When Anonymization Fails: Readable Data in a Published Contract
A decision of the Office for Personal Data Protection of the Slovak Republic confirms that the anonymization of a document intended for publication must be technically effective, rather than merely visual. If personal data become readable after text is copied from a PDF document, the controller may be in breach of its obligation to ensure the ongoing confidentiality of personal data under Article 32(1) of the GDPR, even where contracts are subject to mandatory publication in the Central Register of Contracts.
The Office initiated proceedings of its own motion against a municipality acting as the controller in connection with the publication of documents in the Central Register of Contracts. The proceedings were prompted by an email notification alleging that the personal data of the data subjects became readable after the text had been copied from the published contract. The Office subsequently examined the content of the published contract and found that, although certain personal data were not visibly legible in the document, after the text was copied from the PDF document into a text format supported by Microsoft Word, the following data became readable: birth surname, date of birth, personal identification number and nationality.
In the proceedings, the controller stated that the legal basis for the publication was compliance with a legal obligation under Article 6(1)(c) of the GDPR in conjunction with Act No. 211/2000 Coll. on Freedom of Information. The controller also submitted to the Office a certificate confirming the completion of data protection training, a record of employee familiarization and authorization, and internal instructions governing the publication of data. The controller argued that, after becoming aware of the deficiency, it corrected the issue and re-examined the contracts, and that the incident constituted an isolated human error rather than a systemic failure.
The Office relied on the definition of personal data under Article 4(1) of the GDPR and the broad definition of processing under Article 4(2) of the GDPR. It therefore assessed the publication of a document in the Central Register of Contracts as a processing operation in respect of which the controller is required to comply not only with the requirement for a lawful basis for processing, but also with the requirements of security, integrity and confidentiality.
The key provision cited in the decision is Article 32(1) of the GDPR, under which the controller and the processor must implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. The Office specifically referred to the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, as well as to the need for a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures.
The decision also emphasizes the relationship between the mandatory publication of contracts under Act No. 211/2000 Coll. and the protection of personal data. In particular, the Office cited Section 2(1) of Act No. 211/2000 Coll., pursuant to which municipalities are obliged entities, as well as Sections 5a(6) to (8) and Section 5a(14) of Act No. 211/2000 Coll., which govern the publication of mandatorily disclosed contracts in the register, the submission of contracts for publication and the obligation to prevent the disclosure of provisions containing information that must not be disclosed under the Act.
Particular significance also attaches to the reference to Section 78(4) of Act No. 18/2018 Coll., under which a generally applicable identifier may be used to identify a natural person only where its use is necessary to achieve the purpose of the processing, while the publication of a generally applicable identifier is prohibited unless it is published by the data subject concerned. In this context, the Office expressly emphasized the particular sensitivity of a personal identification number as a permanent identifying item of personal data that ensures the unique identification of a natural person in information systems.
The Office did not refer to the case law of the Court of Justice of the European Union, the EDPB or national courts. However, the decision refers to ISO/IEC 29100:2011, ISO/IEC 20889:2018 and Opinion 05/2014 of the Working Party established under Article 29 of Directive 95/46/EC of 10 April 2014 on anonymization techniques. The Office thereby placed the assessment of anonymization within a broader technical and methodological framework, according to which anonymization is not merely the formal masking of data, but the result of a process intended to prevent identification or the data from becoming readable again.
The obligation to publish a contract under the Freedom of Information Act does not release the controller from its obligation to ensure the confidentiality of personal data. Public-sector transparency and the protection of personal data must be applied concurrently, and a statutory publication obligation cannot justify the disclosure of data beyond the permissible scope.
Anonymization must be effective not only visually but also technically. If personal data can be retrieved through a simple operation, such as copying text from a PDF document, this does not constitute proper protection of ongoing confidentiality within the meaning of Article 32(1) of the GDPR.
The controller’s responsibility is assessed on the basis of the actual outcome of the processing. The existence of internal instructions, training or records confirming that employees have been familiarized with the applicable requirements is not in itself sufficient if the published document permits unauthorized access to personal data.
The Office therefore imposed an administrative fine of EUR 300 on the controller pursuant to Section 102(1)(f) of Act No. 18/2018 Coll. in conjunction with Articles 58(2)(i) and 83(4)(a) of the GDPR, as well as corrective measures pursuant to Section 102(1)(a) of Act No. 18/2018 Coll. and Article 58(2)(d) of the GDPR.
The decision is significant for all controllers that publish or otherwise make documents available in electronic form. From a compliance perspective, it is not sufficient for a document to appear anonymized at first sight. The decisive factor is whether the anonymization technically prevents the data from being recovered. Before publishing documents, controllers should therefore verify, in particular, whether the text can be copied, whether the data are searchable, whether the PDF document contains underlying layers or metadata, and what the result is after the file has been exported or converted. Particular attention is required in relation to data enabling the precise identification of a natural person, especially a personal identification number, date of birth or nationality.
The decision also demonstrates the need to establish a control mechanism and provide regular training to persons who prepare or submit documents for publication. Anonymization cannot depend solely on an employee’s attentiveness, but must form part of a functional technical and organizational process under Article 32 of the GDPR.
The decision confirms that the anonymization of an electronic document is assessed according to its actual effectiveness rather than its visual appearance. If a document enables data that were not intended for publication to be retrieved through a simple technical operation, this may constitute a breach of the obligation to ensure the ongoing confidentiality of personal data under Article 32(1) of the GDPR, resulting in the imposition of corrective measures and an administrative fine.
Article provided by INPLP member: Miroslav Chlipala (Advokáti Chlipala s.r.o., Slovakia)

By Dr. Tobias Höllwarth
