Readers will know that some of the EDPB’s positions in its pseudonymisation guidelines are unconvincing or absolutist by nature. Now, IAB Europe and other associations in the digital ecosystem have submitted their feedback on these guidelines, and the feedback shows the acute need for a review of those guidelines.
This response is well worth the read, and it contains extensive considerations on various CJEU cases (such as Breyer, Scania and SRB), the negative impact that these guidelines might have on the adoption of privacy-enhancing technologies, the importance of taking pseudonymisation properly into account when assessing risk (and taking decisions against controllers/processors), and more.
The full IAB Europe blog post: https://lnkd.in/eZMHpYzY
My highlights of shortcomings of the EDPB’s guidelines: https://lnkd.in/dBqErWhe
Thank you to IAB Europe for the opportunity to contribute to these comments on the pseudonymisation guidelines!
GDPR data protection
Did this analysis get you thinking? Reach out!
DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!
Get in touch ↗ Let's connect on LinkedIn ↗