{"id":1311,"date":"2026-03-23T13:55:43","date_gmt":"2026-03-23T13:55:43","guid":{"rendered":"https:\/\/clt.nliu.ac.in\/?p=1311"},"modified":"2026-03-24T04:58:33","modified_gmt":"2026-03-24T04:58:33","slug":"pseudonymisation-at-edge-srb-the-digital-omnibus-and-the-erosion-of-gdprs-concept-of-personal-data","status":"publish","type":"post","link":"https:\/\/clt.nliu.ac.in\/?p=1311","title":{"rendered":"Pseudonymisation at\u00a0 Edge- Srb, The Digital Omnibus and the Erosion of Gdpr\u2019s Concept Of Personal Data"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Abirami Vishwanathan is a Final Year BBA LLB (Hons.) student at School of Law, Sastra Deemed University.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The European Commission proposed the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/digital-omnibus-regulation-proposal\">Digital Omnibus<\/a> Regulation (COM(2025) 837, 19 November 2025). It amends <a href=\"https:\/\/gdpr-info.eu\/art-4-gdpr\/\">Article 4(1) GDPR<\/a>, clarifying that data relating to a natural person need not be personal data for every entity. Nor for an entity lacking reasonably likely means to identify the person. It would also insert a new Article 41a empowering the Commission, after an EDPB opinion, to adopt implementing acts specifying technical criteria for when pseudonymised data may no longer qualify as personal data for particular actors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In Recital 27 of the Omnibus, the Commission presents this amendment as a clarification and simplification. It takes into account Court of Justice case law on personal data and identifiability. The <a href=\"https:\/\/curia.europa.eu\/site\/upload\/docs\/application\/pdf\/2025-09\/cp250107en.pdf\">EDPS v Single Resolution Board<\/a> judgment (Case C-413\/23 P, EU:C:2025:645, 4 September 2025) offers a key example. Both the Court and the proposal stress that pseudonymised data is not always personal data for every person or entity.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Foundations of Personal Data and Pseudonymisation under the GDPR&nbsp;<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Article 4(1) of the GDPR defines personal data as any information relating to an identified or identifiable natural person, while <a href=\"https:\/\/gdpr-info.eu\/art-4-gdpr\/\">Article 4(5)<\/a> describes pseudonymisation as transforming personal data so that it can no longer be attributed to a specific data subject without additional, separately protected information. <a href=\"https:\/\/gdpr-info.eu\/recitals\/no-26\/\">Recital 26<\/a> adds that identifiability must be assessed by considering all means reasonably likely to be used by the controller or another person, taking into account factors such as cost, time and available technology, and clarifies that pseudonymised data remain personal data where individuals can still be identified by using that additional information. Building on this, the Court in&nbsp;<a href=\"https:\/\/curia.europa.eu\/juris\/document\/document.jsf?docid=184668&amp;doclang=EN\">Patrick Breyer v Bundesrepublik<\/a> Deutschland (Case C-582\/14, ECLI:EU:C:2016:779, 19 October 2016) (\u2018Breyer\u2019), held that dynamic IP addresses were personal data because the website operator had lawful and realistically usable routes to obtain subscriber information, and in&nbsp;EDPS v SRB&nbsp;it applied the same \u2018means reasonably likely to be used\u2019 logic to pseudonymised comments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>EDPS v SRB: Relational Personal Data &amp; Contextual Identifiability under Regulation 2018\/1725 (Homogeneous Interpretation vis-\u00e0-vis the GDPR)<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In&nbsp;EDPS v Single Resolution Board (SRB), the Court recalibrated data \u2018relating to\u2019 an individual and \u2018identifiability\u2019. Drawing on&nbsp; <a href=\"https:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;docid=208102&amp;doclang=EN\">Peter Nowak v. Data Protection Commissioner&nbsp;<\/a> (Case C\u2011434\/16, EU:C:2017:994, 20 December 2017) (\u2018Nowak\u2019), where exam scripts and examiners&#8217; comments were personal data because they conveyed candidate performance and examiner views, SRB held that shareholder\/creditor \u2018right to be heard\u2019 comments likewise constituted personal data as they expressed authors&#8217; views, requiring no separate purpose\/effects inquiry to show they \u2018relate to\u2019 the data subject. Identifiability remains independent: even where information plainly \u2018relates to\u2019 its author, it falls within the data protection regime only if the author is identified or identifiable in the processing circumstances. In SRB, the Single Resolution Board pseudonymised over a thousand stakeholder comments (replacing names with codes, retaining the key) before sending the dataset to Deloitte for analysis; the EDPS argued these remained personal data along the chain, requiring Deloitte to be named as a \u2018recipient\u2019 for transparency.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Court tied analysing identifiability to&nbsp;Breyer&nbsp;(dynamic IP addresses personal data because website operator had lawful, realistically usable routes to subscriber info from access provider) and&nbsp;<a href=\"https:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;docid=283529&amp;doclang=EN\">IAB Europe v Gegevensbeschermingsautoriteit<\/a>, (Case C-604\/22, EU:_C:2024:214, 7 March 2024) (IAB Europe) ; where Transparency and Consent string personal data as it linked to users via ecosystem identifiers even without one actor holding all pieces, establishing with SRB judgement, that identifiability depends on whether an actor has lawful, realistically usable means reasonably likely to reidentify ostensibly pseudonymous\/coded information in the concrete legal\/technical setting.\u200b<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Drawing these strands together, the CJEU in SRB rejected pseudonymised information always being personal data \u2018for every person and in all circumstances\u2019, &nbsp;holding instead that data are personal for a given actor only where that actor has \u2018means reasonably likely to be used\u2019 to reidentify in the particular factual\/legal setting. This creates a structural distinction: controller transparency obligations (assessed at collection from controller&#8217;s standpoint, SRB could not avoid naming\/describing Deloitte as recipient despite pseudonymisation plans, as that duty anchors in the original controller &amp; data subject relationship and cannot depend on later recipient side identifiability assessments) versus recipient specific status of the same dataset.\u200b<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Deloitte, the assessment is conditional: pseudonymised comments fall outside EU data protection law only if Deloitte lacks lawful, realistically usable means to lift\/circumvent protective measures and identify individuals directly or by cross-checking other data. Per&nbsp;Breyer\/IAB Europe, identifiability is not limited to holding the reidentification key but extends to routes reasonably likely to be used by Deloitte, including ecosystem cooperation\/data sharing, so the same dataset remains personal for SRB but may fall outside the personal data concept for Deloitte if those means are genuinely absent.\u200b<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Codifying SRB: The Omnibus\u2019 Actor Relative Redefinition of Identifiability in Article 4(1) and Recitals, with Scope for Technical Criteria in an Implementing Act<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The Omnibus recital (27) lifts over this relational view in tightened, actor-specific terms. The recital states that mere existence of additional information elsewhere does not make pseudonymised data personal \u2018in all cases and for every person or entity\u2019; where a particular entity lacks means reasonably likely to be used to identify the individual, the information is not personal data for that entity and it is, in principle, outside the GDPR for that dataset. Recital 27 also adds that if the same information is transmitted to a third party with realistic identification means (e.g., cross-checking other data), it becomes personal data for that third party alone, without retroactively affecting the earlier entity.\u200b<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SRB articulated this as context specific for each actor, distinguishing the Board\u2019s and Deloitte\u2019s positions in that case\u2019s factual\/legal setting; the Omnibus transforms it into a general GDPR scope rule: information is non-personal for an entity unable to realistically reidentify, with Article 41a empowering the Commission (post EDPB opinion) to set technical \u2018means and criteria\u2019 for when pseudonymised data ceases being personal for particular actors, generalising SRB\u2019s controller transparency (at collection) vs recipient out of scope distinction.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SRB articulated this as context-specific for each actor, distinguishing the Board&#8217;s and Deloitte&#8217;s positions.The Omnibus transforms it into a general GDPR scope rule: information is non-personal for entities unable to realistically reidentify.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><br>Article 41a empowers the Commission (post-EDPB opinion) to set technical &#8216;means and criteria&#8217;. This determines when pseudonymised data ceases being personal for particular actors, generalising SRB&#8217;s controller transparency (at collection) vs recipient out-of-scope distinction<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Current Recital 26 of the GDPR deems a person \u2018identifiable\u2019 via means reasonably likely for the controller or another person, keeping pseudonymised data in scope where ecosystem unlocking is possible;&nbsp;the Digital Omnibus proposal would not rewrite Recital 26 itself, but would instead introduce clarifications in new sentences added to Article 4(1) of the GDPR, read together with Recital (27) of the omnibus, stating that extra information elsewhere does not automatically make pseudonymised data personal \u2018in all cases and for every person or entity\u2019, and information is not personal for a given entity lacking its own reasonably likely means, shifting to a granular actor by actor test, where such entities fall \u2018in principle\u2019 outside the GDPR.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Fragile Chains: How the Omnibus Creates Gaps in the protection given by the GDPR through Actor-Specific Identifiability<\/strong><strong><\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">This shift is problematic not because it newly introduces actor relativity; Breyer, SRB, and related case law already assess identifiability contextually, sometimes recipient specifically; but because the Omnibus codifies that logic in the definition of Article 4(1) and Recital (27) of the GDPR foregrounding that certain recipients are \u2018in principle\u2019 out of scope for pseudonymised datasets. By focusing analysis on whether the specific entity has means reasonably likely to be used for identification, and stating such entities are in principle outside the Regulation for that dataset, the framework may ease intermediaries&#8217; arguments that they fall beyond the reach of GDPR even where ecosystem relinking and downstream identification remain realistic.\u200b<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In reality, as <a href=\"https:\/\/www.edpb.europa.eu\/system\/files\/2025-01\/edpb_guidelines_202501_pseudonymisation_en.pdf\">EDPB pseudonymisation guidance on residual reidentification<\/a> risk underlines, datasets travel through companies, link with other sources, and recombine over time into realistically identifiable profiles supporting precise targeting\/profiling, yet middle players may treat them as \u2018non-personal\u2019 and operate without full transparency duties, data subject rights, or core principles like purpose limitation\/data minimisation, despite downstream actors\/data matches making relinking realistic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Take a scenario where Gym A holds class attendance records with full member identifiers (names, IDs). It pseudonymises the data by replacing names with codes such as M\u20111, keeps the reidentification key, and sends the pseudonymised dataset to Analytics Agency B for usage pattern modelling, with B acting not as a mere processor but as an independent controller that has no contractual right to obtain the key and is subject to strict technical and contractual prohibitions on lifting the pseudonymisation. Ad Tech Company C separately holds rich app data (browsing, location, profiles) on many of the same gym members.\u200b<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Under the current GDPR understanding, the legal position can be framed as follows. For Gym A, the data are clearly personal data: A holds the key and therefore has means reasonably likely to be used to reidentify, so pseudonymisation functions as a security measure rather than anonymisation. For Agency B, the assessment focuses on whether B, as the actor in question, has reasonably likely means to obtain additional information that would enable identification; for example, lawful access routes to the key, realistic access to auxiliary datasets, or other practical mechanisms to relink the codes to individuals in the specific context, as illustrated in Breyer and in the contextual analysis endorsed in SRB and IAB Europe. For Company C, if C receives the pseudonymised dataset and can match it with its own profiles (for instance by correlating attendance times and locations with app tracking data), the combined dataset is personal data for C because C then has realistic means to single out and identify the gym members. The practical effect is that, where such realistic identification routes exist, pseudonymised data tend to remain personal data across the chain, so A, B and C all face the duties mentioned in GDPR in their respective roles, limiting protection gaps in the current framework.\u200b<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Under the Digital Omnibus model, Gym A&#8217;s position remains unchanged: A retains the key, so the dataset is personal data for A. For Agency B, Article 4(1) read with Recital (27) states pseudonymised information is not automatically personal data \u2018in all cases and for every person or entity\u2019, and is not personal data for a given entity lacking means reasonably likely to be used to identify the person; such an entity is then, in principle, outside the GDPR for that dataset. If B (independent controller) has no contractual key right, no technical route to lift measures, and no auxiliary datasets for cross-checking, B can claim the dataset non-personal for B; even though Recital (27) accepts it becomes personal for Company C (with realistic identification means, expressly including cross-checking other data). The policy concern: Omnibus increases intermediaries like B credibly claiming out of scope \u2018in principle\u2019 where their processing materially contributes to later reidentification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On that basis, the troubling gap is best illustrated where Agency B really does lack means reasonably likely to identify gym members under the Omnibus test, for example because B has no contractual entitlement to request the key from Gym A, faces strict technical separation and audited prohibitions on reidentification, and holds no auxiliary datasets that would make cross\u2011matching feasible. Even in that configuration, B\u2019s modelling and onward transfer of the pseudonymised dataset can significantly enable Company C\u2019s later reidentification and targeting once C combines the file with its own rich profile data, which Recital (27) recognises as making the information personal data for C, while B may nonetheless remain out of scope in principle for that dataset, so that an important intermediary phase of processing that is a necessary step in enabling later identification and targeting can sit outside GDPR duties and remain effectively unregulated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By artificially breaking the chain, it lets key intermediaries like Agency B slip right out from under the oversight of the GDPR, even when their analysis and passing on of pseudonymised gym data sets up Company C to reidentify and target people later. If B claims no solo reidentification power, it dodges transparency duties, data subject rights like access, erasure or objection, and core rules on purpose limitation. Gym A can&#8217;t really rein B in through contract alone; Gym A might stipulate \u2018no reidentification\u2019 or \u2018delete after analysis\u2019, but B could still quietly enrich or overshare the data without detection, forcing costly audits with remedies limited to damages, not the direct rights, fines or other rights that the GDPR guarantees. C ends up with a ready-to-use dataset, and individuals lose grip on the whole chain.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Final Implications<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The SRB judgment and Digital Omnibus proposal fundamentally recast GDPR identifiability. They shift it from a contextual, ecosystem-wide safeguard, where pseudonymised data stays protected across linked actors, to a narrow actor-specific test. This makes pseudonymisation a potential escape from the scope of GDPR for recipients without realistic reidentification means, even when downstream players can easily relink and target individuals.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unchecked, this allows pseudonymized datasets to pass through unregulated intermediaries like analytics firms. Such actors dodge transparency obligations, data subject rights (access, erasure, objection), and principles like purpose limitation and data minimization. Upstream controllers have weak contractual leverage, while the end result erodes holistic protections, individual control, and the GDPR&#8217;s core promise of effective oversight in complex data chains.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Abirami Vishwanathan is a Final Year BBA LLB (Hons.) student at School of Law, Sastra Deemed University. The European Commission proposed the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1311","post","type-post","status-publish","format-standard","hentry","category-blog-series","col-md-6 col-sm-6"],"_links":{"self":[{"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=\/wp\/v2\/posts\/1311","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1311"}],"version-history":[{"count":3,"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=\/wp\/v2\/posts\/1311\/revisions"}],"predecessor-version":[{"id":1315,"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=\/wp\/v2\/posts\/1311\/revisions\/1315"}],"wp:attachment":[{"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1311"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1311"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1311"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}