Pseudonymisation and the GDPR: the Advocate General's ground-breaking opinion in EDPS v. SRB (C-413/23 P)
GA Spielman stated in his opinion that the European Data Protection Supervisor (EDPS) should not automatically consider pseudonymised data as personal data, but should examine whether the recipient of the data has the means to identify the persons concerned. If the recipient does not have such means and at the same time the pseudonymisation is sufficiently robust and secure, the data should no longer be considered personal.

A possible shift in the understanding of pseudonymisation
This position represents a significant shift in the understanding of pseudonymisation as a means that could ensure that data is no longer personal to the recipient. If pseudonymisation is done sufficiently and re-identification of individuals is not possible, such data should not be protected by the GDPR.
Opposing position of the EDPS
However, the EDPS has long held a different view. According to him, pseudonymised data remain personal, because it is not decisive whether the recipient has the means to re-identify the persons. It argued similarly in case T-557/20 SRB/EDPS, where it stated that the GDPR does not distinguish between those who keep pseudonymised data and those who keep additional information for re-identification. Thus, in his view, it is always pseudonymised data, not anonymised data.
Implications for practice and future developments
The Court of Justice of the EU (CJEU) has not yet issued a final judgment, which is expected later this year. The Court is not bound by the Advocate General's opinion, so the outcome is still open.
This case will be particularly interesting to follow in the context of the recently published European Data Protection Board (EDPB) guidelines on pseudonymisation, which are currently open for public consultation. It is expected that the outcome of this case may have major implications for data sharing and processing practices in the EU, in particular with regard to the use of pseudonymisation techniques and security policies when handling data.
Conclusion
The Advocate General's opinion provides a new perspective on pseudonymisation as a possible tool to exclude the application of the GDPR to shared data. If the CJEU were to adopt this view, it could facilitate data sharing between organisations, but it could also weaken data protection. We will only know what the final verdict will be in the CJEU's decision, which will have a significant impact on data protection law practice.
About the author
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2025. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 400,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.
