The same file can be personal data for you and not for your processor
The Court of Justice said so in 2016 and confirmed it in 2025. Most data maps, most processor contracts and most anonymisation claims were built on the opposite assumption. Here is what the case law actually holds, and what it does to your scope.
Contents
- What does Article 4(1) GDPR actually require?
- What did the CJEU decide in Breyer, C-582/14?
- Does Breyer mean anyone can identify, therefore everything is personal data?
- What changed between 2016 and 2025?
- What did EDPS v SRB, C-413/23 P, settle in September 2025?
- Is pseudonymised data always personal data?
- Why the Digital Omnibus makes the case law more important, not less
- What does this change in your record of processing?
- Do you still need a DPA with a processor who cannot identify anyone?
- Are IP addresses and security logs personal data?
- The four-question test to apply to every data flow
- Why I defend a narrower scope while arguing for a wider one
- What remains open
The essentials
- Personal data is not a property of a dataset. It is a property of the relationship between a dataset and whoever holds it. The CJEU confirmed this explicitly in EDPS v SRB (C-413/23 P, 4 September 2025). Sufficiently pseudonymised data can be personal data for the originating controller and non-personal data for a recipient who cannot reverse it. Same bytes, two holders, two legal statuses.
- Breyer (C-582/14, 19 October 2016) does not say what most people think it says. It does not hold that identification by anyone, anywhere, makes data personal. It holds that the missing piece may sit with a third party, provided you have a means "likely reasonably to be used" to reach it. The Court expressly excluded identification that is prohibited by law or requires disproportionate effort in time, cost and manpower.
- In Breyer, what tipped the balance was a concrete lawful route. The website operator was logging IP addresses precisely to pursue attackers, and legal channels existed to obtain subscriber data from the ISP. Purpose created the route. Route created the scope.
- This breaks with a decade of supervisory practice. Data protection authorities treated pseudonymised data as invariably personal. That position no longer reflects the Court's holding.
- The legislature tried to codify the relative approach and failed. The Digital Omnibus proposed a new Article 4(1) paragraph in November 2025. The EDPB and EDPS opposed it in Joint Opinion 2/2026. The Council compromise of 20 February 2026 deleted it. The Cypriot presidency withdrew its text from COREPER II at the end of June 2026 for lack of a qualified majority. The case law is the only operative standard.
An organisation I audited last year kept a single line in its record of processing for its entire product telemetry pipeline. Category: technical data. Personal data: no.
The pipeline collected device identifiers, session tokens and IP addresses. It shipped them to an analytics vendor. The vendor could not identify anyone, and that was the stated reason for the "no."
Two problems, in opposite directions.
The first: the company itself could identify almost every one of those sessions, because it held the account database that the session token mapped to. In its own hands, that data was plainly personal. The entry was wrong.
The second, and the more interesting one: the entry was also wrong about the vendor, and wrong in the other direction. Nobody had ever assessed whether that vendor could reach a person. Nobody had written down why not. The company had reached the right conclusion about the vendor by accident, and could not defend it.
One line in a spreadsheet, two errors, pointing opposite ways. That is what happens when you treat "personal data" as a property of the file rather than a property of the holder.
The Court of Justice settled this question. Twice. Almost nobody outside the privacy bar has read either judgment.
What does Article 4(1) GDPR actually require?
Personal data means any information relating to an identified or identifiable natural person.
Everyone stops at "identified." All the difficulty lives in "identifiable."
Recital 26 supplies the test. Account should be taken of all the means reasonably likely to be used, either by the controller or by another person, to identify the individual, directly or indirectly.
Two phrases in that sentence do all the work, and they pull against each other.
"Or by another person" widens the scope. Identification does not have to be something you can perform alone.
"Reasonably likely to be used" narrows it back. Theoretical possibility is not enough.
Every judgment of the last decade is the Court calibrating between those two phrases. Quote one without the other and you will get the answer wrong, in whichever direction suits you.
What did the CJEU decide in Breyer, C-582/14?
Patrick Breyer, a German politician and privacy campaigner, visited websites run by German federal institutions. Those sites logged visitor IP addresses along with pages accessed, search terms entered, timestamps and data volumes. The stated purpose was defending against cyberattacks and enabling prosecution afterwards.
Breyer wanted the logging stopped. The case reached the Bundesgerichtshof, which referred a question to the Court of Justice.
The referred question is the valuable part. Breyer's IP address was dynamic. It changed with each connection. Sitting alone in a federal web server log, it identified nobody. Only the internet service provider held the subscriber record capable of tying that address, at that moment, to a person.
So: is a dynamic IP address personal data in the hands of the website operator, when the operator cannot identify anyone and a third party holds the missing half?
The Court answered yes, subject to conditions.
It held that it is not necessary for all the information enabling identification to be in the hands of one person. Data held by a third party can be taken into account.
But not automatically. The test the Court set was whether the possibility of combining the IP address with the ISP's additional data constitutes a means likely reasonably to be used to identify the person.
And it drew the boundary explicitly. That would not be the case where identification is prohibited by law, or practically impossible because it demands a disproportionate effort in time, cost and manpower, such that the risk of identification is in reality insignificant.
What tipped the case was not abstraction. It was a concrete fact. Because the operator was logging precisely in order to respond to cyberattacks, legal channels existed through which it could approach the competent authority and obtain the subscriber information. The route existed, it was lawful, it was usable. Therefore the IP address was personal data in the operator's hands.
The operator's own purpose is what built the route.
Does Breyer mean anyone can identify, therefore everything is personal data?
No. And this is the reading that has done the most damage.
The popular version of Breyer runs: identification does not have to be by you, it can be by anyone, therefore effectively all data is personal data.
That collapses the test into an absolute one, and the Court specifically declined to go there. Breyer is a relative test with a third-party extension. The extension is real. The test remains relative, and it remains gated by both reasonableness and lawfulness.
The defensible one-line version:
The pieces do not have to sit in the same pair of hands. But you must have a means of reaching the missing piece that is both reasonable and lawful.
That is a very different sentence from "anyone, anywhere, therefore everything." One of them will get you removed from a scoping workshop.
What changed between 2016 and 2025?
Breyer left a hole. It confirmed that third-party information counts, but it did not resolve what happens when a specific holder genuinely cannot get there.
That hole filled slowly. The Court reaffirmed the broad reach of the "relates to" limb in IAB Europe (C-604/22). It reaffirmed the insignificant-risk boundary in OC v Commission (2024): identification means are not reasonably likely where identification is prohibited by law or demands disproportionate effort.
Meanwhile supervisory authorities held a far harder line in practice. The working position, for years, was that pseudonymised data is always personal data, full stop. A key exists somewhere, therefore the data is personal for everyone who touches it.
That position had the virtue of being simple to apply. It also had a defect. It was not what the Court had said.
What did EDPS v SRB, C-413/23 P, settle in September 2025?
Banco Popular Español collapsed in 2017. The Single Resolution Board had to determine whether former shareholders and creditors were owed compensation. It ran a right-to-be-heard consultation and collected written comments from affected stakeholders.
The SRB then sent those comments to Deloitte for valuation work. It stripped the identifying information first. Deloitte received a pseudonymised dataset and never received the key.
Stakeholders complained to the European Data Protection Supervisor. The EDPS held that the comments remained personal data in Deloitte's hands, because the SRB retained the ability to re-identify. Deloitte was therefore a recipient of personal data, and the SRB had failed to name it in its privacy statement.
The General Court annulled that decision in April 2023 (T-557/20), holding that identifiability must be assessed from the recipient's perspective. The EDPS appealed.
On 4 September 2025 the Court of Justice set aside the General Court's judgment, and in doing so said three separate things that must be kept apart.
One. Opinions are personal data by their very nature. The Court disagreed with the General Court on the "relates to" limb. Personal opinions and views, as an expression of a person's thoughts, are inherently linked to their author. No content, purpose or effect analysis is needed. Free-text fields, survey comments, incident reports written in someone's own words: these relate to their author automatically.
Two. "Personal" is not an absolute characteristic of data. Sufficiently pseudonymised data may constitute personal data for the originating controller while not constituting personal data for a recipient who cannot reverse the pseudonymisation and cannot identify by any other reasonably likely means. Same dataset, two holders, two statuses. The Court expressly rejected the EDPS argument that a relative assessment would unduly narrow the concept and weaken protection.
Three. Transparency is nevertheless assessed at collection, from the controller's viewpoint. The SRB still lost on the point that mattered to it. For the obligation to inform data subjects about recipients, identifiability is assessed from the controller's position at the time of collection. You cannot collect data, stay silent about who you intend to send it to, and then argue afterwards that pseudonymisation made the recipient disclosure unnecessary.
The third holding is the one people skip when they get excited about the second. Do not skip it. It is the one that will cost you a finding.
Is pseudonymised data always personal data?
No, and that is the practical break.
For years the working assumption was yes, invariably, in every pair of hands. EDPS v SRB is the first judgment in which the Court has explicitly held otherwise.
The correct formulation now has three parts.
For the controller holding the key, pseudonymised data is personal data. Pseudonymisation is a security measure, not an exit from scope.
For a recipient who does not hold the key and has no other reasonably likely means, the same data may fall outside the definition entirely.
And the burden of demonstrating that second proposition sits with you. It requires a written assessment naming the holder, the means available to that holder, and why the residual re-identification risk is insignificant.
If you built your data map on "pseudonymised equals personal, everywhere, always," your map now describes a rule that no longer exists.
Why the Digital Omnibus makes the case law more important, not less
On 19 November 2025 the European Commission published the Digital Omnibus, the largest set of proposed GDPR amendments since the regulation began to apply. Among them, a new paragraph in Article 4(1) codifying the relative approach almost word for word: information would not be personal for a given entity where that entity cannot identify the person taking account of the means reasonably likely to be used by that entity, and would not become personal merely because a subsequent recipient has such means.
It did not survive.
On 10 February 2026 the EDPB and the EDPS adopted Joint Opinion 2/2026, urging the co-legislators not to adopt the Article 4(1) changes as drafted. Their grounds: the proposal goes far beyond a targeted or technical amendment, it does not accurately reflect the Court's case law, and it is likely to increase legal uncertainty rather than reduce it.
The Council compromise text of 20 February 2026, circulated by the Cypriot presidency, deleted the revised definition entirely, along with the proposed expansion of the scientific research definition and the changes to Article 22.
And the file has not landed since. In late June 2026 the Cypriot presidency withdrew its compromise text from the COREPER II approval process after it became clear it could not command a qualified majority among Member States. The Council passed to the Irish presidency on 1 July 2026 without a settled position. The AI half of the package was adopted by the Council on 29 June 2026. The data half, covering GDPR, ePrivacy, NIS2 and DORA, remains in negotiation, with final adoption not realistically expected before late 2026.
Read the sequence properly. The legislature tried to write down what the Court had already decided. The regulators told it the drafting misstated the case law. It backed off.
Which means the case law is the law. Breyer plus EDPS v SRB is your operative standard today, and there is no statutory shortcut coming that will do the analysis on your behalf.
What does this change in your record of processing?
Most records of processing carry one column: does this processing involve personal data, yes or no.
That column presumes an absolute property. The property does not exist.
The honest structure is per flow and per actor. Is this personal data for us. Is it personal data for the party we send it to. What specifically makes the difference.
Two consequences, and they run in opposite directions, which is why nobody catches both.
You are probably over-scoped somewhere, carrying full GDPR machinery over datasets that are genuinely non-personal in the hands of the entity holding them. That is cost and friction with no protective benefit.
You are almost certainly under-scoped somewhere else, holding something you have been calling anonymous while a lawful route to the missing half sits open in plain view. Breyer is the judgment that catches you there, and it catches security teams more often than anyone else.
Do you still need a DPA with a processor who cannot identify anyone?
If a recipient genuinely cannot identify anyone, taking account of all means reasonably likely to be used, then in that recipient's hands the data is not personal data, and Article 28 does not apply to it as such.
I am not telling you to tear up your processor contracts, and I want to be precise about why.
The assessment is a snapshot. Datasets get enriched. Staff move between organisations. A recipient who cannot identify anyone today may acquire the means tomorrow through an unrelated acquisition or an unrelated data purchase. Contractual commitments are also part of what makes re-identification legally impossible, which is one of the Court's own gates. Remove the contract and you may remove the very thing that put the data out of scope.
What I am telling you is to stop signing them as a reflex and start being able to state, in one paragraph, why this recipient is or is not in scope and what would change the answer.
That paragraph is the artefact an auditor should ask for. In my experience, almost none do.
Are IP addresses and security logs personal data?
This is where Breyer bites hardest, and where security functions are most exposed, because we are the ones generating the data.
Web server logs. VPN and firewall logs. EDR telemetry. Device identifiers. SIEM enrichment. Threat intelligence feeds carrying IP addresses and account names.
The Breyer reasoning applies to all of it directly, and the aggravating factor is our own stated purpose. We retain those logs precisely so that we can pursue attribution when something happens. That purpose is the thing that establishes a lawful route to identification. The German government lost Breyer partly because of why it was logging.
So the argument "these are just IPs, it is technical data, it is not personal" is dead on arrival in a security context. Your own purpose defeats it.
That does not mean stop logging. Breyer confirmed that legitimate interest is available for exactly this. It means log with a lawful basis stated, a retention period you can defend, and an information notice that reflects what you actually do.
The four-question test to apply to every data flow
Per actor, per flow. Never per dataset.
1. Who holds it? Name the specific entity. Controller, processor, sub-processor, recipient. If you cannot name them, you cannot assess.
2. What is the missing piece, and where does it sit? Identify the additional information required to link the data to a person, and identify who holds it.
3. Is there a reasonable and lawful route to that piece? Contract. Statutory power. Purchasable dataset. Regulatory or judicial channel. A key held by an affiliate. Ordinary technical correlation with other data you already hold. If a usable route exists, it is personal data for that holder.
4. If not, why is the residual risk insignificant? Write the reason down. Legal prohibition. Contractual prohibition. Key destroyed or separated under controls. Disproportionate effort in time, cost and manpower. Then state the trigger that would make you re-run the assessment.
Four questions. One page per material flow. That page is what turns a scoping decision from a habit into a position you can defend the first time a supervisory authority asks why something sits outside your scope.
Why I defend a narrower scope while arguing for a wider one
There is an obvious objection to everything above, and it deserves a straight answer rather than a footnote.
The relative approach can be abused. It hands every organisation an argument for shrinking its own scope, and the incentive to reach that conclusion is enormous. The EDPS made exactly this argument to the Court and lost. The EDPB made a version of it against the Digital Omnibus drafting and, on that occasion, prevailed.
I think the concern is legitimate and I think the answer to it is not to pretend the case law says something else.
A relative test does not weaken protection when it is applied honestly, because it is symmetrical. It narrows your scope where you truly cannot reach a person. It widens your scope, and this is the half nobody wants, wherever a lawful route exists that you had not bothered to look for. Applied properly, it produces more scope in security telemetry and in enrichment pipelines than the lazy absolute test ever did.
The abuse is not the relative approach. The abuse is applying half of it. Taking the narrowing without the widening, claiming the recipient exemption without ever writing the assessment, and never once turning question three on your own logs.
If you only use this article to shrink your ROPA, you have used it wrong.
What remains open
Three things worth watching.
The Digital Omnibus data half is still in negotiation under the Irish presidency, with adoption not expected before late 2026 at the earliest. The Article 4(1) revision is out of the Council text as things stand. That can change.
The EDPB's Guidelines 01/2025 on pseudonymisation were drafted before the September 2025 judgment and take a firmer line than the Court did. How the Board reconciles its guidance with EDPS v SRB will matter more to your auditor than the judgment itself.
And the practical question the judgment opens without answering: if a processor is genuinely out of scope, what governs the relationship. Contract law and confidentiality, presumably. But nobody has published a defensible template, and I would not want to be the first organisation to litigate it.
None of that is a reason to wait. The scoping work is the same either way, and the four questions above do not depend on how the Omnibus lands.
Go and look at one flow. Pick the one you have never questioned. That is the one.
Sources
- CJEU, Case C-582/14, Patrick Breyer v Bundesrepublik Deutschland, judgment of 19 October 2016.
- CJEU, Case C-413/23 P, EDPS v SRB, judgment of 4 September 2025, setting aside the General Court judgment in T-557/20 of 26 April 2023.
- CJEU, Case C-604/22, IAB Europe.
- CJEU, OC v Commission, 2024, on insignificant re-identification risk.
- EDPB-EDPS Joint Opinion 2/2026 on the Digital Omnibus Regulation proposal, adopted 10 February 2026.
- Council of the European Union, Cypriot presidency compromise text on the Digital Omnibus, 20 February 2026, and withdrawal from COREPER II approval, late June 2026.
- European Commission, Digital Omnibus package, published 19 November 2025.
- EDPB Guidelines 01/2025 on pseudonymisation.
- Regulation (EU) 2018/1725 (EUDPR), materially equivalent to the GDPR on the definition of personal data and on transparency obligations.
Frequently asked questions
Is an IP address personal data under the GDPR?
It depends on who holds it. Following Breyer (C-582/14), a dynamic IP address is personal data for a website operator where that operator has a reasonable and lawful means of obtaining the subscriber information from the internet service provider. Where no such route exists, it may not be. For a security team logging IP addresses in order to pursue attackers, the route generally exists, because the stated purpose is what creates it.
Does Breyer say that data is personal if anyone can identify the person?
No. That is the most common misreading. Breyer confirms that the additional information enabling identification does not need to be held by the same person, but it conditions this on the combination being a means likely reasonably to be used. The Court expressly excluded identification that is prohibited by law or that requires a disproportionate effort in time, cost and manpower, such that the risk becomes insignificant.
Is pseudonymised data always personal data?
No, not for every holder. In EDPS v SRB (C-413/23 P, 4 September 2025) the Court of Justice confirmed that sufficiently pseudonymised data may be personal data for the controller holding the key while not being personal data for a recipient who cannot reverse the pseudonymisation and has no other reasonably likely means of identification. For the controller holding the key, it remains personal data.
Can the same dataset be personal data for one organisation and not for another?
Yes. That is the direct holding of EDPS v SRB. "Personal" is not an absolute characteristic of the data. It is assessed relative to the entity holding it and the means reasonably likely to be available to that entity.
Do I still need a data processing agreement if my processor cannot identify anyone?
Where the recipient genuinely cannot identify anyone, Article 28 does not apply to that data as such. In practice you should usually keep contractual controls in place: the assessment can change over time, and contractual prohibition on re-identification is itself one of the factors that keeps the data out of scope. The change is that you should be able to justify the position in writing rather than signing by reflex.
Did the Digital Omnibus change the definition of personal data?
Not as things stand. The Commission proposed a revised Article 4(1) in November 2025. The EDPB and EDPS opposed it in Joint Opinion 2/2026 on 10 February 2026, and the Council compromise text of 20 February 2026 removed it entirely. The Cypriot presidency withdrew its text from COREPER II in late June 2026 for lack of a qualified majority, and the file passed to the Irish presidency without a Council position. The case law remains the operative standard.
How do I document an anonymisation claim so it survives an audit?
Name the holder, identify the additional information required for identification and where it sits, state whether a reasonable and lawful route to it exists, and if not, explain why the residual risk is insignificant using the Court's own criteria: legal prohibition, contractual prohibition, absence of the key, or disproportionate effort in time, cost and manpower. Then record the trigger that would require you to reassess. An anonymisation statement that does not name a holder is not an assessment.
Does this apply to security logs and SIEM data?
Yes, and more forcefully than to most other categories. Security logging is retained precisely to support attribution, and that purpose is what establishes a lawful route to identification. The Breyer reasoning applies directly. The correct response is not to stop logging but to state a lawful basis, defend the retention period, and make the privacy notice reflect reality.
Christophe Mazzola is the founder of Cyber Academy and a practising CISO. He delivers PECB and ISACA certification training across Europe, including ISO/IEC 27001 Lead Implementer and Lead Auditor, ISO 31000 Lead Risk Manager and ISO/IEC 27701.
