The dispute arose from the 2017 resolution of Banco Popular Español. The Single Resolution Board (SRB) collected comments from affected shareholders and creditors through an online consultation process. Participants provided identity documents during registration, then submitted comments through a form that assigned each comment a unique code.
The SRB shared coded comments with Deloitte for valuation purposes—but not the registration data needed to identify the authors. The European Data Protection Supervisor found this violated transparency obligations. The SRB argued the comments were not personal data from Deloitte's perspective. The case reached the CJEU.
The Court ruled that personal opinions and views constitute personal data because "as an expression of a person's thinking, [they] are necessarily closely linked to that person." This applies regardless of whether the content explicitly identifies the author.
The Court emphasized that when information constitutes personal opinions, no additional examination of content, purpose, or effect is needed to establish that it "relates to" a natural person under Article 4(1) GDPR (and Article 3(1) of Regulation 2018/1725). The subjective nature of opinions creates an inherent link to their authors.
This builds on the Court's earlier ruling in Nowak (C-434/16), where examiner comments about a candidate's performance were held to constitute personal data both about the candidate and the examiner.
The Court's most significant holding addresses pseudonymization directly. Pseudonymized data "must not be regarded as constituting, in all cases and for every person, personal data" when "pseudonymization may, depending on the circumstances of the case, effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable."
This means the same dataset can be:
The critical factors are whether the recipient has access to:
The risk of identification must be "insignificant", meaning identification is prohibited by law or impossible in practice because it would require disproportionate effort in terms of time, cost, and labor.
The third ruling resolves the procedural question: when must the controller inform data subjects about recipients?
The Court held that the obligation under Article 15 to inform data subjects about recipients applies "prior to the transfer of the data at issue and irrespective of whether or not those data were personal data" from the recipient's perspective after pseudonymization. The assessment of whether data are personal must be made:
This timing matters because the information allows data subjects to "decide, in full knowledge of the facts, whether to provide or, on the contrary, refuse to provide the personal data being collected." The transparency obligation protects the relationship between the data subject and the controller - it cannot depend on what happens after data are transferred to third parties.
Put simply, this means that the controller must include all foreseeable disclosures into the privacy notice, regardless of whether the data is anonymous to the recipient or not.
Organizations processing pseudonymized data should:
The EDPS v SRB judgment brings needed clarity to pseudonymization's role in data protection. Pseudonymization can make data anonymous, but only when technical and organizational measures effectively prevent identification by the recipient.
For controllers, this ruling emphasizes that transparency obligations attach at the point of collection and not at what happens after collection. For recipients, it confirms that careful assessment is needed before treating pseudonymized data as anonymous.
The practical effect is that pseudonymization becomes a more reliable privacy-enhancing technique when properly implemented, but controllers bear the burden of demonstrating that recipients genuinely cannot identify individuals.
This ruling brings new opportunities for data sharing but only if implemented properly.
For additional context on data protection and pseudonymization:
Note: This article reflects the CJEU's ruling in Case C-413/23 P, EDPS v SRB, judgment of 4 September 2025. Organizations should consult legal counsel regarding application to specific circumstances, particularly where national data protection authorities have issued additional guidance on pseudonymization.