TL;DR for the DPO
On February 13, 2026, France's Conseil d'Etat (highest administrative jurisdiction) confirmed CNIL's decision that data 're-identifiable with ordinary effort' remains personal data and thus subject to GDPR. The case concerned pseudonymized health data. For DPOs: the line between anonymization (GDPR doesn't apply) and pseudonymization (GDPR applies) has become sharper.
The case
The CNIL had fined two IT service providers in the healthcare sector for processing health-related data collected from physicians and pharmacies. The companies argued the data had been anonymized prior to use, and thus not subject to GDPR.
The CNIL verified that the datasets remained de facto re-identifiable: by combining prescription dates, treatment codes, pharmacy codes and internal nomenclature, it was possible to reconstruct care pathways and individualize patients. To do this, ordinary tools (Excel) and the nomenclatures provided by the companies themselves were sufficient.
The Conseil d'Etat confirmed CNIL's analysis and rejected the appeal. It emphasized that it is irrelevant whether the companies themselves actually re-identified patients: what matters is the reasonable possibility of re-identification.
The practical difference between anonymization and pseudonymization
Critical distinction
ANONYMIZATION = data cannot be linked to an identifiable person, not even with reasonable means. GDPR doesn't apply. PSEUDONYMIZATION = data is separated from direct identifiers (name, surname, tax code) but re-identification remains possible using additional information (mapping keys, external data). GDPR applies.
The Conseil d'Etat ruling raised the bar: to be considered anonymous, data must be protected against any re-identification 'with reasonable means'. This assessment is contextual and considers information the controller already holds, what's available to third parties, and commonly accessible technological tools.
The 4 EDPB WP216 criteria to verify anonymization
- Singling out: can an individual be isolated in the dataset? (e.g., a patient with a rare combination of pathologies)
- Linkability: can two records relating to the same person be linked? (e.g., multiple visits)
- Inference: can information about a person be deduced with high probability? (e.g., deducing employer from an access pattern)
- If at least one of these 3 is possible, the data is NOT anonymous - it's pseudonymous
What to do for clients claiming 'we anonymize data'
- Verify the anonymization methods used: hashing, salting, generalization, k-anonymity, l-diversity, t-closeness
- Document the 3 WP216 criteria test on the actual dataset
- Consider the environment: who has access to the dataset? What other information could they combine? The realistic attack scenario
- For health data, consider that quasi-identifiers (date of birth, sex, zip code) are enough to re-identify 87% of the US population (Sweeney 2000)
- When in doubt: treat as pseudonymous data, apply GDPR
Comparison with EU case law
- France (Conseil d'Etat Feb 13, 2026): re-identifiable with ordinary effort = personal data
- Germany (BGH II ZR 23/21 of 2024): effective anonymization requires absolute irreversibility
- Italy (Italian DPA 195/2022): pseudonymized health data remains sensitive data
- CJEU (Breyer C-582/14): re-identification assessment is relative to the specific controller
Implications for AI and big data projects
Many data analytics, machine learning, and AI model training projects are based on 'anonymized' datasets. The Conseil d'Etat ruling requires re-evaluation of these projects: if data remains re-identifiable, training an AI model on this data is subject to GDPR. Legal basis, notice, retention, security, data subject rights - everything applies.
In DPO Workspace
For clients claiming 'anonymized datasets', it's useful to create a separate Art. 30 processing activity for each dataset, with explicit reference to re-identification tests conducted and results. This documentation is the first thing an authority asks for in case of inspection.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free