Invoking a new CJEU decision in ongoing proceedings shortly after it has come out? Super! Even better when it confirms what you have been saying for years. I actually had a strong disagreement with an eminent data protection lawyer nearly a decade ago on this particular topic, during a discussion on the nature of cookies from a GDPR and Data Protection Directive perspective.
The gist of the discussion?
This eminent lawyer was stating that with a cookie identifier, given that the user can look up the value of a cookie (e.g. a sessionID cookie) by checking his/her browser, the cookie identifier is personal data because it is linked to the user.
My position at the time was that the user might know that, yet the website operator has no clue about the identity of that user (unless that identifier is tied to a user account with certain data points or a similar form of actual identification) – but that this might change is if the user actually reaches out to the website operator to say “Hi, I’m A.B., and this is evidence that my cookie identifier is CDEF”.
So yes, a cookie identifier, just like any other identifier stored on a user’s device, *can* be personal data. But the circumstances mean that often, it will just be *potentially* personal data – even for the publisher / website operator.
About a decade later, it looks like the CJEU is of the same opinion.
At the time of that discussion, the Breyer judgment was still fairly new, and to be fair to this excellent sparring partner it was a fairly technical discussion, but this shows a common misconception regarding “identifiers” as well as the general lack of support that the “relative” concept of personal data has had.
Identifier” is the term we use for this (session ID cookies and the like, but also other forms of user IDs) but it is actually misleading from a data protection perspective, as these identifiers are *NOT* always sufficient to allow a natural person to be “identified or identifiable”.
So seize upon the discussion being started further to the CJEU’s SRB judgment to bring into question certain assumptions that may have been made. Not in order to weaken protection, but in order to properly assess exactly which obligations apply – and which measures the possible inapplicability of the GDPR frees you up to focus on.
Always remember: potentially personal data is that – *potentially* personal data. The GDPR could apply very quickly. So try to anticipate and to be ready for compliance if those circumstances arise. It’s not a free-for-all but a reminder to be responsible with data.
For more on what SRB actually entails and when data ceases to be personal, do read my in-depth analysis here: https://lnkd.in/e2eNmGUP
For something more audio/visual:
– replay of our webinar on the same day as the judgment: https://lnkd.in/dyQgMEAB
– podcast on SRB and notably some thoughts on adtech / data clean rooms / …: https://lnkd.in/e7CUPhYp
privacy
Did this analysis get you thinking? Reach out!
DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!
Get in touch ↗ Let's connect on LinkedIn ↗