Court of the Netherlands dismissed the appeal. In their ruling, the Supreme Court clarified the relationship between the GDPR and domestic evidentiary rules in civil proceedings. The Court held that it was possible to give evidence in a manner compliant with the GDPR and confirmed the CJEU case of Norra Stockholm Bygg AB (Case C‑268/21). In that case, the CJEU held that the GDPR does not contain an absolute ban on sharing personal data in civil proceedings as that would be in conflict with the right to a fair trial in Article 6 ECHR. However, in doing so, the national court must take into account the principle of proportionality and balance the right to a fair trial and Article 5(1)(c) GDPR (data minimisation). The CJEU concluded that it is for the national courts to determine whether the provision of personal data is sufficient and pertinent to achieve the objective pursued by the applicable provisions of national law and whether that objective could not be achieved by using less intrusive evidence in order to protect the personal data of data subjects. The Supreme Court relied on the CJEU's case to determine the issue at hand and found that the plaintiff's anonymisation of the deeds were not proportionate and veered on an abuse of rights. As a result, their purported reliance on the principle of data minimisation (Article 5(1)(c) GDPR) was unfounded. The plaintiff had the opportunity to provide the relevant evidence in a GDPR-compliant manner for the calculation of compensation, and chose not to. Furthermore, the Court of Appeal had a legal basis in Dutch Law to estimate the compensation without the relevant evidence that the plaintiff decided to not provide. Accordingly, the Supreme Court dismissed the appeal.

### Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t

*Source: Court of Justice of the European Union, C-169/23, 2024-11-28 — https://overview.legal/posts/132158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0169*

In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan Government Office, as controller issuing COVID-19 immunity certificates, was required to provide information to data subjects under Article 14 GDPR where the personal data was not collected directly from them. The Court held that data generated by the controller in the context of its own processes falls within the Article 14(5)(c) exemption from the obligation to provide information, provided that Member State law ensures appropriate measures to protect the data subject's legitimate interests, including data security measures under Article 32. The Court also confirmed that supervisory authorities retain competence to handle complaints under Article 77(1) even where the Article 14(5)(c) exemption applies.

### Judgment of the Court (Fourth Chamber) of 7 March 2024.#IAB Europe v Gegevensbeschermingsautoriteit.#Request for a preliminary ruling from the Hof van beroep te Brussel.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Standard-setting sectoral organisation proposing to its members rules on the processing of users’ consent – Article 4(1) – Concept of ‘personal data’ – String of letters and characters ca

*Source: Court of Justice of the European Union, C-604/22, 2024-03-07 — https://overview.legal/posts/132270 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0604*

In Case C-604/22, the Court of Justice of the European Union ruled on a preliminary reference from the Brussels Court of Appeal in proceedings between IAB Europe and the Belgian Data Protection Authority (Gegevensbeschervingsautoriteit) concerning whether IAB Europe's "Transparency and Consent String" (TC String)—a coded string capturing users' consent preferences—constitutes personal data under GDPR Article 4(1) and whether IAB Europe qualifies as a (joint) controller under Article 4(7). The Court held that the TC String constitutes personal data because it can be linked to an identifiable natural person through reasonably likely means, and that IAB Europe, as a standard-setting sectoral organization determining purposes and means of processing through its framework, acts as a controller even without direct access to the data, with its responsibility extending to subsequent processing by third parties that it does not mandate but facilitates through its rules. No fine was imposed in this preliminary ruling, as the underlying Belgian DPA decision and any sanctions remain before the national court.

### Judgment of the Court (Third Chamber) of 2 March 2023.#Norra Stockholm Bygg AB v Per Nycander AB.#Request for a preliminary ruling from the Högsta domstolen.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 6(3) and (4) – Lawfulness of processing – Production of a document containing personal data in civil court proceedings – Article 23(1)(f) and (j) – Protection of judicial independence and judicial proceedings – Enforcement of civil law clai

*Source: Court of Justice of the European Union, C-268/21, 2023-03-02 — https://overview.legal/posts/132293 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0268*

In Case C-268/21, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Swedish Supreme Court in proceedings between Norra Stockholm Bygg AB and Per Nycander AB concerning the disclosure of an electronic staff register in civil litigation. The Court held that the production of documents containing personal data in civil court proceedings may constitute lawful processing under GDPR Article 6(3) and (4) where Member State law provides a suitable legal basis, and that such processing must comply with the data minimisation principle under Article 5, requiring a proportionate balancing of the parties' interests in judicial protection against the data subjects' rights to privacy and data protection. No fine was imposed.

### Judgment of the Court (First Chamber) of 20 October 2022.#Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(b) and (e) – Principle of ‘purpose limitation’ – Principle of ‘storage limitation’ – Creation, from an existing database, of a datab

*Source: Court of Justice of the European Union, C-77/21, 2022-10-20 — https://overview.legal/posts/132306 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0077*

In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) concerning a personal data breach. The Court held that creating a new database from an existing one for testing and error-correction purposes constitutes further processing requiring compatibility assessment under the purpose limitation principle, and that the storage limitation principle applies such that data must be deleted once the testing purpose is fulfilled. No fine was imposed at the EU level, as the matter was remitted to the referring Hungarian court.

### Rotterdam Court: DPA did not err in finding ING contactless chip payments GDPR-compliant

*Source: District Court Rotterdam, 2026-06-24 — https://overview.legal/posts/96826 — original: https://gdprhub.eu/index.php?title=Rb._Rotterdam_-_ROT_25/7371*

Facts — ING Bank N.V. (the controller) is a bank. In 2022, several data subjects brought a complaint to the DPA regarding the controller’s contactless payments. The data subjects requested the controller to issue debit cards without a chip that would enable contactless payments. The controller stated that this was not possible, however, the contactless payment feature could be disabled on the data subjects’ cards. The data subjects later filed a complaint because the debit cards contained the chips even if the contactless feature was disabled. The DPA dismissed the complaint in 2024, on the grounds that further investigation would be needed to determine whether the controller violated the GDPR or not. The DPA stated that it had limited capacity and such an investigation would place a heavy burden on it. The data subjects appealed this decision to the court, who determined that the DPA had wrongfully failed to hear the data subjects during the objection phase. The DPA issued a new decision in 2025 and concluded that the controller had not violated the GDPR. The data subjects appealed this decision, arguing that the DPA had again not investigated the case sufficiently. In addition, the data subjects argued that the controller processed personal data through the debit card chip without a valid legal basis. This is because the chip allowed payments made with blocked or expired cards, meaning Article 6(1)(b) GDPR did not apply. The controller could also not rely on consent (Article 6(1)(a) GDPR) to process the data. The DPA argued that the GDPR does not require controllers to completely eliminate a risk. In addition, disabling contactless payments or blocking cards were related to the contract between the data subject and the controller; the DPA argued that this did not remove the basis to process personal data. Holding — The court found that the DPA investigated the complaint to an appropriate extent and was not required to conduct a further investigation. According to the court, the data subjects did not provide sufficient evidence that the controller’s statements were incorrect or that the DPA lacked the technical knowledge during its investigations. The court upheld the DPA’s reasoning that Article 32 GDPR does not require a security risk to be completely eliminated, and concluded that the DPA could reasonably decide that there was no violation of the GDPR. Similarly, the court upheld the DPA’s reasoning and concluded that the controller had a valid legal basis to process the data subjects’ personal data. The court saw no need to assess potential violations of other laws (e.g. fraud or forgery) or consumer law issues, on the grounds that the DPA’s investigation is limited to compliance with the GDPR. The DPA is also not required to coordinate or refer the case to other competent authorities. The court dismissed the appeal.

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### VB v Natsionalna agentsia za prihodite

*Source: CJEU, C-340/21, 2023-12-14 — https://overview.legal/posts/51485 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0340*

Data breach alone does not establish inadequate security measures. Burden on controller to prove adequacy.

### Rb. Den Haag - C/09/689833

*Source: District Court Den Haag, 2026-05-27 — https://overview.legal/posts/53095 — original: https://gdprhub.eu/index.php?title=Rb._Den_Haag_-_C/09/689833*

Facts — Kindred Group PLC and Risepoint Limited (the controllers) are companies that provide online gambling products. Several companies within Kindred Group PLC (Risepoint was initially in this group) offered online gambling products before a national law requiring a license entered into force. In response, several lawsuits were filed before courts regarding the validity of the gambling agreements between players and unlicensed online gambling providers. Several data subjects later requested access (Article 15 GDPR, or in the alternative, the right to portability under Article 20 GDPR) to the controller to receive information on specific transaction data and the types of games they participated in. The data subjects did not receive access and brought a claim to the court. The data subjects requested the court to hold both companies liable (jointly or separately) The court initially dismissed the claim based on the code of civil procedure, but allowed the data subjects to amend their arguments regarding the GDPR. Both companies argued that they were not controllers, and that the requests made by the data subjects were abusive. According to the companies, the data subjects requested access for the sole purpose of bringing legal actions against them. Finally, the companies argued that they did not have the obligation to comply with the requests under Article 15(4) GDPR. Holding — The court first clarified that both Kindred Group PLC and Risepoint Limited were controllers. Kindred Group PLC argued that it did not exercise any decisive influence over the purpose and means of processing. The court took into consideration the functional definition of “controller” under Article 4(7) GDPR and CJEU case law, rather than a formal definition. The court found that Kindred Group PLC was a controller for access made between May and October 2024, but not for requests made after October 2024. This is because Kindred had a unified privacy policy for companies under its group, and answered the access request from an email address containing its name. However, after October 2024, Risepoint was no longer a part of the group, and the data from Kindred had been transferred to Risepoint. The court then dismissed the controllers’ arguments, and stated that the access requests were not abusive under Article 12(5) GDPR. Under Article 12(5) GDPR, a controller may refuse a request for access if it is manifestly unfounded or excessive. However, the CJEU has clarified that a data subject does not need to justify an access request, and a controller cannot refuse a request for access on the sole ground that it serves a purpose other than obtaining information about the processing of personal data and verifying its lawfulness. In any case, the court stated that the controller bears the burden in proving that a request is manifestly unfounded or excessive. Similarly, the controllers could not rely on Article 15(4) GDPR to refuse the data subjects’ requests. The court stated that the controllers’ interest in not granting information that data subjects could use against them in court is not recognised under EU law as a basis to refuse access. While the GDPR allows for national law to restrict specific rights under Article 23 GDPR, the court stated that the restriction must be necessary and proportionate. This, however, does not apply for hypothetical situations. The court upheld the data subjects’ claim, and ordered the controllers to provide them with a copy of their transaction data. The court specified that the controllers had the obligation to provide a complete copy, in accordance with CJEU case law.

### Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos

*Source: Court of Justice of the European Union, C-446/21, 2024-10-04 — https://overview.legal/posts/132159 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0446*

In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR Articles 5(1)(b), 5(1)(c), 6(1), and 9 concerning the lawfulness of processing user personal data for personalised advertising on online social networks. The Court addressed whether such processing can be deemed compatible with the original purpose of data collection under a platform's terms of use, the applicability of the data minimisation principle, and the conditions under which special categories of personal data, including data concerning sexual orientation made public by the data subject, may be processed. No fine was imposed, as the ruling provides interpretative guidance to the Austrian Supreme Court for resolution of the underlying dispute.

## Guidance

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

*Source: EDPB, opinion-282024-on-certain-data-protection-aspects-related-to-en, 2024-12-18 — https://overview.legal/posts/125697 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en*

Adopted 1 Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models Adopted on 17 December 2024 Adopted 2 Executive summary AI technologies create many opportunities and benefits across a wide range of sectors and social activities. By protecting the fundamental right to data protection, GDPR supports these opportunities and promotes other EU fundamental rights, including the right to freedom of thought, expression and information,…

### EDPB Work Programme 2024-2025

*Source: EDPB, edpb-work-programme-2024-2025-en, 2024-10-09 — https://overview.legal/posts/125711 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-work-programme-2024-2025_en*

The European Data Protection Board (EDPB) is an independent European body established by the General Data Protection Regulation (GDPR). The EDPB has the following main tasks: 1. In line with the Article 29 of the EDPB Rules of Procedure. This Work Programme is valid from 8 October 2024 until 31 December 2025 and supersedes, for the remaining part of 2024, the previous Work Programme 2023–2024. 2. https://www.edpb.europa.eu/system/files/2024-04/edpb_strategy_2024-2027_en.pdf EDPB Work Programme…

### Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak

*Source: EDPB, guidelines-032020-on-the-processing-of-data-concerning-health-for-the-purpose-en, 2020-04-21 — https://overview.legal/posts/126170 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032020-on-the-processing-of-data-concerning-health-for-the-purpose_en*

Adopted 1 Guidelines 03 /2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID - 19 outbreak Adopted on 21 April 2020 Adopted 2 Version history Version 1.1 30 April 2020 Minor corrections Version 1. 0 21 April 2020 Adoption of the Guidelines Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1) (e) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the…

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries

*Source: EDPB, toolbox-on-essential-data-protection-safeguards-for-enforcement-en, 2022-03-14 — https://overview.legal/posts/125962 — original: https://www.edpb.europa.eu/documents/other-guidance/toolbox-on-essential-data-protection-safeguards-for-enforcement_en*

Adopted Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries Adopted on 14 Mar c h 2022 2 Adopted The European Data Protection Board Having regard to Article 70 (1)(u) and Article 50(a) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the…

### EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)

*Source: EDPB, edpb-edps-joint-opinion-032021-on-the-proposal-for-a-regulation-of-en, 2021-03-11 — https://overview.legal/posts/126050 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032021-on-the-proposal-for-a-regulation-of_en*

1 Adopted EDPB - EDPS Joint Opinion 03 /2021 on the Proposal for a regulation of the European Parliament and of the Coun cil on European data governance (Data Governance Act) Version 1.1 2 Adopted Version history Version 1.1 09 June 2021 Minor editorial changes Version 1.0 10 March 2021 Adoption of the Joint Opinion 3 Adopted 5 Adopted The European Data Protection Board and the European Data Protection Supervisor Having regard to Article 42(2) of the Regulation 2018/1725 of 23 October 2018 on…

### EDPB Document on response to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research

*Source: EDPB, edpb-document-on-response-to-the-request-from-the-european-commission-for-en, 2021-02-02 — https://overview.legal/posts/126069 — original: https://www.edpb.europa.eu/documents/other-guidance/edpb-document-on-response-to-the-request-from-the-european-commission-for_en*

EDPB Document on r esponse to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research Adopted on 2 February 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 70.1.b of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

## Enforcement decisions

### APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender

*Source: APDCAT (Catalonia), 2026-07-17 — https://overview.legal/posts/184715 — original: https://gdprhub.eu/index.php?title=APDCAT_(Catalonia)_-_PS-0036/2026*

Facts — On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing lease. The documents expressly disclosed the identities of the applicants. On 9 May 2025, the controller replaced the original documents with revised versions in which the applicants’ names and surnames were partially redacted, leaving only their initials visible. However, the redaction was performed manually and did not effectively conceal the information, as it remained possible to infer the length of the names and surnames and to identify some of their letters. In addition to the applicants’ identifying information, the documents disclosed detailed financial data, including the exact annual net income of each household. They also revealed information concerning particularly sensitive personal circumstances, including dependency, gender-based violence and addiction, which had been used to calculate the applicants’ respective scores. No adequate anonymisation or redaction measures had been implemented. In July and November 2025, the DPA requested that the controller provide specific information concerning certain aspects of the processing. The controller’s failure to respond or cooperate hindered the DPA’s ability to exercise its investigative powers. Holding — The DPA held that the controller violated Article 5(1)(c) GDPR by publishing personal data that were not necessary for the purpose pursued. The DPA acknowledged that publishing information about the procedure could serve the objective of administrative transparency. However, transparency did not justify disclosing identifying data together with detailed financial information and sensitive personal or family circumstances. The controller had to limit the processing to data that were necessary and proportionate to that objective and consider less intrusive alternatives. The DPA found that the controller’s subsequent redaction did not amount to effective anonymisation. Although most of the characters had been concealed, the applicants could still potentially be reidentified from their initials, the length of their names and surnames and other contextual information. This risk was particularly significant because the municipality had only 277 inhabitants. The controller should therefore have applied complete anonymisation or a pseudonymisation method preventing direct or indirect identification. The DPA also held that the controller violated Article 5(1)(f) GDPR and the duty of confidentiality under Article 5 LOPDGDD. The published documents disclosed the applicants’ exact household income, household composition and scores linked to circumstances such as dependency, addiction, gender-based violence, single-parent status and age. Although this information was relevant to assessing the applications, it was unnecessary to make it publicly accessible in a form linked to identifiable individuals. The DPA considered that the violations of the data-minimisation and confidentiality principles constituted a medial concurrence of infringements. The failure to anonymise the applicants’ identities was the necessary means through which their sensitive personal and family circumstances were disclosed. Nevertheless, the DPA formally declared separate violations of Articles 5(1)(c) and 5(1)(f) GDPR. Additionally, the DPA held that the controller violated Article 31 GDPR by failing to respond to two information requests. This failure breached the controller’s duty to cooperate with the supervisory authority and obstructed the exercise of the DPA’s investigative powers.

### Private individual: Insufficient legal basis for data processing

*Source: Austrian Data Protection Authority (dsb), 2021-08-05 — https://overview.legal/posts/47076 — original: https://www.enforcementtracker.com/ETid-961*

The Austrian DPA has imposed a fine of EUR 600 on a private individual. A private individual had sent a document obtained in a court case between the data subject and himself to the data subject's employer. This document contained information regarding health-related data of the data subject. At no time had the data subject consented to the forwarding of the document to her employer.

### Romanian Post National Company: Insufficient technical and organisational measures to ensure information security

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2020-07-30 — https://overview.legal/posts/46474 — original: https://www.enforcementtracker.com/ETid-359*

Processing of personal data, namely the telephone numbers and e-mail addresses of 81 data subjects, by the Romanian Post as data controller, failing appropriate technical and organisational measures, such as pseudonymisation.

### DSB Austria: sharing medical assessment with municipality lacked Art. 9(2) legal basis

*Source: DSB (Austria), 2021-08-05 — https://overview.legal/posts/184543 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2021-0.518.795*

Facts — Person A is employed at a municipality and has been on sick leave for several weeks in 2013 and 2014. In September 2014, the municipality concluded that Person A's sickness had been caused by another individual (Person B) who was then asked for damages. In another proceeding between Person A and Person B, the latter obtained a medical assessment concerning Person A's state of health. According to Person B's view, this document would have proved the municipality's claim wrong. The document was therefore shared with the municipality (even though no further steps had been taken following the initial claim). For this reasons, Person B is considered controller of Person A's personal data. Holding — The DPA held that there was no legal basis under Article 9(2) GDPR for sending the medical assessment, which contained health data under Article 14 GDPR#15Article 4(15) GDPR, to the municipality. In particular, the controller could not invoke Article 9(2)(f) GDPR ("necessary for the establishment, exercise or defence of legal claims") because i) the municipality had taken no further steps to claim damages from the controller since September 2014 and ii) the claim had already been time-barred under § 1489 General Civil Code (Allgemeines Bürgerliches Gesetzbuch - ABGB) since more than three years had passed since the event that allegedly caused the damage (harming behaviour towards the data subject). Consequently, the DPA held that the disclosure of the data subject's health data were not necessary "for the establishment, exercise or defence of legal claims". To lawfully disclose the data, the data subject's explicit consent would have been required. When deciding on the amount of the administrative fine, the DSB took into account the sensitive nature of the data and wilful conduct of the controller but also the controller's low income and the fact that the controller collaborated with the DSB in the course of the procedure.

### DSB (Austria) - 2020-0.743.659

*Source: DSB (Austria), 2020-11-19 — https://overview.legal/posts/125599 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2020-0.743.659*

Facts — The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR: the restaurant required customers to provide their name, phone number, email (optional) and table number upon being seated. In its data protection notice, the restaurant stated that it collected said data "to protect the life and health of our employees and our guests in connection with the occurrence of the coronavirus and the COVID-19 epidemic". The customer provided his data by using a QR-Code Scanner on 2 October 2020 and sent an access request under Article 15 GDPR afterwards. In their reply the restaurant stated that the processing was based on the Viennese Regulation on Contact Tracing (Wiener Contact-Tracing Verordnung). Dispute — Was it lawful under Article 6 GDPR and Article 9 GDPR to collect data on the customer for the purposes stated by the restaurant? Holding — The DSB held, that the data provided by the customer qualify as health data under Article 4(15) GDPR. Data such as name, phone number, email do not qualify as health data per se but in the context of COVID-19 contact tracing they contain information about the past, present and future physical or mental state of health of the customer. The data are supposed to be processed solely to protect the health of restaurant customers and to forward this data to the local authorities in accordance with the Austrian Epidemic Law. Accordingly, the data processing must also be compliant with the requirements of Article 9 GDPR. In the DSB held that the processing violated Article 5 GDPR, Article 6 GDPR and Article 9 GDPR: Consent under Article 6(1)(a) GDPR, Article 7 GDPR and Article 9(2)(a) GDPR cannot be considered as freely given in the context at hand. It was obligatory for the customer to provide his data to the restaurant, otherwise he would not have been allowed to enter the restaurant or would have been asked to leave. In addition, there was no acceptable alternative for the customer, because all restaurants in Vienna would have made the access to their premises dependent on the customer providing his data for COVID-19 contact tracing. The processing could also not be based on a legal obligation of the restaurant under Article 6(1)(c) GDPR and Article 9(2)(i) GDPR. The provisions of the Viennese Regulation on Contact Tracing do not contain an obligation for restaurants to collect data on customers (under Article 6(1)(c) GDPR) but only an obligation provide certain information (i.e name, phone number, e-mail address and table number) on customers to the local authorities. The DSB acknowledged that the collection of these data is prerequisite of providing such data to the authorities. However, the authorities could only order the restaurant to provide data it had legally obtained, they could not order it to provide non-existent data. Furthermore, the DSB held that theViennese Regulation on Contact Tracing did not meet the requirements of Article 9(2)(i) GDPR in terms of suitable and specific measures to safeguard the rights and freedoms of a data subject. Lastly, the DSB held that the restaurant had violated Article 5(1)(a) GDPR. The restaurant had created a misleading situation by basing the processing on both the customer's consent under Article 6(1)(a) GDPR and Article 9(2)(a) GDPR and the (insufficient) legal obligation under Article 6(1)(c) GDPR and Article 9(2)(i) GDPR. The customer was led to believe that the processing was subject to his control.

### DSB (Austria) - 2020-0.303.727

*Source: DSB (Austria), 2020-09-01 — https://overview.legal/posts/158430 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2020-0.303.727*

Facts — In June 2019, the complainant requested erasure of her personal data from the respondent's website, claiming that an article on that website contained wrong statements about her. After the respondent’s refusal to do so, the complainant lodged a complaint with the DSB. The respondent argued that publishing the article on its website qualified as processing carried out for journalistic purposes under Article 85 GDPR and § 9(1) of the Austrian Data Protection Act (Datenschutzgesetz - DSG). Due to the derogations in § 9(1) DSG, the DSB would hence not be competent to handle the complaint. Dispute — Is the DSB competent to handle the complaint or is the processing on the respondent's website subject to Article 85 GDPR and § 9(1) of the Austrian Data Protection Act? Did the respondent violate the complaint's right to erasure under Article 17 GDPR? Holding — The DSB held, that the respondent qualifies as a media company under § 1(1)(6) of the Austrian Media Act, because it is a company which creates the content of the medium and handles the production, distribution, broadcasting and retrievability of the medium. It further held, that the data processing (publishing the complainant's personal data in an online article) was carried out for journalistic purposes . As the complainant is an former politician and the article revolved around legal procedures that she is involved in there was a public interest in mentioning the complainant's name. Under Article 9(1) DSG, Chapter III and Chapter VI of the GDPR do not apply on data processing carried out by media companies for journalistic purposes. Such GDPR violations must be tried before civil courts. Hence, the DSB considered itself not competent, rejected the complaint and did not investigate the alleged violation of Article 17 GDPR.

### Website providing legal information: Insufficient fulfilment of information obligations

*Source: Belgian Data Protection Authority (APD), 2019-12-17 — https://overview.legal/posts/46284 — original: https://www.enforcementtracker.com/ETid-169*

An operator of a website for legal news had the privacy statement only available in English, although it was also addressed to a Dutch and French speaking audience. In addition, the first version of the privacy statement was not easily accessible and did not mention the legal basis for data processing under the GDPR. Furthermore, with reference to the ECJ ruling on Planet 49, it was determined that effective consent was required for the use of Google Analytics.

### CNPD (Portugal) - Deliberação 2019/494

*Source: CNPD (Portugal), 2019-09-03 — https://overview.legal/posts/122872 — original: https://gdprhub.eu/index.php?title=CNPD_(Portugal)_-_Deliberação_2019/494*

Facts — In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of the national legislator to a set of provisions that could potentially violate EU law, particularly the GDPR. The DPA emphasized the primacy of EU law as outlined in the EU treaties, particularly reflecting on Article 288 of the Treaty on the Functioning of the European Union (TFEU) and reinforced by the jurisprudence of the CJEU, which has consistently stated that national laws cannot obstruct the direct applicability of EU regulations and must comply with EU law to ensure uniform implementation across the Member States. However, Law 58/2019 came into force without incorporating all of the DPA's recommendations. The DPA explains that the decision to not apply some of its provisions aims to ensure legal certainty, reinforcing the importance of consistent GDPR application without being hindered by conflicting national rules. Holding — The DPA has decided to disapply the following provisions of Law 58/2019, in cases of personal data processing under its review due to their conflict with the GDPR: Article 2(1)(2): This article broadens the territorial scope of the GDPR to encompass all personal data processing within national territory and processing linked to national establishments outside the territory. The DPA believes this contradicts Article 3 and Article 56 of the GDPR, which outlines the applicable law in cross-border situations. Additionally, it undermines the one-stop-shop mechanism and fails to address instances where the GDPR applies, such as in Portuguese embassies, consulates, ships, and aircraft. Article 20(1): This article states that the right to be informed and the right of access cannot be exercised when a duty of secrecy is imposed on the data controller/processor. In the view of the DPA, this article lacks legal relevance in relation to the GDPR, as it merely repeats provisions already present in the GDPR, particularly concerning the possibility of restricting the data subject's right to information in cases where data collection is indirect and a legal duty of confidentiality exists. Regarding the possibility of restricting the right to information when collecting data directly from the data subject, this right can only be restricted under the provisions of Article 23 GDPR, and Law58/2019 does not meet the requirements therein, thus contradicting the norms of the GDPR and the Charter of Fundamental Rights. Article 23: This article allows public authorities to reuse personal data for any public interest without ensuring compliance with principles of purpose limitation and data minimization (Article 5 GDPR) and could lead to potential misuse of personal data and a violation of individuals’ rights, as it does not ensure that the reuse of data serves the original purpose for which it was collected nor respecting the requirements imposed in Article 23 GDPR. Article 28(3)(a): The employee's consent cannot be the legal basis if the processing results in a legal or economic advantage for the employee. The Portuguese DPA considers it to be a contraction of the doctrine established by European institutions, which accepts employee consent in situations where the act of giving or refusing consent does not, in itself, have negative consequences for the employee. The DPA therefore believes that this provision does not protect the dignity, fundamental rights, and legitimate interests of employees, and thus fails to meet the requirements set forth in Article 9 (2) (b) and Article 88 GDPR. Regime of Administrative Offenses – Articles 37, 38, and 39: The DPA notes that some of the violations outlined in the law contradict the exhaustive list provided in the GDPR (Article 83). The DPA also criticizes the distinction in sanctioning frameworks based on the size of companies and the collective or individual nature of the entities conducting data processing, as the impact on personal data does not depend on those characteristics but rather on the nature of the activity being carried out. Article 61(2) states that "if the expiration of consent is the reason for terminating a contract in which the data subject is a party, the processing of data is lawful until this occurs." The DPA notes that this provision is incongruent, conflating two types of legal basis: consent and contract execution. The contract in which the data subject is a party is sufficient to justify the processing of the data necessary for its execution. Regarding the reasons that led to publish this decision, the Portuguese DPA clarifies that it did so in order to ensure the transparency of its future decision-making processes and, in this regard, contribute to legal certainty and security. It also clarifies that the non-application, in future specific cases, of the legal provisions listed above results in the direct application of the GDPR provisions that were manifestly restricted, contradicted, or compromised in their useful effect.

## Recent developments

### EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain

*Source: European Data Protection Board, 2026-07-08 — https://overview.legal/posts/53905 — original: https://www.edpb.europa.eu/news/edpb-sheds-light-on-anonymisation-and-web-scraping-for-generative-ai-and-adopts-final-version_en*

Brussels, 8 July– During its latest plenary, the EDPB has adopted guidelines on anonymisation and guidelines on web scraping in the context of generative AI. In addition, the Board has adopted the final version of its guidelines on the processing of personal data through blockchain technologies.Understanding anonymous dataThe new EDPB guidelines bring clarity to the notion of anonymous data, taking also into account the ruling of the Court of Justice of the EU in the case C-413/23 P EDPS v SRB o

### Stakeholder event on anonymisation and pseudonymisation: express your interest

*Source: EDPB, 2025-11-17 — https://overview.legal/posts/49125 — original: https://www.edpb.europa.eu/news/news/2025/stakeholder-event-anonymisation-and-pseudonymisation-express-your-interest_en*

Brussels, 17 November - The EDPB organises a remote event to collect stakeholders’ input on anonymisation and pseudonymisation on implications of the judgement of the Court of Justice of the European Union (CJEU) in EDPS v Single Resolution Board (SRB). The event will take place on 12 December 2025 (time to be confirmed). This will be an opportunity to inform and support the EDPB’s ongoing work on these topics as per its work programme 2024-2025 and it reflects the EDPB’s commitment to stakehold

### User:Nata

*Source: GDPRhub, 2026-07-08 — https://overview.legal/posts/53907 — original: https://gdprhub.eu/index.php?title=User:Nata*

I am Nathalie Pangalos, an Applied Data Science student at the Universitat Oberta de Catalunya (UOC), based in Tenerife, Spain. My focus is data protection and privacy engineering: pseudonymisation, re-identification risk, and anonymisation techniques, which I document in my portfolio. IAPP Student Member, currently preparing for the CIPP/EU certification. Signed up as Country Reporter for the Spanish channel in April 2026, covering AEPD and Spanish court decisions. Co..." New pageI am Nathalie

### De Autoriteit Persoonsgegevens publiceert richtlijnen voor anonimisering.

*Source: IAPP, 2023-02-24 — https://overview.legal/posts/51775*

De Spaanse autoriteit voor gegevensbescherming, de Agencia Española de Protección de Datos, heeft richtlijnen gepubliceerd over het anonimiseren van gegevens. Deze richtlijnen stellen dat een getrainde professional de anonimisering van een dataset met persoonlijke gegevens moet uitvoeren, en dat deze professional ook ervaring moet hebben met pogingen tot heridentificatie. Hoewel er altijd een "resterend risico" bestaat dat gegevens opnieuw geïdentificeerd kunnen worden, moet de verantwoordelijke voor de gegevensverwerking verantwoordelijkheid nemen voor het anonimiseringsproces en "geschikte maatregelen treffen om te zorgen voor naleving, rekening houdend met..."

### Council deletes revised definition of personal data from GDPR omnibus

*Source: EURactiv, 2026-02-20 — https://overview.legal/posts/52808 — original: https://www.euractiv.com/news/council-deletes-revised-definition-of-personal-data-from-gdpr-omnibus/*

The EDPB's upcoming updated guidelines on pseudonymisation are also given more prominence in a compromise text, obtained by Euractiv

## Literature

### Clarifying “personal data” and the role of anonymisation in data protection law: Including and excluding data from the scope of the GDPR (more clearly) through refining the concept of data protection

*Source: Computer Law Security Review, 2024-04-01 — https://overview.legal/posts/132527 — original: https://doi.org/10.1016/j.clsr.2023.105932*

### POJAM OSOBNOG PODATKA U TUMAČENJU SUDA EUROPSKE UNIJE

*Source: Zbornik radova. Aktualnosti građanskog i trgovačkog zakonodavstva i pravne prakse, 2026-07-06 — https://overview.legal/posts/83510 — original: https://doi.org/10.47960/2744-2918.23.2026.281*

U radu se istražuje evolucija pojma osobnih podataka u kontekstu pseudonimizacije kroz analizu recentne sudske prakse i regulatornih smjernica. Središnji dio rada fokusiran je na presudu Suda Europske Unije u predmetu EDPS protiv SRB, kojom se potvrđuje kontinuitet relativnog poimanja pojma osobnog podatka u kontekstu provođenja postupka pseudonimizacije osobnih podataka. Hoće li se određeni podatak smatrati osobnim ovisi, tako, o tome tko podatak obrađuje i raspolaže li i kojim dodatnim informa

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

### Does de-identification require consent under the GDPR and English common law?

*Source: Journal of Data Protection Privacy, 2020-06-01 — https://overview.legal/posts/132522 — original: https://doi.org/10.69554/wzzy1745*

Data de-identification has many benefits in the context of the General Data Protection Regulation (GDPR). One of the recurring questions is whether consent is required to anonymise or de-identify data. In this paper, the authors make the case that no consent is required for anonymisation or other forms of de-identification under the GDPR, although additional conditions have to be met where special category data is anonymised. Further, under the English equitable duty of confidentiality, consent

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Pseudonymization** — https://overview.legal/topics/pseudonymization
  Processing data in a pseudonymized manner
- **Security** — https://overview.legal/topics/beveiliging
  Technical and organizational measures to protect personal data
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Identification** — https://overview.legal/topics/identificatie
  Methods and processes for identifying individuals

---
Generated by overview.legal · https://overview.legal/topics/anonimisering · 2026-08-22
