On February 10, 2020, the German Government Commissioner for Information Protection and Independence of Details (BfDI) initiated its initial public consultation procedure upon the anonymization of private data, with a specific concentrate on providers of digital communication services. Because the European Commission Communication in A European Technique for Data identified, anonymized data can be utilized for most purposes and bring enormous advantages to citizens, for instance, by improving mobility and street safety.
In its declaration, the BfDI reasoned that anonymization, according to the process used, is actually a valid option to the deletion of information. Expert people, stakeholders and businesses have before end of Monday, March 23, 2020, to take part in the consultation treatment. They’re encouraged to submit their proposals about anonymization in light of the overall Information Protection Regulation (GDPR) via email to konsultation@bfdi.bund.de.
What Is the Reason for this Consultation Procedure?
Through the consultation method, the BfDI hopes to initiate a public debate about anonymization and receive input from the general public and affected stakeholders with regards to the way the industry is coping with the topic. The BfDI intends to create guidance to worried stakeholders and telecoms suppliers on the usage of anonymization strategies. Interestingly, the assistance can not only be appropriate to those that belong to the competence of the BfDI (i.electronic., telecoms providers and open public bodies), but can be anxiously awaited by additional industries.
Anonymization Beneath the GDPR (And the TKG)
Both the GDPR and the TKG make reference to the anonymization of data. Pursuant to Sect. 96 pra. 3 and 98 pra. hands down the German Telecommunications Work (TKG), a service service provider must either anonymize visitors and location information (respectively) or delete them.
Although mentioned in the recitals of the GDPR and directly in the TKG, which transposes the ePrivacy Directive within Germany and therefore regulates the processing of traffic data (and the like), the anonymization of personal data is neither described nor further described within the GDPR nor the TKG, and continues to be debated among scholars. Neither the GDPR nor the TKG supply any help with how to make this happen within the framework of the GDPR and TKG.
With insufficient a definition, the BfDI utilizes recital 26 of the GDPR, in accordance with which anonymous data is “information, which will not relate with an identified or even identifiable natural individual,” that is to be dependant on taking “all the means reasonably apt to be used, such as for example singling away, either by the controller or even by another person to recognize the natural individual directly or even indirectly. To see whether means are usually reasonably apt to be used to recognize the natural individual, account ought to be taken of most objective factors, like the expenses of and the period of time necessary for identification, considering the available technology during the processing and technologies developments.”
Moreover, the BfDI promotes an impression previously represented within Germany, in accordance with which anonymization shouldn’t be construed to imply that absolutely simply no re-engineering is necessary to make sure that identification is completely excluded. Nevertheless, the BfDI is crystal clear that it believes the re-identification ought to be therefore burdensome that no re-identification is feasible since it would become either very costly, time-eating, or would require an excessive amount of manpower.
Given that technologies is advancing so quick that what’s considered anonymous today might not be real tomorrow, it is apparent that the anonymization of information requires an ongoing hard work by controllers to make sure data remains anonymized. This implies it is a continuing challenge for information controllers to seriously anonymize data and keep maintaining technical actions in this respect.
The question remains on what much anonymization will do. In addition, just how much effort is necessary of a controller to make sure that information remains anonymized?
Anonymization And the necessity for a Legal Schedule
The BfDI considers that the practice of processing information for the purposes of anonymizing this is a information processing operation that will require a legal foundation.
The BfDI proposes that Art. 6 pra. 4 GDPR could possibly be a choice, which enables the more processing of personal information for compatible reasons, if the brand new purpose works with with the initial purpose. Predicated on Art. 6 pra. 1 b) GDPR, the controller might use an Art. 6 pra. 4 GDPR balancing check. For example, where customer personal information was processed through the efficiency of a agreement and is currently planned to end up being anonymized to assess solutions in certain areas by stripping the initial data right down to only age group, host to residence and providers bought, the BfDI factors that the initial legal schedule could continue steadily to supplement the digesting because of this new purpose. Nevertheless, if the purposes aren’t compatible, this will not answer fully the question what lawful basis would be relevant for the anonymization, as Art. 6 pra. 4 GDPR takes a legal base, but will not provide one.
While this may open a door, Artwork. 6 pra. 4 GDPR works and then the extent that upcoming and past processing reasons are compatible, which demands the controller to endure such assessment.
An factor not specifically addressed in the discussion is whether Article 6.4 of the GDPR may be used to to help expand process traffic information.
COVID-19
Telecom operators in lots of European countries have decided to share visitors and location information to greatly help public authorities combat the COVID-19 pandemic. The rules on anonymization can help operators and authorities to make sure that the data will be anonymized and its make use of for mapping the positioning and distribute of the condition, among others.
Conclusion
The adoption of the guidance should ensure it is easier for telecommunication companies and for information controllers in general to handle anonymization, instead of data deletion. Subsequently, such data can be utilized for brand new purposes that could benefit citizens and business in lots of different ways.
Squire Patton Boggs will continue steadily to monitor developments of this type, as the BfDI procedures the input received to create its last guidance.
The post Anonymization of Personal Data with Concentrate on Traffic Data: First Public Consultation Procedure by the Federal German Data Protection Workplace appeared 1st on SECURITY & PRIVACY // BYTES.

