News
Consolidation of the French doctrine on personal data and pseudonymisation after the CJEU’s SRB ruling
Following the CJEU's SRB ruling (C-413/23, 4 September 2025), French doctrine on the qualification of personal data and pseudonymisation has consolidated through the decisions of the Conseil d'État (13 February 2026, n° 498628) and the CNIL in the IQVIA case (26 May 2026, n°SAN-2026-008): pseudonymisation remains a risk-reducing security measure, not a passport to anonymity.
Whether pseudonymised data qualifies as personal data is one of the most consequential questions in EU data protection law. This issue has been settled by the Court of Justice of the European Union (“CJEU”) in its SRB ruling of 4 September 2025 (C-413/23), a much-commented decision arguably read too broadly. But not in France, which has produced a subtle body of doctrine on this issue. The French Conseil d’État anchored its reading in its decision n°498628 of 13 February 2026, followed by the French data protection authority (“CNIL”), imposing a high administrative fine to IQVIA Operations France in its recent decision SAN-2026-008 of 26 May 2026. Read together, these decisions show a French doctrine that is firmly settled and subtly aligned with EU case law.
Step one: The CJEU’s SRB ruling: personal data as a relative, fact-sensitive notion
The SRB, the Single Resolution Board (EU authority responsible for the orderly resolution of failing banks within the Banking Union) had collected stakeholder comments, assigned each a randomly generated alphanumeric code, and transmitted the pseudonymised comments to Deloitte for evaluation. The CJEU held that pseudonymisation may, depending on the circumstances, prevent recipients other than the controller from identifying the data subject, so that for them, the person is no longer identifiable.
The Court attached two conditions to that outcome for a recipient: the recipient must be unable to reverse the pseudonymisation measures in any processing under its control, and those measures must effectively prevent the recipient from re-attributing the data to the individual, including by cross-referencing other information. Conversely, the controller that had performed the pseudonymisation normally retains the additional information and therefore continues to hold personal data. The Court also stressed that the relevant perspective for assessing identifiability depends essentially on the circumstances of each case, and expressly situated SRB in the continuity of its earlier Breyer (C-582/14) and OC v Commission (C-479/22) rulings. The “reasonable means” test of recital 26 GDPR remains the governing standard.
Step two: The French Conseil d’État (13 February 2026) applies a concrete re-identification test
Drawing on the aforementioned OC v Commission ruling, the French supreme administrative court, the Conseil d’État, held that data can be treated as anonymised only where the risk of identification is insignificant and re-identification is practically unrealisable, requiring a disproportionate effort in time, cost and labour.
The French supreme court therefore endorsed the CNIL’s concrete assessment of re-identification risk in this case concerning health databases fed by data collected from physicians and pharmacies, which included numerous and various data: the authority had established that pseudonymity could be lifted by reasonable means, so the data, though pseudonymised, were not anonymised. With no serious difficulty of interpretation, the Conseil d’État declined to refer a preliminary question to the CJEU, which is a strong signal that the French and EU positions coincide.
Step three: The CNIL’s IQVIA decision (26 May 2026): SRB not a passport to anonymity for the controller
IQVIA operates two health-data warehouses built from data collected from pharmacies and physicians’ software, pseudonymised through successive trusted third parties. After SRB, IQVIA argued that the warehoused data were anonymous and thus outside the GDPR, invoking the fact that the same dataset could be personal for one entity and anonymous for another unable to identify individuals by reasonable and lawful means.
CNIL rejected this on several grounds, offering welcome clarifications of its doctrine.
First, CNIL distinguishes the position of a controller from that of a mere recipient of pseudonymised data. IQVIA is not a recipient like the Deloitte in SRB; it designed and governs the entire processing chain from collection onward.
Second, unlike isolated, randomly coded comments like in SRB, IQVIA’s data are rich and permit longitudinal tracking of each patient through a unique identifier.
Third, echoing the EDPB’s 2021 WhatsApp binding decision, the fact that IQVIA had not intention to re-identify the patients is irrelevant. What matters is the fact that even a single person can be re-identified by reasonable means. The CNIL showed that combining warehouse data with open-source information allowed a patient to be isolated in minutes.
Fourth, the CNIL refined the “unlawful means” limb of Breyer (reprised at point 82 of SRB): a contractual ban on re-identification agreed between private parties is not an identification “prohibited by law.
CNIL concluded that pseudonymisation here did not eliminate the correlation risk, so the data remained personal for IQVIA.
Considering that, IQVIA was therefore indeed processing personal data, and was fined €5,000,000 for various infringements of the GDPR and was issued injunctions under a daily penalty.
Article provided by INPLP members: Charlotte Barraco-David and Marie-Hélène Tonnellier (OYAT, France)
Co-Author: Clyde Coutellier
Discover more about the INPLP and the INPLP-Members
Dr. Tobias Höllwarth (Managing Director INPLP)
News Archiv
- Alle zeigen
- Juli 2026
- Juni 2026
- Mai 2026
- April 2026
- März 2026
- Februar 2026
- Jänner 2026
- Dezember 2025
- November 2025
- Oktober 2025
- September 2025
- August 2025
- Juli 2025
- Juni 2025
- Mai 2025
- April 2025
- März 2025
- Februar 2025
- Jänner 2025
- Dezember 2024
- November 2024
- Oktober 2024
- September 2024
- August 2024
- Juli 2024
- Juni 2024
- Mai 2024
- April 2024
- März 2024
- Februar 2024
- Jänner 2024
- Dezember 2023
- November 2023
- Oktober 2023
- September 2023
- August 2023
- Juli 2023
- Juni 2023
- Mai 2023
- April 2023
- März 2023
- Februar 2023
- Jänner 2023
- Dezember 2022
- November 2022
- Oktober 2022
- September 2022
- August 2022
- Juli 2022
- Mai 2022
- April 2022
- März 2022
- Februar 2022
- November 2021
- September 2021
- Juli 2021
- Mai 2021
- April 2021
- Dezember 2020
- November 2020
- Oktober 2020
- Juni 2020
- März 2020
- Dezember 2019
- Oktober 2019
- September 2019
- August 2019
- Juli 2019
- Juni 2019
- Mai 2019
- April 2019
- März 2019
- Februar 2019
- Jänner 2019
- Dezember 2018
- November 2018
- Oktober 2018
- September 2018
- August 2018
- Juli 2018
- Juni 2018
- Mai 2018
- April 2018
- März 2018
- Februar 2018
- Dezember 2017
- November 2017
- Oktober 2017
- September 2017
- August 2017
- Juli 2017
- Juni 2017
- Mai 2017
- April 2017
- März 2017
- Februar 2017
- November 2016
- Oktober 2016
- September 2016
- Juli 2016
- Juni 2016
- Mai 2016
- April 2016
- März 2016
- Februar 2016
- Jänner 2016
- Dezember 2015
- November 2015
- Oktober 2015
- September 2015
- August 2015
- Juli 2015
- Juni 2015
- Mai 2015
- April 2015
- März 2015
- Februar 2015
- Jänner 2015
- Dezember 2014
- November 2014
- Oktober 2014
- September 2014
- August 2014
- Juli 2014
- Juni 2014
- Mai 2014
- April 2014
- März 2014
- Februar 2014
- Jänner 2014
- Dezember 2013
- November 2013
- Oktober 2013
- September 2013
- August 2013
- Juli 2013
- Juni 2013
- Mai 2013
- April 2013
- März 2013
- Februar 2013
- Jänner 2013
- Dezember 2012
- November 2012
- Oktober 2012
- September 2012
- August 2012
- Juli 2012
- Juni 2012
- Mai 2012
- April 2012
- März 2012
- Februar 2012
- Jänner 2012
- Dezember 2011
- November 2011
- Oktober 2011
- September 2011
- Juli 2011
- Juni 2011
- Mai 2011
- April 2011
- März 2011
- Februar 2011
- Jänner 2011
- November 2010
- Oktober 2010
- September 2010
- Juli 2010
