About Projects Contact

The Legal Uncertainty behindIndirectly Sensitive Personal Data

Learn more
Read my Master’s Thesis in Swedish

Introduction

In August 2022, the Court of Justice of the European Union (CJEU) rendered a landmark decision affirming the concept of indirectly sensitive personal data.1See judgment of 1 August 2022, Vyriausioji tarnybínes etikos komisija, C-184/20, EU:C:2022:601, but also C-21/23 Lindenapotheke, both of which are analysed in my thesis. This ruling expanded the scope of Article 9 of the GDPR beyond what had been previously established through case law.

Labeling someone as homosexual clearly discloses their sexual orientation under Article 9. Similarly, the court notes that pairing someone’s name with their spouse or partner’s gender-revealing name is liable to reveal their sexual orientation.

Nevertheless, as is often the case with judicial decisions, the CJEU’s ruling left numerous critical and interrelated questions unanswered. It is these unresolved matters that formed the crux of my master’s thesis in law.

Here, I provide a brief overview.

Unequivocal or indicative?

Not all indirectly sensitive personal data are the same. While certain data may unequivocally and indirectly disclose sensitive information, a vast amount of data can be used to indirectly deduce such sensitive data only through mere indication.

Among the examples I chose to include were the revelations of ethnicity and sexual orientation based on customer names. The latter point is rooted in customer loyalty programs whereby customers can connect and combine their accounts to collect and leverage loyalty points together. This practice is typically limited to cohabitants, primarily couples in romantic relationships.2There are exceptions to this, of course, such as university roommates, which broadly speaking can be filtered out on the account of their age. Hence, the inference.

These indications raise the question of which statistical thresholds or discretionary methods should be used to assess these types of uncertain cases. Simply put, does the likelihood of the circumstances underpinning the sensitive category being true, or people nonetheless acting on them on such basis, have to be over 50%? Is 30% enough in the spirit of high protection? Or do we need to reach close to 90–100% to weed out extreme, unlikely, and impractical scenarios that prevent certainty?

However, my thesis does not provide simple answers, as there are no detailed and definitive criteria to be applied generally.” Instead, it contends that indicatively sensitive data must be determined on a case-by-case basis, taking into account whether credible or sufficient reasons to classify personal data as indirectly sensitive exist. One reinforcing factor should be when the data concerned is typically deemed to reveal a sensitive category.

In practical application, a couple of examples can be provided. On the one hand, information on pupils attending confessional schools in Sweden do not automatically reveal religious beliefs, as there are both objective and subjective reasons for choosing such schools unrelated to their confessional profile. On the other hand, attendance in a Sami school does, in fact, reveal ethnicity, despite the theoretical possibility of non-Sami people attending one, as there are no non-Sami people who have chosen to attend one in practice.

Finally, a number of observations can be made when categorising personal data as sensitive:

  • The purposive approach, i.e. the data controller’s intention behind the processing, is not decisive.3C-252/21, Meta Platforms Inc and Others v Bundeskartellamt, para 69–70, and Opinion of Advocate General Rantos, para 40–41; also see chapter 2.4 and 3.2.1 in my thesis.
  • The precautionary principle might apply.4 What’s important is the possibility that such processing “could” create significant risks to the fundamental rights and freedoms, regardless if that the possbility materialises, see the Opinion of Advocate General Rantos in C-252/21, para 40, and GDPR recital 51.
  • Complicated analyses are not expected nor taken into account, unless they are actually carried out.5See the Danish supervisory authority Datatilsynet, ”Klage over Radius’ fjernaflæsning af elmålere”, chapter 4.1, 2023-02-10; C-582/14, Breyer, para 46; GDPR, recital 26.

Principle of Proportionality

The significant scope of Article 9 can results in unintentionally far-reaching conclusions. And when all else fails, there is always the principle of proportionality as a limiting factor in EU law.

Technically sensitive, in reality not.

Information on heterosexuality reveals sexual orientation; Scandinavian origin of a person living in Sweden reveals ethnicity; and information that a person is healthy reveals health data. Yet, few would categorise these aspects as sensitive, considering they simply describe characteristics typical of the majority population—the norm.

The notion that such trivialities could potentially lead to “significant risks” seems almost implausible. In other words, these personal data arguably do not warrant the level of protection mandated by a strict and formal interpretation of Article 9. Instead, in my opinion, such protection exceeds necessity and unjustly curtails opposing interests. This holds true for sensitive data in general, irrespective of whether it is direct or indirect. Nonetheless, I cannot dismiss the possibility that such data may constitute sensitive personal data on a case-by-case basis, depending on the context.

Data to be used in the inferrence

A lingering unanswered question pertains to the extent of information from which an inference to a sensitive category can be drawn. According to the CJEU judgment, it should be determined whether data are capable of disclosing a special category of sensitive personal data through an “intellectual operation involving comparison or deduction”.

Regrettably, the CJEU fails to clarify the scope of reference materials to be utilized in the assessment. In my thesis, I draw an analogy to the C-582/14 Breyer case.”

Learn more
Read my Master’s Thesis in Swedish
  • 1
    See judgment of 1 August 2022, Vyriausioji tarnybínes etikos komisija, C-184/20, EU:C:2022:601, but also C-21/23 Lindenapotheke, both of which are analysed in my thesis.
  • 2
    There are exceptions to this, of course, such as university roommates, which broadly speaking can be filtered out on the account of their age.
  • 3
    C-252/21, Meta Platforms Inc and Others v Bundeskartellamt, para 69–70, and Opinion of Advocate General Rantos, para 40–41; also see chapter 2.4 and 3.2.1 in my thesis.
  • 4
    What’s important is the possibility that such processing “could” create significant risks to the fundamental rights and freedoms, regardless if that the possbility materialises, see the Opinion of Advocate General Rantos in C-252/21, para 40, and GDPR recital 51.
  • 5
    See the Danish supervisory authority Datatilsynet, ”Klage over Radius’ fjernaflæsning af elmålere”, chapter 4.1, 2023-02-10; C-582/14, Breyer, para 46; GDPR, recital 26.