Anonymisation through the eyes of the French Data Protection Authority: Lessons from the CNIL’s €5 Million Decision (July 2026)
Key takeaways
If you are a data privacy professional or regularly encounter personal data in your work, you will no doubt be aware of the ongoing debate around “what is personal data?”, “is it pseudonymised or anonymised?”, and “is it identifiable in our hands?”. These questions require detailed factual and legal analysis — and the stakes for getting the answer wrong have just become significantly clearer.
The French data protection authority (CNIL) has issued a landmark €5 million fine against a global leader in clinical research and health data analytics. After concluding that the data processed in the company’s health data warehouses was pseudonymised rather than anonymous, the CNIL found that the company was processing personal data and sanctioned it for multiple infringements of the GDPR and the French Data Protection Act in connection with the operation of its health data warehouses. The decision has significant implications for life sciences organisations involved in clinical trials, real-world evidence generation, data licensing, and commercial data partnerships. Organisations should review whether their identifiability assessments would withstand the rigorous, multi-factorial analysis applied by the CNIL.
What were the facts?
The company operates two data warehouses:
Pharmacy warehouse: This collects information about medicines dispensed by pharmacies. Each patient is assigned a unique ID which is the same across all pharmacies, meaning a patient’s purchases and prescription details can be linked across various pharmacies.
Physician warehouse: This collects a wide range of consultation details, including patient ID, date of visit, diagnosis, prescriptions, and demographic information like gender and marital status.
In both cases, the data collected from pharmacies and physicians undergoes a pseudonymisation process carried out by various third parties before it is uploaded into the respective warehouse. Critically, these third-party providers were designated by, contracted with, and/or operating to specifications defined by the company. Despite receiving only pseudonymised data, the company argued that the data in its warehouses was anonymous and therefore fell outside the scope of the EU GDPR. It is worth noting that this has not always been the company’s position. Prior to the SRB case – referred to below – the company determined that the data within its warehouses was personal data.
The CNIL’s findings
The CNIL concluded that the data in the company’s warehouses constitutes personal data and that the company is the controller for that data. Importantly, the CNIL found this to be the case from the point of initial collection at pharmacies and physicians’ practices, not just from receipt at the company’s servers. The CNIL’s analysis involved several interlocking factors:
Single processing chain: The CNIL treated all operations — from initial collection at pharmacies, through successive pseudonymisation steps by trusted third parties, to warehouse upload — as a single processing chain pursuing a single objective determined by the company. The involvement of multiple actors did not break the chain of controllership.
Failure to resist the risk of individualisation: The CNIL found that the data did not resist the risk of individualisation because each data subject was assigned a unique identifier, enabling all information relating to that individual to be consistently isolated within the dataset. The CNIL considered that this persistent unique identifier, combined with the richness of the health and contextual data, made it possible to single out individual records.
Re-identification by reasonable means: The CNIL applied a structured re-identification risk analysis drawing on EDPB guidance and CJEU case law. The analysis examined whether individuals could be singled out within the dataset, whether records could be linked, and whether inferences could be drawn — considering both the richness of the data and the availability of external information. In one illustrative example, the CNIL demonstrated that a patient with a rare disease could be re-identified in minutes using publicly available social media posts.
Re-identification of one individual renders the whole dataset personal data. Following the example referred to above, the CNIL determined that having the ability to identify one individual within the dataset, renders the entire dataset personal data.
Content in privacy notice: The company’s own patient information leaflet explicitly states that the company is a controller of the data collected for the creation of the physician warehouse.
The company argued that it had no intention of re-identifying patients and that contractual restrictions prevented it from doing so. The CNIL rejected both arguments:
Intention is irrelevant: The motivation of a controller or third party to re-identify individuals is not a relevant factor. What matters is technical capacity, not subjective intent. This aligns with the EDPB’s draft guidelines on anonymisation, which note that motivation is inherently subjective and can change over time.
Contractual restrictions alone are insufficient: The CNIL held that contractual prohibitions on re-identification do not render re-identification “prohibited by law” within the meaning of the CJEU’s case law. While such restrictions may be a helpful risk-reducing measure, they do not change the legal classification of the data.
The SRB judgment does not assist: The company sought to rely on the CJEU’s September 2025 judgment in SRB [see our article on this case here], which held that pseudonymised data could, in certain circumstances, lose its personal character for a recipient who lacks the means to re-identify individuals. The CNIL distinguished SRB on the facts: unlike the audit firm in that case (which merely received pseudonymised comments), the company was not simply a recipient of pseudonymised data — it was responsible for the entire processing chain from the point of collection. The CNIL emphasised that the assessment of identifiability depends on “the circumstances characterising the data processing in each particular case”, including the role played by the organisation in question.
Why does this decision matter for life sciences organisations?
The company’s data warehouses — which track patient care pathways, aggregate prescription data from pharmacies, and enable longitudinal real-world studies — are operationally similar to many life sciences data programmes. The CNIL’s findings are therefore directly relevant to organisations involved in clinical research, post-marketing surveillance, and commercial data partnerships with healthcare providers.
Whether a dataset is classified as personal data can have significant consequences: not only do the full obligations of the EU GDPR become applicable, but it can considerably restrict what an organisation can do with the data (for example, lawfulness and purpose limitation principles). For organisations that have concluded their data is sufficiently anonymised, the CNIL’s reasoning should prompt a careful reassessment.
There is, however, a positive dimension to the CNIL’s rigorous approach. The decision provides welcome regulatory certainty about how identifiability assessments will be conducted. Organisations can no longer take false comfort from assumptions that their pseudonymised data falls outside the EU GDPR — those that undertake robust assessments and implement appropriate safeguards will have greater confidence that their compliance positions are defensible.
What should life sciences organisations do now?
For organisations that process pseudonymised health data at scale — whether through clinical research programmes, real-world evidence platforms, or commercial data partnerships — this decision should prompt a careful review. The CNIL’s analysis, which aligns with the direction of the EDPB’s draft guidelines on anonymisation, represents a rigorous application of established principles that other regulators may follow.
Scrutinise anonymisation assumptions: Organisations that treat pseudonymised data as falling outside the EU GDPR should assess whether that position would withstand the multi-factorial analysis applied by the CNIL. This requires consideration of technical, contextual, and organisational factors — including the nature of the data, the availability of external information sources, and the organisation’s role in the processing chain. Such assessments should be documented and revisited periodically, as the means reasonably likely to be used for re-identification can evolve.
Review controllership positions: The CNIL’s “single processing chain” analysis has implications for organisations that receive data through intermediaries or trusted third parties. Where an organisation determines the purposes and means of upstream collection and pseudonymisation activities — for example, by specifying data formats, defining extraction parameters, or selecting processing partners — it may be considered a controller from the point of collection, notwithstanding that it never receives data in an identifiable form.
Audit transparency materials: In reaching its decision, the CNIL examined the company’s patient information leaflets, which identified the company as a controller and described a pathway for re-identification to enable exercise of data subject rights. Organisations should review their privacy documentation to ensure it accurately reflects their processing activities and controllership positions — and be aware that such materials may be used as evidence of data classification.
Although this decision is not binding in the UK, the analytical framework applied by the CNIL — including the concepts of “singling out”, “linkability”, and “inference” drawn from the Article 29 Working Party’s guidance — closely mirrors the ICO’s approach in its guidance on anonymisation. However, there are several factors that the CNIL failed to consider which, in our view, would have been considered had the same case been reviewed by the ICO. One such example is that the CNIL failed to assess the “likeliness” of adopting the means that may be available to the company to reidentify the patients. This is one area where the ICO has published detailed guidance, including as a key part of its “motivated intruder test”. Organisations operating across both jurisdictions should therefore not expect consistent regulatory expectations.
We will continue to monitor developments, including the EDPB’s consultation process on its draft anonymisation guidelines. In the meantime, organisations processing pseudonymised health data — particularly those involved in clinical research, real-world evidence generation, or commercial data partnerships — should consider whether their current assessments would withstand regulatory scrutiny of the kind applied here. We regularly advise life sciences organisations on identifiability assessments, including structuring data flows, documenting controllership positions, and preparing defensible records of processing. If you would like to discuss how your organisation’s data practices compare to those examined by the CNIL, please contact our Data Protection team or your usual Stephenson Harwood contact.