Identification
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Methods and processes for identifying individuals
Overview
24 sources · Jul 23, 2026Legal Framework
Identification sits at the heart of the GDPR's scope. Article 4(1) defines "personal data" by reference to whether a natural person is identified or identifiable, directly or indirectly, through identifiers such as a name, identification number, location data, or online identifier. This definitional threshold determines whether the Regulation applies at all. Once data qualifies as personal, Article 5(1)(e) imposes a temporal constraint: data may be kept in a form permitting identification only as long as necessary for the processing purpose.
"an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person"
— GDPR Art. 4(1)
Article 11 provides a narrow relief valve: where the controller's purposes do not require identification, the controller need not acquire additional information solely to comply with GDPR obligations. However, data subject rights under Articles 15–20 remain exercisable if the individual provides supplementary information enabling identification.
Key Developments
The CJEU's ruling in Breyer established the controlling test for indirect identifiability. The Court held that a dynamic IP address constitutes personal data for a website operator if that operator has legal means enabling it to identify the user through third parties. The threshold turns on whether identification is legally permissible and practically feasible:
"that would not be the case if the identification of the data subject was prohibited by law or practically impossible on account of the fact that it requires a disproportionate effort in terms of time, cost and man-power, so that the risk of identification appears in reality to be insignificant."
— Breyer ¶46
Crucially, the Court in Breyer clarified that the mere existence of legal channels — even indirect ones, such as contacting authorities who can compel an ISP to disclose subscriber data — suffices to render data personal:
"in the event of cyber attacks legal channels exist so that the online media services provider is able to contact the competent authority, so that the latter can take the steps necessary to obtain that information from the internet service provider"
— Breyer ¶47
Earlier, Rijkeboer confirmed that storage limitation under Article 5(1)(e) requires controllers to fix time limits calibrated to the period during which identification remains necessary for the stated purpose. Rynes reinforced the broad scope of "personal data," covering information relating to physical identity and any factor specific to the individual.
Status of the Debate
This topic is actively contested in court. The core fault line concerns the boundary of indirect identifiability — specifically, how to weigh the theoretical availability of legal channels against practical impossibility. Breyer adopted a relatively expansive reading, treating the existence of legal pathways to identification as sufficient, even where the controller itself cannot directly access the linking data. National courts and DPAs continue to grapple with applying this standard to new contexts such as pseudonymised datasets, hashed identifiers, and biometric templates. What would resolve the open question is further CJEU guidance on whether the "disproportionate effort" test should account for the controller's own operational capacity or only objective legal and technical constraints — a distinction Breyer left ambiguous.
Practical Guidance
- Assess identifiability contextually, not abstractly. Determine whether your organisation, alone or through lawful channels involving third parties, can link data to an individual. The Breyer standard looks at legal possibility, not just technical ease.
- Document the identification analysis. Article 30(1) records must reflect whether transfers involve data that permits identification, and Article 11(2) requires informing data subjects when you claim inability to identify them.
- Apply storage limitation by purpose. Under Article 5(1)(e), set and document erasure time limits tied to when identification ceases to be necessary for each processing purpose, following Rijkeboer.
- Re-evaluate when circumstances change. If new legal channels, technical capabilities, or additional data sources emerge that make identification feasible, data previously treated as non-personal may cross the threshold — triggering GDPR obligations retroactively.
- Use pseudonymisation as a risk mitigant, not an exemption. Article 4(5) defines pseudonymised data as still personal where additional information exists that could re-identify the subject; it reduces risk but does not remove the data from the GDPR's scope.