• Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Kurzberatung
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

GDPR and Pseudonymization: A Surprising Ruling by the ECJ

5. June 2023
in Data protection Law, EU law
Reading Time: 4 mins read
0 0
A A
0
dsgvo 3589608 1280
Key Facts
  • The European Court ruled that the GDPR does not apply to pseudonymized data that has no direct personal reference.
  • It must no longer be possible to assign pseudonymized data to an identifiable person without additional information.
  • The ruling could have far-reaching consequences for companies and their data protection practices.
  • Technical and organizational risk mitigation measures are necessary to respond to data protection regulations.
  • The EDPS decided not to use remedial powers as the SRB had taken measures to ensure data protection.
  • Recommendation to the SRB: Data protection declarations should cover all potential data recipients and data processing.
  • The ruling emphasizes the need to ensure transparency with regard to data processing and the identity of recipients.

Introduction

Content Hide
1. Introduction
2. What is pseudonymization?
3. Key points of the ruling
4. Impacts and recommendations
5. Conclusion and outlook: Data protection and pseudonymization in practice
5.1. Author: Marian Härtel

The application of the General Data Protection Regulation (GDPR) to pseudonymized data is a controversial topic that generates much debate in the legal and data protection community. Pseudonymized data is data where identifiers have been removed or replaced to prevent or make it significantly more difficult to identify the data subjects. However, the question of whether this data qualifies as personal data within the meaning of the GDPR is controversial.

Recently, the Court of Justice of the European Union (CFI) issued a surprising ruling that calls into question previous legal practice and is causing a stir. In a decision that many consider unexpected, the court ruled that the GDPR does not apply when it comes to pseudonymized data that has a relative personal reference. This means that the data has been processed in such a way that it can no longer be directly assigned to a specific person without additional information.

The court went further and found that the GDPR does not apply even if the data recipient has no means of re-identification. In other words, if the recipient of the data is not able to attribute the pseudonymized data to a specific person, this data is not covered by the GDPR. This ruling represents a significant change in the interpretation and application of the GDPR and could have far-reaching effects on the data protection practices of companies and organizations.

What is pseudonymization?

Pseudonymization is a process in which personal data are processed in such a way that they can no longer be assigned to a specific data subject without additional information. This is often achieved by replacing identifying elements in the data with artificial identifiers or pseudonyms. This additional information needed for identification must be kept separately and be subject to technical and organizational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.

A good example of such a practice is the use of truncated IP addresses in tools such as Google Analytics. In this case, the IP address that could provide a direct link to a specific user is shortened or “masked” to prevent the identification of the user. While this protects the user’s privacy, it also presents a challenge for the application of the GDPR.

The question is whether such pseudonymized data, such as truncated IP addresses, should be considered personal data in the sense of the GDPR. The recent ECJ ruling suggests that this is not the case if the recipient of the data has no possibility of re-identification. This could mean that companies using techniques such as IP masking may not have to comply with the full requirements of the GDPR.

However, it is important to emphasize that this is a complex and rapidly evolving area of law. Companies should therefore ensure that they regularly keep abreast of the latest developments and rulings and adapt their data protection practices accordingly.

Key points of the ruling

The court found that the data shared by the SRB with Deloitte could be considered pseudonymized data because the consultation phase responses were personal data and the SRB shared the alphanumeric code that allowed the responses received during the registration phase to be linked to those received during the consultation phase.

It was also found that Deloitte was a recipient of personal data of the complainants within the meaning of Article 3 No. 13 of Regulation 2018/1725. The fact that Deloitte is not mentioned in the SRB’s privacy statement as a potential addressee of the personal data collected and processed by the SRB as a controller in the context of the consultation procedure constitutes a violation of the data protection principles set forth in Art. 15 para. 1(d) of Regulation 2018/1725 constitutes a duty to provide information.

Impacts and recommendations

Despite the identified breach, the EDPS decided not to make use of his remedial powers under Article 58(2). 2 of Regulation 2018/1725, as the SRB had put in place technical and organizational measures to mitigate risks to the right of individuals to the protection of their data in the context of the procedure concerning the right to be heard.

However, the EDPS recommended the SRB to ensure in future procedures concerning the right to be consulted that its privacy statements cover the processing of personal data during both the registration and consultation phases and that they include all potential recipients of the data collected in order to comply with the information obligation towards data subjects pursuant to Article 15 of Regulation 2018/1725.

Conclusion and outlook: Data protection and pseudonymization in practice

This ruling by the ECJ underscores the importance of data protection in all aspects of data processing, including sensitive areas such as bank processing. It emphasizes the need for all parties involved, including external consultants, to comply with data protection rules and ensure transparency to data subjects regarding the processing of their personal data and the identity of the recipients of that data.

The ruling also shows that the EDPS is willing to take pragmatic decisions when organizations take measures to mitigate risks, even if they have violated data protection rules. However, it is clear that such breaches should be taken seriously and avoided to ensure public confidence in compliance with data protection rules.

It remains to be seen how this ruling will affect the future application of the GDPR. However, it emphasizes the need to comply with data protection regulations in all aspects of data processing and to respect the rights of data subjects.

Overall, this case shows that the topic of data protection, and in particular the application of the GDPR to pseudonymized data, continues to be a dynamic and complex field that requires constant attention and adaptation. It is an important notice for all organizations that process personal data and emphasizes the need to comply with data protection regulations in all aspects of data processing and to respect the rights of data subjects.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: CustomizationEntscheidungenGeneral Data Protection RegulationGoogleIP addressJudgmentsLegal fieldPersonal dataPrivacyRegulation

Weitere spannende Blogposts

Chamber Court on Influencers and Advertising

medienrecht
23. January 2019

In the meantime, there is a few more information about the decision of the Court of Appeal (the Higher Regional...

Read moreDetails

Warning letters because of unencrypted contact form

LG Munich: Data protection consent on dating platform
7. November 2022

Just a few weeks ago, I published an article on the subject here. Now there is apparently again a wave...

Read moreDetails

BaFin and the regulation of e-money (including computer games)

BaFin and the regulation of e-money (including computer games)
11. December 2022

What is BaFin? BaFin is the Federal Financial Supervisory Authority and is the German supervisory authority for credit institutions, insurance...

Read moreDetails

Federal Court of Justice rules on cookie storage consent

ECJ: Cookies require explicit consent of users
7. November 2022

The I. Civil Senate of the Federal Court of Justice, which is responsible among other things for claims under the...

Read moreDetails

New OLG rulings on product descriptions in online trade

New OLG rulings on product descriptions in online trade
5. October 2023

Misleading product descriptions: New OLG rulings reveal pitfalls for online retailers Anyone who sells products in online stores naturally wants...

Read moreDetails

Attorney’s fees of a warning association not refundable

abmahnung
3. June 2019

If a competition association itself has issued a warning and asks the admonisher to provide further explanation of this warning,...

Read moreDetails

Is “Sponsored Post” enough as an advertising label?

Legal form as an influencer? A few hints!
17. April 2019

At the moment I have a case in which the question arises whether the word "sponsored post" is sufficient as...

Read moreDetails

Judgment on surreptitious advertising by the LG Trier

Brief reminder: Influencer as target of warning letters
13. August 2024

Case law on the obligation to label advertising is constantly evolving. A recent ruling by the Regional Court of Trier...

Read moreDetails

Smart Contracts, DeFi and AI: Innovative Business Ideas and their Legal Challenges in IT Law

Blockchain in the supply chain
17. October 2023

In a recently published LinkedIn post, it was announced that the interface between smart contracts, decentralized financial systems (DeFi) and...

Read moreDetails
Contractual regulations for no-code/low-code software development
Other

Contractual regulations for no-code/low-code software development

21. May 2025

No-code and low-code platforms enable rapid software development without extensive manual programming. Applications are increasingly being developed on the basis...

Read moreDetails
Erotic content on OnlyFans: Copyright and personality rights protection for creators

Erotic content on OnlyFans: Copyright and personality rights protection for creators

20. May 2025
Goodbye hustle culture? Startup life between 24/7 grind and work-life balance

Goodbye hustle culture? Startup life between 24/7 grind and work-life balance

19. May 2025
Startup buzzwords 2025: Bullshit bingo in marketing German Introduction: Bullshit bingo in marketing German

Startup buzzwords 2025: Bullshit bingo in marketing German Introduction: Bullshit bingo in marketing German

18. May 2025
From the metaverse boom to AI euphoria – a tech lawyer in the hype cycle

From the metaverse boom to AI euphoria – a tech lawyer in the hype cycle

17. May 2025

Podcastfolge

86fe194b0c4a43e7aef2a4773b88c2c4

On the dark side? A lawyer in the field of tension of innovative start-ups

26. September 2024

In this personal and engaging episode, the experienced IT and media lawyer delves deep into the gray area of his...

Read moreDetails
d5e1e6cad87cb839a9e23af79034bd94

AI in the legal system: Towards a digital future of justice

16. October 2024
8ffe8f2a4228de20d20238899b3d922e

Web3, blockchain and law – a critical review

26. September 2024
c9c5d7fd380061a8018074c2ca5a81bf

Startups and innovation in Germany – challenges and opportunities

26. September 2024
092def0649c76ad70f0883df970929cb

Influencers and gaming: legal challenges in the digital entertainment world

26. September 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung