Pseudonymisation of location data and personal data by Viacryp

Pseudonymisation of location data: what the Enschede ruling teaches us

A municipality that counts passers-by to make its shopping streets more attractive is fined €600,000 by the Dutch Data Protection Authority (AP), and subsequently wins in court. It sounds like good news for municipalities and retailers that use Wi-Fi tracking to map visitor flows. But a careful reading of the judgment by the Overijssel District Court shows above all that the case turned on a problem with the AP’s evidence, not on a licence to handle location data carelessly.

In this blog, we explain the case, set out exactly what happened from a legal perspective, and show what proper pseudonymisation of MAC addresses could have meant in practice. For Enschede, and for every organisation that collects similar data.

The case: Wi-Fi tracking in Enschede city centre

Between 2018 and 2020, the municipality of Enschede had ten sensors installed in the city centre to measure the number of passers-by 24 hours a day. The aim was to gain better insight into visitor numbers so that shopping streets and events could be optimised. The sensors recorded the MAC address of every mobile device with Wi-Fi enabled and thus tracked which device passed which sensor.

Following reports from concerned citizens, the AP launched an investigation. It concluded that the municipality had allegedly processed personal data without a valid legal basis, in breach of Article 5(1)(a) and Article 6(1) of the GDPR. The AP imposed an administrative fine of €600,000. Enschede lodged an objection and subsequently appealed to the Overijssel District Court.

Read more

The withdrawal of the SRB case: why the CJEU approach to pseudonymisation continues to serve as the de facto standard

In recent months, the European privacy community had been closely following the case that had been brought before the General Court of the European Union by the Single Resolution Board (SRB). That case had the potential to bring further clarity to the question of when data should be considered personal data and how pseudonymisation fits into this.

Read more
Municipality of Zaanstad

Interview: How does the pseudonymisation and depseudonymisation of personal data help the Municipality of Zaanstad with data analysis?

More and more organisations are facing the challenge of performing data analyses of personal data within the framework of the General Data Protection Regulation (AVG). And more and more organisations are opting to pseudonymise personal data. We asked Tom Pots, programme manager for data-driven working at the Municipality of Zaanstad, about his challenges in this area. What has he experienced thus far when it comes to the pseudonymisation of data, and what has this yielded in concrete terms?

Read more

Pseudonymisation service for traffic research | Viacryp

Parking Management Congress 2020

The annual Parking Management Congress is once again taking place on Tuesday, November 3, 2020, this time online. The focus will be on exchanging visions and experiences, gathering knowledge and getting to know each other to shape future policy and implement parking management efficiently and effectively.

Read more

Pseudonymisation in practice

Pseudonymisation in practice

The process which underpins the pseudonymisation of data is quite technical, but it’s comparable to when an author writes a book under a pseudonym. The crux is that no one knows who is behind that pseudonym. When personal data is made unrecognisable in that way, organisations can use it to conduct valuable research without running the risk of violating the privacy of those concerned.

Read more

The precarious balance between privacy and convenience

The precarious balance between privacy and convenience

The right to not feel spied on, whether in your own home or digitally, is a significant fundamental right. Privacy extends beyond legislation. We not only need to look at what’s permitted but also at what we as a society consider desirable or not when it comes to how our data is used.

Read more

This is how pseudonymisation works

This is how pseudonymisation works

An author who doesn’t want the public to know he has written a particular book will use a pseudonym. Applying this concept to data analysis allows data from various sources to be compared without compromising the privacy of those involved. But how does pseudonymisation actually work? Edwin Kusters, co-founder and director of Viacryp, is happy to explain.

(This article was published on https://www.ictmagazine.nl/)

Read more

New NEN standard for pseudonymisation - Viacryp

New NEN standard for pseudonymisation

The NEN recently published the ‘NEN 7524’, the new standard for pseudonymisation service provision. This health care standard is expected to lead to improved patient safety and better cooperation between providers and users of pseudonymisation services, such as in mental health care services.

Read more

The GDPR a year on – in control of your personal data thanks to Data Usage Board - Viacryp

The GDPR a year on – in control of your personal data thanks to Data Usage Board

A year has passed since the General Data Protection Regulation (GDPR) went into full effect. So where are we now, what are the most important lessons learned for organisations that process personal data and what smart solutions have become available?

Read more

What is pseudonymisation - Viacryp

What is pseudonymisation?

The introduction of the General Data Protection Regulation (GDPR) has led to privacy becoming a hot topic. Organisations have been working on taking appropriate measures and, in that context, the term ‘pseudonymisation’ is popping up more and more. But what exactly is pseudonymisation?

Read more