CJEU - C‑769/22 - European Commission v Hungary
The background In 2021 Hungary adopted "Law LXXIX of 2021 adopting stricter measures against persons convicted of paedophilia and amending certain laws for the protection of children" ("the amending law").
How it connects
References
Related across sources
Full text 11 paragraphs
Facts — The background In 2021 Hungary adopted "Law LXXIX of 2021 adopting stricter measures against persons convicted of paedophilia and amending certain laws for the protection of children" ("the amending law"). The law introduced a number of rules to restrict the access of minors to content portraying or promoting gender identities that do not correspond to the sex assigned at birth, sex reassignment or homosexuality. The law also introduced new rules for access to public documents, requiring public bodies to allow broad access to information about individuals convicted of sexual offences against children. The alleged purpose of the law was to protect minors. In 2021 the Commission sent a formal letter to Hungary contesting the amending law's compliance with EU law. After some unproductive back-and-forth, the Commission escalated the case to the CJEU, requesting the CJEU to declare the amending law incompatible with EU law.
The European Commission filed four pleas, claiming that Hungary violated of a long list of provisions from primary and secondary EU law . Only the Commission's fourth plea invokes data protection law- specifically, Article 8(2) of the EU Charter of Fundamental Rights (CFR) ("Protection of personal data") and Article 10 GDPR ("Processing of personal data relating to criminal convictions and offences"). The fourth plea: Article 10 GDPR The alleged violation of the GDPR relates to the amended law's rules on access to information about individuals convicted of sexual offences against children. The law amended the "Law on the criminal record system" and made documents about sexual offences accessible to a broad audience. Under the new rules, any adult who is either a relative or a guardian of a minor ("authorised person"), has the right to access and share information about individuals convicted of sexual offences against children (the data subjects) from bodies with access to registered data.
The Commission claimed that the amended law failed to specify with sufficient clarity who is authorised to submit a data request and, therefore, did not provide sufficient guarantees for the rights and freedoms of data subjects regarding the conditions of access to their personal data. On these grounds, the Commission claimed that the amended law infringed Article 10 of the GDPR (as well as Art. 8(2) CFR). In its defense, Hungary argued that the law accurately identified "authorised persons" when read in light of the definition of "relatives" in the Hungarian civil code. Additionally, Hungary claimed that there were two additional criteria access to personal data under Hungarian law: the authorised person must consider the relevant data to be probably necessary, and it must be disproportionately difficult for them to access the subjects' data if they are not disclosed. e. "any adult who is either a relative of, or educates, supervises or cares for, a person who has not attained 18 years of age"- where "relative" was to be understood in the well-defined sense of Hungarian civil law); (ii) the disclosure was probably necessary to keep the minor safe; (iii) it was disproportionately difficult for the authorized person to access the data otherwise.
Hungary claimed that these criteria were clearly defined and provided sufficient safeguards for data subjects. On this basis, Hungary argued that the amended law complied with Article 10 GDPR and 8(2) CFR. Advocate General Opinion — AG Cápeta clarified that, according to CJEU case law, the GDPR did not impose an absolute ban on the disclosure of personal data from public authorities. The GDPR did, however, require a balancing between the purpose of such disclosures, and the rights and freedoms of data subjects. In particular, the disclosure of personal data regarding criminal convictions, required strict justification and clear legal safeguards, because of the sensitive nature of such data. In the case at hand, the AG conceded that the data disclosure pursued an important public interest (the protection of minors). So, the question was whether the amending law correctly balanced this interest against the right to data protection.
The AG opined that the amending law failed to do so and exceeded what was strictly necessary to protect minors, for two reasons. First, the AG agreed with the Commission that the notion of "authorised persons" was too broad and unclearly defined under the amending law, even when the amending law was interpreted in light of domestic civil law. In this regard, the AG pointed to the CJEU case law on the access to personal data from national authorities: in order to satisfy the requirement of proportionality, national law that allowed for such access "must lay down clear and precise rules governing the scope and application of the measure in question and imposing minimum safeguards". The AG further opined that such criteria would also apply to access from private citizens, as in the case at hand. : the probable necessity of the disclosure, and the difficulty of otherwise accessing the data) were overly generic and were to be assessed by the authorized person themselves.
The AG argued that such a self-declaratoty regime lent itself to abuse and deprived the disclosing body of any control over the necessity and proportionality of the disclosure. For this reason, the AG opined that the amending law failed to provide the required safeguards for data subjects. On these grounds, the AG opined that the amended law was disproportionate and violated Article 10 GDPR as well as Article 8(2) CFR. Holding — The court first noted that one of the objectives of the GDPR is to ensure a high level of protection of data subjects’ fundamental rights and freedoms, in accordance with Article 1 GDPR and Article 8(1) CFR. Therefore, any processing of personal data must be lawful, in accordance with Articles 5(1)(a) and 6(1) GDPR. In addition, any legal basis other than consent (Article 6(1)(a) GDPR) must be interpreted restrictively. The court then assessed whether the processing was lawful under Article 6(1)(e) and 86 GDPR.
Article 6(1)(e) GDPR provides for a legal basis based on public interest or in the exercise of official authority vested in the controller. In the case of disclosing this data, Article 86 GDPR states that this may be done to reconcile public access to official documents with the right to the protection of personal data. The court stated that, in principle, the processing of data related to criminal convictions (including its disclosure) could be lawful under Article 6(1)(e) and 10 GDPR. However, Article 10 GDPR makes the processing subject to additional restrictions (for example, the processing must provide for appropriate safeguards). In addition, limits to the fundamental rights to privacy and data protection must respect the essence of the fundamental right and be proportionate, in accordance with Article 52(1) CFR. This is especially relevant in this case, as data related to criminal convictions is particularly sensitive and its processing can be a particularly serious interference with data subjects’ fundamental rights.
The court followed the reasoning of the AG in stating that the protection of minors was an important public interest. However, the court considered the amending law incompatible with Article 10 GDPR. The law was not sufficiently precise, particularly in defining the concept of “authorised person”. The court considered that the processing was not limited to what is strictly necessary, as the circle of persons potentially entitled to submit a request was too broad. Finally, the court concurred with the AG, and stated that the amending law was not proportionate. This is because it relied on the person requesting the data to justify the need to access it. Therefore, the amending law did not provide for appropriate safeguards by relying on the self-declaration regarding the necessity and proportionality of accessing the data. The court concluded that the amending law did not meet the requirements under Article 10 GDPR, meaning it could not justify its processing under Article 6(1)(e) GDPR.
With this, Hungary had failed to fulfil its obligations under Article 10 GDPR and Article 8(2) CFR. Holding — The court first noted that one of the objectives of the GDPR is to ensure a high level of protection of data subjects’ fundamental rights and freedoms, in accordance with Article 1 GDPR and Article 8(1) CFR. Therefore, any processing of personal data must be lawful, in accordance with Articles 5(1)(a) and 6(1) GDPR. In addition, any legal basis other than consent (Article 6(1)(a) GDPR) must be interpreted restrictively. The court then assessed whether the processing was lawful under Article 6(1)(e) and 86 GDPR. Article 6(1)(e) GDPR provides for a legal basis based on public interest or in the exercise of official authority vested in the controller. In the case of disclosing this data, Article 86 GDPR states that this may be done to reconcile public access to official documents with the right to the protection of personal data.
The court stated that, in principle, the processing of data related to criminal convictions (including its disclosure) could be lawful under Article 6(1)(e) and 10 GDPR. However, Article 10 GDPR makes the processing subject to additional restrictions (for example, the processing must provide for appropriate safeguards). In addition, limits to the fundamental rights to privacy and data protection must respect the essence of the fundamental right and be proportionate, in accordance with Article 52(1) CFR. This is especially relevant in this case, as data related to criminal convictions is particularly sensitive and its processing can be a particularly serious interference with data subjects’ fundamental rights. The court followed the reasoning of the AG in stating that the protection of minors was an important public interest. However, the court considered the amending law incompatible with Article 10 GDPR.
The law was not sufficiently precise, particularly in defining the concept of “authorised person”. The court considered that the processing was not limited to what is strictly necessary, as the circle of persons potentially entitled to submit a request was too broad. Finally, the court concurred with the AG, and stated that the amending law was not proportionate. This is because it relied on the person requesting the data to justify the need to access it. Therefore, the amending law did not provide for appropriate safeguards by relying on the self-declaration regarding the necessity and proportionality of accessing the data. The court concluded that the amending law did not meet the requirements under Article 10 GDPR, meaning it could not justify its processing under Article 6(1)(e) GDPR. With this, Hungary had failed to fulfil its obligations under Article 10 GDPR and Article 8(2) CFR. Comment — Share your comments here!