Skip to content
Case Law · CJEU ·317/25 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

An AG opined that consent to marketing by unidentified “partners” is not sufficiently informed

A later controller must obtain fresh consent before sending electronic direct marketing.

CJEU

How it connects

Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Apr 17, 2023 Supervision Controllers Supervisory Authorities
2025 EDPB Annual Report 2024 De EDPB heeft het Jaarraport van 2024 gepubliceerd. Met ook een handzame samenvatting voor degene die geen tijd hebben. Er wordt ook een lijst met zaken van enkele DPAs… Apr 23, 2025 AI Enforcement Actions Mutual Assistance Between Member States for AI Oversight Cookies
€280,000 Garante per la protezione dei dati personali (Italy) · 10269624 The controller is a publishing company that sells subscriptions to consumer information services through its website. Users can sign up by filling in a registration form on the… Art. 6, 7, 12 +2 Right to Object Personal Data Direct Marketing
2020 EDPB Annual Report 2019 EDPB Annual Report 2019 1 EDPB Annual Report 2019 1 European Data Protection Board 2019 Annual Report WORKING TOGETHER FOR STRONGER RIGHTS An Executive Summary of this report,… May 18, 2020 Privacy by Design & Default Privacy by Default Supervision

Full text

An AG opined that consent to marketing by unidentified “partners” is not sufficiently informed. A later controller must obtain fresh consent before sending electronic direct marketing. English Summary. Facts. In 2021, Groupe Canal + SAS, the controller, carried out electronic direct marketing campaigns targeting approximately 3.9 million people. Their personal data had initially been collected by two internet service providers (ISPs). When collecting the data, the ISPs asked their subscribers to tick a box consenting to the use of their personal data for direct marketing by the ISPs’ “partners”. However, the partners were not identified on the collection form, through a hyperlink or by any other means. Consequently, the data subjects did not know that the controller could subsequently receive and use their data for electronic direct marketing. Following several complaints concerning the controller’s marketing activities the DPA carried out inspections. On 12 October 2023, the DPA found