Skip to content
News · noyb - European Center for Digital Rights EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Complaint: Amazon doesn’t allow baseline TLS security

Data Security Baseline email security missing.

Full text

Data Security Baseline email security missing. During their route to the recipient, emails are handled by different entities, nodes and service providers which may intercept, manipulate and unlawfully use the content. In order to reduce these risks, it is a baseline industry standard to use so-called TLS encryption. View complaint (PDF) “TLS is like an envelope around a letter. If not used, anyone can read the content of an email in transfer.” Stefano Rossetti, privacy lawyer at noyb Surprisingly the Amazon servers reject TLS connections in certain cases, for example when third party sellers on Amazon communicate with customers vie email. This means that millions of emails that are sent via Amazon may be exposed everyday. Violation of GDPR. Article 32 of the GDPR requires companies to implement “appropriate” security measures, such as encryption, to protect the confidentiality of communications. As TLS encryption is very cheap and simple to implement and the number of sellers and custo

How it connects

C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… CJEU ·Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
C-687/21 BL v MediaMarktSaturn Hagen-Iserlohn GmbH In Case C-687/21, the Court of Justice of the European Union interpreted Articles 5, 24, 32, and 82 of the GDPR in response to a preliminary ruling request from the Amtsgericht… CJEU ·Third Chamber Jan 25, 2024 Liability Integrity and Confidentiality Principle Data Breaches
Statement 03/2021 ePrivacy Regulation Statement ·EDPB Mar 9, 2021 Telecommunications Encryption Cookies
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer
KHO:2026:64 KHO: Consent required for cookies and web requests; no CJEU referral needed A media company that provides news services did not request user context for the placement and use of cookies or certain web requests on several websites it managed. In June 2023,… Supreme Administrative Court Aug 27, 2026 Consent IP Address Recipient