Tweet · 10 Apr 2018, 03:01 UTC

Replying to @profcarroll

Pseudonymous data is personal data under the GDPR, no disagreement there. HIPAA-level de-id would definitely not make my bar for anonymous data; the classic AOL or Netflix deanonymisation cases were both HIPAA-grade but that didn’t cut it.