News

When Is Data Really Anonymous? Lessons from EDPS v. SRB

When Is Data Really Anonymous? Lessons from EDPS v. SRB

At the beginning of the month, MyData-TRUST participated in the specialised event on anonymisation and pseudonymisation, organised by the European Data Protection Board (‘EDPB’) in light of the EDPS v. SRB judgment[1].

This recent ruling has raised significant questions for stakeholders and has prompted a reassessment of how personal data are defined and interpreted under EU data protection law. In this context, MyData-TRUST welcomes the EDPB’s initiative to engage with the professional community, listen to its concerns, and gather informed feedback.

During the event, MyData-TRUST contributed its interdisciplinary expertise, combining the perspectives of our legal and scientific teams, and highlighted key considerations specific to the Life Sciences sector. In particular, we focused on clarifying the practical impact of the judgment on the clinical trials ecosystem, where data are typically processed in coded form (e.g., with direct identifiers replaced by a code). We emphasised the sensitive nature of such data, the multiple processing activities involved, and the importance of reflecting real-world practices in regulatory guidance.

To illustrate these challenges, MyData-TRUST shared several use cases demonstrating the heightened risks associated with health data, as well as the unique characteristics and identifiability concerns linked to genetic data.

In light of these discussions, MyData-TRUST encourages the EDPB to consider the following next steps:

  1. Develop a practical methodology, in addition to guidance, to support stakeholders in applying the relative approach to personal data. This methodology should address relevant criteria to be considered, data types, technical and organisational measures, recommended frequency for reassessing identifiability risks, and documentation requirements, thereby enhancing legal certainty and accountability.
  2. Maintain and expand multi-stakeholder dialogue, both through similar consultation events and through the development of guidance and the proposed methodology.
  3. Draft, in collaboration with all relevant stakeholders, a realistic framework that enables scientific research and innovation, including AI, while taking into account the specific needs and constraints of the scientific and Life Sciences industries.
  4. Avoid an over-reliance on contractual safeguards, for preventing re-identification by data recipients. Where feasible, complementary technical and organisational safeguards that reduce risk in practice should be encouraged, rather than measures that depend solely on the recipient’s intent.
  5. Clarify controllers’ obligations and liabilities in cases involving data of a dual nature, (i.e., personal data for the sender and anonymous data for the recipient), including whether and how Chapter V of the GDPR applies in such scenarios.

The event generated a lively debate among participants, reflecting the complexity and relevance of the topics discussed. While opinions varied, there was general agreement that a case-by-case, risk-based assessment is essential, and that stakeholders require clear guidance and a practical methodology to implement anonymisation and pseudonymisation effectively.

Furthermore, it was highlighted that the EDPB’s Guidelines 01/2025 on Pseudonymisation should be reviewed in light of the EDPS v. SRB judgment, and that guidelines on anonymisation should be drafted to provide clarity and regulatory certainty, taking into account the judgment’s implications for the Life Sciences and broader sectors.

MyData-TRUST welcomes the EDPB’s ongoing engagement with the professional community and looks forward to contributing further to the development of guidance that is both practical and aligned with real-world data processing practices, particularly in the Life Sciences sector.

[1] CJEU Case C-413/23 P, EDPS v SRB, 4 September 2025.