[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcDGJYN39nxK0goO20EGd9ww_SE1jipDJ2O-CEks3Cho":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"45d3b8fc-2123-43e2-b6a3-a870f75ccf99","pseudonymized-health-data-still-counts-as-personal-data-under-gdpr","5693b39b-2780-4d3e-94b8-0a8f6ba8456b","Pseudonymized Health Data Still Counts as Personal Data Under GDPR","Czech courts, including the Supreme Administrative Court, ruled that pseudonymized health data remains personal data under GDPR when re-identification is reasonably possible using available information. The company's belief that random identifiers constituted sufficient anonymization was legally flawed — courts found that combining gender, birth year, diagnoses, and treatment details creates a fingerprint that modern technical means can exploit. This aligns with the CJEU's Breyer ruling, which established that data is personal if any party could plausibly re-identify an individual, not just the data holder. Organizations handling health data must understand that pseudonymization is a risk-reduction measure, not a legal safe harbor equivalent to true anonymization. Misclassifying personal data as anonymous can expose organizations to significant regulatory penalties and erode patient trust.","**Immediate actions:**\n- Commission a formal re-identification risk assessment on all datasets currently classified as pseudonymized or anonymous.\n- Apply GDPR obligations (lawful basis, data subject rights, breach notification) to any dataset where re-identification cannot be ruled out with high confidence.\n\n**Long-term improvements:**\n- Implement true anonymization techniques (k-anonymity, differential privacy, data aggregation) where legally and operationally feasible, and document the methodology.\n- Establish a Data Protection Impact Assessment (DPIA) process specifically for health data processing activities involving pseudonymization.\n- Train data governance, legal, and IT teams on the legal distinction between pseudonymization and anonymization under GDPR and relevant case law.\n\n**Detection & compliance measures:**\n- Maintain a Records of Processing Activities (RoPA) entry that accurately reflects the re-identification risk level for each health dataset.\n- Periodically re-evaluate anonymization claims as new re-identification techniques and auxiliary datasets emerge.\n- Engage your Data Protection Officer (DPO) to review data classification decisions before sharing or processing health datasets externally.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 4(1) — Definition of Personal Data","GDPR Article 4(5) — Definition of Pseudonymisation","GDPR Recital 26 — Principles of Anonymisation","GDPR Article 35 — Data Protection Impact Assessment","CJEU Case C-582\u002F14 (Breyer v Germany)","NIST SP 800-188 — De-Identification of Government Datasets","NIST Privacy Framework PR.DS-P5 — Data De-identification","CIS Control 3 — Data Protection","ISO\u002FIEC 29101 — Privacy Architecture Framework","ENISA Pseudonymisation Techniques and Best Practices (2019)","published","2026-08-03T12:20:27.163002+00:00","2026-08-03T12:20:27.038+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=NSS_-_1_As_183\u002F2023-62&diff=52587&oldid=52581","nss-1-as-183-2023-62-c63964","NSS - 1 As 183\u002F2023-62",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]