Ruling
EDPS v SRB: pseudonymised data are not always personal data for everyone, but the information duty applies from collection
- Date
- Status
- final
- Body
- Hof van Justitie van de EU (Eerste kamer), Europese Toezichthouder voor gegevensbescherming (EDPS) tegen Gemeenschappelijke Afwikkelingsraad (SRB)
- Reference
- C-413/23 P, ECLI:EU:C:2025:645
What it is about
Question: were the pseudonymised shareholder comments the SRB passed to Deloitte personal data, and from whose perspective must identifiability be assessed? Ruling: the General Court wrongly required the EDPS to examine the content, purpose or effect of opinions; a personal opinion is by nature closely linked to its author. Pseudonymised data may be non-personal for a recipient without the key, but only where the technical and organisational measures actually prevent that recipient from identifying data subjects; if the recipient has reasonable means to identify them, for example by cross-checking with other data, they remain personal data. The controller's duty to inform about recipients is assessed at the time of collection and from the controller's own perspective, regardless of whether the data remain personal data for the recipient after pseudonymisation. The General Court's judgment is set aside and Case T-557/20 is referred back to the General Court.
What this means in practice
Pseudonymisation can genuinely change the position of a recipient such as a research firm or analytics vendor, but it does not relieve you as controller of the information duty: you must inform data subjects at collection about transfers to such recipients. Assess per recipient whether re-identification by reasonable means is possible and record it. This judgment interprets Regulation 2018/1725 for EU institutions, but the definitions and the information duty mirror the GDPR (Article 4 and Article 13(1)(e)).
The GDPR articles concerned
Source: EUR-Lex, arrest C-413/23 Pchecked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
- Article 3 AI Act: Definitions
- Article 5 AI Act: Prohibited AI practices
- Article 6 AI Act: Classification rules for high-risk AI systems
- Article 14 AI Act: Human oversight
- Article 16 AI Act: Obligations of providers of high-risk AI systems
- Article 25 AI Act: Responsibilities along the AI value chain
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
- Article 50 AI Act: Transparency obligations for providers and deployers of certain AI systems
- Article 86 AI Act: Right to explanation of individual decision-making
Case law8 of 10
- SCHUFA: a credit score on which third parties draw strongly is automated decision-making
2023-12-07 · final, Hof van Justitie van de EU (Eerste kamer), OQ tegen Land Hessen, met SCHUFA Holding AG als interveniënt
- IAB Europe: the TC String is personal data and the industry body is a joint controller
2024-03-07 · final, Hof van Justitie van de EU (Vierde kamer), IAB Europe tegen Gegevensbeschermingsautoriteit (België)
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland
- Overijssel District Court revokes DPA fine for wifi tracking in Enschede
2024-02-02 · final, Rechtbank Overijssel
- Deutsche Wohnen: a fine on a legal person needs no identified natural person, but does require fault
2023-12-05 · final, Hof van Justitie van de EU (Grote kamer), Deutsche Wohnen SE tegen Staatsanwaltschaft Berlin
- Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
2024-05-31 · status not established, Rechtbank Den Haag, voorzieningenrechter (kort geding, team handel)
- Lindenapotheke: competitors may sue over GDPR breaches and pharmacy order data are health data
2024-10-04 · final, Hof van Justitie van de EU (Grote kamer), ND tegen DR (twee Duitse apothekers)
Guidelines8 of 12
- Guidelines on transparency under Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR (legitimate interest)
2024-10-08 · adopted, European Data Protection Board (EDPB)
- Guidelines 02/2026 on Anonymisation
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
2021-07-07 · final, European Data Protection Board (EDPB)
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 05/2020 on consent under Regulation 2016/679
2020-05-04 · final, European Data Protection Board (EDPB)
Enforcement and fines
- Dutch DPA fines Uber 824.99 million euros for automated driver deactivation
2026-08-21 · under appeal, Autoriteit Persoonsgegevens
- 10 million euro fine for Uber over unclear retention and transfer information, objection rejected
2023-12-11 · under appeal, Autoriteit Persoonsgegevens
- Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
2025-10-16 · final, Autoriteit Persoonsgegevens
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
- Netflix fined 4.75 million euros for failing to properly inform customers
2024-11-26 · under appeal, Autoriteit Persoonsgegevens
- Clearview AI: 30.5 million euro fine and penalty orders for illegal facial database
2024-05-16 · final, Autoriteit Persoonsgegevens
Legislation in motion6 of 9
- Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: no information duty in clear, non data-intensive relationships (Article 13(4) GDPR)
2025-11-19 · proposal, Europese Commissie
- Proposal: relative definition of personal data (Article 4(1) GDPR)
2025-11-19 · proposal, Europese Commissie
- European Parliament: joint ITRE-LIBE draft report, amendments tabled, no committee vote yet
2026-06-22 · under negotiation, Europees Parlement, commissies ITRE en LIBE (gezamenlijke commissie)
- Proposal: implementing acts on when pseudonymised data ceases to be personal data (new Article 41a GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap