In its judgment of 4 September 2025 (C-413/23 P), the EU Court of Justice has ruled on the interpretation of ‘personal data’ once pseudonymised and the related information obligations under Regulation (EU) 2018/1725 (the ‘EU Data Protection Regulation’). The Court clarified that, although pseudonymised data does not necessarily qualify as personal data for every recipient, this does not relieve the controller of its initial transparency obligation towards data subjects.
Facts of the case
The case concerns a dispute that arose following the resolution of Banco Popular Español by the Single Resolution Board (‘SRB’), an EU agency ensuring the orderly resolution of failing banks. The SRB asked Deloitte to assist in its evaluation of the comments submitted by the relevant shareholders and creditors exercising their right to be heard in the context of the resolution proceedings. The SRB (original controller) pseudonymised the comments before sending them to Deloitte (the recipient), so that only the SRB held the additional information (the key) to re-identify the authors of the comments.
Several affected shareholders and creditors submitted complaints to the European Data Protection Supervisor (‘EDPS’), claiming that the SRB’s privacy statement had not informed them that their data would be transmitted to Deloitte. The EDPS upheld the complaints, holding that the SRB had failed to comply with its information obligation under the EU Data Protection Regulation. Following an action for annulment lodged by the SRB, the General Court annulled that decision, after which the case was brought before the EU Court of Justice by the EDPS.
Findings of the Court of Justice
The core of the legal dispute is whether pseudonymised data (transferred by an EU authority to an external service provider) qualify as ‘personal data’, and whether the related information obligations apply.
With regard to the qualification as personal data
The Court first notes that the definition of the concept of ‘personal data’ set out in the EU Data Protection Regulation is essentially identical to that in the GDPR.
First, to qualify as personal data, it must concern information that ‘relates to’ a natural person. The General Court had held that the EDPS could not classify the comments of the shareholders as personal data solely on the basis of the finding that they were personal opinions or views, but that it should also have examined the content, purpose, and effect of those comments, in order to determine whether they were linked to a particular person. The Court rejects this reasoning, as it finds that personal opinions express a person’s thinking and as such ‘are necessarily closely linked to that person’.
The second condition is that the natural person concerned is ‘identified or identifiable’.
This can be seen as the central point of the judgment. Building upon its previous case law, the Court of Justice confirms that, contrary to what the EDPS maintained, pseudonymised data must not be regarded as constituting, in all cases and for every person, personal data, because pseudonymisation may effectively prevent persons other than the controller from identifying the data subject concerned. For those persons, the data subject is not or is no longer identifiable.
With regard to the information obligations
Article 15 of the EU Data Protection Regulation determines the information which the controller must provide to the data subject, which includes information relating to the potential recipients of the personal data. The purposes of this obligation is to enable that data subject to decide whether or not to provide the personal data being collected from him or her.
In this regard, the Court clarifies that, for the purposes of applying the obligation to provide information, the identifiable nature of the data subject must be assessed (i) at the time of data collection and (ii) from the perspective of the controller, and not from the recipient’s point of view as the General Court decided. The question whether the controller has met its obligation to provide information cannot depend on possibilities of identifying the data subject, which may, where appropriate, be open to any recipient after a subsequent transfer of the data in question.
Therefore, the Court finds that SRB’s obligation to provide information was applicable prior to the transfer of the data to Deloitte, and irrespective of whether or not those pseudonymised data were identifiable for Deloitte.
Final remarks
As said, the Court’s findings in SRB v. EDPS also apply to the processing of personal data under the GDPR. The Court clearly opts for the relative interpretation of personal data, confirming that pseudonymised data is considered personal data only for those who can reasonably identify the data subjects. Moreover, the duty of transparency and responsibility is strengthened, as controllers cannot avoid their information obligations by claiming that the data is no longer personal after the transfer. In practice, this implies that data protection notices should be precisely adapted to explicitly cover pseudonymised data flows and name recipients.
The decision is also relevant in areas such as AI model training or big data analytics. On the one hand, when pseudonymised data is passed on to such third parties, transparency obligations must be strictly observed. On the other hand, the relative nature of personal data can facilitate the use of certain data for AI training purposes.