NSS - 1 As 183/2023-62
Czech courts rule pseudonymized health data remains personal under GDPR.
Summary
Czech courts have upheld decisions that pseudonymized health data, even with a random identifier, is still considered personal data under GDPR. The company's appeals, including to the Supreme Administrative Court, were dismissed as the courts found that the combination of factors like gender, birth year, diagnoses, and treatment details, along with other available information, could lead to patient identification. The courts cited modern technical capabilities and the CJEU's Breyer case, emphasizing that pseudonymization is not the same as anonymization.
Full text
Help NSS - 1 As 183/2023-62: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 09:54, 3 August 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators252 editsmTag: Visual edit← Older edit Latest revision as of 11:55, 3 August 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators252 editsmTag: Visual edit (One intermediate revision by the same user not shown)Line 109: Line 109: The company lodged an administrative appeal with the Czech DPA (UOOU), which rejected it. The company lodged an administrative appeal with the Czech DPA (UOOU), which rejected it. The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4 (1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case, C-582/14, according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in Case T-557/20, SRB v. EDPS, which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety.The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4(1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case ([https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62014CJ0582 C-582/14]), according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in [https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62020TJ0557 Case T-557/20] (SRB v. EDPS), which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety. The company filed a cassation appeal with the Supreme Administrative Court, arguing that the information had been anonymised. It alleged that the addition of a random code with no independent meaning would not alter their anonymous nature. It claimed that the Municipal Court had not explained what specific additional information could be used to identify the patients and had relied on hypothetical scenarios. The company stated that it was objectively impossible to obtain such data through other requests in a detailed and non-aggregated form. It also argued that iron deficiency was not a rare disease, but was associated with a large number of patients and various conditions and that the data had undergone both randomisation and generalisation so the risk of identification was therefore low. Finally, the company emphasized that the tables without the random identifier could not be used effectively for the intended analysis. It further argued that the DPA and the Municipal Court had not adequately balanced the right of access to information against the right to the protection of personal data.The company filed a cassation appeal with the Supreme Administrative Court, arguing that the information had been anonymised. It alleged that the addition of a random code with no independent meaning would not alter their anonymous nature. It claimed that the Municipal Court had not explained what specific additional information could be used to identify the patients and had relied on hypothetical scenarios. The company stated that it was objectively impossible to obtain such data through other requests in a detailed and non-aggregated form. It also argued that iron deficiency was not a rare disease, but was associated with a large number of patients and various conditions and that the data had undergone both randomisation and generalisation so the risk of identification was therefore low. Finally, the company emphasized that the tables without the random identifier could not be used effectively for the intended analysis. It further argued that the DPA and the Municipal Court had not adequately balanced the right of access to information against the right to the protection of personal data. Line 115: Line 115: The DPA argued that the random identifier constituted personal data when considered in conjunction with the health data to which it would be linked. It stated that the concept of personal data was not limited to information that directly identifies an individual nor did it require that all necessary additional information be held by the same entity. Replacing direct identifiers with a code did not anonymise the data, but made it pseudonymised. Moreover, it argued that certain categories contained a relatively small number of records and that combining them with other data could make it possible to select and identify a specific insured person and their treatment history. It further argued that, even if identifiability was relative, it should be assessed in relation to all potential information applicants and their ability to obtain contextual information.The DPA argued that the random identifier constituted personal data when considered in conjunction with the health data to which it would be linked. It stated that the concept of personal data was not limited to information that directly identifies an individual nor did it require that all necessary additional information be held by the same entity. Replacing direct identifiers with a code did not anonymise the data, but made it pseudonymised. Moreover, it argued that certain categories contained a relatively small number of records and that combining them with other data could make it possible to select and identify a specific insured person and their treatment history. It further argued that, even if identifiability was relative, it should be assessed in relation to all potential information applicants and their ability to obtain contextual information. The Supreme Administrative Court stayed the proceedings in the case pending the CJEU’s decision in Case C-413/23 P, EDPS v. SRB. After the judgment was issued, the company argued that whether the data were pseudonymised or anonymised should be assessed in relation to the specific recipient of the data and the means that it could reasonably use. It stated that it did not have any means of re-identification and that only specific and practically available cross-referencing possibilities should be taken into account.The Supreme Administrative Court stayed the proceedings in the case pending the CJEU’s decision in Case [https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62023CJ0413 C-413/23 P