Take-Aways (AI)
  • Anony­mizati­on means eli­mi­na­ti­on of the per­so­nal refe­rence; abso­lu­te impos­si­bi­li­ty of re-iden­ti­fi­ca­ti­on is not neces­sa­ry, but prac­ti­cal impos­si­bi­li­ty is sufficient.
  • Anony­mizati­on is a pro­ce­s­sing of per­so­nal data and requi­res a legal basis; it may be com­pa­ti­ble with the ori­gi­nal purpose.
  • Anony­mizati­on can replace era­su­re if the per­so­nal refe­rence has been effec­tively remo­ved and the data was ori­gi­nal­ly coll­ec­ted lawfully.
  • Anony­mizati­on often invol­ves high risks; spe­cial rules, trans­pa­ren­cy obli­ga­ti­ons and, as a rule, a data pro­tec­tion impact assess­ment are required.

The Ger­man Fede­ral Com­mis­sio­ner for Data Pro­tec­tion and Free­dom of Infor­ma­ti­on (BfDI; respon­si­ble for public data pro­tec­tion, but in the tele­com­mu­ni­ca­ti­ons [TC] sec­tor also for pri­va­te indi­vi­du­als) has – fol­lo­wing a public hea­ring – published a posi­ti­on paper on anony­mizati­on under the GDPR, with par­ti­cu­lar refe­rence to the TC sector.

Con­cept of anonymization

The BfDI first addres­ses the Con­cept of anony­mizati­on which is not expli­ci­t­ly defi­ned in the GDPR. The start­ing point is the con­cept of per­so­nal data: what is anony­mous is not per­so­nal data. As with the defi­ni­ti­on of per­so­nal data, no abso­lu­te stan­dard the­r­e­fo­re applies:

Abso­lu­te anony­mizati­on in such a way that it is not pos­si­ble for anyo­ne to re-estab­lish the refe­rence to a per­son is often not pos­si­ble and is gene­ral­ly not requi­red by data pro­tec­tion law. As a rule, it is suf­fi­ci­ent that the refe­rence to a per­son can be is remo­ved in such a way that re-iden­ti­fi­ca­ti­on is prac­ti­cal­ly not fea­si­ble becau­se the per­so­nal refe­rence can only be resto­red with a dis­pro­por­tio­na­te effort in terms of time, costs and manpower.

Legal basis of anony­mizati­on wit­hout deletion

The anony­mizati­on pro­cess its­elf repres­ents a Pro­ce­s­sing of per­so­nal data and requi­res – accor­ding to the GDPR – a legal basis. In par­ti­cu­lar, the que­sti­on ari­ses as to when anony­mizati­on still repres­ents a com­pa­ti­ble pur­po­se and is cover­ed by the ori­gi­nal legal basis.

In this con­text, it is par­ti­cu­lar­ly plea­sing to note that the BfDI assu­mes that a com­pa­ti­ble pur­po­se can be based on the legal basis of the ori­gi­nal pur­po­se and then does not requi­re an inde­pen­dent legal basis. This can be based on sen­tence 2 of reci­tal 50, but is dis­pu­ted in the doctrine.

Anony­mizati­on is com­pa­ti­ble in this sen­se if the cri­te­ria accor­ding to Artic­le 6 (4) of the GDPR are met. Here, the BfDI sta­tes that the pur­po­se of anony­mizati­on is not to remo­ve the refe­rence to a per­son, but “the under­ly­ing actu­al inte­rest of the con­trol­ler”; this should the­r­e­fo­re be inclu­ded in the con­side­ra­ti­on. In my opi­ni­on, this is wrong, becau­se the under­ly­ing inte­rest does not rela­te to the pro­ce­s­sing of per­so­nal data and must the­r­e­fo­re be exclu­ded from con­side­ra­ti­on under data pro­tec­tion law. From the point of view of the BfDI, it would be per­mis­si­ble, for exam­p­le, to anony­mi­ze cus­to­mer data in order to deter­mi­ne the dis­tri­bu­ti­on of ser­vices by regi­on and age cohorts.

Anony­mizati­on as dele­ti­on equivalent

The BfDI fur­ther sta­tes that anony­mizati­on is per­mis­si­ble if dele­ti­on is as well, becau­se anony­mizati­on is basi­cal­ly equi­va­lent to deletion:

Accor­ding to the syste­ma­tics of the GDPR, dele­ting the data is the­r­e­fo­re appar­ent­ly only one of seve­ral pos­si­bi­li­ties to ful­fill the requi­re­ments of Art. 5 (1) (e) GDPR. It is then not neces­sa­ry if the per­so­nal refe­rence can be effec­tively eli­mi­na­ted by anony­mizati­on. […] It fol­lows that in the case whe­re only anony­mi­zed infor­ma­ti­on, i.e. infor­ma­ti­on wit­hout per­so­nal refe­rence, is available, the obli­ga­ti­ons under the GDPR and thus also the obli­ga­ti­on to any fur­ther sto­rage limi­ta­ti­on under Art. 5(1)(e) GDPR do not apply.

It could be argued against the pos­si­bi­li­ty of ful­fil­ling the dele­ti­on obli­ga­ti­on through anony­mizati­on that a resi­du­al risk of re-iden­ti­fi­ca­ti­on remains with anony­mizati­on com­pared to dele­ti­on. Howe­ver, it can be argued against this, that both pro­ce­s­ses – dele­ti­on and anony­mizati­on – ent­ail a rem­oval of the per­so­nal refe­rence and that even dele­ti­on does not neces­s­a­ri­ly lead to a final des­truc­tion of the data. The fact that it is era­su­re and des­truc­tion are two alter­na­ti­ve pro­ce­s­sing ope­ra­ti­ons, is also cla­ri­fi­ed by the wor­ding “the dele­ti­on or des­truc­tion” in Art. 4 No. 2 GDPR. This rea­so­ning can also be applied to the right to era­su­re under Art. 17 GDPR.

From the point of view of the BfDI, the obli­ga­ti­on to dele­te per­so­nal data can be only be ful­fil­led by anony­mizati­on if the per­so­nal data were coll­ec­ted lawful­ly (cf. Art. 17(1)(a) GDPR).

Thus, by the way the Austri­an data pro­tec­tion aut­ho­ri­ty also deci­ded.

More hints

Final­ly, the BfDI points to spe­cial legal regu­la­ti­ons of anony­mizati­on, in this case of the Ger­man tele­com­mu­ni­ca­ti­ons legis­la­ti­on, to the trans­pa­ren­cy obli­ga­ti­on of the respon­si­ble par­ty and to data pro­tec­tion impact assess­ments. Regar­ding the latter:

In the case of anony­mizati­on, the per­son respon­si­ble must usual­ly assu­me that a high risk existsbecau­se the cri­ter­ion of “lar­ge-sca­le pro­ce­s­sing” and, at least curr­ent­ly, the cri­ter­ion of “new tech­no­lo­gies” regu­lar­ly app­ly to anony­mizati­on. […] As a rule, a data pro­tec­tion impact assess­ment must be car­ri­ed out befo­re anonymization.