Legislation in motion
Proposal: relative definition of personal data (Article 4(1) GDPR)
- Date
- Status
- proposal
- Body
- Europese Commissie
- Reference
- COM(2025) 837 final, artikel 3, punt 1, onder a (wijziging artikel 4, punt 1 AVG); 2025/0360(COD); ST 15698/25
What it is about
The proposal adds sentences to the definition of personal data. Information relating to a person is not necessarily personal data for every entity merely because another entity can identify that person. Information is not personal for an entity that cannot identify the person using means reasonably likely to be used by that entity, even if a later recipient has such means. In Joint Opinion 2/2026 of 10 February 2026 the EDPB and EDPS strongly urge the co-legislators not to adopt this change.
What this means in practice
If adopted, whether pseudonymised data counts as personal data for you would depend on your own means of identification. This may reduce the burden for recipients of pseudonymised datasets, but you would need to document which means you could reasonably use. This is still a proposal; nothing changes today.
The GDPR articles concerned
Source: Raad van de EU, register (COM(2025) 837 final als ST 15698/25)checked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Part of the file
Themes where this returns
The counterpart in the other law
- Article 3 AI Act: Definitions
- Article 5 AI Act: Prohibited AI practices
- Article 6 AI Act: Classification rules for high-risk AI systems
- Article 16 AI Act: Obligations of providers of high-risk AI systems
- Article 25 AI Act: Responsibilities along the AI value chain
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
- Article 50 AI Act: Transparency obligations for providers and deployers of certain AI systems
Case law8 of 9
- IAB Europe: the TC String is personal data and the industry body is a joint controller
2024-03-07 · final, Hof van Justitie van de EU (Vierde kamer), IAB Europe tegen Gegevensbeschermingsautoriteit (België)
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- EDPS v SRB: pseudonymised data are not always personal data for everyone, but the information duty applies from collection
2025-09-04 · final, Hof van Justitie van de EU (Eerste kamer), Europese Toezichthouder voor gegevensbescherming (EDPS) tegen Gemeenschappelijke Afwikkelingsraad (SRB)
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland
- Overijssel District Court revokes DPA fine for wifi tracking in Enschede
2024-02-02 · final, Rechtbank Overijssel
- Deutsche Wohnen: a fine on a legal person needs no identified natural person, but does require fault
2023-12-05 · final, Hof van Justitie van de EU (Grote kamer), Deutsche Wohnen SE tegen Staatsanwaltschaft Berlin
- Lindenapotheke: competitors may sue over GDPR breaches and pharmacy order data are health data
2024-10-04 · final, Hof van Justitie van de EU (Grote kamer), ND tegen DR (twee Duitse apothekers)
- Meta v Bundeskartellamt: competition authority may find a GDPR breach, strict conditions for legal bases behind personalised advertising
2023-07-04 · final, Hof van Justitie van de EU (Grote kamer), Meta Platforms Inc., Meta Platforms Ireland Ltd en Facebook Deutschland GmbH tegen Bundeskartellamt
Guidelines8 of 10
- Guidelines 02/2026 on Anonymisation
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
2021-07-07 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines 05/2020 on consent under Regulation 2016/679
2020-05-04 · final, European Data Protection Board (EDPB)
- Guidelines 01/2025 on Pseudonymisation
2025-01-16 · adopted, European Data Protection Board (EDPB)
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
Enforcement and fines
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
Legislation in motion6 of 17
- European Parliament: joint ITRE-LIBE draft report, amendments tabled, no committee vote yet
2026-06-22 · under negotiation, Europees Parlement, commissies ITRE en LIBE (gezamenlijke commissie)
- Proposal: implementing acts on when pseudonymised data ceases to be personal data (new Article 41a GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- Proposal: cookie rules move from ePrivacy to the GDPR, with new exceptions and a six-month rule (new Article 88a GDPR and Article 5(3) ePrivacy)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)
2025-11-19 · under negotiation, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper