Pseudonymised Data and Personal Data — a Landmark CJEU Judgment
Are pseudonymised data always personal data? For years, data protection authorities generally answered this question in the affirmative. However, the CJEU judgment of 4 September 2025 in EDPS v SRB (C-413/23 P) presents a more nuanced approach. The Court held that the status of the same data may depend on the specific entity involved. They may constitute personal data for one recipient, but not for another.
The key factor is whether the individual can be identified. Therefore, it is necessary to assess whether a given entity has means “reasonably likely to be used” to identify that person. However, the judgment does not mean that pseudonymisation automatically removes data from the scope of the GDPR. A controller that can still identify individuals remains subject to all applicable GDPR obligations.
The ruling is particularly relevant to organisations sharing data, conducting analytics or developing AI solutions. In this article, I explain the key findings of the judgment and their practical consequences.
Background to the Case
The case arose from the restructuring of the Spanish bank Banco Popular. The Single Resolution Board, or SRB, conducted proceedings concerning possible compensation. Former shareholders and creditors could submit comments as part of that process. The SRB collected those comments and then pseudonymised them. Each form received a unique alphanumeric code, while direct identifiers were removed. The SRB then transferred 1,104 comments to Deloitte. Deloitte was expected to use them when assessing the effects of the restructuring.
However, the problem concerned the transparency obligation. The people submitting comments were not informed that their statements could be shared with Deloitte. Following complaints, the European Data Protection Supervisor examined the matter.
The EDPS considered Deloitte a recipient of personal data. It noted that the SRB still possessed information allowing the comments to be linked back to specific individuals. Consequently, the EDPS found that the SRB had breached its transparency obligation. The General Court later annulled that decision. It held that the status of the data should also be assessed from the recipient’s perspective, namely Deloitte’s. The EDPS appealed. The CJEU then set aside the judgment and referred the case back to the General Court.
Formally, the case concerned Regulation 2018/1725, which applies to EU institutions. However, that regulation closely mirrors many GDPR provisions. Therefore, the judgment also has significant implications for interpreting the concept of personal data under the GDPR.
Three Key Conclusions from the CJEU Judgment
1. Opinions and Views May Constitute Personal Data
The first conclusion concerns the nature of the information submitted to the SRB. The Court held that opinions and views expressed by an individual are inherently linked to their author. For this reason, they may constitute information relating to a specific person. This has broad practical significance. Companies often collect surveys, comments, customer ratings or employee feedback. Removing a name does not automatically place such content outside the GDPR. If the information relates to an identifiable person, it may still constitute personal data.
2. The Status of Pseudonymised Data May Depend on the Specific Entity
This is the most important part of the judgment. The CJEU clearly distinguished pseudonymisation from anonymisation. Pseudonymisation reduces the risk of identification, but it does not automatically make data anonymous. At the same time, the Court rejected the view that pseudonymised data must always have the same status for every entity.
The sender may possess a key that allows the person’s identity to be restored. In that case, the information remains personal data for the sender. However, the recipient may not have that key. It may also lack any other realistic means of identifying the individuals. In such circumstances, the same dataset may not constitute personal data for that recipient.
A purely theoretical possibility of identification is not enough. The assessment must determine whether there are means reasonably likely to be used. Relevant factors may include access to additional information, technology, time, cost and the possibility of obtaining data from other entities.
3. Transparency Obligations Are Assessed from the Controller’s Perspective
The third conclusion has particular practical importance. The controller should assess its transparency obligations at the time the data are collected. At that point, the controller’s own perspective matters.
The SRB retained information that allowed the comments to be linked back to specific individuals. Therefore, the data remained personal data for the SRB. The planned disclosure to Deloitte should consequently have been reflected in the information provided to those individuals. This remains true even if Deloitte itself could not identify any of the authors. In short, pseudonymisation does not remove the controller’s transparency obligations.
What the Judgment Changes in Practice
On the one hand, the CJEU confirmed the contextual nature of the concept of personal data. The status of information may depend on who holds it and what means that entity can use. This approach is particularly important when organisations share datasets. A dataset may remain personal data for the sender while having a different status for the recipient. However, this requires the absence of means reasonably likely to identify the individuals. The judgment may therefore affect research, analytics, data sharing and AI-related projects.
On the other hand, the CJEU did not lower the level of protection required from controllers. An entity that collected the data and can still identify individuals must continue to comply with the GDPR. This also applies where the organisation later pseudonymises the data and transfers them to another recipient. Moreover, the identifiability assessment cannot focus only on information directly available to the recipient. It must also consider the possibility of obtaining information from other sources.
Pseudonymisation Is Not Anonymisation
The judgment once again highlights the difference between pseudonymisation and anonymisation.
Pseudonymisation makes it more difficult to attribute data to a specific individual. For example, an organisation may replace a name, surname or customer number with a random code. However, this does not mean that the data cease to be personal data. An entity holding the key or other identifying information still processes personal data.
Anonymisation, by contrast, aims at a more far-reaching result. If the process is effective, the individual cannot be identified using means reasonably likely to be used. In that case, the data fall outside the scope of the GDPR.
Therefore, simply replacing identifiers with codes is not enough. Organisations must assess the entire context, the available information and the realistic capabilities of the specific entity.
What the Judgment Means for Companies
For organisations using pseudonymisation, the judgment mainly requires a more careful assessment of data status. Before sharing a dataset, several questions should be considered:
- Do the data remain personal data for the sender? If the organisation holds an identification key, the answer will usually be yes.
- What is the recipient’s position? It is necessary to assess whether the recipient can realistically identify the individuals.
- Can the recipient obtain additional information? Means available through third parties should also be taken into account.
- Does the transparency obligation cover the recipient? The assessment should be made from the controller’s perspective when the data are collected.
- Has the analysis been documented? Organisations should record their assumptions, the means considered and the outcome of the assessment.
- Is the re-identification key adequately protected? It should remain separate from the main dataset.
- Is the assessment still current? Technology and the availability of additional data can change over time.
It is also important to classify opinions and comments correctly. Surveys and customer ratings may constitute personal data. This may remain the case even after obvious identifiers have been removed.
Common Mistakes When Using Pseudonymisation
Treating pseudonymisation as anonymisation. Replacing identifying information with codes does not automatically remove the data from the scope of the GDPR.
Assuming the data always have the same status. The same dataset may have a different status for the sender and the recipient.
Failing to mention the recipient in the privacy notice. Pseudonymisation does not remove the controller’s transparency obligations.
Assessing only the recipient’s direct capabilities. Additional information available from other sources must also be considered.
Failing to document the identifiability assessment. The organisation should be able to explain why it classified the data in a particular way.
Inadequate protection of the key. Access to information enabling re-identification should be strictly limited.
Treating the assessment as a one-off exercise. Technological developments or new data sources may increase the possibility of re-identification.
Pseudonymisation and Data Sharing — Practical Checklist
- Determine the status of the data for the sender. Check whether you can link them back to specific individuals.
- Assess the recipient’s position. Determine the recipient’s realistic ability to re-identify individuals.
- Consider additional sources of information and means available through other entities.
- Identify recipients or categories of recipients in the relevant privacy information.
- Do not confuse pseudonymisation with anonymisation.
- Document the identifiability assessment and the basis for the chosen data classification.
- Keep the re-identification key separate from the dataset.
- Restrict access to information that allows re-identification.
- Apply appropriate technical and organisational measures to protect additional information.
- Repeat the assessment regularly, particularly after technological changes or changes in data sharing.
Do You Need to Assess the Status of Pseudonymised Data?
Correctly distinguishing between pseudonymised, anonymous and personal data can be crucial for GDPR compliance. The classification determines the obligations of both the controller and the recipient. It also matters when sharing datasets, conducting analytics or developing data and AI projects.
At Dr Joanna Maniszewska-Ejsmont Law Firm, we support organisations in assessing data status from both the sender’s and recipient’s perspective.
We help conduct identifiability assessments, evaluate re-identification risks and properly document the process. We also prepare privacy notices and documentation relating to data sharing.
If you use pseudonymisation in analytics, research or AI projects, explore our GDPR audit and compliance support services or contact us.

Contact us — we can help assess the status of your data and structure the process before further use or disclosure.
