This is a big one – the Polish Supreme Administrative Court confirms that cookies & IP addresses aren’t always personal data (even in case of use of Google Analytics), and the burden of proof that they are in specific circumstances rests on the national authority, not the controller.
It’s another good application of the EU Court of Justice’s Breyer case law, and the Polish court (“NSA” in Polish) handles a few other cases along the way, notably Planet49 to show why cookies cannot be presumed to be personal data in each case.
Interestingly, it’s for once a case involving (notably) Google Analytics in which the judges actually look at whether there is processing of personal data.
I have highlighted various sections (pages 5-7) specifically on the issue.
Of note:
– “there are no grounds for considering that an IP address – regardless of whether it is a permanent (static) or variable (dynamic) address, and regardless of who controls it and what possibilities exist to use it to identify a natural person, should always be treated as personal data. The same conclusion applies to cookie identifiers
– “The possibility of self-identification by the data subject
should not be decisive in this respect” (= dismissing a counterargument often used, i.e. “but a data subject can show the cookie ID is theirs!”)
– Last but certainly not least, on what is “identification”:
the identification of a natural person does not necessarily involve determining their first and last name. This observation is particularly important in the digital environment, where identification boils down to marking a given user in order to exert a specific influence on them. […] Identifying a person does not therefore require knowledge of their first name or surname, but rather knowledge of certain unique characteristics that distinguish them from others. This is how the phrase “can be identified” should be understood – not only as the possibility of referring specific information to a specific person, but as the possibility of identifying that person, understood as actually distinguishing them from other persons
This is very important: “identifiable” must result in being able to distinguish one person from another. Not one device from another – one *person*. You need more than an IP address or a cookie identifier to do that. Maybe not the name – but sufficient information to know that this is someone specific.
[The Polish NSA goes on to say the Google Analytics documentation *doesn’t* show there that threshold was met here.]
For more on this topic:
– CJEU judgment of SRB, meaning and consequences: https://lnkd.in/e2eNmGUP
– Further thoughts on cookies & personal data: https://lnkd.in/ejM6CXW4
– Comments on other Polish NSA decision, somewhat related: https://lnkd.in/ePCTB_BD
And link to original decision in Polish:
https://lnkd.in/eiMZmmE8
Data protection GDPR privacy
Did this analysis get you thinking? Reach out!
DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!
Get in touch ↗ Let's connect on LinkedIn ↗