Skip to search boxSkip to navigationSkip to main content

Legal analysis of the nature of synthetic data: Personal data, anonymous data, or a sui generis category?

*Corresponding author for this work
Research Output:
Contribution to journal
Article
Peer-review

Open access

Publication Information

Output type

Research Output:
Contribution to journal
Article
Peer-review

Original language

English

Article number

106379

Journal (Volume, Issue Number)

Computer Law and Security Review (Volume 62)

Publication milestones

  • Published - 09/2026

Publication status

Published - 09/2026

ISSN

2212-473X

Publication IDs

  • Scopus: 105045915613

Abstract

Synthetic data constitutes a conceptual disruption that challenges the foundations of data protection law, raising questions about whether it should be classified as personal data, anonymized data, or a sui generis category. This paper examines the inadequacy of the binary framework of the General Data Protection Regulation (GDPR) to address technologies that preserve statistical properties without direct individual correspondence. A strict distinction is made between an analysis of current positive law (lege lata) and proposals for reform (lege ferenda): under current law, synthetic data is evaluated within the existing binary framework by applying the standard set forth in Recital 26; the sui generis category is formulated as a recommendation for future legislation. Through a dogmatic analysis of comparative law, three regulatory models are examined: the permissive approach of the ICO (United Kingdom), the cautious approach of the CNIL (France), and the proactive approach of the Datatilsynet (Norway). The legal status has been partially clarified by CJEU Judgment C-413/23 P (2025) and Opinion 28/2024 of the EDPB. A graduated framework of three risk levels, a voluntary certification system, and an implementation roadmap for the Peruvian legal system from a Latin American perspective are proposed.