<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Insights</title>
    <link>https://www.regulyn.com/insights</link>
    <description>Regulyn Insights on AI, R&amp;D and data protection regulation.</description>
    <language>en</language>
    <pubDate>Wed, 29 Jul 2026 10:24:47 GMT</pubDate>
    <dc:date>2026-07-29T10:24:47Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Research Regulation in Finland - 2026 Edition</title>
      <link>https://www.regulyn.com/insights/fi-fi/insights/research-regulation-finland</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.regulyn.com/insights/fi-fi/insights/research-regulation-finland?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.regulyn.com/hubfs/Research_Genetics.png" alt="Research Regulation in Finland - 2026 Edition" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: var(--body-font-line-height);"&gt;In Finland, research regulation is extensive and precisely defines how clinical trials may be conducted and data used. Staying up to date on these regulations while focusing on your daily work can be time-consuming.&lt;/p&gt; 
&lt;p style="line-height: var(--body-font-line-height);"&gt;At Regulyn, we have compiled key legislation related to clinical research and health and social services registry research. The goal is to make the work of researchers and healthcare professionals easier. This way, you can return focus to your passion.&lt;/p&gt; 
&lt;p style="line-height: var(--body-font-line-height);"&gt;This list is updated regularly (last updated May 1, 2026).&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.regulyn.com/insights/fi-fi/insights/research-regulation-finland?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.regulyn.com/hubfs/Research_Genetics.png" alt="Research Regulation in Finland - 2026 Edition" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: var(--body-font-line-height);"&gt;In Finland, research regulation is extensive and precisely defines how clinical trials may be conducted and data used. Staying up to date on these regulations while focusing on your daily work can be time-consuming.&lt;/p&gt; 
&lt;p style="line-height: var(--body-font-line-height);"&gt;At Regulyn, we have compiled key legislation related to clinical research and health and social services registry research. The goal is to make the work of researchers and healthcare professionals easier. This way, you can return focus to your passion.&lt;/p&gt; 
&lt;p style="line-height: var(--body-font-line-height);"&gt;This list is updated regularly (last updated May 1, 2026).&lt;/p&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=147848222&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.regulyn.com%2Finsights%2Ffi-fi%2Finsights%2Fresearch-regulation-finland&amp;amp;bu=https%253A%252F%252Fwww.regulyn.com%252Finsights&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Wed, 29 Jul 2026 10:23:28 GMT</pubDate>
      <author>katri.harjuvetelainen@regulyn.com (Katri Harjuveteläinen)</author>
      <guid>https://www.regulyn.com/insights/fi-fi/insights/research-regulation-finland</guid>
      <dc:date>2026-07-29T10:23:28Z</dc:date>
    </item>
    <item>
      <title>EU AI Act Risk Categories</title>
      <link>https://www.regulyn.com/insights/eu-ai-act-risk-categories</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.regulyn.com/insights/eu-ai-act-risk-categories?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.regulyn.com/hubfs/AI_and_human.jpg" alt="EU AI Act Risk Categories" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div style="height: auto;"&gt; 
 &lt;h5 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-4-size-value))/25));"&gt;The &lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689#tit_1" style="text-decoration-line: underline; text-decoration-thickness: 1px;"&gt;&lt;u&gt;&lt;span&gt;EU Artificial Intelligence Act&lt;/span&gt;&lt;/u&gt;&lt;/a&gt; (“EU AI Act”) is the first comprehensive legal framework governing AI systems. It introduces a risk-based approach, classifying AI systems into four categories. This tiered approach ensures that regulatory burden matches the potential harm an AI system could cause.&lt;/h5&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;Understanding these classifications is essential for organizations operating AI systems in the European market.&lt;/p&gt; 
 &lt;h2&gt;Prohibited AI Systems (Unacceptable Risk)&lt;/h2&gt; 
 &lt;br&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;Certain AI practices are &lt;span style="font-weight: bold;"&gt;entirely banned&lt;/span&gt; within the EU due to unacceptable risks to fundamental rights and safety.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;&#x1f6ab; Prohibited practices include:&lt;/strong&gt;&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Subliminal manipulation techniques&lt;/li&gt; 
  &lt;li&gt;Exploitation of vulnerabilities (related to age, disability, or socio-economic status)&lt;/li&gt; 
  &lt;li&gt;Social scoring&lt;/li&gt; 
  &lt;li&gt;Real-time remote biometric identification (narrow exceptions apply)&lt;/li&gt; 
  &lt;li&gt;Biometric categorization using sensitive attributes (race, political opinions, sexual orientation)&lt;/li&gt; 
  &lt;li&gt;Emotion recognition in workplace and educational settings&lt;/li&gt; 
  &lt;li&gt;Untargeted scraping of facial images (from internet or CCTV)&lt;/li&gt; 
  &lt;li&gt;Specific use cases in law enforcement (limited exceptions exist)&lt;/li&gt; 
  &lt;li&gt;NEW: nudifiers and generation of unconsentual sexual images&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;The prohibition applies both to the intended purpose and the actual effect of an AI system. An AI system producing manipulative or exploitative effects falls under the prohibition even where such outcomes were unintended.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Compliance consideration:&lt;/strong&gt; Organizations must ensure prohibited AI systems are not placed on the market, put into service, or used within EU territory. The ban applies regardless of where the system was developed.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Example:&lt;/strong&gt; A multinational corporation cannot deploy emotion recognition technology to assess employee engagement, motivation, or dissatisfaction in its EU offices, even if the same system operates legally in non-EU locations.&lt;/p&gt; 
 &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;High-Risk AI Systems&lt;/h2&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;⚠️ &lt;span style="font-weight: bold;"&gt;High-risk AI systems &lt;/span&gt;face the most extensive regulatory requirements under the EU AI Act. Two pathways lead to high-risk classification.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;First pathway:&lt;/strong&gt; AI systems serving as safety components of products covered by EU harmonization legislation (such as medical devices, machinery, or aviation equipment), or products themselves subject to such legislation.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Second pathway:&lt;/strong&gt; AI systems operating in specific application areas listed in Annex III:&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Biometric identification and categorization&lt;/li&gt; 
  &lt;li&gt;Management and operation of critical infrastructure&lt;/li&gt; 
  &lt;li&gt;Education and vocational training (determining access, assessing learning outcomes)&lt;/li&gt; 
  &lt;li&gt;Employment, worker management, and access to self-employment (recruitment, promotion, contract termination)&lt;/li&gt; 
  &lt;li&gt;Access to essential private services and public assistance benefits&lt;/li&gt; 
  &lt;li&gt;Law enforcement (risk assessments, evaluation of evidence reliability)&lt;/li&gt; 
  &lt;li&gt;Migration, asylum, and border control management&lt;/li&gt; 
  &lt;li&gt;Administration of justice and democratic processes&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;De minimis exception:&lt;/strong&gt; Annex III systems avoid high-risk classification when they perform narrow procedural tasks, improve human activity results, or detect decision-making patterns—provided they do not replace human assessment and do not materially influence outcomes.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Compliance obligations for high-risk systems include:&lt;/strong&gt;&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Comprehensive risk management system&lt;/li&gt; 
  &lt;li&gt;Data governance and management practices&lt;/li&gt; 
  &lt;li&gt;Technical documentation&lt;/li&gt; 
  &lt;li&gt;Automatic logging capabilities&lt;/li&gt; 
  &lt;li&gt;Transparency and information provision&lt;/li&gt; 
  &lt;li&gt;Human oversight measures&lt;/li&gt; 
  &lt;li&gt;Accuracy, robustness, and cybersecurity requirements&lt;/li&gt; 
  &lt;li&gt;Quality management system&lt;/li&gt; 
  &lt;li&gt;Registration in EU database&lt;/li&gt; 
  &lt;li&gt;Post-market monitoring&lt;/li&gt; 
  &lt;li&gt;Incident reporting obligations&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;Obligations fall primarily on providers (those placing systems on the market or putting them into service). Deployers face specific requirements including human oversight implementation, input data monitoring, use according to instructions, and registration duties.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Examples:&lt;/strong&gt;&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;em&gt;Recruitment AI:&lt;/em&gt; An organization uses AI to screen CVs, rank candidates based on predicted performance, or recommend hiring decisions. This qualifies as high-risk employment AI requiring comprehensive documentation, risk management, and human oversight.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;em&gt;Medical device AI:&lt;/em&gt; A healthcare provider implements AI software analyzing real-time patient conversations to assess depression or anxiety severity. The system likely falls under both EU AI Act high-risk requirements (as safety component software) and Medical Device Regulation obligations, requiring dual compliance.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Compliance consideration:&lt;/strong&gt; Organizations often benefit from structured legal support when implementing high-risk AI systems given the breadth of obligations and potential penalties for non-compliance (up to €35 million or 7% of global annual turnover).&lt;/p&gt; 
 &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Limited-Risk AI Systems&lt;/h2&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&#x1f916; Limited-risk AI systems trigger primarily transparency obligations under Chapter IV of the EU AI Act. While not explicitly defined as a risk category, these systems typically involve human interaction or synthetic content generation.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Transparency requirements apply when:&lt;/strong&gt;&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;AI systems interact directly with natural persons (Article 50)&lt;/li&gt; 
  &lt;li&gt;AI generates or manipulates image, audio, or video content (deepfakes)&lt;/li&gt; 
  &lt;li&gt;AI generates or manipulates text for public information purposes&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Provider obligations include:&lt;/strong&gt;&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Disclosing AI interaction to users (chatbots, virtual assistants)&lt;/li&gt; 
  &lt;li&gt;Labeling AI-generated or manipulated content (synthetic media)&lt;/li&gt; 
  &lt;li&gt;Designing systems to enable deployers to meet their transparency obligations&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Deployer obligations include:&lt;/strong&gt;&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Informing natural persons when emotion recognition or biometric categorization AI processes their data&lt;/li&gt; 
  &lt;li&gt;Disclosing deepfakes and AI-manipulated text published to inform the public (exceptions for authorized detection activities, content clearly labeled as parody/satire)&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Example:&lt;/strong&gt; A government agency implements an AI chatbot on its public website to help citizens navigate services and locate information. The chatbot must clearly disclose to users that they are interacting with an AI system rather than a human agent.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Compliance consideration:&lt;/strong&gt; Transparency obligations may also arise under other regulations, particularly GDPR Article 13-14 (information to data subjects) and Article 22 (automated decision-making). Organizations should ensure coordinated compliance across applicable frameworks.&lt;/p&gt; 
 &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Minimal-Risk AI Systems&lt;/h2&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&#x1f197; Some AI applications fall into the minimal-risk category, facing no specific obligations under the EU AI Act. These systems pose no risk to safety, health, or fundamental rights.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;The Act encourages but does not mandate voluntary codes of conduct for minimal-risk AI. Organizations may adopt such codes to demonstrate responsible AI practices and align with broader governance expectations.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Examples:&lt;/strong&gt;&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;em&gt;Spam filtering:&lt;/em&gt; Email systems using AI to detect and categorize spam messages&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;em&gt;Video enhancement:&lt;/em&gt; Creative software applying AI for color correction, resolution enhancement, or editing assistance&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Compliance consideration:&lt;/strong&gt; While the EU AI Act imposes no specific requirements, minimal-risk AI remains subject to other applicable regulation. GDPR requirements apply where personal data processing occurs. Sector-specific rules may impose additional obligations depending on the application context.&lt;/p&gt; 
 &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Classification Methodology&lt;/h2&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;Determining correct risk classification requires systematic analysis.&lt;/p&gt; 
 &lt;ol&gt; 
  &lt;li&gt;&lt;strong&gt;Prohibited use check:&lt;/strong&gt; Does the system or its effects fall within Article 5 prohibitions?&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Harmonized legislation assessment:&lt;/strong&gt; Does the AI system serve as a safety component for products under EU harmonization legislation?&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Annex III evaluation:&lt;/strong&gt; Does the system operate in a listed high-risk application area? If yes, does the de minimis exception apply?&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Transparency trigger analysis:&lt;/strong&gt; Does the system interact with humans or generate synthetic content?&lt;/li&gt; 
 &lt;/ol&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Compliance consideration:&lt;/strong&gt; Classification is not always straightforward, particularly for general-purpose AI systems, AI components within larger products, or systems with multiple functions. Organizations facing classification uncertainty benefit from legal assessment early in development or deployment planning.&lt;/p&gt; 
 &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Practical Next Steps&lt;/h2&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;Organizations operating AI systems in the EU market should prioritize:&lt;/p&gt; 
 &lt;ol&gt; 
  &lt;li&gt;&lt;strong&gt;System inventory:&lt;/strong&gt; Document all AI systems in use or development, including purpose, data sources, and deployment contexts&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Classification assessment:&lt;/strong&gt; Apply the risk-based framework to each identified system&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Obligation mapping:&lt;/strong&gt; Identify specific compliance requirements for each classified system&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Gap analysis:&lt;/strong&gt; Assess current practices against required documentation, technical measures, and governance structures&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Implementation planning:&lt;/strong&gt; Develop timelines and resource allocation for achieving compliance&lt;/li&gt; 
 &lt;/ol&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;Organizations with high-risk AI systems face the most substantial compliance burden and should consider structured legal support to ensure comprehensive implementation of required controls.&lt;/p&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.regulyn.com/insights/eu-ai-act-risk-categories?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.regulyn.com/hubfs/AI_and_human.jpg" alt="EU AI Act Risk Categories" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div style="height: auto;"&gt; 
 &lt;h5 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-4-size-value))/25));"&gt;The &lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689#tit_1" style="text-decoration-line: underline; text-decoration-thickness: 1px;"&gt;&lt;u&gt;&lt;span&gt;EU Artificial Intelligence Act&lt;/span&gt;&lt;/u&gt;&lt;/a&gt; (“EU AI Act”) is the first comprehensive legal framework governing AI systems. It introduces a risk-based approach, classifying AI systems into four categories. This tiered approach ensures that regulatory burden matches the potential harm an AI system could cause.&lt;/h5&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;Understanding these classifications is essential for organizations operating AI systems in the European market.&lt;/p&gt; 
 &lt;h2&gt;Prohibited AI Systems (Unacceptable Risk)&lt;/h2&gt; 
 &lt;br&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;Certain AI practices are &lt;span style="font-weight: bold;"&gt;entirely banned&lt;/span&gt; within the EU due to unacceptable risks to fundamental rights and safety.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;&#x1f6ab; Prohibited practices include:&lt;/strong&gt;&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Subliminal manipulation techniques&lt;/li&gt; 
  &lt;li&gt;Exploitation of vulnerabilities (related to age, disability, or socio-economic status)&lt;/li&gt; 
  &lt;li&gt;Social scoring&lt;/li&gt; 
  &lt;li&gt;Real-time remote biometric identification (narrow exceptions apply)&lt;/li&gt; 
  &lt;li&gt;Biometric categorization using sensitive attributes (race, political opinions, sexual orientation)&lt;/li&gt; 
  &lt;li&gt;Emotion recognition in workplace and educational settings&lt;/li&gt; 
  &lt;li&gt;Untargeted scraping of facial images (from internet or CCTV)&lt;/li&gt; 
  &lt;li&gt;Specific use cases in law enforcement (limited exceptions exist)&lt;/li&gt; 
  &lt;li&gt;NEW: nudifiers and generation of unconsentual sexual images&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;The prohibition applies both to the intended purpose and the actual effect of an AI system. An AI system producing manipulative or exploitative effects falls under the prohibition even where such outcomes were unintended.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Compliance consideration:&lt;/strong&gt; Organizations must ensure prohibited AI systems are not placed on the market, put into service, or used within EU territory. The ban applies regardless of where the system was developed.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Example:&lt;/strong&gt; A multinational corporation cannot deploy emotion recognition technology to assess employee engagement, motivation, or dissatisfaction in its EU offices, even if the same system operates legally in non-EU locations.&lt;/p&gt; 
 &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;High-Risk AI Systems&lt;/h2&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;⚠️ &lt;span style="font-weight: bold;"&gt;High-risk AI systems &lt;/span&gt;face the most extensive regulatory requirements under the EU AI Act. Two pathways lead to high-risk classification.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;First pathway:&lt;/strong&gt; AI systems serving as safety components of products covered by EU harmonization legislation (such as medical devices, machinery, or aviation equipment), or products themselves subject to such legislation.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Second pathway:&lt;/strong&gt; AI systems operating in specific application areas listed in Annex III:&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Biometric identification and categorization&lt;/li&gt; 
  &lt;li&gt;Management and operation of critical infrastructure&lt;/li&gt; 
  &lt;li&gt;Education and vocational training (determining access, assessing learning outcomes)&lt;/li&gt; 
  &lt;li&gt;Employment, worker management, and access to self-employment (recruitment, promotion, contract termination)&lt;/li&gt; 
  &lt;li&gt;Access to essential private services and public assistance benefits&lt;/li&gt; 
  &lt;li&gt;Law enforcement (risk assessments, evaluation of evidence reliability)&lt;/li&gt; 
  &lt;li&gt;Migration, asylum, and border control management&lt;/li&gt; 
  &lt;li&gt;Administration of justice and democratic processes&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;De minimis exception:&lt;/strong&gt; Annex III systems avoid high-risk classification when they perform narrow procedural tasks, improve human activity results, or detect decision-making patterns—provided they do not replace human assessment and do not materially influence outcomes.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Compliance obligations for high-risk systems include:&lt;/strong&gt;&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Comprehensive risk management system&lt;/li&gt; 
  &lt;li&gt;Data governance and management practices&lt;/li&gt; 
  &lt;li&gt;Technical documentation&lt;/li&gt; 
  &lt;li&gt;Automatic logging capabilities&lt;/li&gt; 
  &lt;li&gt;Transparency and information provision&lt;/li&gt; 
  &lt;li&gt;Human oversight measures&lt;/li&gt; 
  &lt;li&gt;Accuracy, robustness, and cybersecurity requirements&lt;/li&gt; 
  &lt;li&gt;Quality management system&lt;/li&gt; 
  &lt;li&gt;Registration in EU database&lt;/li&gt; 
  &lt;li&gt;Post-market monitoring&lt;/li&gt; 
  &lt;li&gt;Incident reporting obligations&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;Obligations fall primarily on providers (those placing systems on the market or putting them into service). Deployers face specific requirements including human oversight implementation, input data monitoring, use according to instructions, and registration duties.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Examples:&lt;/strong&gt;&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;em&gt;Recruitment AI:&lt;/em&gt; An organization uses AI to screen CVs, rank candidates based on predicted performance, or recommend hiring decisions. This qualifies as high-risk employment AI requiring comprehensive documentation, risk management, and human oversight.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;em&gt;Medical device AI:&lt;/em&gt; A healthcare provider implements AI software analyzing real-time patient conversations to assess depression or anxiety severity. The system likely falls under both EU AI Act high-risk requirements (as safety component software) and Medical Device Regulation obligations, requiring dual compliance.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Compliance consideration:&lt;/strong&gt; Organizations often benefit from structured legal support when implementing high-risk AI systems given the breadth of obligations and potential penalties for non-compliance (up to €35 million or 7% of global annual turnover).&lt;/p&gt; 
 &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Limited-Risk AI Systems&lt;/h2&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&#x1f916; Limited-risk AI systems trigger primarily transparency obligations under Chapter IV of the EU AI Act. While not explicitly defined as a risk category, these systems typically involve human interaction or synthetic content generation.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Transparency requirements apply when:&lt;/strong&gt;&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;AI systems interact directly with natural persons (Article 50)&lt;/li&gt; 
  &lt;li&gt;AI generates or manipulates image, audio, or video content (deepfakes)&lt;/li&gt; 
  &lt;li&gt;AI generates or manipulates text for public information purposes&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Provider obligations include:&lt;/strong&gt;&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Disclosing AI interaction to users (chatbots, virtual assistants)&lt;/li&gt; 
  &lt;li&gt;Labeling AI-generated or manipulated content (synthetic media)&lt;/li&gt; 
  &lt;li&gt;Designing systems to enable deployers to meet their transparency obligations&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Deployer obligations include:&lt;/strong&gt;&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Informing natural persons when emotion recognition or biometric categorization AI processes their data&lt;/li&gt; 
  &lt;li&gt;Disclosing deepfakes and AI-manipulated text published to inform the public (exceptions for authorized detection activities, content clearly labeled as parody/satire)&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Example:&lt;/strong&gt; A government agency implements an AI chatbot on its public website to help citizens navigate services and locate information. The chatbot must clearly disclose to users that they are interacting with an AI system rather than a human agent.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Compliance consideration:&lt;/strong&gt; Transparency obligations may also arise under other regulations, particularly GDPR Article 13-14 (information to data subjects) and Article 22 (automated decision-making). Organizations should ensure coordinated compliance across applicable frameworks.&lt;/p&gt; 
 &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Minimal-Risk AI Systems&lt;/h2&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&#x1f197; Some AI applications fall into the minimal-risk category, facing no specific obligations under the EU AI Act. These systems pose no risk to safety, health, or fundamental rights.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;The Act encourages but does not mandate voluntary codes of conduct for minimal-risk AI. Organizations may adopt such codes to demonstrate responsible AI practices and align with broader governance expectations.&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Examples:&lt;/strong&gt;&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;em&gt;Spam filtering:&lt;/em&gt; Email systems using AI to detect and categorize spam messages&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;em&gt;Video enhancement:&lt;/em&gt; Creative software applying AI for color correction, resolution enhancement, or editing assistance&lt;/p&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Compliance consideration:&lt;/strong&gt; While the EU AI Act imposes no specific requirements, minimal-risk AI remains subject to other applicable regulation. GDPR requirements apply where personal data processing occurs. Sector-specific rules may impose additional obligations depending on the application context.&lt;/p&gt; 
 &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Classification Methodology&lt;/h2&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;Determining correct risk classification requires systematic analysis.&lt;/p&gt; 
 &lt;ol&gt; 
  &lt;li&gt;&lt;strong&gt;Prohibited use check:&lt;/strong&gt; Does the system or its effects fall within Article 5 prohibitions?&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Harmonized legislation assessment:&lt;/strong&gt; Does the AI system serve as a safety component for products under EU harmonization legislation?&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Annex III evaluation:&lt;/strong&gt; Does the system operate in a listed high-risk application area? If yes, does the de minimis exception apply?&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Transparency trigger analysis:&lt;/strong&gt; Does the system interact with humans or generate synthetic content?&lt;/li&gt; 
 &lt;/ol&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Compliance consideration:&lt;/strong&gt; Classification is not always straightforward, particularly for general-purpose AI systems, AI components within larger products, or systems with multiple functions. Organizations facing classification uncertainty benefit from legal assessment early in development or deployment planning.&lt;/p&gt; 
 &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Practical Next Steps&lt;/h2&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;Organizations operating AI systems in the EU market should prioritize:&lt;/p&gt; 
 &lt;ol&gt; 
  &lt;li&gt;&lt;strong&gt;System inventory:&lt;/strong&gt; Document all AI systems in use or development, including purpose, data sources, and deployment contexts&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Classification assessment:&lt;/strong&gt; Apply the risk-based framework to each identified system&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Obligation mapping:&lt;/strong&gt; Identify specific compliance requirements for each classified system&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Gap analysis:&lt;/strong&gt; Assess current practices against required documentation, technical measures, and governance structures&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Implementation planning:&lt;/strong&gt; Develop timelines and resource allocation for achieving compliance&lt;/li&gt; 
 &lt;/ol&gt; 
 &lt;p style="line-height: var(--body-font-line-height);"&gt;Organizations with high-risk AI systems face the most substantial compliance burden and should consider structured legal support to ensure comprehensive implementation of required controls.&lt;/p&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=147848222&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.regulyn.com%2Finsights%2Feu-ai-act-risk-categories&amp;amp;bu=https%253A%252F%252Fwww.regulyn.com%252Finsights&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>AI</category>
      <category>AI Act</category>
      <pubDate>Tue, 28 Jul 2026 20:05:56 GMT</pubDate>
      <author>katri.harjuvetelainen@regulyn.com (Katri Harjuveteläinen)</author>
      <guid>https://www.regulyn.com/insights/eu-ai-act-risk-categories</guid>
      <dc:date>2026-07-28T20:05:56Z</dc:date>
    </item>
    <item>
      <title>SRB Ruling - Can pseudonymization make data anonymous?</title>
      <link>https://www.regulyn.com/insights/srb-ruling-can-pseudonymization-make-data-anonymous</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.regulyn.com/insights/srb-ruling-can-pseudonymization-make-data-anonymous?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.regulyn.com/hubfs/Screenshot%202026-07-29%20at%2010.19.18.png" alt="SRB Ruling - Can pseudonymization make data anonymous?" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div style="color: #0d2755;"&gt; 
 &lt;div style="width: auto;"&gt; 
  &lt;div style="width: 856.75px;"&gt; 
   &lt;div style="height: auto;"&gt; 
    &lt;h5 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-4-size-value))/25));"&gt;The Court of Justice of the European Union delivered a landmark judgment in September 2025 that fundamentally clarifies how pseudonymization affects data protection obligations.&lt;/h5&gt; 
    &lt;h5 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-4-size-value))/25));"&gt;The ruling in &lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62023CJ0413" style="text-decoration-line: underline; text-decoration-thickness: 1px;"&gt;&lt;em&gt;EDPS v SRB&lt;/em&gt;&lt;span&gt; &lt;/span&gt;(C-413/23 P)&lt;/a&gt; addresses a question that compliance teams have wrestled with for years: when does pseudonymized data stop being personal data?&lt;/h5&gt; 
    &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;The Case: Banking Resolution and Data Sharing&lt;/h2&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The dispute arose from the 2017 resolution of Banco Popular Español. The Single Resolution Board (SRB) collected comments from affected shareholders and creditors through an online consultation process. Participants provided identity documents during registration, then submitted comments through a form that assigned each comment a unique code.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The SRB shared coded comments with Deloitte for valuation purposes—but not the registration data needed to identify the authors. The European Data Protection Supervisor found this violated transparency obligations. The SRB argued the comments were not personal data from Deloitte's perspective. The case reached the CJEU.&lt;/p&gt; 
    &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Three Key Rulings&lt;/h2&gt; 
    &lt;h4 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-4-size-value))/25));"&gt;1. Personal Opinions Are Personal Data&lt;/h4&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The Court ruled that &lt;span style="font-weight: bold;"&gt;personal opinions and views constitute personal data&lt;/span&gt; because "as an expression of a person's thinking, [they] are necessarily closely linked to that person." This applies regardless of whether the content explicitly identifies the author.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The Court emphasized that when information constitutes personal opinions, no additional examination of content, purpose, or effect is needed to establish that it "relates to" a natural person under Article 4(1) GDPR (and Article 3(1) of Regulation 2018/1725). The subjective nature of opinions creates an inherent link to their authors.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;This builds on the Court's earlier ruling in &lt;em&gt;Nowak&lt;/em&gt; (C-434/16), where examiner comments about a candidate's performance were held to constitute personal data both about the candidate and the examiner.&lt;/p&gt; 
    &lt;h4 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-4-size-value))/25));"&gt;2. Pseudonymization Can Make Data Anonymous&lt;/h4&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The Court's most significant holding addresses pseudonymization directly. Pseudonymized data "must not be regarded as constituting, in all cases and for every person, personal data" when "pseudonymization may, depending on the circumstances of the case, effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable."&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;This means the &lt;span style="font-weight: bold;"&gt;same dataset can be:&lt;/span&gt;&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt;&lt;strong&gt;Personal data&lt;/strong&gt; for the controller (who retains the means to re-identify individuals)&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;Anonymous data&lt;/strong&gt; for recipients (who lack any reasonable means of identification)&lt;/li&gt; 
    &lt;/ul&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The critical factors are whether the recipient has access to:&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt;The additional information needed for re-identification&lt;/li&gt; 
     &lt;li&gt;Legal means to obtain such information&lt;/li&gt; 
     &lt;li&gt;Practical ability to cross-reference with other data&lt;/li&gt; 
    &lt;/ul&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The &lt;strong&gt;risk of identification must be "insignificant&lt;/strong&gt;", meaning identification is prohibited by law or impossible in practice because it would require disproportionate effort in terms of time, cost, and labor.&lt;/p&gt; 
    &lt;h4 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-4-size-value))/25));"&gt;3. Controllers Must Disclose All Recipients When Collecting Data&lt;/h4&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The third ruling resolves the procedural question: when must the controller inform data subjects about recipients?&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The Court held that the obligation under Article 15 to inform data subjects about recipients applies "prior to the transfer of the data at issue and irrespective of whether or not those data were personal data" from the recipient's perspective after pseudonymization. The assessment of whether data are personal must be made:&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt;&lt;strong&gt;At the time of collection&lt;/strong&gt; (not transfer)&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;From the controller's perspective&lt;/strong&gt; (not the recipient's)&lt;/li&gt; 
    &lt;/ul&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;This timing matters because the information allows data subjects to "decide, in full knowledge of the facts, whether to provide or, on the contrary, refuse to provide the personal data being collected." The transparency obligation protects the relationship between the data subject and the controller - it cannot depend on what happens after data are transferred to third parties.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;Put simply, this means that &lt;strong&gt;the controller must include all foreseeable disclosures into the privacy notice&lt;/strong&gt;, regardless of whether the data is anonymous to the recipient or not.&lt;/p&gt; 
    &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Practical Recommendations&lt;/h2&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;Organizations processing pseudonymized data should:&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt;&lt;strong&gt;Review and update privacy notices.&lt;/strong&gt; Privacy notices provided at data collection should identify all entities that will receive personal data, regardless of pseudonymization. This is particularly important for research studies and clinical trials with extended timelines and multiple data recipients.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;Document pseudonymization measures.&lt;/strong&gt; Organizations should create detailed records of technical measures preventing re-identification by recipients, organizational measures (contractual restrictions, access controls) and risk assessments of identification likelihood.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;Conduct recipient-specific assessments.&lt;/strong&gt; When sharing pseudonymized data, organizations should evaluate each recipient's ability to identify individuals and document why data should be considered anonymous from that recipient's perspective.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;Train staff on the distinction.&lt;/strong&gt; The ruling confirms that "personal data" is not a fixed characteristic of a dataset—it depends on who is processing the data and what means they have available. Teams need to understand when data transition from personal to anonymous.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;Consider contractual protections.&lt;/strong&gt; When sharing pseudonymized data, contracts should explicitly prohibit recipients from attempting re-identification and from combining the data with other sources that could enable identification.&lt;/li&gt; 
    &lt;/ul&gt; 
    &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Conclusion&lt;/h2&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The &lt;em&gt;EDPS v SRB&lt;/em&gt; judgment brings needed clarity to pseudonymization's role in data protection. Pseudonymization can make data anonymous, but &lt;span style="font-weight: bold;"&gt;only &lt;/span&gt;when technical and organizational measures effectively prevent identification by the recipient.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;For controllers, this ruling emphasizes that transparency obligations attach at the point of collection and not at what happens after collection. For recipients, it confirms that careful assessment is needed before treating pseudonymized data as anonymous.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The practical effect is that pseudonymization becomes a more reliable privacy-enhancing technique when properly implemented, but controllers bear the burden of demonstrating that recipients genuinely cannot identify individuals.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;This ruling brings &lt;span style="font-weight: bold;"&gt;new opportunities for data sharing&lt;/span&gt; but only if implemented properly.&lt;/p&gt; 
    &lt;h3 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-3-size-value))/25));"&gt;Further Reading&lt;/h3&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;For additional context on data protection and pseudonymization:&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt;&lt;strong&gt;CJEU Judgment:&lt;/strong&gt; &lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62023CJ0413" style="text-decoration-line: underline; text-decoration-thickness: 1px;"&gt;EDPS v SRB (C-413/23 P)&lt;/a&gt;, 4 September 2025&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;GDPR Article 4(5):&lt;/strong&gt; &lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679#art_4" style="text-decoration-line: underline; text-decoration-thickness: 1px;"&gt;Definition of pseudonymization&lt;/a&gt;&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;Recital 26 GDPR:&lt;/strong&gt; &lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679#rct_26" style="text-decoration-line: underline; text-decoration-thickness: 1px;"&gt;Principles of data protection and pseudonymization&lt;/a&gt;&lt;/li&gt; 
    &lt;/ul&gt; 
   &lt;/div&gt; 
   &lt;div style="height: auto;"&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Note:&lt;/strong&gt; This article reflects the CJEU's ruling in Case C-413/23 P, &lt;em&gt;EDPS v SRB&lt;/em&gt;, judgment of 4 September 2025. Organizations should consult legal counsel regarding application to specific circumstances, particularly where national data protection authorities have issued additional guidance on pseudonymization.&lt;/p&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.regulyn.com/insights/srb-ruling-can-pseudonymization-make-data-anonymous?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.regulyn.com/hubfs/Screenshot%202026-07-29%20at%2010.19.18.png" alt="SRB Ruling - Can pseudonymization make data anonymous?" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div style="color: #0d2755;"&gt; 
 &lt;div style="width: auto;"&gt; 
  &lt;div style="width: 856.75px;"&gt; 
   &lt;div style="height: auto;"&gt; 
    &lt;h5 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-4-size-value))/25));"&gt;The Court of Justice of the European Union delivered a landmark judgment in September 2025 that fundamentally clarifies how pseudonymization affects data protection obligations.&lt;/h5&gt; 
    &lt;h5 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-4-size-value))/25));"&gt;The ruling in &lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62023CJ0413" style="text-decoration-line: underline; text-decoration-thickness: 1px;"&gt;&lt;em&gt;EDPS v SRB&lt;/em&gt;&lt;span&gt; &lt;/span&gt;(C-413/23 P)&lt;/a&gt; addresses a question that compliance teams have wrestled with for years: when does pseudonymized data stop being personal data?&lt;/h5&gt; 
    &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;The Case: Banking Resolution and Data Sharing&lt;/h2&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The dispute arose from the 2017 resolution of Banco Popular Español. The Single Resolution Board (SRB) collected comments from affected shareholders and creditors through an online consultation process. Participants provided identity documents during registration, then submitted comments through a form that assigned each comment a unique code.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The SRB shared coded comments with Deloitte for valuation purposes—but not the registration data needed to identify the authors. The European Data Protection Supervisor found this violated transparency obligations. The SRB argued the comments were not personal data from Deloitte's perspective. The case reached the CJEU.&lt;/p&gt; 
    &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Three Key Rulings&lt;/h2&gt; 
    &lt;h4 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-4-size-value))/25));"&gt;1. Personal Opinions Are Personal Data&lt;/h4&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The Court ruled that &lt;span style="font-weight: bold;"&gt;personal opinions and views constitute personal data&lt;/span&gt; because "as an expression of a person's thinking, [they] are necessarily closely linked to that person." This applies regardless of whether the content explicitly identifies the author.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The Court emphasized that when information constitutes personal opinions, no additional examination of content, purpose, or effect is needed to establish that it "relates to" a natural person under Article 4(1) GDPR (and Article 3(1) of Regulation 2018/1725). The subjective nature of opinions creates an inherent link to their authors.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;This builds on the Court's earlier ruling in &lt;em&gt;Nowak&lt;/em&gt; (C-434/16), where examiner comments about a candidate's performance were held to constitute personal data both about the candidate and the examiner.&lt;/p&gt; 
    &lt;h4 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-4-size-value))/25));"&gt;2. Pseudonymization Can Make Data Anonymous&lt;/h4&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The Court's most significant holding addresses pseudonymization directly. Pseudonymized data "must not be regarded as constituting, in all cases and for every person, personal data" when "pseudonymization may, depending on the circumstances of the case, effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable."&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;This means the &lt;span style="font-weight: bold;"&gt;same dataset can be:&lt;/span&gt;&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt;&lt;strong&gt;Personal data&lt;/strong&gt; for the controller (who retains the means to re-identify individuals)&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;Anonymous data&lt;/strong&gt; for recipients (who lack any reasonable means of identification)&lt;/li&gt; 
    &lt;/ul&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The critical factors are whether the recipient has access to:&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt;The additional information needed for re-identification&lt;/li&gt; 
     &lt;li&gt;Legal means to obtain such information&lt;/li&gt; 
     &lt;li&gt;Practical ability to cross-reference with other data&lt;/li&gt; 
    &lt;/ul&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The &lt;strong&gt;risk of identification must be "insignificant&lt;/strong&gt;", meaning identification is prohibited by law or impossible in practice because it would require disproportionate effort in terms of time, cost, and labor.&lt;/p&gt; 
    &lt;h4 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-4-size-value))/25));"&gt;3. Controllers Must Disclose All Recipients When Collecting Data&lt;/h4&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The third ruling resolves the procedural question: when must the controller inform data subjects about recipients?&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The Court held that the obligation under Article 15 to inform data subjects about recipients applies "prior to the transfer of the data at issue and irrespective of whether or not those data were personal data" from the recipient's perspective after pseudonymization. The assessment of whether data are personal must be made:&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt;&lt;strong&gt;At the time of collection&lt;/strong&gt; (not transfer)&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;From the controller's perspective&lt;/strong&gt; (not the recipient's)&lt;/li&gt; 
    &lt;/ul&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;This timing matters because the information allows data subjects to "decide, in full knowledge of the facts, whether to provide or, on the contrary, refuse to provide the personal data being collected." The transparency obligation protects the relationship between the data subject and the controller - it cannot depend on what happens after data are transferred to third parties.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;Put simply, this means that &lt;strong&gt;the controller must include all foreseeable disclosures into the privacy notice&lt;/strong&gt;, regardless of whether the data is anonymous to the recipient or not.&lt;/p&gt; 
    &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Practical Recommendations&lt;/h2&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;Organizations processing pseudonymized data should:&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt;&lt;strong&gt;Review and update privacy notices.&lt;/strong&gt; Privacy notices provided at data collection should identify all entities that will receive personal data, regardless of pseudonymization. This is particularly important for research studies and clinical trials with extended timelines and multiple data recipients.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;Document pseudonymization measures.&lt;/strong&gt; Organizations should create detailed records of technical measures preventing re-identification by recipients, organizational measures (contractual restrictions, access controls) and risk assessments of identification likelihood.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;Conduct recipient-specific assessments.&lt;/strong&gt; When sharing pseudonymized data, organizations should evaluate each recipient's ability to identify individuals and document why data should be considered anonymous from that recipient's perspective.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;Train staff on the distinction.&lt;/strong&gt; The ruling confirms that "personal data" is not a fixed characteristic of a dataset—it depends on who is processing the data and what means they have available. Teams need to understand when data transition from personal to anonymous.&lt;br&gt;&lt;br&gt;&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;Consider contractual protections.&lt;/strong&gt; When sharing pseudonymized data, contracts should explicitly prohibit recipients from attempting re-identification and from combining the data with other sources that could enable identification.&lt;/li&gt; 
    &lt;/ul&gt; 
    &lt;h2 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-2-size-value))/25));"&gt;Conclusion&lt;/h2&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The &lt;em&gt;EDPS v SRB&lt;/em&gt; judgment brings needed clarity to pseudonymization's role in data protection. Pseudonymization can make data anonymous, but &lt;span style="font-weight: bold;"&gt;only &lt;/span&gt;when technical and organizational measures effectively prevent identification by the recipient.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;For controllers, this ruling emphasizes that transparency obligations attach at the point of collection and not at what happens after collection. For recipients, it confirms that careful assessment is needed before treating pseudonymized data as anonymous.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;The practical effect is that pseudonymization becomes a more reliable privacy-enhancing technique when properly implemented, but controllers bear the burden of demonstrating that recipients genuinely cannot identify individuals.&lt;/p&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;This ruling brings &lt;span style="font-weight: bold;"&gt;new opportunities for data sharing&lt;/span&gt; but only if implemented properly.&lt;/p&gt; 
    &lt;h3 style="font-style: var(--heading-font-font-style); line-height: calc(var(--heading-font-line-height) * (1 + (1 - var(--heading-3-size-value))/25));"&gt;Further Reading&lt;/h3&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;For additional context on data protection and pseudonymization:&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt;&lt;strong&gt;CJEU Judgment:&lt;/strong&gt; &lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62023CJ0413" style="text-decoration-line: underline; text-decoration-thickness: 1px;"&gt;EDPS v SRB (C-413/23 P)&lt;/a&gt;, 4 September 2025&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;GDPR Article 4(5):&lt;/strong&gt; &lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679#art_4" style="text-decoration-line: underline; text-decoration-thickness: 1px;"&gt;Definition of pseudonymization&lt;/a&gt;&lt;/li&gt; 
     &lt;li&gt;&lt;strong&gt;Recital 26 GDPR:&lt;/strong&gt; &lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679#rct_26" style="text-decoration-line: underline; text-decoration-thickness: 1px;"&gt;Principles of data protection and pseudonymization&lt;/a&gt;&lt;/li&gt; 
    &lt;/ul&gt; 
   &lt;/div&gt; 
   &lt;div style="height: auto;"&gt; 
    &lt;p style="line-height: var(--body-font-line-height);"&gt;&lt;strong&gt;Note:&lt;/strong&gt; This article reflects the CJEU's ruling in Case C-413/23 P, &lt;em&gt;EDPS v SRB&lt;/em&gt;, judgment of 4 September 2025. Organizations should consult legal counsel regarding application to specific circumstances, particularly where national data protection authorities have issued additional guidance on pseudonymization.&lt;/p&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=147848222&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.regulyn.com%2Finsights%2Fsrb-ruling-can-pseudonymization-make-data-anonymous&amp;amp;bu=https%253A%252F%252Fwww.regulyn.com%252Finsights&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Data Protection</category>
      <category>Pseudonymization</category>
      <category>CJEU</category>
      <pubDate>Tue, 28 Jul 2026 19:27:48 GMT</pubDate>
      <author>katri.harjuvetelainen@regulyn.com (Katri Harjuveteläinen)</author>
      <guid>https://www.regulyn.com/insights/srb-ruling-can-pseudonymization-make-data-anonymous</guid>
      <dc:date>2026-07-28T19:27:48Z</dc:date>
    </item>
  </channel>
</rss>
