Skip to main content
The SRB Ruling Didn't Redefine Personal Datageneral
5 min readFor Privacy Officers

The SRB Ruling Didn't Redefine Personal Data

The conventional wisdom

Privacy officers across Europe are treating the CJEU's SRB ruling as a pivotal moment that fundamentally redefines what counts as personal data under GDPR. Conference presentations frame it as a compliance reset. processor newsletters warn that your data inventories are suddenly incomplete. The message: you need to re-audit everything because the definition just changed.

This interpretation misses the point entirely.

Why we disagree

The SRB ruling didn't redefine personal data. It clarified how Article 4(1) applies when data points relate to legal entities but also reveal information about natural persons. That's not a new definition; it's an application of the existing one to a specific fact pattern.

Here's what actually happened: the CJEU examined whether information about a company's financial position could constitute personal data when that information also identifies individual decision-makers or shareholders. The court applied the same test it always has: does the information relate to an identified or identifiable natural person?

The panic stems from conflating "new application" with "new rule." When you treat every CJEU clarification as a ground-up redefinition, you create compliance theatre instead of compliance. Your team scrambles to re-classify data that was already correctly classified. You delay legitimate projects while legal reviews every corporate record. You brief executives on a crisis that doesn't exist.

The operational cost is real. I've watched teams spend six months re-documenting their Article 30 records because someone interpreted SRB as requiring a new category of personal data. They weren't wrong about the law; they were wrong about what changed.

The evidence

Article 4(1) defines personal data as "any information relating to an identified or identifiable natural person." That definition hasn't changed since GDPR took effect. The SRB ruling applied this definition to a scenario where corporate data revealed individual information. It's a clarification of scope, not a revision of substance.

The CJEU has consistently followed this pattern. In previous rulings on IP addresses, cookie identifiers, and inference from aggregated data, the court hasn't rewritten Article 4(1). It's shown how the definition operates in contexts the drafters didn't explicitly enumerate. That's how case law works in every legal system.

Consider what SRB actually tells you: if your records about Company X also identify or make identifiable Person Y (a director, a beneficial owner, a sole trader), then those records constitute personal data with respect to Person Y. This isn't revolutionary. It's the same relatability test you apply to employee records, customer accounts, and processor contacts.

The ruling matters for specific use cases: corporate registries, beneficial ownership databases, financial supervision records. If you're processing these data types, SRB gives you clearer guidance on your Article 6 lawful basis and your Article 13/14 transparency obligations. If you're not, the ruling confirms what you already knew: data that identifies natural persons is personal data, regardless of whether it's filed under a corporate heading.

What to do instead

Stop treating CJEU rulings as compliance emergencies. Start treating them as interpretive guidance that helps you apply existing obligations more precisely.

When a new ruling drops, ask three questions:

First, does this affect data types you actually process? SRB matters if you maintain corporate registers, process beneficial ownership data, or conduct financial supervision. It doesn't matter if you run an e-commerce platform or manage employee benefits. Match the ruling's fact pattern to your processing activities before you mobilize resources.

Second, were you already treating this data correctly under Article 4(1)? If you've been applying the "relating to" test consistently, SRB likely confirms your approach rather than contradicting it. Review your data inventory for the specific categories at issue, not your entire processing ecosystem.

Third, what specific compliance action does the ruling require? Don't invent work. If SRB clarifies that certain corporate records constitute personal data, your action items are concrete: update your Article 30 record for those processing activities, confirm your lawful basis under Article 6, verify your transparency obligations under Article 13 or 14. That's a targeted update, not a compliance overhaul.

For most organizations, the practical response to SRB is minimal. You confirm that data linking corporate entities to natural persons is already in your personal data inventory. You verify that your existing lawful basis covers this processing. You check that your transparency notices address it. You document the analysis and move on.

When the conventional wisdom is right

The alarm is justified in one scenario: you've been treating corporate data as categorically exempt from GDPR because it relates to legal entities rather than natural persons.

If your data governance framework assumes that anything filed under a company name falls outside Article 4(1), then yes, SRB requires immediate action. You need to identify every processing activity where corporate records also identify natural persons. You need to establish lawful bases where you don't have them. You need to issue transparency notices you've been omitting. That's not compliance theatre; that's correcting a fundamental misreading of the regulation.

This applies particularly to beneficial ownership registries, corporate due diligence processes, and financial supervision activities. If you're a supervisory authority, a financial institution conducting know-your-customer checks, or a corporate registry operator, SRB directly affects your compliance posture. The ruling clarifies that you can't dodge Article 6 lawful basis requirements or Article 15 DSAR obligations by labeling the data "corporate information."

The conventional wisdom is also right about one broader point: CJEU rulings shape how supervisory authorities interpret GDPR. Even when a ruling doesn't change your compliance obligations, it influences how your supervisory authority will assess your practices in an audit or investigation. You need to know the case law, not because it rewrites the rules, but because it shows how those rules will be applied.

But knowing the case law isn't the same as treating every ruling as a compliance crisis. SRB clarified the application of Article 4(1) to a specific data type. If that's your data type, act accordingly. If it's not, file the ruling in your legal updates folder and focus on the compliance work that actually needs doing.

Topics:general

You Might Also Like