Robin Berjon @robinberjon · 10 Apr 2018 Replying to @profcarroll Pseudonymous data is personal data under the GDPR, no disagreement there. HIPAA-level de-id would definitely not make my bar for anonymous data; the classic AOL or Netflix deanonymisation cases were both HIPAA-grade but that didn’t cut it.