Skip to content

The ECJ’s SRB Decision: Redefining Personal Data in the Age of Civic Infrastructure

October 17, 20254 minute read

Excerpt
The European Court of Justice’s SRB decision deepens the meaning of “personal data” under GDPR — recognizing that data is relational, contextual, and civic in nature. As the boundary between private information and public infrastructure blurs, Europe is quietly building the blueprint for digital governance in the 21st century.

The ECJ’s SRB Decision: Redefining Personal Data in the Age of
Civic Infrastructure

When the European Court of Justice speaks about data, the entire digital economy should listen.

Earlier this month, the Court handed down a fascinating decision — EDPS v. Single Resolution Board (Case C-413/23 P) — clarifying what counts as “personal data” under EU law. On paper, the issue looked dry: whether internal notes containing personal opinions about an individual fall under the General Data Protection Regulation (GDPR).

But in truth, this judgment is a milestone in Europe’s evolving philosophy of data governance. It’s about much more than opinions on a document — it’s about the nature of information itself, and how we manage the digital infrastructure of our societies.

A Bit of Legal Context
For those who follow EU data law, this decision is part of a growing lineage of cases that have slowly expanded — and nuanced — the meaning of “personal data.”
• Nowak (C-434/16) — examiners’ handwritten comments on a student’s paper were personal data, because they related to the individual’s performance.
• Breyer (C-582/14) — dynamic IP addresses can count as personal data if the controller can reasonably identify the person behind them.

Now, SRB (C-413/23 P) takes that logic further:
• Subjective opinions or assessments about someone are personal data if the individual is identifiable.
• Pseudonymized data isn’t automatically “personal”; it depends on whether the recipient can realistically re-identify the person.

The key message? Context is everything. Whether something counts as personal data depends not on what the data is, but on how it can be used.

The Broader Implications
This case might seem narrow, but it lands at a crucial moment. Europe is increasingly treating data not as a private commodity, but as civic infrastructure — something that underpins the functioning of modern society, much like roads or energy grids.

From this perspective, personal data isn’t just about privacy; it’s about how we organize trust, accountability, and participation in digital life.

When the Court insists that even opinions count as personal data, it’s making a subtle but powerful point: data is relational. It connects people, institutions, and decisions. It is the scaffolding of our civic digital space.

Data as Civic Infrastructure
If the industrial economy was built on physical infrastructure — railways, factories, shipping routes — the digital economy is built on informational infrastructure.

The flow of personal data defines access to healthcare, education, finance, and innovation. Treating data as civic infrastructure changes the stakes:
• Individuals are not passive “data subjects,” but co-owners of the informational commons.
• Organizations are not owners of data, but stewards of shared resources.
• Governments and regulators become architects of trust networks, ensuring fair, transparent, and secure data exchanges.

In this light, the GDPR isn’t just a compliance framework; it’s an early governance model for shared data infrastructure. The SRB ruling strengthens that model by re-anchoring “personal data” in context, rather than format.

A Shift Toward Governance, Not Just Protection
The practical side of this evolution is already visible. Across Europe, data protection authorities and courts are converging toward a logic of governance, not just limitation.

Questions of data classification — whether information is personal, pseudonymized, or anonymized — are becoming the basis for taxation, accountability, and trade.

We are entering an era where the classification of data defines economic sovereignty:
• Who pays tax on data transfers.
• Who can train AI models.
• Who holds liability when algorithmic decisions go wrong.

The technical question of “is this personal data?” is quickly turning into the political question of “who controls the digital infrastructure?”

Why It Matters
For organizations and policymakers, the lesson from SRB is clear:
• Reassess what counts as personal data — context and identifiability now matter more than ever.
• Build transparency into your data flows — even pseudonymized information may carry personal data obligations.
• Think civically, not just commercially — data is the connective tissue of modern societies; treat it as a public good that requires stewardship.

The SRB decision may not grab headlines like AI regulation or the Digital Markets Act. But in the long arc of European data law, it marks a subtle pivot — from regulating privacy to designing the civic architecture of the data economy.

The future of governance will depend on how we define and protect that infrastructure — not just for compliance, but for democracy itself.

If you enjoyed this essay, subscribe to our S8FE.AI newsletter for future insights on how data law, AI, and digital sovereignty are reshaping the modern economy.

Share this article

Back To Top