Data-protection law is triggered by a deceptively simple concept: personal information (“personal data” in the EU). Once information no longer relates to an identified or identifiable person, the entire regulatory framework falls away. The difficulty lies in determining when that line is crossed, particularly where information has been pseudonymised rather than fully anonymised.
Pseudonymisation is not anonymisation — but context matters
Traditionally, regulators have taken an absolute approach: if data can be re-identified by anyone, somewhere, then it remains personal data everywhere. From the perspective, pseudonymised data is always personal data, because a key exists that could, in theory, restore identity.
That assumption has been seriously challenged by the Single Resolution Board v European Data Protection Supervisor (SRB v EDPS) litigation. In that case, the EU banking resolution authority shared pseudonymised submissions with Deloitte for valuation analysis. Deloitte received only coded data and had no legal or practical access to the re-identification key.
The General Court held that the regulator erred by failing to assess identifiability from the recipient’s perspective. The Court emphasised that the correct test is context-specific: whether the recipient has reasonably likely, lawful means to re-identify the data subjects. In Deloitte’s hands, the data was therefore not personal data at all.
While the matter was successfully appealed, the core principle survived: pseudonymised data is not automatically personal data in every context. Identifiability must be assessed relatively, not abstractly, and regulators must conduct a risk-based analysis, not rely on labels alone .
The South African echo: substance over assumption
A strikingly similar theme emerges from the recent South African High Court judgment involving the Department of Basic Education and the Information Regulator. In that case, the Information Regulator issued an enforcement notice on the assumption that the publication of matric results using examination numbers necessarily involved the processing of personal information.
The Court was critical of this categorical reasoning. It emphasised that whether information is “personal information” under POPIA depends on identifiability in fact, not on abstract possibility or regulatory assertion. Where learners could not reasonably be identified from the published information, the regulator could not simply presume a POPIA breach. The judgment underscores that regulators must analyse how identification actually occurs, rather than treating all coded or indirect references as inherently personal.
Although the case did not turn expressly on pseudonymisation doctrine, its reasoning aligns closely with SRB v EDPS: identifiability is contextual, evidentiary, and practical, not hypothetical.
The combined effect of these developments is significant:
- Pseudonymisation can, in the right context, break the link to personal information — particularly for downstream recipients who lack access to re-identification keys.
- Regulators must perform a risk-based, context-specific assessment of identifiability, rather than assuming that any theoretical re-identification keeps data within scope.
- Responsible parties must distinguish between data in their own hands and data in the hands of recipients, especially auditors, researchers, and analysts.
This does not mean that pseudonymised data is “safe” in all circumstances. Poorly designed pseudonymisation, unlawful access to keys, or realistic re-identification techniques may still render data personal, but it does mean that the nature of personal information is no longer fixed at the moment of collection; it can change depending on who holds the data and what they can realistically do with it.
A quieter shift with big consequences
Both SRB v EDPS and the South African judgment signal a judicial move away from formalist assumptions toward functional analysis. For organisations, this creates space for more nuanced data-sharing models. For regulators, it raises the bar: assertion is no substitute for analysis.
