Skip to main content
seudonimizacion

Pseudonymization and personal data

Anonymization and pseudonymization are two security measures (covered in Article 32.1 of the GDPR) that can lead to confusion.

What is pseudonymization?

Pseudonymized information is a set of data that cannot be attributed to an interested party without using additional information.

It requires that such additional information be provided separately and, furthermore, be subject to technical and organizational measures designed to ensure that personal data are not attributed to an identified or identifiable natural person (Art. 4.5 of the GDPR).

The pseudonymization process generates two new data sets: the pseudonymized information and the additional information that allows the pseudonymization to be reversed.

The pseudonymized dataset, and the additional information linked to said dataset, are within the scope of the GDPR, as well as the processing that generates them.

The processing of pseudonymized data is considered the processing of personal data; since the person can still be identified using additional information that is kept separately.

What is anonymization?

Anonymous information, as we explained in a previous post, is a set of data that is not related to an identified or identifiable natural person (Recital 26 of the GDPR).

The anonymized data set is not within the scope of the GDPR (Recital 26 of the GDPR); although it may fall within the scope of other regulations (e.g., national security, public health, critical infrastructure, etc.).

Main differences between anonymization and pseudonymization

Anonymization:

  • Process: Irreversible removal of direct identifiers and the ability to link data to a person.
  • Reversibility: Not reversible.
  • Regulatory application: Not subject to the GDPR, as the data cannot be attributed to an individual.

Pseudonymization:

  • Process: Replacement of direct identifiers with a pseudonym or code, while maintaining the ability to re-identify with a separate key.
  • Reversibility: Reversible if additional (key) information is available.
  • Regulatory application: Subject to GDPR, as re-identification is possible.

Is pseudonymized data personal data?

Last September, the Court of Justice of the European Union (CJEU) ruled a key Judgment to pseudonymization.

In that Judgment, the CJEU establishes that pseudonymized data is not automatically anonymous; it remains personal data if there is a possibility of re-identification, by the Data Controller or by third parties, with additional information

Therefore, pseudonymized data can be:

  • Personal: For whom it can be re-identified (since it is not entirely and irrevocably anonymized).
  • Non-personal: For those who cannot, without disproportionate effort, link that data to a natural person.

The wording of the ruling has given rise to different perspectives on what should be considered personal data. Thus, two different views on this concept have emerged:

  • The absolute doctrine: It considers as personal data any information that, directly or indirectly, could be associated with a natural person, however remote or improbable this link may be (Art. 4.1 of the GDPR).
  • The subjective doctrine: Data will only be personal for someone who has reasonable means of linking this data to an individual.

Through this Judgment, the CJEU reaffirms the subjective doctrine and, at the same time, declares that pseudonymized data processed by a Data Controller may be personal data for him and not be so for a transferee, in case the latter cannot (reasonably) carry out a re-identification of the data.

Practical implications of the ruling on data protection

In cases where the pseudonymized data can be re-identified and is therefore considered personal data, the Data Controller must comply with the following obligations:

  • Legal basis (Art. 6 of the GDPR): There must be a sufficient legal basis for the transfer of data to a third party.
  • Inform the data subject about the processing (Articles 13 and 14 of the GDPR): Data subjects must be informed about transfers to recipients who will receive their personal data and, at the same time, data subjects must be informed about transferees who will not be able to link the pseudonymized data with the data subjects.
  • The assignee could be considered the Controller: The assignee could be considered the Controller of the processing if it can, reasonably, re-identify the interested party.

Conversely: if pseudonymized data does not allow the data controller to re-identify the subject, it could be considered non-personal data, and therefore the GDPR would not apply.

That said, you should be aware that the GDPR still considers pseudonymized data as personal data, and that when in doubt, it is always advisable to prioritize the data subject’s rights as much as possible.

Author: Sandra Santiago, Lawyer.

If you need help writing Data Protection regulations, contact us!


    Information on data protection

    Company name
    LEGAL IT GLOBAL 2017, SLP
    Purpose
    Providing the service.
    Sending the newsletter.
    Legal basis
    Compliance with the service provision.
    Consent.
    Recipients
    Your data will not be shared with any third party, except service providers with which we have signed a valid service agreement.

    Rights
    You may access, rectify or delete your data and exercise the rights indicated in our Privacy Policy.

    Further information
    See the Privacy Policy.

    Do you want to stay up to date on all legal news?

    Subscribe to our newsletter for news, articles, and events.


    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.