Legal analysis of the nature of synthetic data: Personal data, anonymous data, or a sui generis category?
- ,
- Miguel Nunez-del-Prado,
- Hugo Alatrista-Salas(corresponding author),
- Jennifer Guiselle Rojas Alvarado
- ,
- Universidad Peruana de Ciencias Aplicadas,
- Research Center,
- Museo de Historia Natural, Universidad Ricardo Palma
Open access
Publication Information
Output type
Original language
EnglishArticle number
106379Journal (Volume, Issue Number)
Computer Law and Security Review (Volume 62)Publication milestones
- Published - 09/2026
Publication status
ISSN
2212-473XPublication IDs
- Scopus: 105045915613
Abstract
Synthetic data constitutes a conceptual disruption that challenges the foundations of data protection law, raising questions about whether it should be classified as personal data, anonymized data, or a sui generis category. This paper examines the inadequacy of the binary framework of the General Data Protection Regulation (GDPR) to address technologies that preserve statistical properties without direct individual correspondence. A strict distinction is made between an analysis of current positive law (lege lata) and proposals for reform (lege ferenda): under current law, synthetic data is evaluated within the existing binary framework by applying the standard set forth in Recital 26; the sui generis category is formulated as a recommendation for future legislation. Through a dogmatic analysis of comparative law, three regulatory models are examined: the permissive approach of the ICO (United Kingdom), the cautious approach of the CNIL (France), and the proactive approach of the Datatilsynet (Norway). The legal status has been partially clarified by CJEU Judgment C-413/23 P (2025) and Opinion 28/2024 of the EDPB. A graduated framework of three risk levels, a voluntary certification system, and an implementation roadmap for the Peruvian legal system from a Latin American perspective are proposed.
