Context Is Not a Loophole
The EDPB’s Quiet Demolition of the Post-SRB Panic
This is the second post in a five-part series on the EDPB’s new anonymisation guidelines and what they mean for the EU’s Digital Omnibus. Post 1 set out the overview: the EDPB has accepted contextual anonymisation, but has left too much operational uncertainty for the Omnibus to fix. This post takes the privacy argument head-on. Post 3 will turn to innovation, research, SMEs and AI development; Post 4 will set out the Omnibus settlement I think the EU should actually adopt; and Post 5 will address the wider data taxonomy question: anonymous, anonymised, synthetic and other non-personal data.
Contextual anonymisation theoretically preserves the rights floor because the legal test asks who can realistically identify whom, using what means, and in what context.
The second post has to begin with an uncomfortable point. Much of the immediate civil society response to EDPS v SRB and then to the Digital Omnibus was politically understandable, but legally poor. Bad legal analysis in the service of good instincts is still bad legal analysis. It may win a quote in a newspaper, harden the activist line, and make the Commission look like a stooge in a permanent deregulatory conspiracy. But it does not make data protection law more coherent, and it does not help data subjects if the practical consequence is that lawful, contextual anonymisation becomes so unattractive that controllers continue to process personal data under heavier, messier, and more opaque compliance structures.
The EDPB’s new Guidelines 02/2026 on anonymisation, adopted for public consultation on 7 July 2026, should therefore be read as more than a technical update. The Board states that anonymous data is data that does not relate to an identified or identifiable natural person, that whether this is so may vary from one entity to another, and that anonymity should be assessed from each relevant entity’s perspective, typically the party for whom the data is intended to be anonymous. That is the heart of the contextual approach. THIS IS NOT A GIFT TO INDUSTRY. It is the application of the identifiability test in Recital 26 GDPR and the case law to the actual party, actual means, actual access conditions, and actual re-identification risk at issue.
Civil society groups and their omnipresent representatives did not invent the risks here. There are real risks. There are bad actors. Some companies will put a privacy-enhancing label on a barely modified spreadsheet and call it “anonymous” with a straight face. There are AI developers who would happily turn “synthetic” into a magical incantation. There are data brokers whose business model consists of living in the grey zone between what the law formally says and what the data subject can realistically discover. The EDPB is fully alive to this. It warns against misleading descriptions such as “anonymous”, “de-identified” or “de-personalised” when people remain identifiable, requires a legal basis and transparency for the anonymisation process itself, and says that documentation of anonymisation and testing should be retained. What is objectionable is not the privacy concern. It is the leap from privacy concern to legal absolutism.
The panic frame arrived quickly. I listened to EDRi’s reps warn that the Digital Omnibus would be “the biggest rollback of digital fundamental rights in EU history!” and urged the Commission to halt attempts to reopen the GDPR, the ePrivacy framework, and the AI Act. noyb, EDRi and ICCL similarly described the draft as a threat to fundamental rights, said it changed core elements of the GDPR, and warned of a “blank check” for AI companies. The rhetoric was effective, and some of the underlying concerns were fair, particularly around the Commission’s drafting technique and the attempt to legislate quickly through an Omnibus that did far more than tidy up administrative edges.
But the legal line pushed by parts of this debate went further than that. noyb’s Digital Omnibus report argued that there is “very little room” to exempt pseudonyms from the GDPR, framed the Commission’s approach as a selective interpretation of SRB, and stressed that the judgment concerned a specific fact pattern. The same report later claimed that other CJEU rulings go in another direction, that even SRB does not support the Commission’s proposal, and that the wording would likely be annulled for conflict with Article 8 of the Charter. Again, there are serious points buried in there. The Commission’s third sentence on subsequent recipients was always more challenging than the basic relative approach. The proposed implementing-act mechanism also raises obvious constitutional questions. But the broader implication that contextual identifiability is some alien deregulatory infection is simply wrong.
It is also revealing. The privacy maximalist reading of SRB seeks to preserve the part of the judgment that supports its case (i.e., the controller-perspective point on the transparency obligation) while treating the contextual part as a narrow, fact-bound curiosity. That is not how judgments work, and it certainly isn’t how SRB works.
SRB is not an absolutist judgment. It preserves controller-perspective obligations in their proper setting while rejecting the idea that pseudonymised data is personal in all cases and for every person.
The EDPB’s own discussion of SRB is the simplest way to see the point. The case concerned the obligation to inform data subjects of the recipients of their personal data at the time of collection. The SRB argued that because the information might be anonymous from Deloitte’s perspective, the transfer would not qualify as a transfer of personal data for the information obligation. The CJEU rejected that argument. The obligation had to be assessed at the time of collection and from the controller’s perspective, because that obligation formed part of the legal relationship between the data subject and the controller. So far, so good. If this were all SRB did, the maximalist reading would have some force.
But it is not all SRB did. The same judgment, and now the EDPB’s anonymisation guidance built after it, preserves the contextual point: whether information is personal may vary from one entity to another. The EDPB expressly states that information may be anonymised for some entities but not others, and that the goal of anonymisation can be to anonymise data for everyone or only for particular entities. It also asks the practical question that the absolutist reading cannot answer: for whom is the data intended to be anonymous?
That is not a loophole; rather, it is the structure of the very legal test I have argued elsewhere existed all along. The GDPR does not regulate data because it once had a biographical history. It regulates personal data, which depends on whether a natural person is identified or identifiable. Identifiability, in turn, depends on the means reasonably likely to be used. If the relevant party cannot identify the person, cannot reasonably obtain the means to identify the person, is not acting on behalf of a controller who can identify the person, and is bound within a practical context in which re-identification risk is insignificant in reality, calling the data personal for that party is not rights protection; on the contrary, it is a category error.
This is the first flaw in the civil society panic line: it treated context as evasion. But context is not evasion. Context is how Recital 26 has always worked! It is how Breyer works. It is how the GDPR’s definition of personal data works once you take the words “identified or identifiable” seriously rather than treating them as a one-way ratchet. The legal question is not whether identification is imaginable. The legal question is whether it is reasonably likely, from the relevant perspective, using means reasonably likely to be used. The EDPB is not inventing that. It is trying, with some caution and considerable complexity, to operationalise it.
The second flaw is the attempt to treat SRB as if it were too peculiar to matter. Of course the facts matter. The facts always matter in identifiability analysis. But that is an argument for contextuality, not against it. The fact that SRB involved comments, codes, Deloitte and the SRB’s own re-identification key does not make the judgment irrelevant to anonymisation. It shows why a single answer for every actor is poor law. The controller with the key is in one position. A recipient without the key, without access to the mapping table, and without reasonably likely means to reconstruct identity may be in another. A recipient acting as a processor may be in another still. The point is not that every recipient gets a free pass. My point has always been that legal consequences follow role, access and means, not slogans.
The third flaw is more serious. Some of the civil society analysis implicitly relies on a constitutional-freezing argument: Article 8 of the Charter protects personal data, Directive 95/46 uses a broad definition, and therefore the legislature has little room to clarify when pseudonymised or anonymised information falls outside the GDPR’s scope. noyb’s report presents a version of this argument by describing the Article 8 definition as a minimum standard, suggesting that the legislator has no power to change the definition of personal data outside the scope of Directive 95/46, and warning that exclusions for pseudonyms would conflict with the Charter. There is a kernel of truth here: the legislature cannot hollow out Article 8 by definitional trickery. But the move from that proposition to “very little room” for relative identifiability is much too quick.
The Charter does not require the law to ignore reality. It does not require the EU to treat information as personal for an entity that cannot identify the person using means reasonably likely to be used. It does not require every pseudonym, every coded record and every anonymised output to carry the full GDPR regime for every actor merely because somebody else, somewhere else, may have additional information. Article 8 is a rights guarantee, not a metaphysical theory of data ontology. It protects data subjects against real risks to their rights and interests. It does not require the law to pretend that all risks are the same.
The EDPB’s new guidelines make this especially hard for the maximalist camp because the Board has not adopted an industry-friendly caricature of contextuality. Quite the opposite. It interprets “means” broadly. It says means may include means available through a third party. It warns that relevant entities may include recipients, rogue employees, people with access to auxiliary information, investigative journalists, domestic or foreign intelligence agencies, unethical companies, and cybercriminals, depending on the circumstances. It cautions against relying too readily on lack of motivation. It treats contractual restrictions as relevant but not equivalent to a prohibition by law. It warns that re-identification risk increases over time. This approach appears to be a cautious, possibly overcautious, data-protection-risk framework.
That is precisely why the civil society line is now in trouble. The EDPB’s anonymisation guidelines seem to accept contextual anonymisation while retaining an aggressive view of the means and actors that may matter. It has done the hard privacy work that EDRi and noyb claimed was absent from the Omnibus debate. It has been shown that one can stand opposed to a Commission-drafting technique without rejecting contextuality as such.
The processor boundary is the answer to the laundering objection. Where the recipient acts on the controller’s instructions, the controller’s identifiability follows the processing.
The processor section is the point the panic merchants should have been waiting for, although I suspect it will not be advertised as a victory in their newsletters. The EDPB says that where an entity processes information on behalf of another, whether the data is personal for that entity should be assessed by reference to the controlling entity’s perspective. If the controller can identify the individuals and determine the purposes and means, the information is personal data for the processor as well. The EDPB calls this a teleological application of the GDPR, because the processor concept exists to prevent controllers from avoiding data protection obligations by outsourcing processing to third parties.
This is devastating to the lazy “contextual anonymisation equals laundering” critique. A controller cannot simply hand data to a technically blind vendor and declare GDPR dead. If the vendor is processing on behalf of the controller, the controller’s perspective follows the processing. The e-commerce example in the guidelines says exactly this: customer-record excerpts sent to an agency for analysis remain personal data for both the retailer and the agency, with the retailer able to identify customers and the agency acting on its behalf. By contrast, a hospital sending excerpts to an independent research institute can be different, where the institute determines its own purposes and means, the data is not returned, and the institute is not acting on the hospital’s instructions.
That is the missing discipline in the debate, not a loophole. The law distinguishes between processors and independent recipients because the risk, control relationship, and allocation of responsibility differ. Data protection law becomes more accurate, not weaker, when it notices this. If civil society wants to attack genuine laundering, it should attack sham role allocation, fake independence, weak separation, return flows, hidden keys, undisclosed matching, and contractual theatre, as it looks like DG COMP risks doing with DMA 6(11). I would join that attack. What it should not do is pretend that the only privacy-respecting position is to deny the relevance of the recipient’s perspective altogether.
The fourth flaw is the persistent collapse of pseudonymisation, anonymisation and non-personal data into a single, undifferentiated category. Pseudonymisation is a technique applied to personal data: it reduces linkability but does not necessarily take the data outside the scope of the GDPR. Anonymisation describes an outcome, assessed contextually but objectively, in which a person is no longer identifiable by means reasonably likely to be used from the legally relevant perspective. Non-personal data is broader still: it includes information that was never personal, synthetic and aggregate data, statistics, successfully anonymised data and, following SRB, data that may be personal to one entity but non-personal to another.
Much of the civil-society critique trades on obscuring these distinctions. The proposition that “pseudonymised data remains personal data” is treated as though it answers the different question whether the same dataset must be personal data in the hands of every recipient. It does not, nor does contextual analysis simply allow pseudonyms to escape the GDPR. The more difficult question is whether the EDPB is now using “anonymous for whom?” as shorthand for information that is non-personal from a particular entity’s legally relevant perspective; and, if so, whether that defensible substantive move comes at the cost of blurring an important taxonomy? I will return to that question in Post Five, where I examine whether anonymisation should remain a more absolute category within the broader universe of non-personal data, or whether “contextual anonymisation” has become the necessary vocabulary for the relativity recognised in SRB. The guidelines are careful. They say anonymisation is any processing that successfully produces anonymous data under the GDPR, whether or not the original data is deleted. They also say that when anonymising information in some respects but not others, the controller must still comply with the GDPR in the respects in which the data remains personal. That little rule is the nuance civil society keeps trampling over in its haste to denounce. Contextual anonymisation does not say “once anonymous for someone, anonymous for everyone”. It says the opposite: identify the relevant perspectives and assess them properly.
The fifth flaw is the refusal to treat over-inclusion as a rights problem. This will sound strange to some privacy professionals because the field’s culture often treats over-inclusion as harmless caution. If in doubt, keep the GDPR on. If in doubt, treat data as personal. If in doubt, impose the heavier regime. That approach is sometimes defensible. It is also sometimes intellectually lazy. The EDPB itself recognises that the simplified approach may go beyond the legal standard and may lead a controller to treat data as personal even where it would actually be anonymous for some relevant entities. It calls this a shift from false positives to false negatives: safer in doubt, perhaps, but not the legal standard.
A legal system that constantly overstates the scope of personal data does not merely inconvenience firms. It changes incentives. It may discourage anonymisation because the legal benefit becomes uncertain. It may discourage data sharing in controlled research environments. It may push controllers to keep richer personal datasets under internal control rather than to produce tested, anonymised outputs for safer reuse. It may make privacy-enhancing technologies look like expensive theatre rather than a route to reduced risk. In other words, the absolutist approach can increase personal-data processing by making the exit from personal data legally unusable.
This data protection argument is the one civil society should be making and too often is not. Proper anonymisation is privacy protection. It is not a concession. The point of anonymisation is to reduce the number of situations in which identifiable people are in play. A system that treats anonymisation as practically impossible does not strengthen privacy. It removes one of privacy law’s best risk-reduction tools.
Civil society’s vocabulary can be politically useful, but legal analysis still has to pass through Recital 26, means reasonably likely, role allocation and objective factors.
None of this means that EDRi, noyb and other civil society organisations were wrong about everything in the Omnibus debate. Reopening core concepts through a fast-moving omnibus instrument is institutionally risky. The EDPB and EDPS were right to object that the proposed changes to the definition of personal data went beyond a targeted technical amendment, did not accurately reflect the CJEU case law, and risked significantly narrowing the concept of personal data. They were also right to be concerned about giving the Commission implementing powers over what counts as no longer personal data after pseudonymisation. And more careful academic commentary has drawn a fair distinction: the relative approach itself may stem from prior case law, but the Commission’s treatment of subsequent recipients may go further than the Court’s.
That is the position I think is worth defending. Not the Commission draft as written. Not the industry fantasy that “de-identified” means “do what you like”. Not a blank cheque for AI training. But also not the civil society fantasy that contextual identifiability is a loophole merely because it refuses to treat every actor as if they held every key, every auxiliary dataset and every possible future capability. The EDPB/EDPS joint opinion on the Omnibus is more balanced than the activist line around it. It strongly opposed the proposed changes to the definition of personal data. Still, it also supported some simplification measures, including higher breach-notification thresholds and common templates, welcomed harmonisation of scientific research, accepted that legitimate interest may in some cases be used for AI models under the current GDPR, and recommended improvements rather than outright denial in several AI-related areas. That is what serious privacy supervision looks like: not maximal restriction, not business-as-usual deregulation, but discrimination between the bad, the workable, the under-specified and the genuinely useful.
The same discrimination is needed here. Contextual anonymisation should be defended precisely because it is a privacy-preserving middle path. It says that if the controller can identify, it remains subject to the GDPR. If the recipient is a processor, the controller’s perspective follows. If a recipient is independent, lacks identifiers, lacks access to keys, lacks reasonably likely means of re-identification, and operates under technical and organisational controls, it may be legitimate to treat the data as anonymous from that recipient’s perspective. If circumstances change later, reassessment may be needed. If the data is publicly released, the risk universe expands. If inference becomes specific and meaningful, the No Inference criterion may be violated. If a label is misleading, the controller is wrong. If documentation is absent, the controller has not done the work. That is law, not deregulation.
Contextual anonymisation is privacy-enhancing because it creates a route to less personal data processing, provided the route is tested, documented, and enforceable.
The irony is that civil society should have an interest in ensuring that contextual anonymisation works. If the law gives controllers a credible route from personal data to anonymous data, privacy advocates can demand that route be used wherever possible. They can ask why an AI developer needs raw personal data if an anonymised or synthetic alternative would suffice. They can ask why a public authority is retaining identifiers when aggregate or anonymous outputs would do. They can ask why a research infrastructure has not adopted key separation, access controls, re-identification testing and periodic reassessment. They can insist that the anonymisation process itself has a legal basis, transparency and documentation. They can push the EDPB to convert this high-level framework into certification and assurance pathways. That is a much stronger privacy agenda than simply yelling “rollback” whenever the law admits that context matters.
The absolutist route is emotionally satisfying but strategically shallow. It assumes that the best way to defend data subjects is to keep as much data as possible inside GDPR for as long as possible. Sometimes that is right. More often it is not. The best protection may be to minimise, delete, aggregate, anonymise, separate keys, restrict access and move use into a non-personal or recipient-anonymous environment. Treating those moves as suspect by default is not privacy protection. It is regulatory hoarding.
This is also why the “civil society versus innovation” framing is too simple. My Innovation Mandate is not an argument for lowering the rights floor. It is an argument that, where Union law leaves discretion, supervisors should explain the route in a way that is proportionate, coherent, innovation-aware and no more burdensome than the law requires. Civil society has a crucial role in that model, but not as a veto machine. Its role is to defend the rights floor while scrutinising both permissive and restrictive supervision. That means it should criticise fake anonymisation, yes. It should also criticise supervisory absolutism where it prevents safer forms of data use without giving adequate reasons.
A privacy movement that cannot distinguish those two tasks will keep mistaking seriousness for severity. Severity is easy. Say no, widen the scope, multiply the risk, assume the worst, and call the result “rights protection”. Seriousness is much harder. It asks which risks are real, which actors have which means, which controls work, which legal relationship is present, which inferences matter, and which institutional mechanisms can make the assessment auditable rather than decorative. The EDPB’s guidelines are imperfect, but they are closer to seriousness than much of the reaction to SRB.
The proper criticism of the guidelines is therefore not that they accept contextual anonymisation. They should. The proper criticism is that they do not yet make it usable enough. They do not give sufficient technical recipes. They leave too much cost and uncertainty on each controller. They are cautious about the legal force of controlled environments. They tell organisations to reassess over time without defining operational triggers. They accept contextuality but still risk producing compliance anxiety through expansive adversary lists and broad “means” analysis. Those are real criticisms. They are Omnibus criticisms. They are not maximalist criticisms.
This is where the privacy argument and the Omnibus argument meet. The Omnibus should not codify a loophole. It should codify a discipline. It should preserve the processor anti-evasion rule. It should distinguish public release, controlled-access research, internal analytics and independent-recipient sharing. It should give legal weight to audited governance environments. It should create rebuttable presumptions for recognised anonymisation methods and privacy-enhancing technologies. It should define reassessment triggers. It should keep misleading labels actionable. And it should make clear that anonymous or recipient-anonymous data is not outside all law; it is outside GDPR only insofar as it is not personal data, while AI, data, cyber, contract, sectoral and public-law safeguards may still apply.
The EDPB has now made the absolutist line for civil society harder to sustain. It has accepted that anonymity may vary by entity. It has accepted that the contextual approach reflects the full nuance of the legal standard. It has preserved the simplified approach for those who want caution. It has retained the three criteria from 2014 while making clear that failing one of them does not automatically mean the data is personal. It has distinguished population-level learning from specific meaningful inference. And it has drawn a processor boundary that blocks the obvious outsourcing loophole.
That is a privacy-preserving settlement. It is not the final settlement, but it is a better starting point than the panic line. EDRi and noyb are right to be suspicious of claims about bad anonymisation. They are right to distrust Commission shortcuts. They are right to insist that Article 8 cannot be hollowed out by clever drafting. But they are wrong when they treat contextual identifiability as a betrayal of the GDPR. They are wrong when they use SRB as a prop for an absolutist position the case itself does not support. They are wrong when they confuse the possibility of abuse with the legal nature of the test. And they are wrong if they think a high-rights legal order is strengthened by refusing to reason about context.
The privacy community should do better. It should stop treating anonymisation as a trick and start treating it as a demanding form of privacy engineering. It should stop treating non-personal data as an ideological threat and start asking how the transition from personal to non-personal can be tested, documented and supervised. It should stop pretending that every clarification of identifiability is deregulation and start distinguishing between lawful contextuality and actual evasion.
The rights floor matters and that is precisely why the analysis has to be better.
Source notes
1. EDPB, Guidelines 02/2026 on Anonymisation, version 1.0, adopted 7 July 2026, especially pp. 2–3, 5–8, 15–18, 21–23 and 26–29.
2. CJEU, Case C‑413/23 P, EDPS v SRB.
3. noyb, “Open letter: Digital omnibus brings deregulation, not simplification”, 11 November 2025.
4. noyb, Digital Omnibus: First Analysis of Select GDPR and ePrivacy Proposals by the Commission, 2025.
5. EDRi, “Forthcoming Digital Omnibus would mark point of no return”, 13 November 2025; and “Why the Digital Omnibus puts GDPR and ePrivacy at risk”, 19 November 2025.
6. EDPB/EDPS, Joint Opinion 02/2026 on the Digital Omnibus.
7. Julie Mannekens, “Personal data in the Digital Omnibus: where are we going?”, KU Leuven CiTiP Blog, 6 January 2026.






