Legal analysis reveals synthetic data challenges existing classifications under data protection law, suggesting reforms.
Synthetic data constitutes a conceptual disruption that challenges the foundations of data protection law, raising questions about whether it should be classified as personal data, anonymized data, or a sui generis category. This paper examines the inadequacy of the binary framework of the General Data Protection Regulation (GDPR) to address technologies that preserve statistical properties without direct individual correspondence. A strict distinction is made between an analysis of current positive law ( lege lata ) and proposals for reform ( lege ferenda ): under current law, synthetic data is evaluated within the existing binary framework by applying the standard set forth in Recital 26; the sui generis category is formulated as a recommendation for future legislation. Through a dogmatic analysis of comparative law, three regulatory models are examined: the permissive approach of the ICO (United Kingdom), the cautious approach of the CNIL (France), and the proactive approach of the Datatilsynet (Norway). The legal status has been partially clarified by CJEU Judgment C-413/23 P (2025) and Opinion 28/2024 of the EDPB. A graduated framework of three risk levels, a voluntary certification system, and an implementation roadmap for the Peruvian legal system from a Latin American perspective are proposed.
No takes yet. Share an insight, caveat, or question.
Francia et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: