DMA-GDPR Joint Guidelines: analysis of consultation responses

Some key findings from the responses to the DMA-GDPR Interplay consultation, now made public by the Commission & EDPB:
– Quite a few civil society responses are copies of one another. Going through the submissions, you’ll see many with identical titles (“uncompromised privacy”, “ensuring data portability is practical and secure”, …) and content. Fortunately there are a few notable exceptions.

– Many such civil society responses refer to the need for compliance with the “high anonymization standard” of the GDPR regarding Art. 6(11) DMA… despite the fact that such anonymisation can only meet the *regulators’ interpretation* of anonymisation if the controller’s own dataset is anonymised, something that none of those responses suggest. This is interesting, as it suggests that – knowingly or not – civil society considers GDPR-compliant anonymisation to be *relative*, not *absolute*, at least where required by law. This goes against the view that data protection regulators have adopted over the years. See my analysis of that question here: https://lnkd.in/eQdrcQrP

– Civil society responses regularly allege that the GDPR prevails over the DMA (while industry responses often say the opposite, namely that the DMA is a lex specialis). The idea that the GDPR might prevail appears hard to justify already based on the very existence + content of Art. 5(2) DMA, so I’m unsure what the basis is for these allegations, but I would love to get some insights into the line of reasoning.

– The responses by academics and by individual companies were particularly interesting. For instance:
— A very well-written in-depth piece on personalised pricing
— A well though-out critique of the “inferred and derived” data inclusion in data portability – and an equally well considered submission by another company saying the exact opposite
— On 6(11) anonymisation: one interesting in-depth piece on 6(11) anonymisation (aligned with my article linked to above), while some others ask for various specific data points to be left intact to preserve utility
— A piece by a small company warning against misclassifications of technical identifiers as personal data (see also my post on that here: https://lnkd.in/eQdrcQrP )

– The consultation response management shows that anonymisation can be hard – even *relative* anonymisation. The Commission & EDPB have included a redacted version of a submission, with the name of the company redacted in the text… yet the file is located within a folder named after a well-known service of only one company. Subtle.

Post concerning a submission by yours truly: https://lnkd.in/e-hcR_sb
All of the submissions can be found here: https://lnkd.in/eCCfri-T

🫖

Did this analysis get you thinking? Reach out!

DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!

Get in touch ↗   Let's connect on LinkedIn ↗