CJEU - Case C‑5/25 - Pilev
In September 2023, the Bulgarian Public Prosecutor’s Office brought a criminal case against a data subject to the Sofia City Court.
How it connects
Related across sources
Full text 4 paragraphs
Facts — In September 2023, the Bulgarian Public Prosecutor’s Office brought a criminal case against a data subject to the Sofia City Court. According to the Prosecutor’s Office, the data subject bribed police officers, and worked as a taxi driver without the necessary license. During the proceedings, the court requested personal data from the data subject in order to verify their identity. While a data subject can be identified with their identity card, national law requires national courts to ask further questions to further verify the data subject’s identity. The court had doubts on the compatibility of said national law provisions with the Bulgarian Constitution, and stayed proceedings. g. place of birth, ethnicity, or marital status) is necessary, and whether the national provisions are consistent with Article 10 Law Enforcement Directive 2016/680. The court referred the matter to the Constitutional Court.
The Constitutional Court refused to give a substantive ruling, and the court therefore requested a preliminary ruling from the CJEU. Advocate General Opinion — The AG first stated that the data processing fell in the scope of the LED in accordance with Article 2(1) Law Enforcement Directive 2016/680. The LED is applicable if the data processing is carried out by a competent authority (Article 3(7) Law Enforcement Directive 2016/680) and for the purposes listed in Article 1(1) Law Enforcement Directive 2016/680. The LED is the lex specialis of the GDPR, which excludes from its scope processing of personal data that falls within the scope of the LED. In the AG’s view, the court falls within the definition of a competent authority; while it may not expressly follow the definition of competent authority, it can be inferred from the provisions’ context. The AG also considered that the definition of “prosecution of criminal offenses” can be interpreted broadly, and therefore the court’s processing activities fell under the scope of the LED.
This does not contradict the principle that exceptions to the GDPR (as lex generalis) should be interpreted strictly, as criminal court proceedings would not be exempt from data protection regulations. The AG also highlighted that having two different data protection laws apply at different stages of the court proceedings and by different law enforcement actors would lead to a fragmented legal regime, in contradiction to the principle of legal certainty and consistent protection of personal data. Finally, the AG noted that the LED grants law enforcement authorities more flexibility in processing data, particularly in the case of processing sensitive personal data prohibited under Article 9(1) GDPR. In terms of national law provisions, the AG opined that national law requiring the systematic processing of data subjects’ personal data when verifying their identity was not compatible with the LED, when this data is not necessary for that purpose.
The purpose of verifying that a data subject is the person being indicted is a legitimate purpose. However, the AG opined that requiring courts to systematically process data such as ethnicity, marital status or previous convictions were not compatible with the principle of data minimisation (Article 4(1)(c) Law Enforcement Directive 2016/680) or lawfulness (Article 8(1) Law Enforcement Directive 2016/680). This is because this information is not necessary at the stage of proceedings of verifying the data subject’s identity. Even in cases where this information was needed, the AG noted that the systematic nature of this data processing was disproportionate. Finally, the AG highlighted that the court would systematically process special categories of personal data, which Article 10 Law Enforcement Directive 2016/680 allows only where strictly necessary. Holding — TBD. Holding — TBD. Comment — Share your comments here!