All news
Case law February 13, 2026 5 min

France's Conseil d'Etat: the line between anonymization and pseudonymization narrows

February 13, 2026 ruling: data 're-identifiable with ordinary effort' remains personal data under GDPR

TL;DR for the DPO

On February 13, 2026, France's Conseil d'Etat (highest administrative jurisdiction) confirmed CNIL's decision that data 're-identifiable with ordinary effort' remains personal data and thus subject to GDPR. The case concerned pseudonymized health data. For DPOs: the line between anonymization (GDPR doesn't apply) and pseudonymization (GDPR applies) has become sharper.

The case

The CNIL had fined two IT service providers in the healthcare sector for processing health-related data collected from physicians and pharmacies. The companies argued the data had been anonymized prior to use, and thus not subject to GDPR.

The CNIL verified that the datasets remained de facto re-identifiable: by combining prescription dates, treatment codes, pharmacy codes and internal nomenclature, it was possible to reconstruct care pathways and individualize patients. To do this, ordinary tools (Excel) and the nomenclatures provided by the companies themselves were sufficient.

The Conseil d'Etat confirmed CNIL's analysis and rejected the appeal. It emphasized that it is irrelevant whether the companies themselves actually re-identified patients: what matters is the reasonable possibility of re-identification.

The practical difference between anonymization and pseudonymization

Critical distinction

ANONYMIZATION = data cannot be linked to an identifiable person, not even with reasonable means. GDPR doesn't apply. PSEUDONYMIZATION = data is separated from direct identifiers (name, surname, tax code) but re-identification remains possible using additional information (mapping keys, external data). GDPR applies.

The Conseil d'Etat ruling raised the bar: to be considered anonymous, data must be protected against any re-identification 'with reasonable means'. This assessment is contextual and considers information the controller already holds, what's available to third parties, and commonly accessible technological tools.

The 4 EDPB WP216 criteria to verify anonymization

  • Singling out: can an individual be isolated in the dataset? (e.g., a patient with a rare combination of pathologies)
  • Linkability: can two records relating to the same person be linked? (e.g., multiple visits)
  • Inference: can information about a person be deduced with high probability? (e.g., deducing employer from an access pattern)
  • If at least one of these 3 is possible, the data is NOT anonymous - it's pseudonymous

What to do for clients claiming 'we anonymize data'

  • Verify the anonymization methods used: hashing, salting, generalization, k-anonymity, l-diversity, t-closeness
  • Document the 3 WP216 criteria test on the actual dataset
  • Consider the environment: who has access to the dataset? What other information could they combine? The realistic attack scenario
  • For health data, consider that quasi-identifiers (date of birth, sex, zip code) are enough to re-identify 87% of the US population (Sweeney 2000)
  • When in doubt: treat as pseudonymous data, apply GDPR

Comparison with EU case law

  • France (Conseil d'Etat Feb 13, 2026): re-identifiable with ordinary effort = personal data
  • Germany (BGH II ZR 23/21 of 2024): effective anonymization requires absolute irreversibility
  • Italy (Italian DPA 195/2022): pseudonymized health data remains sensitive data
  • CJEU (Breyer C-582/14): re-identification assessment is relative to the specific controller

Implications for AI and big data projects

Many data analytics, machine learning, and AI model training projects are based on 'anonymized' datasets. The Conseil d'Etat ruling requires re-evaluation of these projects: if data remains re-identifiable, training an AI model on this data is subject to GDPR. Legal basis, notice, retention, security, data subject rights - everything applies.

In DPO Workspace

For clients claiming 'anonymized datasets', it's useful to create a separate Art. 30 processing activity for each dataset, with explicit reference to re-identification tests conducted and results. This documentation is the first thing an authority asks for in case of inspection.

Official source:Inside Privacy: France's Highest Administrative Court Upholds CNIL's Standard On Anonymization

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Case law
200 €for the loss of control

Real employee data inside the test system: what loss of control is worth

Testing a new HR system with real data is not forbidden: transferring more fields than the test needs is. The German Federal Labour Court ordered an employer to pay two hundred euro because it had uploaded salary, home address, tax ID and marital status although it had agreed a list of nine fields with the works council. And it confirmed that a delayed answer to an access request is not, in itself, a damage.

Aug 21, 2026New 5 min
Case law
7i criteri di bilanciamento CEDU

You don't delete the article, you delete the name

On 5 August 2026 the CNIL clarified the boundaries of a right that is often exercised and widely misunderstood. Against a press organisation, objection and erasure remain available; access and rectification do not. And a refusal must be reasoned concretely: six generic formulas are named as inadmissible.

Aug 05, 2026New 4 min
Case law
3condizioni cumulative del test

Legitimate interest is not the fallback legal basis

In Case C-621/22 the Court of Justice held that a commercial interest can constitute a legitimate interest under Article 6(1)(f). Many people read only that line. The rest of the judgment recalls that the conditions remain three and cumulative, and that the third - the balancing against the data subject's reasonable expectations - is where the case at hand was lost. For the DPO the consequence is practical: legitimate interest exists only if it is written down somewhere.

Aug 12, 2026New 6 min