🤖 AI Summary
This paper addresses the individual identifiability of pseudonymous data in behavioral targeting advertising, challenging whether such data qualifies as “personal data” under regulations like the GDPR. Methodologically, it integrates legal text analysis, privacy risk assessment frameworks, and empirical modeling using real-world behavioral datasets. Results demonstrate that non-identifying attributes—such as device identifiers and browsing trajectories—enable high-accuracy re-identification of natural persons, exposing a critical interpretive gap in the prevailing legal “single individual” definition vis-à-vis contemporary technical capabilities. The paper makes two key contributions: first, it proposes a novel two-dimensional criterion for personal data classification—grounded in *identifiability likelihood* and *identification cost*; second, it recommends regulatory adaptation requiring platforms to bear the burden of proof for the ongoing effectiveness of anonymization measures. These findings provide both theoretical grounding and actionable policy pathways for enhancing the technical enforceability of data protection law.