NEW

How could the words “kill the boer” not be hate speech?

The case of AfriForum v Economic Freedom Fighters and Others was decided in May 2024 and was subsequently appealed to the Constitutional Court.  In March 2025 the Constitutional Court declined to hear the matter which effectively marks the end of the road for the...

Communicating clearly about data sharing in genomics

In early 2025 Paul Esselaar attended a very useful workshop organised by the GA4GH (Global Alliance for Genomics and Health) workshop in Boston and met several fascinating experts in the area of genomics law. This part of GA4GH called "REWS" (Regulatory and Ethics...

What can I do if a photographer posted photos of my children on social media without my permission?

I was recently contacted by a client who had the following problem: Earlier this year she contacted a photographer and asked the photographer to take some photographs of her, her husband and their two small children. They agreed by means of Whatsapp on a price and a...

Data Privacy in Healthcare: Addressing Emerging Challenges and Trends in Africa

Privacy Hub is hosting a seminar on Data Privacy in Healthcare: Addressing Emerging Challenges and Trends in Africa on Saturday, 25th May 2024 at 5pm (South African time). Join Paul Esselaar and various other speakers who will discuss latest trends in managing medical...

Why South Africa’s draft revised material transfer agreement is not fit for purpose

Forcing a square into a circle: why South Africa’s draft revised material transfer agreement is not fit for purpose

PAIA manual

View the PAIA manual HERE 20230626_PAIA_Manual_Esselaar Attorneys_PGE

Paul Esselaar

Paul Esselaar completed his BA, LLB at Rhodes University in Grahamstown in 1997. Thereafter he attended the School for Legal Practice at the University of Cape Town in 2000 and went on to complete his articles at Kessler De Jager Inc. During his articles he focussed...

Web Site Terms and Conditions

The Esselaar Attorneys Web Site is subject to copyright by Esselaar Attorneys or is licenced under copyright from third party owners. You may reproduce any web page - subject to the disclaimer below - for personal use only. Any comments and statements contained within...

Email Disclaimer

This message and any accompanying attachment(s) may contain confidential and copyrighted information. If you are not the addressee(s) indicated in this message or responsible for delivery of the message to the addressee(s), do not copy or deliver this message or the...

Financial Services Laws General Amendment Bill tabled in Parliament

According to the South African Government News Agency (SANews) the Financial Services Laws General Amendment Bill was tabled in Parliament last week. In short, 'the Bill, which was released for public comment in March, addresses urgent issues in eleven financial...

NEW

How could the words “kill the boer” not be hate speech?

The case of AfriForum v Economic Freedom Fighters and Others was decided in May 2024 and was subsequently appealed to the Constitutional Court.  In March 2025 the Constitutional Court declined to hear the matter which effectively marks the end of the road for the...

Communicating clearly about data sharing in genomics

In early 2025 Paul Esselaar attended a very useful workshop organised by the GA4GH (Global Alliance for Genomics and Health) workshop in Boston and met several fascinating experts in the area of genomics law. This part of GA4GH called "REWS" (Regulatory and Ethics...

What can I do if a photographer posted photos of my children on social media without my permission?

I was recently contacted by a client who had the following problem: Earlier this year she contacted a photographer and asked the photographer to take some photographs of her, her husband and their two small children. They agreed by means of Whatsapp on a price and a...

Data Privacy in Healthcare: Addressing Emerging Challenges and Trends in Africa

Privacy Hub is hosting a seminar on Data Privacy in Healthcare: Addressing Emerging Challenges and Trends in Africa on Saturday, 25th May 2024 at 5pm (South African time). Join Paul Esselaar and various other speakers who will discuss latest trends in managing medical...

Why South Africa’s draft revised material transfer agreement is not fit for purpose

Forcing a square into a circle: why South Africa’s draft revised material transfer agreement is not fit for purpose

PAIA manual

View the PAIA manual HERE 20230626_PAIA_Manual_Esselaar Attorneys_PGE

Paul Esselaar

Paul Esselaar completed his BA, LLB at Rhodes University in Grahamstown in 1997. Thereafter he attended the School for Legal Practice at the University of Cape Town in 2000 and went on to complete his articles at Kessler De Jager Inc. During his articles he focussed...

Web Site Terms and Conditions

The Esselaar Attorneys Web Site is subject to copyright by Esselaar Attorneys or is licenced under copyright from third party owners. You may reproduce any web page - subject to the disclaimer below - for personal use only. Any comments and statements contained within...

Email Disclaimer

This message and any accompanying attachment(s) may contain confidential and copyrighted information. If you are not the addressee(s) indicated in this message or responsible for delivery of the message to the addressee(s), do not copy or deliver this message or the...

Financial Services Laws General Amendment Bill tabled in Parliament

According to the South African Government News Agency (SANews) the Financial Services Laws General Amendment Bill was tabled in Parliament last week. In short, 'the Bill, which was released for public comment in March, addresses urgent issues in eleven financial...

Data-protection law is triggered by a deceptively simple concept: personal information (“personal data” in the EU). Once information no longer relates to an identified or identifiable person, the entire regulatory framework falls away. The difficulty lies in determining when that line is crossed, particularly where information has been pseudonymised rather than fully anonymised.

Pseudonymisation is not anonymisation — but context matters

Traditionally, regulators have taken an absolute approach: if data can be re-identified by anyone, somewhere, then it remains personal data everywhere. From the perspective,  pseudonymised data is always personal data, because a key exists that could, in theory, restore identity.

That assumption has been seriously challenged by the Single Resolution Board v European Data Protection Supervisor (SRB v EDPS) litigation. In that case, the EU banking resolution authority shared pseudonymised submissions with Deloitte for valuation analysis. Deloitte received only coded data and had no legal or practical access to the re-identification key.

The General Court held that the regulator erred by failing to assess identifiability from the recipient’s perspective. The Court emphasised that the correct test is context-specific: whether the recipient has reasonably likely, lawful means to re-identify the data subjects. In Deloitte’s hands, the data was therefore not personal data at all.

While the matter was successfully appealed, the core principle survived: pseudonymised data is not automatically personal data in every context. Identifiability must be assessed relatively, not abstractly, and regulators must conduct a risk-based analysis, not rely on labels alone  .

The South African echo: substance over assumption

A strikingly similar theme emerges from the recent South African High Court judgment involving the Department of Basic Education and the Information Regulator. In that case, the Information Regulator issued an enforcement notice on the assumption that the publication of matric results using examination numbers necessarily involved the processing of personal information.

The Court was critical of this categorical reasoning. It emphasised that whether information is “personal information” under POPIA depends on identifiability in fact, not on abstract possibility or regulatory assertion. Where learners could not reasonably be identified from the published information, the regulator could not simply presume a POPIA breach. The judgment underscores that regulators must analyse how identification actually occurs, rather than treating all coded or indirect references as inherently personal.

Although the case did not turn expressly on pseudonymisation doctrine, its reasoning aligns closely with SRB v EDPS: identifiability is contextual, evidentiary, and practical, not hypothetical.

The combined effect of these developments is significant:

  • Pseudonymisation can, in the right context, break the link to personal information — particularly for downstream recipients who lack access to re-identification keys.
  • Regulators must perform a risk-based, context-specific assessment of identifiability, rather than assuming that any theoretical re-identification keeps data within scope.
  • Responsible parties must distinguish between data in their own hands and data in the hands of recipients, especially auditors, researchers, and analysts.

This does not mean that pseudonymised data is “safe” in all circumstances. Poorly designed pseudonymisation, unlawful access to keys, or realistic re-identification techniques may still render data personal, but it does mean that the nature of personal information is no longer fixed at the moment of collection; it can change depending on who holds the data and what they can realistically do with it.

A quieter shift with big consequences

Both SRB v EDPS and the South African judgment signal a judicial move away from formalist assumptions toward functional analysis. For organisations, this creates space for more nuanced data-sharing models. For regulators, it raises the bar: assertion is no substitute for analysis.