08 Sep CJEU clarifies pseudonymized data: what it means for clinical trial sponsors and GDPR Article 27 compliance
In a pivotal ruling, the Court of Justice of the European Union (CJEU) has clarified that pseudonymized data may not always constitute personal data for the recipient, depending on whether they have “reasonable means” to reidentify individuals. However, this does not absolve upstream parties – such as clinical trial sponsors – from their obligations under the GDPR.
The case involved the Single Resolution Board (SRB) and Deloitte, where pseudonymized stakeholder comments were shared during a bank resolution process. The CJEU ruled that while Deloitte could not reidentify individuals, the SRB retained that capability and therefore remained subject to GDPR obligations.
Sponsors as controllers: a persistent responsibility
For clinical trial sponsors, this ruling does not change their status as “controllers” under Article 4(7) of the GDPR. Sponsors determine the purpose and essential means of processing personal data, even if the data they receive is pseudonymized. The key point is that the CRO or investigator site, acting as a “processor”, typically retains the reidentification key. This means the data remains personal in the hands of the processor – and by extension, the sponsor remains a controller by virtue of its relationship with that processor.
This interpretation is consistent with the GDPR’s accountability framework, which places responsibility on the entity that orchestrates the processing, regardless of whether it directly accesses identifiable data.
Article 27 Representative requirement still applies
Given that sponsors are controllers of personal data processed in the EU, those not established in the EU must still appoint an EU Representative under Article 27. This requirement is triggered by the monitoring of EU data subjects – such as clinical trial participants – and is unaffected by whether the sponsor can reidentify individuals.
The CJEU’s ruling may reduce compliance burdens for data recipients who truly lack reidentification capabilities. But for sponsors, the core obligations remain intact. They must:
- Maintain appropriate contracts with processors (e.g. CROs).
- Ensure transparency and data subject rights are upheld.
- Appoint an EU Representative if not established in the EU (and ditto in the UK under UK GDPR).
Conclusion
The ruling reinforces a contextual approach to data protection, but it does not dilute the responsibilities of sponsors. Pseudonymization may offer technical safeguards, but it does not negate the legal obligations of those who determine the purpose and means of processing. Sponsors must continue to treat pseudonymized data as personal data and comply fully with GDPR requirements, including Article 27.