No Key, No Processor. The Duty to Inform Still Applies
The relative concept of personal data can put the same dataset inside GDPR's scope on your side and outside it on the recipient's. That asymmetry belongs in the definitions of the data processing agreement and in the Art. 13 GDPR privacy notice — not buried in a footnote of the pseudonymisation concept.
Casimir von Firn, MLaw
In June 2019, the Single Resolution Board (SRB) sent Deloitte 1,104 shareholder and creditor comments on Banco Popular, each tagged with nothing more than an alphanumeric code. The SRB kept the key. Out of that transfer, the Court of Justice of the European Union (CJEU) built, in its judgment of 4 September 2025 in Case C-413/23 P, the proposition that pseudonymised data is not personal data “in all cases and for every person” (para. 86) — and in the same judgment held that the duty to inform is assessed by reference to the controller at the moment of collection, not to the recipient (paras. 111–112).
So the asymmetry sits right there in the judgment itself. The same transfer may fall within scope on your side and outside it on your counterparty’s. Anyone who notes that only in the pseudonymisation concept has filed it in the wrong place: the asymmetry belongs in the definitions of the data processing agreement and in the disclosure required under Art. 13(1)(e) GDPR.
What the Judgment Actually Separates
The Court works with two vantage points on a single dataset. For the Resolution Board, which held the key, the comments remained “necessarily” personal data (para. 76). For Deloitte, which did not have the key and had no reasonable means of re-identification, the same information could lose that quality (para. 77). The yardstick is the “means reasonably likely to be used” test from recital 16 of Regulation (EU) 2018/1725, which the Court in para. 79 applies both to the controller and to “another person”. Which vantage point applies depends, per para. 100, on the circumstances of the specific processing.
What the judgment interprets is Regulation (EU) 2018/1725 — the data protection rules for the EU institutions — not the GDPR. For data processing agreements under the GDPR, the interpretation carries over, because Art. 3(1) of Regulation 2018/1725 and Art. 4(1) GDPR use the same definition of personal data. But the Court has not decided the point for the GDPR itself.
That is not a free pass — it is an evidentiary question, and the burden sits with the sender. We covered that part on 1 July in relation to the data room; nothing has moved there.
The Half Everyone Skipped Over
Yet the Resolution Board lost the case on precisely this point. Under para. 110, the duty to inform concerns the data as received by the controller — that is, before any transfer. The recipient therefore had to be named, even though the data might lose that status on arrival at the recipient’s end.
Under the GDPR, the duty sits in Art. 13(1)(e) and Art. 14(1)(e): the recipients or categories of recipients must be disclosed. Swiss law has the parallel in Art. 19(2)(c) of the Swiss Data Protection Act (DSG), which requires disclosure of “the recipients or categories of recipients, where applicable”. Neither provision makes disclosure contingent on what the data legally amounts to once it lands with the recipient. Anyone who strips a category of recipient from the privacy notice because that recipient doesn’t get the key has turned an observation about the recipient into relief for the sender. That doesn’t hold up.

Where the Market Moved Too Fast
The reading that has taken hold since the judgment is that pseudonymised transfers now routinely fall outside the GDPR. The regulators haven’t caught up everywhere. The EDPB Guidelines 01/2025 on pseudonymisation, adopted for public consultation on 17 January 2025, state in para. 22 that pseudonymised data remains personal data where it could be combined with the additional information “having regard to the means reasonably likely to be used by the controller or by another person”. And expressly: that applies even where the data and the additional information are not held by the same party.
The EDPB has moved on the neighbouring topic — the anonymisation guidelines we discussed on 11 July. The pseudonymisation guidelines have been in draft for a year and a half now and still appear as an open item in the 2026–2027 work programme. Whoever reviews your file is working from that draft, not from para. 86.
What Belongs in the Contract
Art. 28(3) GDPR requires the data processing agreement to set out the subject matter and duration, the nature and purpose of the processing, “the type of personal data” and “the categories of data subjects”. Those are exactly the particulars that the relative concept of personal data dissolves on the recipient’s side. If the dataset isn’t personal data in the recipient’s hands, the obligations under Art. 28(3) lose their statutory anchor against it. Whether the recipient is even a processor at all then becomes a live dispute — precisely at the moment you schedule an audit.
The fix is a drafting one, not a doctrinal one. The duty to act only on instructions (Art. 28(3)(a)), deletion or return at the end of the engagement (Art. 28(3)(g)) and the audit right (Art. 28(3)(h)) need to be spelled out as freestanding contractual obligations, not incorporated by reference to Art. 28 GDPR. A reference clause that goes nowhere once the provision stops applying costs you exactly the right you were counting on.
Second, once personal-data status falls away, Chapter V GDPR goes with it, and so does Art. 16 DSG on cross-border disclosure. That’s the commercially attractive part — and also the most fragile. It holds only for as long as the recipient acquires no means of attribution. The agreement therefore needs a warranty that prohibits three things: acquiring the key, combining the data with other datasets, and staying silent once either risk materialises. If the status flips, it flips retroactively — against you.
Concretely, for Monday: pull the “type of personal data” schedule from the last three contracts you signed involving pseudonymised transfers, and check whether the obligations listed there would still be enforceable without Art. 28 GDPR behind them.
What’s Settled and What Isn’t
What’s settled is paras. 111–112: the duty to inform stays with the controller and is assessed at the moment of collection. What isn’t settled is how the test applies in practice. The CJEU referred the case back to the General Court; the test was never actually applied, because the parties settled. To date, there is still no worked example.
It will be the Digital Omnibus that resolves this, not case law. On 19 November 2025 the Commission proposed writing the entity-relative test into Art. 4(1) GDPR; the EDPB and EDPS rejected that in their Joint Opinion 2/2026 of 10 February 2026 as going beyond a mere technical correction. According to reporting by EU Tech Reg, the Irish Council presidency dropped the Cypriot compromise text in July 2026 and sent member states a questionnaire that names pseudonymisation explicitly; by 15 July 2026 Parliament had more than 1,000 amendments on the table, and a negotiating position isn’t expected before February 2027. The next Council presidency compromise text is the document that will show whether the asymmetry becomes statute or stays a matter of judicial interpretation. Until then, it’s your contract that carries it.