Can pseudonymised personal data ever become anonymous data in the hands of a Third Party?

The question in the heading arises from the DSG v ICO (Court of Appeal) and SBS v EDPS (CJEU) legal sagas (see references).  There is confusion as to whether or not pseudonomysed personal data, in the hands of a Third Party, can be treated as anonymous data, when that Third Party does not have any access to any details that could identify any data subject.

Some researchers, for instance, are of the view that, as such data is always outside the scope of the UK_GDPR.  Indeed, the Data (Use and Access) Act encourages the diminishing of data protection by permitting re-use of personal data for research purposes without consideration of important obligations (e.g. transparency, incompatibility).

Meanwhile the ICO’s advice sits on the fence. It states “If you share pseudonymised data (but not the additional [identification] information) with another organisation, it may be anonymous information in their hands” (my emphasis); sadly the guidance does not give many clues as to how to decide what “may” means in practice.

In my view, this blog will disabuse those who believe the non-identifiable data, derived from personal data that have been pseudonomysed, are anonymous data. In addition, the blog makes some important observations concerning anonymisation in the age of AI.

The confusion has arisen partly because of comments like those made by the Upper Tribunal in the DSG case.  It said:

“…in instances of pseudonymisation, the same information may be personal data in the hands of the data controller (who retains the key to the identifying material), but not personal data in the hands of a third party, if the third parties do not have the means to access the additional information that the data controller holds which enables the identification of living individuals.” (para 122).

DSG’s point of view, developed in its legal arguments, takes this idea a step further.  If information in the hands of a Third Party hacker is not personal data, then it follows that there cannot be a reportable personal data breach on the part of the controller.  Quite simply, there is no risk to any data subject arising from the hacker’s further use or disclosure, as the data themselves are non-identifiable.

The factual context will help clarify the last paragraph.  In the DSG case, there was a 9 month long cyber-attack where the attacker(s) captured transaction details from point-of-sale terminals etc in real time. More than 5.6 million payment cards were affected.

In many cases, the attacker(s) only obtained the 16 digit card number and expiry date;  they did not obtain the cardholders’ names or any information that would enable them to identify the cardholder.

After an investigation, the ICO served a monetary penalty notice (MPN) for a maximum sum of £500,000 (the maximum under the DPA1998).  DSG appealed to the First-Tier Tribunal (FTT) contending that in the “hands” of a Third Party, the data (card number plus expiry date) were not personal data. It follows that could be no security obligations enforced on DSG as a result of the acquisition of non-identifiable data by the hacker.

The FTT rejected this contention though it reduced the MPN by half (i.e. to £250K) arguing that some of the data obtained by the hacker (i.e. the Third Party in this case) was personal data and some were not. This, in effect, accepted DSG’s argument that in about half the number of cases, in the hands of the hacker,  the data were not personal data.

Being “half right”, it is not unsurprising that DSG appealed to the Upper Tribunal.  Here a panel of three judges decided that the “question of whether the hacker (i.e. Third-Party) had acquired personal data had to be analysed from the perspective of the Third Party”.

Hence their conclusions (at paragraph 122 quoted earlier): namely that personal data in the hands of a controller were not personal data in the hands of a hacker.

It followed that the hackers’ acquisition of data was not through the “unauthorised or unlawful processing of personal data” as the data acquired were not personal data (i.e. the data did not identify any individual to whom the data related, and the hacker had no means of identifying any individual).

It also followed that there should be no monetary penalty for the security breach.

Note that in UK_GDPR terms, the hacking was a personal data breach in the controller’s hands, which was a non-reportable breach to the ICO. This position arises because there was no risk to any data subject because, in the hacker’s hands, the card data were incapable of being linked to the particular cardholder.

Although this judgment from the Court of Appeal relates to the DPA1998, the definition of personal data and the text of Recital 26 of Directive 95/46/EC are the same as in the UK_GDPR.  As this is the case, the impact of this judgment carries over, from the DPA1998, into the UK_GDPR.

The judgment reversed the Upper Tribunal position, mainly by establishing that what was in the hands of the hacker was largely irrelevant because the data were personal data in the hands of the controller (i.e. in DSG hands).

To get to this position, the Court considered the definition of personal data (“personal data’ means any information relating to an identified or identifiable natural person”).  Note that definition of personal data does not specify who performs the identification of the natural person. The definition does not say, for example, “ ’personal data’ in the hands of a Third Party has to be information relating to an identified or identifiable natural person”.

This is where Recital 26 comes in:

Recital 26: “….To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller OR by another person to identify the natural person directly or indirectly.”  (my emphasis)

Note that identification can be by the controller (e.g. DSG) OR any other person (e.g. a hacker).

As identification can be achieved by the person described on either side of the OR, it follows that if the controller can perform the identification, the data are personal data in the hands of the Third Party.  In other words, there is no need to consider the position from the standpoint of the Third Party if the controller can perform the identification.

This is made clear when the Court of Appeal concluded:

“My main conclusions can be stated in this way. Information is “personal data” if it falls within the statutory definition of that term. One of the statutory criteria, and the key criterion for present purposes, is that the individual to whom the information relates is identifiable to the data controller. The security duty requires any data controller of any such information to safeguard it.  If the data are “personal” from the perspective of the data controller, it will be unnecessary to pose the further question of whether they are personal data “in the hands of” or “from the perspective” of any other person. (para 70; my emphasis).

Applying this conclusion to pseudonomysed personal data, the controller can always identify the data subject as he possesses the identification details. It follows that any Third Party who is processing the non-identification details of the pseudonomysed dataset, is also processing personal data.

Please note that this conclusion only applies when the Third Party holds the exact non-identification details of the pseudonomysed dataset.  If these details have been altered to make them different to the non-identification details of the pseudonomysed dataset, then the test of whether or not these data are personal data is subject to test in Recital 26 (as discussed below in “What about anonymisation?”).

The Court of Appeal judgement is consistent with the CJEU’s judgement in the case of SRB v EDPS; however in this case the Third Party was not a hacker. Despite this Third Party difference, the central issue before the CJEU was similar: namely, whether pseudonomysed personal data in the hands of a Third Party were personal data if the Third Party could not identify any data subject.

A few quotations will help explain the CJEU’s conclusions:

Para 70: “….pseudonymisation is therefore not part of the definition of ‘personal data’, but refers to the establishment of technical and organisational measures to reduce the risk of a data set being correlated with the identity of data subjects. According to recital 17 of that regulation, pseudonymisation ‘can [only] reduce the risks’ of such correlation for those data subjects and, in doing so, ‘help controllers and processors to meet their data protection obligations’

This is saying that the definition of personal data has no interaction nor overlap with the definition of pseudonymisation; the latter is a legal description of a technical mechanism to protect personal data from being linked to a specific data subject.  The fact that the data have been pseudonymised therefore is not a consideration when assessing whether or not, a particular set of information is personal data.

Para 73: “…the concept of ‘pseudonymisation’ presupposes the existence of information enabling the data subject to be identified. The very existence of such information precludes data that have undergone pseudonymisation from being regarded, in ALL cases, as anonymous data, which is excluded from the scope of that regulation” (my emphasis).

The CJEU are saying that the fact that a personal dataset has been pseudonymised means that the non-identifiable parts of that dataset should be regarded as personal data because it can be reasonably assumed that a link to the identification details exists (and is available).

The CJEU also implicitly touched on the “in the hands of a Third Party” issue that explicitly was at the centre of the Court of Appeal judgement.  The CJEU stated:

Para 85: “…Accordingly, in so far as it cannot be ruled out that those third parties have means reasonably allowing them to attribute pseudonymised data to the data subject ….the data subject must be regarded as identifiable as regards both that transfer and any subsequent processing of those data by those third parties. In such circumstances, pseudonymised data should be considered to be personal in nature.”

Because a Third Party is processing the non-identifiable pseudonymised dataset, it cannot be ruled out that the Party has the means readily available to identify the data subject (e.g. by reference back to the identification details held by a controller).

Indeed, one can combine the CJEU decision with the Court of Appeal decision: if the controller can identify the data subject (which he can when a personal dataset is pseudonomysed), then it does not matter much whether the Third Party holding the non-identifiable part of the dataset cannot identify the data subject.

In such circumstances, the non-identifiable pseudonomysed data in the hands of a Third Party should be assumed to be personal data, full stop.

Just de-linking the identification details in a pseudonomysed database from the related non-identification details is unlikely to be enough to be sure that the non-identifiable part of the database is “anonymous”.

This is because Recital 26 of the GDPR refers to the “means [that] are reasonably likely to be used to identify the natural person”. This includes taking into account factors such as “the costs of and the amount of time required for identification” and “the available technology at the time of the processing and technological developments”.

In Recital 26 terms, the application of AI technology (or advanced search functionality) to a quest to re-identify data subjects from the non-identification details would constitute “available technology”.  Its ubiquitous nature, means that such functionality is “reasonably likely to be used” to perform (or attempt to perform) any re-identification.

As this is the case, before a pseudonomysed set of personal data can be considered safe for use or disclosure as anonymous data, the non-identification details have to be:

  • de-linked from the identification details AND
  • “massaged” in some way so they cannot assist in-re-identification of data subjects AND
  • tested by the controller to see whether it is likely that the new “de-linked” dataset can be linked to specific data subjects.

As AI techniques improve, the more massaging and testing will be required especially if links to relevant public domain data are available.

That is why it is increasingly important to add warnings concerning the offence in Section 171 of the DPA2018 into relevant data sharing contracts or agreements if pseudonomysed personal data, suitably massaged, are to be shared. (S.171 makes it an offence to “re-identify information that is de-identified personal data without the consent of the controller responsible for de-identifying the personal data”).

Such contracts/agreements should also insist that any personal data as well as any de-personalised data should be returned or securely destroyed at the end of the contract or agreement.  Contracts which, for example, merely require that “personal data shall be destroyed or returned” could permit the contractor to retain the non-identification parts of a dataset. The claim could be that the data are not personal data and the contractual requirement only applies to “personal data”.

Additionally, if an unauthorised person does successfully reconstitute personal data which have been de-identified by the controller, then the latter controller risks being seen as suffering a data breach (which is likely to be reportable, especially if the data were derived from special category or confidential personal data).

It can now be seen that the data breach clauses in processor contracts should be appropriately modified so that they can be considered for inclusion in data sharing agreements/contracts relating to shared pseudonymised de-personalised data.

For example, provisions that relate to termination of data sharing if: re-identification is attempted, return or deletion of data or data derived from the shared data or, reporting any suspicion that personal data have been re-constituted by any external recipient.

This set of circumstances could also give rise to an offence under section 170 of the DPA2018 by any person processing the reconstituted personal data (as they are processing personal data without the anonymising controller’s consent).

I would also consider such clauses if an anonymous dataset (by today’s standard), derived from a set of personal data, were also shared.  With the advent of further sophisticated AI techniques in future, one should not risk sharing such data on a wing and a prayer.

In summary, the “reasonably accessibility” of AI technology is likely to mean that what is “anonymous” today might not necessarily be “anonymous” tomorrow.

This could have major privacy consequences if, for example, “anonymous” data derived from confidential personal data or special category of personal data, are freely transferred today to a Third Country that has available to it, immense, AI enabled, processing resources in the absence of any applicable data protection law that protects the interests of UK data subjects.

Consequently an increasingly important question to ask is: “What do we do if we become aware that, without our consent, our “anonymised” data or our pseudonomysed non-identifiable data have become re-linked to our identifiable data subjects?”.

This is especially the case if such data are transferred abroad or placed in the public domain.

In summary, the upcoming courses (full details on the Amberhawk website) are:

  • Data (Use and Access) Act Workshop (1 day: Zoom only) and Thursday, 10 September 2026
  • Data Protection Practitioner (5 days: Zoom and onsite): 21– 25 September 2026
  • Data Protection Foundation (3 days: Zoom and onsite): 20-22 October 2026

EDPS v SRB;   CJEU C-413/23 P;  4th September 2025

DSG Retail v ICO; [2026] EWCA Civ 140.

Just published at the same time as the blog: EDPB Guidelines 02/2026 on Anonymisation, https://www.edpb.europa.eu/system/files/2026-07/edpb_guidelines_202602_anonymisation_v1_en_0.pdf

2 responses

  1. Your interpretation of SRB directly contradicts the actual judgment. Paragraph 73 says that the existence of separately held identifying information prevents pseudonymised data from being regarded as anonymous in all cases. Your post reads those words as though the Court had said that pseudonymised data must remain personal in all cases. Paragraphs 75 to 77 provide the immediate answer: effective technical and organisational measures may make the comments not personal in nature for Deloitte, even though they remained personal for the SRB. Paragraph 80 adds that treating pseudonymised data as personal in all cases and for every person would deprive the “means reasonably likely” test of practical effect.

    Your post also extracts the passage concerning potential subsequent transfers and then concludes that the controller’s ability to identify means that the recipient’s inability “does not matter one jot”. But paragraph 85 applies conditionally, where particular downstream recipients have, or may have, means reasonably allowing them to identify the data subjects. Paragraph 86 then states expressly that pseudonymised data must not be regarded as personal data “in all cases and for every person”. Paragraph 87 further limits “another person” to persons who have, or may have, access to means reasonably likely to enable identification. Those paragraphs dismantle rather than support your post’s “personal data, full stop” conclusion. Finally, the general availability of AI cannot replace that recipient-specific assessment of accessible auxiliary information, cost, time, legal restrictions, organisational controls and foreseeable technical capability. Technological developments may require periodic review, but they do not make anonymous information permanently personal by origin.

    1. Thanks for the comments which are limited to SRB v EDPS; I will look at them carefully. In summary, you don’t need that judgement to get to the position of the blog; DSG v ICO is enough.

      If you look at DSG v ICO judgement, the Court of Appeal clearly says that if the controller can ID the data subject, then the non-identifiable parts of the pseudonymous data is personal data and it does not matter what is in the hands of the Third Party.

      That is also why I added the section on anonymous data in the blog.

      C

Leave a Reply

Your email address will not be published. Required fields are marked *

Share this blog post...

Further reading...