On the Criteo decision of the French Conseil d’État: beyond the question of whether online identifiers are sufficient for identification (see below), this is a typical case of a court keeping fines 100% intact after questioning the scope of processing. It’s not the first time I have seen this: a court says “this isn’t all covered by [the GDPR / infringement A/B/C / …]” but then it confirms the financial penalty in full.
The Conseil d’État basically says “at least some of the very large number of data subjects were identifiable by means that did not involve a disproportionate effort in terms of time, cost and manpower” – before saying (I’m paraphrasing) “because it’s such a big processing activity, with over 370 million identifiers, including 50 million for France, we’re confirming the full extent of the fine imposed”. So it’s admitting that there is no evidence that all 50 / 370 million identifiers are “personal data” while maintaining 100% of the fine *and* saying that the scale of the processing is what justifies the large fine.
This is a very awkward piece of legal justification. If scale is a justification for the size of a fine, you don’t maintain 100% but try to establish how much % is justified.
On the first part, I think we are dealing with a recurrent terminological issue. For many years we have talked about “identifiers” in the digital context to denote not just “Peter Craddock” but also “A1B2C3”. Yet A1B2C3, while sufficient perhaps in order to single out a data point, does nothing to help me identify a natural person. In other words, the natural person is not identifiable – the baseline for “personal data” (and for the GDPR to apply).
As I wrote in an in-depth piece on pseudonymisation, in my view “identification” of a natural person “requires in essence three things:
(i) the ability to attribute certain information to a natural person,
(ii) the ability to distinguish that person from any other persons (= i.e. so it is a specific natural person, not just any natural person) and
(iii) that distinction must be of such a nature as to make it possible to act upon or in relation to such person.
(More here: https://lnkd.in/e2gC5xzw )
As far as I can tell, both the CNIL and the Conseil d’État have failed to establish that in practice. They have seized upon the notion of “identifiers” as meaning a natural person is “identifiable” when in fact they seem to mean that the natural person can be singled out – and they claim at most to have shown in *theory* some (?) could be reidentified, with their own wording clearly suggesting that this is not the case for all.
Perhaps we need to apply random sampling if there is a serious allegation that not everything is personal data? Regulators should avoid making assumptions, after all.
I’ll soon be publishing a piece on how the EU legislator views anonymisation – and how that might differ from regulatory views. Stay tuned!
Decision: https://lnkd.in/eRWvhQWB
Data protection
Did this analysis get you thinking? Reach out!
DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!
Get in touch ↗ Let's connect on LinkedIn ↗