[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fP6J7HMqvz-bP8AvM3CwONP9AEzgZz-WjwJbclEvxIVk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":43},"da169437-a003-40a0-a90f-f96544218904","dutch-dpa-fine-overturned-pseudonymized-data-classification-fails-legal-test","5fda2f17-5cc5-421f-b140-1d82b424ed17","Dutch DPA Fine Overturned: Pseudonymized Data Classification Fails Legal Test","The Municipality of Enschede collected pseudonymized MAC addresses and location data for pedestrian counting without establishing a clear legal basis under GDPR, resulting in a €600,000 fine from the Dutch DPA. However, the Dutch Council of State overturned the fine because the DPA could not sufficiently demonstrate that re-identification of the pseudonymized data was realistically feasible, meaning the data did not conclusively qualify as 'personal data' under GDPR. This case highlights the critical importance of conducting thorough Data Protection Impact Assessments (DPIAs) before deploying data collection systems, even when data appears anonymized or pseudonymized. It also underscores that regulators bear a burden of proof when classifying data as personal, and that organizations must proactively document their anonymization methods and re-identification risk assessments. The case matters because it sets a precedent for how pseudonymization strength is evaluated in regulatory enforcement.","**Immediate actions:**\n- Conduct a formal Data Protection Impact Assessment (DPIA) before deploying any data collection system, even for seemingly anonymous datasets.\n- Document the technical controls and reasoning that support a classification of data as anonymous or pseudonymized rather than personal data.\n- Establish a legal basis review process requiring sign-off from a Data Protection Officer before processing begins.\n\n**Long-term improvements:**\n- Implement a data classification policy that includes re-identification risk scoring for all pseudonymized and anonymized datasets.\n- Engage legal counsel and privacy engineers jointly to evaluate whether collected data meets the GDPR threshold for 'personal data' on an ongoing basis.\n- Build a centralized data inventory (Record of Processing Activities) that tracks data types, legal bases, and pseudonymization methods used.\n\n**Detection & Governance measures:**\n- Schedule periodic audits of active data collection initiatives to verify continued compliance with the stated legal basis.\n- Establish a regulatory monitoring process to track evolving DPA guidance and court rulings on data classification and pseudonymization standards.\n- Train technical and procurement staff on the distinction between anonymization and pseudonymization and their respective GDPR implications.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 4(1) — Definition of personal data","GDPR Article 5(1)(b) — Purpose limitation","GDPR Article 6 — Lawfulness of processing","GDPR Article 25 — Data protection by design and by default","GDPR Article 35 — Data Protection Impact Assessment (DPIA)","GDPR Recital 26 — Principles of anonymization","NIST SP 800-188 — De-identification of Government Datasets","NIST Privacy Framework PR.DS-P1 — Data processing practices","ISO\u002FIEC 29101 — Privacy Architecture Framework","CIS Control 3 — Data Protection","ITIL Service Design — Information Security Management","published","2026-08-04T12:20:19.397179+00:00","2026-08-04T12:20:19.084+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=RVS_-_202401622\u002F1\u002FA3&diff=52601&oldid=52572","rvs-202401622-1-a3-e9c703","RVS - 202401622\u002F1\u002FA3",[31,37],{"id":32,"name":33,"slug":34,"description":35,"color":36},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]