- Anonymization means elimination of the personal reference; absolute impossibility of re-identification is not necessary, but practical impossibility is sufficient.
- Anonymization is a processing of personal data and requires a legal basis; it may be compatible with the original purpose.
- Anonymization can replace erasure if the personal reference has been effectively removed and the data was originally collected lawfully.
- Anonymization often involves high risks; special rules, transparency obligations and, as a rule, a data protection impact assessment are required.
The German Federal Commissioner for Data Protection and Freedom of Information (BfDI; responsible for public data protection, but in the telecommunications [TC] sector also for private individuals) has – following a public hearing – published a position paper on anonymization under the GDPR, with particular reference to the TC sector.
Concept of anonymization
The BfDI first addresses the Concept of anonymization which is not explicitly defined in the GDPR. The starting point is the concept of personal data: what is anonymous is not personal data. As with the definition of personal data, no absolute standard therefore applies:
Absolute anonymization in such a way that it is not possible for anyone to re-establish the reference to a person is often not possible and is generally not required by data protection law. As a rule, it is sufficient that the reference to a person can be is removed in such a way that re-identification is practically not feasible because the personal reference can only be restored with a disproportionate effort in terms of time, costs and manpower.
Legal basis of anonymization without deletion
The anonymization process itself represents a Processing of personal data and requires – according to the GDPR – a legal basis. In particular, the question arises as to when anonymization still represents a compatible purpose and is covered by the original legal basis.
In this context, it is particularly pleasing to note that the BfDI assumes that a compatible purpose can be based on the legal basis of the original purpose and then does not require an independent legal basis. This can be based on sentence 2 of recital 50, but is disputed in the doctrine.
Anonymization is compatible in this sense if the criteria according to Article 6 (4) of the GDPR are met. Here, the BfDI states that the purpose of anonymization is not to remove the reference to a person, but “the underlying actual interest of the controller”; this should therefore be included in the consideration. In my opinion, this is wrong, because the underlying interest does not relate to the processing of personal data and must therefore be excluded from consideration under data protection law. From the point of view of the BfDI, it would be permissible, for example, to anonymize customer data in order to determine the distribution of services by region and age cohorts.
Anonymization as deletion equivalent
The BfDI further states that anonymization is permissible if deletion is as well, because anonymization is basically equivalent to deletion:
According to the systematics of the GDPR, deleting the data is therefore apparently only one of several possibilities to fulfill the requirements of Art. 5 (1) (e) GDPR. It is then not necessary if the personal reference can be effectively eliminated by anonymization. […] It follows that in the case where only anonymized information, i.e. information without personal reference, is available, the obligations under the GDPR and thus also the obligation to any further storage limitation under Art. 5(1)(e) GDPR do not apply.
It could be argued against the possibility of fulfilling the deletion obligation through anonymization that a residual risk of re-identification remains with anonymization compared to deletion. However, it can be argued against this, that both processes – deletion and anonymization – entail a removal of the personal reference and that even deletion does not necessarily lead to a final destruction of the data. The fact that it is erasure and destruction are two alternative processing operations, is also clarified by the wording “the deletion or destruction” in Art. 4 No. 2 GDPR. This reasoning can also be applied to the right to erasure under Art. 17 GDPR.
From the point of view of the BfDI, the obligation to delete personal data can be only be fulfilled by anonymization if the personal data were collected lawfully (cf. Art. 17(1)(a) GDPR).
Thus, by the way the Austrian data protection authority also decided.
More hints
Finally, the BfDI points to special legal regulations of anonymization, in this case of the German telecommunications legislation, to the transparency obligation of the responsible party and to data protection impact assessments. Regarding the latter:
In the case of anonymization, the person responsible must usually assume that a high risk existsbecause the criterion of “large-scale processing” and, at least currently, the criterion of “new technologies” regularly apply to anonymization. […] As a rule, a data protection impact assessment must be carried out before anonymization.