The Croatian authority issues an opinion on the legal effects of pseudonymisation and anonymisation of personal data
The Croatian Data Protection Authority (AZOP) has clarified the legal status of pseudonymised data transmitted to a processor, specifying that they remain personal data subject to the GDPR when the controller retains the ability to re-identify.
In an opinion, the authority stated that pseudonymised data transmitted by a controller to a processor cannot be considered anonymous for the latter if it acts on behalf of the controller and the latter retains the ability to re-identify the data subjects. This analysis, based on the European Data Protection Board (EDPB) Guidelines 02/2026 and judgment C-413/23 P, holds that the qualification of the data must be assessed from the controller's perspective. Consequently, the relationship remains subject to the obligations of Article 28 of the GDPR, and pseudonymisation constitutes a security measure and not an exemption from concluding a processing contract. If the processor is located in a third country, this transmission is considered a personal data transfer under Chapter V of the GDPR, requiring appropriate safeguards such as standard contractual clauses.
The same reasoning applies to the relationship between a processor and a sub-processor. Even if the latter cannot re-identify the data, it is bound by the same data protection obligations as the main processor under Article 28, paragraph 4, of the GDPR, as long as it processes the data within the mission entrusted by the original controller. The authority concludes that pseudonymisation does not exclude the application of Article 28 as long as the recipient acts as a processor and the possibility of re-identification is maintained upstream in the processing chain.
In an opinion, the authority stated that pseudonymised data transmitted by a controller to a processor cannot be considered anonymous for the latter if it acts on behalf of the controller and the latter retains the ability to re-identify the data subjects. This analysis, based on the European Data Protection Board (EDPB) Guidelines 02/2026 and judgment C-413/23 P, holds that the qualification of the data must be assessed from the controller's perspective. Consequently, the relationship remains subject to the obligations of Article 28 of the GDPR, and pseudonymisation constitutes a security measure and not an exemption from concluding a processing contract. If the processor is located in a third country, this transmission is considered a personal data transfer under Chapter V of the GDPR, requiring appropriate safeguards such as standard contractual clauses.
The same reasoning applies to the relationship between a processor and a sub-processor. Even if the latter cannot re-identify the data, it is bound by the same data protection obligations as the main processor under Article 28, paragraph 4, of the GDPR, as long as it processes the data within the mission entrusted by the original controller. The authority concludes that pseudonymisation does not exclude the application of Article 28 as long as the recipient acts as a processor and the possibility of re-identification is maintained upstream in the processing chain.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire