Categories: Insights, Case Law

Tag: data protection, Garante Privacy, Privacy


29 May 2023

Pseudonymised data: Court of Justice of the European Union rules against European Data Protection Supervisor

In judgment of 26 April 2023 (case T-557/20), the Court of Justice of the European Union (‘CJEU’) ruled that pseudonymised data transmitted to a recipient who does not have the means to identify the data subject is not personal data. This means that such information does not fall within the scope of the legislation on the protection of personal data.

Before entering into the merits of the judgment in comment, it seems appropriate to define what is meant by ‘pseudonymisation’. According to Article 4 of Regulation (EU) 2016/679 (better known by the acronym ‘GDPR’) pseudonymisation means ‘the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person’.

The facts of the case

The case examined by the CJEU is examined below.

The case originates from several complaints received by the European Data Protection Supervisor (the ‘EDPS’) reporting specific conduct of the Single Resolution Board (‘SRB’).   

Specifically, the SRB, after collecting through an electronic form some opinions of shareholders and creditors (the ‘data subjects’), had transferred the answers obtained to a consulting firm. Before forwarding it to the consulting firm, however, the SRB had pseudonymised this data by replacing the names of the data subjects with alphanumeric codes. However, the latter complained to the EDPS that the information notices on the processing of personal data provided by the SRB did not specify that their personal data would be shared with third parties.

The EDPS stated that, although the data thus disclosed did not allow the company to identify the authors of the survey, the data, although pseudonymised, should nevertheless be considered personal data, also in view of the fact that the outsourcer received the alphanumeric code that allowed it to link the replies received.

For these reasons, the EDPS held the consulting firm (the recipient of personal data) and the SRB liable for the breach referred to in Article 15 of the GDPR – governing the right of access of the data subject – for not having provided, among other things, information about the recipients or categories of recipients to whom the personal data would be disclosed.

The decision of the Court of Justice of the European Union

The judges of the CJEU overturned the EDPS’s decision. The CJEU, in fact, stated that the decision taken by the EDPS on the nature of the pseudonymised data was incorrect, as the EDPS had not verified whether or not the company to which the data had been disclosed was able to re-identify the data subjects. That verification should have taken place on the basis of the instruments it held, or did not hold, enabling it to identify natural persons.

To identify whether or not pseudonymised information disclosed to a recipient constitutes personal data, it is necessary to ‘consider the recipient’s perspective’. If the recipient does not have additional information enabling him/her to identify the data subjects or does not have legal means to access it, the disclosed data are considered to be anonymous data and therefore are not personal data. Therefore, they are excluded from the scope of application of the principles in force regarding data protection. On the contrary, the fact that the party disclosing the data has the means to identify the data subjects is irrelevant.

On these grounds, the Court of Justice annulled the EDPS’s decision and ordered it to pay the costs of the proceedings.

Other related insights:
GDPR: security measures to support data protection

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

3 Aug 2026

Pay Transparency: the first requests from employees are starting to arrive (Il Sole 24 Ore, 3 august 2026 – Vittorio De Luca)

Two months after the decree. Since Legislative Decree 96/2026 came into force on 7 June, according to a flash survey conducted by GIDP, 8% of HR directors have…

30 Jul 2026

Corporate controls and data protection: what balance?

A recent judgment of the Court of Pisa, No. 800 of 13 June 2026, addresses a topic of particular interest for companies: the delicate balance between the protection…

30 Jul 2026

Unfair dismissal and reinstatement: the employee must repay the payment in lieu of notice

With order no. 22187 of 28 June 2026, the Italian Supreme Court addressed the issue of whether payment in lieu of notice paid to an employee must be…

30 Jul 2026

Did you know that… an employee’s natural incapacity does not prevent the time limit for challenging a dismissal from running?

In judgment no. 23486 of 18 July 2026, the Joint Chambers of the Italian Supreme Court (i.e. “Corte di Cassazione”) held that the natural incapacity of an employee…

22 Jul 2026

An employee may not steer clients toward a competitor before resigning (Camera di Commercio Francese in Italia, 22 July 2026 – Vittorio De Luca, Silvia Zulato)

With Order No. 1723 of 26 May 2026, the Italian Supreme Court (Corte di Cassazione) confirmed the liability of an employee who, prior to the termination of his…

20 Jul 2026

Access to Naspi (Top24 Lavoro Ai – Il Sole 24 Ore, 20 July 2026 – Vittorio De Luca e Alessandra Zilla)

Regulatory Framework  The New Social Insurance for Employment (NASpI), introduced by Legislative Decree No. 22 of 4 March 2015, is the primary income support scheme for employees who…