NSS - 1 As 183/2023-62
Czech court upholds refusal to disclose random identifier for health data.
Summary
The Supreme Administrative Court of the Czech Republic has ruled that a random identifier added to health datasets would allow a healthcare consultancy to link treatment records and identify patients. The court upheld the refusal to disclose this identifier, stating it would constitute pseudonymization rather than anonymization under GDPR. This decision considered modern technical capabilities and the availability of public information for re-identification.
Full text
Help NSS - 1 As 183/2023-62: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 11:25, 4 August 2026 view sourceFm (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators109 editsm Tag: Visual edit← Older edit Latest revision as of 14:20, 4 August 2026 view source Fm (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators109 editsm Tag: Visual edit Line 96: Line 96: }}}} The Supreme Administrative Court held that adding a random identifier to health datasets supplied to a healthcare consultancy would allow it to link treatment records and identify some patients. It therefore upheld the refusal to disclose the identifier.The Supreme Administrative Court held that adding a random identifier to health datasets supplied to a healthcare consultancy would allow it to link treatment records and identify some patients. It therefore upheld the refusal to disclose the identifier in a freedom of information request. == English Summary ==== English Summary == Line 107: Line 107: The public health insurer provided then the company with five separate tables regarding the diagnoses, diagnoses in conjunction with medical procedures, the DRG codes and prescribed medications. It aggregated the parameters of the provided data as follows: five-year age groups, dates were given only at the monthly level, and healthcare providers were classified into broad geographic regions. However, it refused to add a unique random identifier which would allow linking the individual records and tables pertaining to the same patient. The public health insurer considered that providing the code would result in the disclosure of special categories of personal data.The public health insurer provided then the company with five separate tables regarding the diagnoses, diagnoses in conjunction with medical procedures, the DRG codes and prescribed medications. It aggregated the parameters of the provided data as follows: five-year age groups, dates were given only at the monthly level, and healthcare providers were classified into broad geographic regions. However, it refused to add a unique random identifier which would allow linking the individual records and tables pertaining to the same patient. The public health insurer considered that providing the code would result in the disclosure of special categories of personal data. The company lodged an administrative appeal with the Czech DPA (UOOU), which rejected it. The company lodged a complaint with the Czech DPA (UOOU), which rejected it. The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4(1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case ([https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62014CJ0582 C-582/14]), according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in [https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62020TJ0557 Case T-557/20] (SRB v. EDPS), which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety.The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4(1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case ([https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62014CJ0582 C-582/14]), according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in [https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62020TJ0557 Case T-557/20] (SRB v. EDPS), which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety. Line 121: Line 121: The court relied on Case C-413/23 and noted that pseudonymised data under [[Article 4 GDPR|Article 4(5) GDPR]] does not automatically constitute personal data in relation to every person. Therefore, it examined whether the company had lawful means that could reasonably be expected to be used to identify the patients directly or indirectly. The court relied on Case C-413/23 and noted that pseudonymised data under [[Article 4 GDPR|Article 4(5) GDPR]] does not automatically constitute personal data in relation to every person. Therefore, it examined whether the company had lawful means that could reasonably be expected to be used to identify the patients directly or indirectly. The court found that the tables, without the random identifier, did not allow for the identification of specific insured individuals. It held that the requested random identifier would link the records from the different tables and allow for the aggregation of information on the diagnoses, medical procedures, hospitalizations, and medications for the same patient during the eight- year period. Certain combinations of these data, along with age group, gender, and region, could be unique and allow for the identification of patients using information from public sources. It pointed out that although iron deficiency was a very common diagnosis and some tables contained a very large number of entries, other categories were not sufficiently generalised. According to the court, in certain cases, such as rare diseases, unusual treatment combinations, or particularly young or old age, knowing even a few details about a person could make it possible to identify the corresponding record. The risk was not negligible, given that information about a person’s age, gender, hospitalization, diagnosis, or treatment could be available in the media or on social media. Consequently, the court held that adding the random identifier, in conjunction with the data already provided, would make the dataset personal data in relation to the company under [[Article 4 GDPR|Article 4(1) GDPR]], including health data falling under [[Article 9 GDPR]].The court found that the tables, without the random identifier, did not allow for the identification of specific insured individuals. It held that the requested random identifier would link the records from the different tables and allow for the aggregation of information on the diagnoses, medical procedures, hospitalizations, and medications for the same patient during the eight-year period. Certain combinations of these data, along with age group, gender, and region, could be unique and