CIPP-E · Question #188
Pursuant to Article 4(5) of the GDPR, data is considered "pseudonymized" if?
The correct answer is A. It cannot be attributed to a data subject without the use of additional information. According to Article 4(5) of the GDPR, pseudonymization is "the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is…
Question
Pursuant to Article 4(5) of the GDPR, data is considered "pseudonymized" if?
Options
- AIt cannot be attributed to a data subject without the use of additional information.
- BIt cannot be attributed to a person under any circumstances.
- CIt can only be attributed to a person by the controller.
- DIt can only be attributed to a person by a third party.
How the community answered
(45 responses)- A93% (42)
- B2% (1)
- C4% (2)
Explanation
According to Article 4(5) of the GDPR, pseudonymization is "the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person." Therefore, option A is the correct definition of pseudonymization. Option B is incorrect because pseudonymized data can still be attributed to a person with the use of additional information. Option C is incorrect because pseudonymization does not depend on who can attribute the data to a person, but on how the data is processed.
Topics
Community Discussion
No community discussion yet for this question.