{"id":100014,"date":"2025-09-04T12:06:38","date_gmt":"2025-09-04T11:06:38","guid":{"rendered":"https:\/\/www.ictrechtswijzer.be\/?p=100014"},"modified":"2025-09-05T08:48:41","modified_gmt":"2025-09-05T07:48:41","slug":"when-is-pseudonymized-data-still-personal-data","status":"publish","type":"post","link":"https:\/\/www.ictrechtswijzer.be\/en\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/","title":{"rendered":"When is pseudonymized data still personal data?"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Transferring data after identifying characteristics such as a name have been removed is an everyday practice. But when is this \"pseudonymized\" information still considered personal data under the <a href=\"https:\/\/www.ictrechtswijzer.be\/en\/data-protection\/\" target=\"_blank\" rel=\"noreferrer noopener\">General Data Protection Regulation (GDPR)<\/a>? In a <a href=\"https:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;docid=303863&amp;pageIndex=0&amp;doclang=NL&amp;mode=req&amp;dir=&amp;occ=first&amp;part=1&amp;cid=16611243\" target=\"_blank\" rel=\"noreferrer noopener\">judgment of 4 September 2025<\/a> (C-413\/23 P), the European Court of Justice clarified this issue. The conclusion is nuanced: although data may be anonymous to the recipient, the original party collecting the data (the controller) remains bound by the transparency obligation and must inform the data subject about the transfer.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-de-feiten-de-zaak-edps-t-srb\">The facts: the case of EDPS v. SRB<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The case revolved around the resolution of Spanish bank Banco Popular. The <a href=\"https:\/\/www.srb.europa.eu\/en\" target=\"_blank\" rel=\"noreferrer noopener\">European Single Resolution Board (SRB)<\/a>, the central resolution authority within the banking union, collected comments from shareholders and creditors in this context. To have these comments analyzed, the SRB forwarded them to the consultant Deloitte. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Crucially, the SRB had pseudonymized the data: the names of the individuals were replaced by a unique alphanumeric code. Only the SRB possessed the key to re-link this code to a specific person. Deloitte was thus unable to identify the authors.  Some shareholders filed a complaint about this with the <a href=\"https:\/\/www.edps.europa.eu\/_en\" target=\"_blank\" rel=\"noreferrer noopener\">European Data Protection Supervisor (EDPS)<\/a>, the European privacy regulator. Their argument: they were never informed that their comments would be shared with a third party such as Deloitte. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The EDPS vindicated the complainants and ruled that the SRB had violated its duty to provide information. <sup><\/sup>However, the EU General Court overturned this decision, <sup><\/sup>after which the case came before the Court of Justice. <sup><\/sup><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-de-beslissing-van-het-hof-van-justitie\">The decision of the Court of Justice<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The ECJ overturned the General Court's ruling and largely found in favor of the EDPS, albeit based on very nuanced reasoning. <sup><\/sup> The judgment falls into three key points:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>A personal opinion is personal data:<\/strong> The Court states unequivocally that personal opinions or views, as expressions of a person's thoughts, are inseparable from that person. An analysis of content, purpose or effect is not necessary to conclude that such information \"relates to\" a natural person. <\/li>\n\n\n\n<li><strong>The term \"personal data\" is relative:<\/strong> The Court confirms that pseudonymized data should not be considered personal data in all cases and for everyone.  Whether data are identifiable depends on the context and the resources available to a party. Thus, it is perfectly possible that data for the recipient (Deloitte) is not personal data, because it does not have the means to identify those involved, while the same data remains personal data for the sender (SRB). <\/li>\n\n\n\n<li><strong>The duty to disclose is assessed from the point of view of the controller:<\/strong> This is the crux of the judgment. The obligation to inform a data subject (including about the recipients of his data) arises at the time of data collection.  To assess whether this duty has been met, one must place oneself in the perspective of the data controller (the SRB) at that time. Since the SRB could trace the data back to the individuals, they were personal data for the SRB. Thus, the SRB should have informed the data subjects of the potential transfer to Deloitte, regardless of whether or not the data were identifiable to Deloitte. <\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-juridische-analyse-en-duiding\">Legal analysis and interpretation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This ruling brings clarity to a long-running debate involving two opposing views of the concept of personal data: the <strong>absolute<\/strong> and <strong>relative approach<\/strong>. According to the absolute view, data remain personal data as long as re-identification is theoretically possible, regardless of who holds the data. In contrast, the relative or contextual approach holds that qualification depends on the specific party holding the data and their reasonable ability to identify the person.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this judgment, the Court of Justice unequivocally opts for the <strong>relative or contextual approach<\/strong>, which was already initiated in the <a href=\"https:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;docid=184668&amp;pageIndex=0&amp;doclang=NL&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=541857\"><em>Breyer<\/em>-ruling<\/a>. Data are not personal data in the abstract; their qualification depends on whether a specific party (the holder or recipient) has means by which they can reasonably be expected to identify a person. The Court clearly states that \"...<em>pseudonymised data must not be regarded as constituting, in all cases and for every person, personal data ...<\/em>\".  The Court thus goes directly against this, which is a major victory for data-driven sectors such as scientific research and AI development<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the same time, the Court places a fundamental caveat here. The principles of transparency and accountability of the original data controller weigh more heavily at the time of data collection. The obligation under Article 15 of <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2018\/1725\/oj\" target=\"_blank\" rel=\"noreferrer noopener\">Regulation 2018\/1725<\/a> (the equivalent of Articles 13 and 14 GDPR) is precisely to enable the data subject to make an informed decision on whether or not to provide his data. The Court therefore held that identifiability for this particular obligation must be assessed from the point of view of the controller at the time of collection. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thus, the Court's reasoning is twofold: the concept is relative, but the obligations of the controller are not. The controller cannot hide behind the technical measures of pseudonymization to circumvent its own basic transparency obligations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-wat-dit-concreet-betekent\">What this specifically means<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>For the controller (your organization):<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>Transparency is crucial:<\/strong> Even if you pseudonymize data for transfer, you must inform data subjects (customers, employees, etc.) from the outset about the categories of recipients with whom the data may be shared. Your data protection statement should explicitly state this.<\/li>\n\n\n\n<li><strong>You remain responsible:<\/strong> The fact that the recipient cannot trace the data does not relieve you of your duties under the GDPR for the data that you keep yourself. For you, it remains personal data.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>For the recipient of the data (e.g., a consultant, researcher):<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>Analyze your position:<\/strong> If you receive pseudonymized data and you have no contractually and technically reasonable ability to identify the individuals, you may not be processing personal data.<\/li>\n\n\n\n<li><strong>Avoid re-identification:<\/strong> You must make every effort to avoid re-identification. Combining the received data set with other information you have at your disposal may still make the data personal data to you.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>For the data subject (the citizen):<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>Enhanced right to information:<\/strong> This ruling confirms your right to know in advance who will potentially receive your data, even if your name is removed. An organization may not simply pass on your opinions or feedback without informing you.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-faq-veelgestelde-vragen\">FAQ (frequently asked questions)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What is the difference between pseudonymization and anonymization?<\/strong> <br>Pseudonymization replaces identifiable data with a pseudonym (e.g., a code). Re-identification remains possible with additional information (the \"key\"). Anonymization involves processing the data in such a way that the person is irrevocably no longer identifiable.  Anonymous data falls outside the GDPR, pseudonymized data in principle does not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Is a personal opinion always personal data?<\/strong> <br>Yes. The Court of Justice confirms that an opinion or point of view is inseparable from the person expressing it. Once the author of the opinion is identifiable (even if only to the party collecting the opinion), the opinion itself is considered personal data. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Can I pass on pseudonymized data now?<\/strong> <br>Yes, but you have to do this in a transparent way. The crux of the ruling is not that the transfer is prohibited, but that the SRB should have informed data subjects about it in advance in its data protection statement. So make sure your data protection policy clearly states the types of third parties to which you can transfer data (even pseudonymized).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Does it matter if the recipient of the data is a \"processor\"?<\/strong> <br>Yes, that is an essential distinction that this ruling leaves open. The ruling concerned a recipient who was considered a separate \"data controller. If the recipient is a 'processor' acting purely on the instructions of the controller, it is generally considered to be the controller's extension. In that case, the data remain within the control of the controller and are treated as personal data throughout the chain.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-conclusie\">Conclusion <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The EDPS v. SRB ruling brings much-needed nuance to the debate on pseudonymization. It affirms the contextual nature of the concept of personal data, which leaves room for innovation and data sharing. At the same time, it draws a clear red line: the fundamental duty of transparency of the data controller is absolute and cannot be eroded by technical artifice. For organizations, the message is clear: be clear from the start about what you do with data, even if you later pass it on pseudonymized.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\">Are you facing a complex data protection or data transfer case? Our attorneys specializing in privacy and data protection law are ready to analyze your case. Feel free to contact us for an initial consultation.<\/a><\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>","protected":false},"excerpt":{"rendered":"<p>Het doorgeven van data nadat identificerende kenmerken zoals een naam zijn verwijderd, is een dagelijkse praktijk. Maar wanneer wordt deze &#8216;gepseudonimiseerde&#8217; informatie nog steeds beschouwd als een persoonsgegeven onder de Algemene Verordening Gegevensbescherming (AVG)? In een arrest van 4 september 2025 (C-413\/23 P) heeft het Europees Hof van Justitie hierover duidelijkheid geschept. De conclusie is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":100015,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[61],"tags":[],"class_list":["post-100014","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-gdpr"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Wanneer is gepseudonimiseerde data nog steeds een persoonsgegeven? - ICT Rechtswijzer Advocaat<\/title>\n<meta name=\"description\" content=\"Mag u gepseudonimiseerde data doorgeven? Het hof van Justitie stelt dat het afhangt van de context, maar uw transparantieplicht als verwerkingsverantwoordelijke absoluut is.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ictrechtswijzer.be\/en\/when-is-pseudonymized-data-still-personal-data\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Wanneer is gepseudonimiseerde data nog steeds een persoonsgegeven?\" \/>\n<meta property=\"og:description\" content=\"Mag u gepseudonimiseerde data doorgeven? Het hof van Justitie stelt dat het afhangt van de context, maar uw transparantieplicht als verwerkingsverantwoordelijke absoluut is.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ictrechtswijzer.be\/en\/when-is-pseudonymized-data-still-personal-data\/\" \/>\n<meta property=\"og:site_name\" content=\"ICT Rechtswijzer Advocaat\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-04T11:06:38+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-09-05T07:48:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/09\/skyscraper-5489696_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Joris Deene\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Joris Deene\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\\\/\"},\"author\":{\"name\":\"Joris Deene\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/person\\\/29025dc007e8d33a89422580a534d685\"},\"headline\":\"Wanneer is gepseudonimiseerde data nog steeds een persoonsgegeven?\",\"datePublished\":\"2025-09-04T11:06:38+00:00\",\"dateModified\":\"2025-09-05T07:48:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\\\/\"},\"wordCount\":1412,\"publisher\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/skyscraper-5489696_1280.jpg\",\"articleSection\":[\"GDPR - AVG\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\\\/\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\\\/\",\"name\":\"Wanneer is gepseudonimiseerde data nog steeds een persoonsgegeven? - ICT Rechtswijzer Advocaat\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/skyscraper-5489696_1280.jpg\",\"datePublished\":\"2025-09-04T11:06:38+00:00\",\"dateModified\":\"2025-09-05T07:48:41+00:00\",\"description\":\"Mag u gepseudonimiseerde data doorgeven? Het hof van Justitie stelt dat het afhangt van de context, maar uw transparantieplicht als verwerkingsverantwoordelijke absoluut is.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/skyscraper-5489696_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/skyscraper-5489696_1280.jpg\",\"width\":1280,\"height\":853},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wanneer is gepseudonimiseerde data nog steeds een persoonsgegeven?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#website\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/\",\"name\":\"ICT Rechtswijzer Advocaat\",\"description\":\"Advocaten in IP, AI, IT, privacy &amp; media\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Organization\",\"LegalService\"],\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#organization\",\"name\":\"ICT Rechtswijzer\",\"alternateName\":\"ICT Rechtswijzer, kennisplatform van Everest Advocaten\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg\",\"width\":638,\"height\":479,\"caption\":\"ICT Rechtswijzer\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/be.linkedin.com\\\/company\\\/everest-law\",\"https:\\\/\\\/www.everest-law.eu\\\/\"],\"description\":\"Kennisplatform van het departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht van Everest Advocaten, onder leiding van mr. Joris Deene.\",\"parentOrganization\":{\"@type\":\"LegalService\",\"name\":\"Everest Advocaten\",\"url\":\"https:\\\/\\\/www.everest-law.eu\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"Bollebergen 2A bus 20\",\"postalCode\":\"9052\",\"addressLocality\":\"Gent\",\"addressCountry\":\"BE\"}}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/person\\\/29025dc007e8d33a89422580a534d685\",\"name\":\"Joris Deene\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g\",\"caption\":\"Joris Deene\"},\"description\":\"Mr. Joris Deene is advocaat-partner bij Everest Advocaten en leidt het departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht. ICT Rechtswijzer is het kennisplatform van dat departement. Joris publiceert en doceert over auteursrecht, merkenrecht, softwarerecht, de AVG, de AI-Act, de DSA en het mediarecht.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/joris-deene-5144096\\\/\"],\"honorificPrefix\":\"Mr.\",\"knowsAbout\":[\"intellectuele eigendom\",\"auteursrecht\",\"merkenrecht\",\"IT-recht\",\"AI-recht\",\"gegevensbescherming\",\"AVG\",\"mediarecht\",\"digitaledienstenverordening\",\"AI-verordening\"],\"knowsLanguage\":[\"Nederlands\",\"Engels\",\"Frans\"],\"jobTitle\":\"Advocaat-partner, hoofd departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht\",\"worksFor\":\"Everest Advocaten\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/en\\\/author\\\/joris-deene\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"When is pseudonymized data still personal data? - ICT Legal Guide Lawyer","description":"Can you transmit pseudonymized data? The court says it depends on the context, but your duty of transparency as a data controller is absolute.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ictrechtswijzer.be\/en\/when-is-pseudonymized-data-still-personal-data\/","og_locale":"en_US","og_type":"article","og_title":"Wanneer is gepseudonimiseerde data nog steeds een persoonsgegeven?","og_description":"Mag u gepseudonimiseerde data doorgeven? Het hof van Justitie stelt dat het afhangt van de context, maar uw transparantieplicht als verwerkingsverantwoordelijke absoluut is.","og_url":"https:\/\/www.ictrechtswijzer.be\/en\/when-is-pseudonymized-data-still-personal-data\/","og_site_name":"ICT Rechtswijzer Advocaat","article_published_time":"2025-09-04T11:06:38+00:00","article_modified_time":"2025-09-05T07:48:41+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/09\/skyscraper-5489696_1280.jpg","type":"image\/jpeg"}],"author":"Joris Deene","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Joris Deene","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ictrechtswijzer.be\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/#article","isPartOf":{"@id":"https:\/\/www.ictrechtswijzer.be\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/"},"author":{"name":"Joris Deene","@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/person\/29025dc007e8d33a89422580a534d685"},"headline":"Wanneer is gepseudonimiseerde data nog steeds een persoonsgegeven?","datePublished":"2025-09-04T11:06:38+00:00","dateModified":"2025-09-05T07:48:41+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ictrechtswijzer.be\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/"},"wordCount":1412,"publisher":{"@id":"https:\/\/www.ictrechtswijzer.be\/#organization"},"image":{"@id":"https:\/\/www.ictrechtswijzer.be\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/09\/skyscraper-5489696_1280.jpg","articleSection":["GDPR - AVG"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.ictrechtswijzer.be\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/","url":"https:\/\/www.ictrechtswijzer.be\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/","name":"When is pseudonymized data still personal data? - ICT Legal Guide Lawyer","isPartOf":{"@id":"https:\/\/www.ictrechtswijzer.be\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.ictrechtswijzer.be\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/#primaryimage"},"image":{"@id":"https:\/\/www.ictrechtswijzer.be\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/09\/skyscraper-5489696_1280.jpg","datePublished":"2025-09-04T11:06:38+00:00","dateModified":"2025-09-05T07:48:41+00:00","description":"Can you transmit pseudonymized data? The court says it depends on the context, but your duty of transparency as a data controller is absolute.","breadcrumb":{"@id":"https:\/\/www.ictrechtswijzer.be\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ictrechtswijzer.be\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ictrechtswijzer.be\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/#primaryimage","url":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/09\/skyscraper-5489696_1280.jpg","contentUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/09\/skyscraper-5489696_1280.jpg","width":1280,"height":853},{"@type":"BreadcrumbList","@id":"https:\/\/www.ictrechtswijzer.be\/wanneer-is-gepseudonimiseerde-data-nog-steeds-een-persoonsgegeven\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ictrechtswijzer.be\/"},{"@type":"ListItem","position":2,"name":"Wanneer is gepseudonimiseerde data nog steeds een persoonsgegeven?"}]},{"@type":"WebSite","@id":"https:\/\/www.ictrechtswijzer.be\/#website","url":"https:\/\/www.ictrechtswijzer.be\/","name":"ICT Lawyer","description":"Lawyers in IP, AI, IT, privacy &amp; media","publisher":{"@id":"https:\/\/www.ictrechtswijzer.be\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ictrechtswijzer.be\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Organization","LegalService"],"@id":"https:\/\/www.ictrechtswijzer.be\/#organization","name":"ICT Legal Guide","alternateName":"ICT Rechtswijzer, kennisplatform van Everest Advocaten","url":"https:\/\/www.ictrechtswijzer.be\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/logo\/image\/","url":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2018\/08\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg","contentUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2018\/08\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg","width":638,"height":479,"caption":"ICT Rechtswijzer"},"image":{"@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/be.linkedin.com\/company\/everest-law","https:\/\/www.everest-law.eu\/"],"description":"Knowledge platform of the Intellectual Property, IT Law, AI Law, Data Protection, and Media Law department at Everest Advocaten, led by Joris Deene, Esq.","parentOrganization":{"@type":"LegalService","name":"Everest Advocaten","url":"https:\/\/www.everest-law.eu","address":{"@type":"PostalAddress","streetAddress":"Bollebergen 2A bus 20","postalCode":"9052","addressLocality":"Gent","addressCountry":"BE"}}},{"@type":"Person","@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/person\/29025dc007e8d33a89422580a534d685","name":"Joris Deene","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g","caption":"Joris Deene"},"description":"Mr. Joris Deene is a partner at Everest Attorneys and heads the department of intellectual property, IT law, AI law, data protection, and media law. ICT Legal Guide is that department\u2019s knowledge platform. Joris publishes and teaches on copyright law, trademark law, software law, the GDPR, the AI Act, the DSA, and media law.","sameAs":["https:\/\/www.linkedin.com\/in\/joris-deene-5144096\/"],"honorificPrefix":"Mr.","knowsAbout":["intellectuele eigendom","auteursrecht","merkenrecht","IT-recht","AI-recht","gegevensbescherming","AVG","mediarecht","digitaledienstenverordening","AI-verordening"],"knowsLanguage":["Nederlands","Engels","Frans"],"jobTitle":"Advocaat-partner, hoofd departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht","worksFor":"Everest Advocaten","url":"https:\/\/www.ictrechtswijzer.be\/en\/author\/joris-deene\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/posts\/100014","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/comments?post=100014"}],"version-history":[{"count":0,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/posts\/100014\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/media\/100015"}],"wp:attachment":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/media?parent=100014"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/categories?post=100014"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/tags?post=100014"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}