Release time:2024-08-15 13:38:52
IP addresses, Cookies, BSSIDs and TC strings, though not necessarily able to directly identify the name of the information subject, can "identify" a specific natural person when combined with other information. The Civil Code of China defines personal information as follows: Personal information refers to various information recorded by electronic or other means that can identify a specific natural person either alone or in combination with other information. Article 4 of the EU General Data Protection Regulation (GDPR) defines "personal information" as any information relating to an identified or identifiable natural person. It is evident that "identifiability" is of particular importance for the determination of which information falls into the scope of personal information.
Regarding the interpretation of "identifiable", the EU General Data Protection Regulation (GDPR) provides that an identifiable natural person refers to a natural person who can be identified directly or indirectly through identifiers. The Article 29 Data Protection Working Party of the EU gives a more vivid description: "a natural person can be considered as‘identified’when, within a group of person, he or she is‘distinguished’from all other members of the group." That is, "identifiability means being able to recognize a specific natural person from a crowd." Recital 26 of the GDPR stipulates that when determining whether a natural person is identifiable, all reasonable methods shall be taken into account, and the reasonableness of such methods shall be considered in combination with factors such as cost and current technical feasibility. The aforementioned cases also provide us with important experience for grasping the connotation of "identifiable" in practice:
Does this information not constitute "personal information" if it is not combined with "other information" for identification purposes?
In the appeal cases of Google v. Judith Vidal-Hall et al., Google contended that it had effectively segregated other information that could be combined with cookies, that is, it had not combined the "other information" with cookies to identify individuals, and therefore cookie information does not constitute personal information. The Court of Appeal of the United Kingdom did not uphold this argument. It ruled that pursuant to the definition of personal information under EU law, information that can indirectly identify an individual constitutes personal information as long as it is in the possession of the data processor and can be used to identify an individual, and it is irrelevant whether such use has actually been implemented or is intended.
As regards the wording of section 1(1)(b), this refers simply to information "in the possession of" the data controller, and appears only to be concerned with whether data "can be used" to identify an individual (not with whether it has been used or is intended to be used in this way). On a straightforward and literal construction of the section, therefore, the fact that a data controller might not aggregate the relevant information in practice is immaterial. What matters is whether the defendant has "other information" actually within its possession which it could use to identify the subject of the BGI, regardless of whether it does so or not.
Does the information in possession not constitute personal information where "other information" cannot be obtained?
In the case of Patrick Breyer v. Federal Republic of Germany, the Federal Government of Germany, as the website content provider, does not hold Breyer's IP address on its own, based on which the Federal Court of Justice of Germany rendered an erroneous judgment. The determination of whether an IP address constitutes personal information in this case shall be made on a case-by-case basis: an IP address may be deemed as personal information only when it is in the possession of an internet service provider, as the internet service provider also holds "other information" that can be combined with the IP address to identify Breyer's identity. For a website content provider such as the Federal Government of Germany, which is incapable of obtaining the aforesaid "other information", the relevant IP address shall not be deemed as personal information under such circumstance. The Court of Justice of the European Union does not endorse this ruling, holding that under EU law, when judging whether a piece of information qualifies as information that can indirectly identify a natural person, consideration shall be given not only to the information accessible to the current information controller through reasonable means, but also to the information accessible to other entities through reasonable means. In other words, EU law does not take all such information being held by the same entity as a prerequisite for determining that the information constitutes personal information.
Furthermore, recital 26 of Directive 95/46 states that, to determine whether a person is identifiable,account should be taken of all the means ly reasonably to be used either by the controller or by any other person to identify the said person.In so far as that recital refers to the means ly reasonably to be used by both the controller and by "any other person", its wording suggests that, for information to be treated as "personal data" within the meaning of Article 2(a) of that directive, it is not required that all the information enabling the identification of the data subject must be in the hands of one person.
Is it merely the formulator of information processing rules that has no access to information whatsoever, or a personal information controller?
Sometimes, it is assumed that one can completely isolate itself from information security risks as long as it does not access information. In the case of *IAB Europe v Gegevensbeschermingsautoriteit*, IAB Europe had no access to information throughout its entire business operations, yet it was adjudicated as a joint controller (t-controller) of personal information and held liable for formulating the processing rules for TC strings. The Court of Justice of the European Union responded to this as follows: Where a public body provides its members with rules on the processing of personal information, which include not only the technical specifications for information processing, but also rules on information distribution and storage, such public body shall be defined as a "joint controller". This is because the public body has exerted influence on the information processing process, and has jointly determined the purposes and methods of information processing with its member entities. The objective fact that the public body does not have direct access to information shall not accordingly exclude it from the role of joint controller.
First,a sectoral organisation,in so far as it proposes to its members a framework of rules that it has established relating to consent to the processing of personal data,which contains not only binding technical rules but also rules setting out in detail the arrangements for storing and disseminating personal data relating to such consent,must be classified as a t controller. it exerts influence over the personal data processing at issue,for its own purposes,and determines tly with its members,the purposes and means of such processing.The fact that such a sectoral rganisation does not itself have direct access to the personal data. does not preclude it from holding the status of t controller.