Pseudonymization and the GDPR
Are pseudonymous data personal data? Dr. Vlieger explains the relative concept based on case law of the European Court.
Pseudonymous data & Pseudonymisation
Pseudonymisation is a term from the GDPR that causes a great deal of confusion. Does it involve personal data—meaning the GDPR applies—or not? As is often the case, the answer from legal experts is: it depends. This is because 'pseudonymous data' does not constitute a specific category or type of data. In the GDPR, pseudonymisation appears only as a technique: Article 4(5) defines it as "the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person."
Simply put, pseudonymization means replacing a name like 'Antoinette Vlieger' with, for example, the number '1973.' The difference compared to anonymization is that a key or list still exists, making it possible to trace number 1973 back to Vlieger. In medical research, the preference is almost always for pseudonymization rather than anonymization. This allows findings to be reported back to the treating physician if necessary or enables requests for additional data should they prove essential for the study at a later stage.
Legal jargon vs. plain language
However, bear in mind that there is always a distinction between ordinary language and legal terminology (the sort of thing lawyers explain at parties: "this wasn't murder, but manslaughter," even though everyone around them saw it as murder). In everyday speech, therefore, pseudonymization refers to processing personal data in such a way that the data can no longer be linked to a specific data subject without the use of additional information. Yet the GDPR adds a further component to this: "provided that such additional information is kept separately and technical and organisational measures are taken to ensure that the personal data are not attributed to an identified or identifiable natural person." It must also be documented who has (exclusive) access to the key.
Does the GDPR apply to pseudonymized data?
But does the GDPR actually apply to such data or not? That depends on whether the data constitutes 'personal data, ' and the concept of personal data is a relative one. The GDPR applies whenever an individual's privacy is at stake because the data can be traced back to a specific person. If a university hospital conducts research on patient number 1973 and holds the list linking that number to, say, a person named Vlieger, then the data constitutes personal data for that hospital. If they provide this data (e.g., to train an AI tool) to mathematicians who do not have the list, then for those mathematicians, it is not personal data; the GDPR does not apply. If the same dataset is provided to Statistics Netherlands (CBS)—which also lacks the list but can combine the data with its own records to reveal the identities involved—then the data constitutes personal data for CBS. To complicate matters further: if the mathematicians (for whom the data is not personal data) publish it on a public website where CBS can access it (and for whom it is personal data), or apply very sloppy security measures, then the act of making it public or available to crooks, transforms it into personal data, meaning the GDPR applies—even to the mathematicians.
Context-dependent
The GDPR therefore applies when personal data is involved—specifically, data held by certain individuals and within a particular context. Pseudonymous data may or may not qualify as personal data depending on the circumstances. Caution is also required regarding the concept of anonymous data. Truly anonymous data is anonymous to everyone; such data does not constitute personal data, and the GDPR does not apply to it. However, there is also "relatively anonymous" data—data that is anonymous to me, for instance, but not to Statistics Netherlands (CBS). To avoid confusion, it is best to label only truly anonymous data as "anonymous." The GDPR does not apply to such data in any case. However, for relatively anonymous data and pseudonymous data, one must always assess whether the GDPR applies.

Is this confirmed by case law?
Many people want to know whether European courts have confirmed that the above holds true. However, there is no case law specifically addressing the concept of pseudonymisation itself. While there are rulings that discuss pseudonymised data, they invariably apply the existing case law regarding the concept of ‘personal data’.
The GAR/EDPS judgment (April 2023) clearly illustrated how the European court handles this issue. The EDPS argued that the data shared by GAR with Deloitte was pseudonymised data and therefore constituted personal data (para. 32). GAR contended that, for the recipient Deloitte, the data was anonymous rather than pseudonymised, given that GAR had not shared the information required for re-identification with Deloitte (para. 76). Notably, the court did not address whether the data was pseudonymised or anonymous in its ruling, focusing instead solely on whether it constituted personal data. That was the extent of the court's analysis.
EDPB Guideline 01/2025 on pseudonymisation (January 2025) states the same principle (recital 22): if pseudonymised data and additional information can be combined—taking into account the means reasonably used by the controller or by another person—then the pseudonymised data constitutes personal data. Nevertheless, many remained doubtful as to whether this was truly the intended meaning: that ‘personal data’ is a relative concept, dependent on the context.
Appeal
In the meantime, the appeal in the GAR/EDPS case was heard. The Advocate General clearly addressed this (in February 2025) in paragraph 52: Pseudonymised data do not automatically cease to be personal data—since, "under certain conditions," they are personal data, but this is not always the case. The highest courts subsequently settled the matter. In September 2025, it was confirmed in case C-413/23 P that the concept of personal data is relative; thus, whether a specific set of data constitutes personal data depends on the context. If the data are held in a secure environment inaccessible to others (where only those without key can access them) then they do not constitute personal data; consequently, the GDPR does not apply, and no legal basis is required. However, if one possesses the key, or if the context allows access by someone capable of reversing the pseudonymisation, then the GDPR does apply.
Is pseudonymization always mandatory?
The GDPR therefore sometimes applies to pseudonymized data and sometimes does not. But if you had not yet pseudonymized the data, is doing so required under the GDPR? The legal answer to that is also: sometimes yes, sometimes no. In short: if it is possible, it is mandatory (and must be done as soon as possible); if it is not possible, you may still work with the data depending on the circumstances: provided there is a compelling purpose and the data is highly secure.
Still in doubt? Contact Dr. Antoinette Vlieger for advice.
