A city open-data portal publishes only aggregates that, after rigorous assessment, cannot identify any resident even when combined with other reasonably available information. How should the GDPR personal-data rules apply?
Select an answer to reveal the explanation.
Short Explanation
If the numbers truly cannot point back to anyone—even with other reasonable clues—you have left the personal-data zone. GDPR cares about identifiable people, not about every spreadsheet that ever touched a city hall. Real anonymisation is the off-ramp; weak masking is not.
Full Explanation
Recital 26 GDPR explains that the principles of data protection do not apply to anonymous information, including information that does not relate to an identified or identifiable natural person. When aggregates are assessed as truly anonymous—including resistance to re-identification with reasonably available means—they fall outside personal-data rules. Origin from personal records does not permanently lock data into the GDPR if identification is no longer possible.