In-depth commentaries

Incidental processing and GDPR: from bystanders to spontaneous notes, do data protection rules apply?

Another week, another product announcement from someone involving AI in your pocket, on your wrist, in front of your eyes. I have met people whose lives have literally been transformed as a result of some of these tools, such as an individual who is suddenly able to use a camera in glasses to film his […]

Read Analysis →

DMA & anonymisation: regulatory risks of under-anonymisation

How solid is your anonymisation? Is “good enough + contractual prohibition to re-identify” really sufficient? The Commission’s DMA team seems to think so, though its own idea of “good enough” relies on magic personal data scrubbers. Perhaps the Commission’s DMA team should read up again on GDPR case law on “personal data” (Breyer, Scania, SRB […]

Read Analysis →

Anonymisation of personal data: compliance vs utility, regulators vs the law

The clear repudiation of an “absolute” concept of personal data has thrown a sharp focus on the process of pseudonymisation in the world of data protection. Through its SRB judgment of 4 September 2025, the Court of Justice of the European Union (CJEU) made it clear that personal data that has undergone pseudonymisation can be […]

Read Analysis →

Making the GDPR realistic? Authorities only want that in part

[This is a translation of an op-ed in French that was published in the French journal Revue Politique on SRB and the Digital Omnibus, plus the newest EDPB & EDPS Joint Opinion on the topic. The original in French can be found on the Revue Politique website. + The banner image is a jest – […]

Read Analysis →

Pseudonymisation & “means reasonably likely to be used” for identification: when does data become personal?

As I was in a meeting when the European Data Protection Board opened registration for its pseudonymisation stakeholder event of 12 December 2025, I missed the short (approx. 1h) registration window and they placed me on a waiting list instead – a pity given my frequent interventions on the EU Court of Justice’s SRB judgment […]

Read Analysis →

DMA-GDPR Guidelines: formal response to public consultation

When I pointed out issues with the DMA-GDPR Guidelines & resulting risks for *all* controllers (not just gatekeepers), the EDPB’s Gwendal Le Grand said something to the effect of “Don’t just post about it, submit a response”. So here we go, a copy of the response submitted yesterday to the public consultation by the Commission […]

Read Analysis →

When is data no longer personal? And what are the implications?

The ruling of the Court of Justice of the European Union (CJEU) of yesterday, 4 September 2025, in the EDPS v SRB case is significant – never mind the naysayers. It is the first time that the CJUE has clearly, explicitly said that if a dataset initially contains personal data but is pseudonymised, and that […]

Read Analysis →

What is the “combination” of data under the Digital Markets Act?

In law, the choice of words matters, and a given interpretation can mean the difference between a behaviour being permitted or prohibited. When some recently claimed that the Cologne Higher Regional Court might have misinterpreted one of the European Union’s newer data-related acts, the Digital Markets Act (DMA for short), the challenge to the judges’ […]

Read Analysis →

Good & bad in judgment on Meta AI training & personal data (legitimate interests, sensitive data) + new French & German guidance

Does training of AI systems involve the processing of personal data, and is it permitted under the GDPR? These were the two fundamental questions that I have already looked into in two previous articles: On the date of that second article, the Cologne Higher Regional Court (the Oberlandesgericht Köln – the Cologne HRC) delivered a […]

Read Analysis →

AI Agents – When agency and subordination go hand in hand

This is an article that I wrote in the context of a Chatham House rules roundtable on questions to be tackled more extensively in the future regarding the interaction between AI systems & data protection. This particular one relates to AI agents and the notion of authority, notably as regards (i) the user’s perspective (subordination?), […]

Read Analysis →