By Leslie StevensAs a lawyer I am accustomed to, but sceptical of, hard and fast categories – we know all too well that bright line rules and seemingly fixed categories raise more questions than they provide answers. In data protection several such categories exist: anonymous data and personal data, sensitive personal data and ordinary personal data, data controller and data processor and so forth. Given the current reform of data protection law in Europe, and the anticipated introduction of the General Data Protection Regulation circa 2016/2017, questions should be (and have been) raised as to the effectiveness of these categories as regulatory tools. The lines between anonymous data and personal data have been blurred – the ease with which data may be re-identified and the power of data linkage has revealed the fallacy that is truly ‘anonymous’ data. Ordinary personal data, once considered innocuous, when combined with any countless array of other data, are likely to reveal intimate details about people’s lives – far more sensitive than data protection law would recognise.
