Menu
VideoParliament
VideoParliament Irish politics in one place — download the app
Get app
VideoParliament
VideoParliament for Windows Get the desktop app — notifications about new speeches
Get app
Michael McNamara: Questions on AI De-anonymisation

Michael McNamara: Questions on AI De-anonymisation

MEP Michael McNamara questioned the EDPB about anonymisation, the risk of AI-driven de-anonymisation, and delays to anonymisation guidelines following the SRB judgment and the Digital Omnibus debate. He raised concerns that a proposed change to the definition of personal data could go beyond existing case law and asked who will be bound by forthcoming EDPB guidance.

Key questions raised


Michael McNamara pressed the EDPB on whether anonymisation remains a reliable safeguard given recent studies - including work by Anthropic and a Zurich research institute - showing AI can de-anonymise data at scale. He challenged the idea that anonymised datasets are a panacea for European companies or for global firms handling European data.

Guidelines and timing


McNamara noted criticism from the private sector about delays in publishing anonymisation guidelines. The EDPB confirmed the guidelines are planned for July and said they were delayed to incorporate recent case law, notably the SRB judgment, and to allow stakeholder events before finalisation.

Definition of personal data and legal risks


The MEP warned that the Commission's proposed amendment to the definition of personal data in the Digital Omnibus appears to exceed current jurisprudence. He argued that such foundational changes require nuanced assessment and an impact assessment rather than a few sentences in omnibus legislation.

Michael McNamara — clip from remarks: Michael McNamara: Questions on AI De-anonymisation (08.06.2026)

Consistency across authorities


The EDPB responded that inconsistencies have been addressed since last year’s Helsinki meeting. It will introduce a channel to flag divergent national guidance, and reiterated that data protection authorities are committed to following EDPB guidelines. McNamara also asked whether the GDPR procedures regulation, due in 2027, has already affected interactions between national DPCs; the answer indicated continued work on coordination.

We publish thousands of recordings to make Irish politics transparent and resistant to manipulation. Spotted an error? Report it — together we are building a reliable archive of Irish politics.

Transcript
Thank you very much, President. Thank you very much for your presentation, Madam. I unfortunately missed part of it, so please excuse me if I misunderstood, but did I understand that you have some concerns with the definition or the so-called codification of the SRB judgement as proposed in the Digital Omnibus? If I did misunderstand that, please excuse me. Could I ask if you have, or if the EDPB has concerns about anonymisation, and in particular the potential of AI to de-anonymise data at scale? A number of studies have been published, one by Anthropic and a research institute in Zurich, pointing out the vast capabilities that AI has to de-anonymise data now. And if, in the light of that, the move towards presenting anonymised data is somehow a panacea for all the problems of European companies that are looking to use data, and in particular companies worldwide that are looking to use Europeans' data, is somewhat misplaced. You said that the guidelines – do I understand that you're hoping to publish them in July? I mean, I heard your reply to Ms DuPont, but these guidelines are – there's considerable criticism, I have to say, in the private sector of the delays in publishing these guidelines, and indeed publishing guidelines generally by the EDPB. Who do you think will be bound by them, and do you think that the various DPCs across Europe will apply them? And lastly, I was one of the many colleagues in this committee involved with the GDPR procedures regulation last year, and I'm just wondering what impact – I know that it enters into effect in 2027, but has it yet had any impact on the interaction between DPCs from across the European Union, from various member states, and indeed in states where there's more than one in the interaction between them there? Thank you very much for your questions. I start with the question of inconsistencies. This is something that we actually addressed in Helsinki last year, and this is also something where we made a commitment to find a way to ensure that, for example, the national DPA's guidelines would not diverge from the EDPB's guidelines. And we will shortly implement a channel on our website which makes it possible for the different stakeholders to flag that to us in case there are some inconsistencies. I think that here it is also very important to note that inconsistencies might come from the national law as well, so it is not necessarily the question of how it is enforced by the data protection authorities. The GDPR does provide a national flexibility, so it is important to understand that the inconsistencies might be sourced from different reasons. We are working on to make sure that it is not the data protection authorities who are the weak link here. When it comes to the definition of personal data, yes, indeed, we are very concerned about the Commission's proposal to amend the definition of personal data. And why is that? Because it is not actually codifying to current jurisprudence. It goes beyond the court's case law. And as we are addressing here very multi-layered topics, it is important to have the nuanced approach, and this cannot be done with a couple of sentences in the law. Also, it is a very important notion for the whole regulation, and given that there is not, for example, the impact assessment, it is quite concerning that this type of amendment would be done within the omnibus frameworks. On the guidelines, on the anonymization, it should come out in July, and I am indeed very well aware of the criticism of the delayed guidelines. This is also something that we addressed last summer in Helsinki to make our internal working methods more efficient, and I believe that the results start to show sometime soon. When it comes to the anonymization guidelines, this is something that we also had to take into account the recent case law, so the SRB judgment. And this is why we delayed the process to be able to implement the recent case law into our guidelines. We also organized the stakeholder events before finalizing the guidelines, and I believe that this was – Then who are bound by our guidelines? We, the data protection authorities, we are committed to follow our guidelines, and like I said, in case there are some inconsistencies, we are in the process to create a channel which can be used to flag these inconsistencies. Thank you.