Pseudonymization

The issue of pseudonymization has been gaining prominence in recent times.

The European Committee has issued guidelines 01/2025 together with a summary document on when and how to implement pseudonymization, which is open for public consultation until March 14, 2025.

The European Court’s ruling of April 26, 2023 (in case T-557/20) – annulling the EDPS decision which, among other things, reaffirmed that pseudonymized data could be classified as “personal data” – was challenged by the European Supervisor and is scheduled for a final decision by the Court of Justice in case C-413/23 P.

Meanwhile, on February 6, 2025, the Advocate General presented his conclusions with relevant assessments on this issue.

Given the important role of pseudonymization in the context of personal data protection, we will focus on these developments.

Pseudonymization as processing

Consisting of personal data processing operations, pseudonymization is ‘processing of personal data’ in itself, as confirmed by the definition contained in the GDPR [Article 4(5)]; consequently, it must comply with the principles (Art. 5) and lawfulness requirements (Art. 6) prescribed by the general regulation.

Lawfulness requirements 

In accordance with the principle of transparency, pseudonymization must be communicated by the data controller to the data subject through the privacy notice at the time of data collection (Article 13) or within the terms established by law, in the case of data acquisition from third-party sources (Article 14, GDPR).

In line with the interpretation of the Advocate General in case C-413/23 P, the privacy policy must also include the methods of use of pseudonymized data, together with an indication of the recipients in the event of their communication.

In general, also taking into account the logical reasoning followed by the Advocate General, the following considerations can be outlined:

  • pseudonymized data must necessarily be considered “personal data” for the data controller who carried out the pseudonymization, as they have additional information that allows them to re-identify the data subject
  • consequently, in relation to these operations, the data controller is subject to legal obligations, including the obligation to provide information regarding pseudonymized data
  • the obligation to provide information requires the controller to indicate the recipients or potential recipients of the data, i.e., the subjects to whom the data are transmitted or who may access the pseudonymized data
  • however, the information notice has an impact on the exercise of the right to object if the legal basis for the processing of pseudonymization is found in the legitimate interest of the controller or third parties.

Condividi

Post Recenti

Workshop – Come realizzare una FRIA

Beyond the Algorithm: Safeguarding the Human in the Age of Artificial Intelligence

Energy Telemarketing: Law 49/2026 Changes the Rules of the Game – 2