Laws · GDPR ·art-5-par-1-pnt-a EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);
How it connects
Cited by
- Italian DPA sanctions Municipality of Policoro for CCTV signage, retention and DPO
- Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them
- Guidelines 8/2020 on the targeting of social media users
- Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)
- Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR
All 147
- Private individual: Insufficient legal basis for data processing
- Company: Insufficient legal basis for data processing
- HvJ EU 9 januari 2025, C‑394/23 (Mousse).
- One-Stop-Shop case digest on right of access
- hier
- Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- EDPB Annual Report 2024
- Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH
- Opinion 16/2025 regarding the draft decision of the German North Rhine Westphalia Supervisory Authority regarding Trusted Site Data Privacy (TÜV IT) certification criteria
- Guidelines 3/2025 on the interplay between the DSA and the GDPR
- Deutsche Wohnen SE v Staatsanwaltschaft Berlin
- Garante per la protezione dei dati personali (Italy) - 10214411
- AEPD (Spain) - EXP202306354 (PS/00312/2024)
- Cass.Civ. - 15625/2026
- UODO fines accounting firm €2,760 for email breach security failures
- BGH - V ZB 90/25
- FTT allows appeal: NMC should have neither confirmed nor denied holding nurse's data
- The Magician’s Eye
- AKI (Estonia) - No. 2.1-1/24/397-890-38
- Garante per la protezione dei dati personali (Italy) - 382/2026
- BGH - VI ZR 375/2
- Generative AI and data protection
- DSB (Austria) - 2026-0.016.479
- UODO (Poland) - DKE.561.4.2026
- Garante per la protezione dei dati personali (Italy) - 471/2026
- Garante per la protezione dei dati personali (Italy) - 10192784
- APD/GBA (Belgium) - 11/2022
- APD/GBA (Belgium) - 131/2024
- LG Rostock: Pre-ticked cookie consent boxes invalid under Art 6(1)(a) GDPR
- BVwG - W 108 2284491-1
- Belgian DPA finds MediaHuis violated GDPR fairness over cookie banner design
- Garante per la protezione dei dati personali (Italy) - 10128005
- Garante per la protezione dei dati personali (Italy) - 419/2026
- GC T-318/24: EPSO access logs and Article 17 access requests under Regulation 2018/1725
- DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health
- DPC (Ireland) reprimands Kildare County Council over surveillance tech and CCTV compliance
- DPC (Ireland) - 06/SIU/2018
- Greek HDPA: Classroom video surveillance at school unlawful; oral notice insufficient
- Norwegian DPA: Legelisten.no may process healthcare reviews without prior consent
- EDPB Annual Report 2025
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- Statement 4/2024 on the recent legislative developments on the Draft Regulation laying down additional procedural rules for the enforcement of the GDPR
- Report of the work undertaken by the ChatGPT Taskforce
- EDPB Annual Report 2023
- Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms
- EDPB-EDPS Joint Opinion 02/2023 on the Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro
- Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- EDPB Annual Report 2022
- EDPB Annual Report 2021
- Opinion 39/2021 on whether Article 58(2)(g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject
- EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)
- Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications
- Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects
- Article 29 Working Party - Guidelines on transparency under Regulation 2016/679
- WhatsApp Ireland Ltd v European Data Protection Board
- X v Russmedia Digital SRL and Inform Media Press SRL
- Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- L. H. v Ministerstvo zdravotnictví
- Maximilian Schrems v Meta Platforms Ireland Limited
- Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens
- HTB Neunte Immobilien Portfolio geschlossene Investment UG & Co. KG and Ökorenta Neue Energien Ökostabil IV geschlossene Investment GmbH & Co. KG v Müller Rechtsanwaltsgesellschaft mbH and Others
- Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V
- SO
- Endemol Shine Finland Oy
- ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts
- VX and AT v Gemeinde Ummendorf
- UF and AB v Land Hessen
- OQ v Land Hessen
- Meta Platforms Ireland Ltd, formerly Facebook Ireland Ltd v European Commission
- Meta Platforms Ireland Ltd, formerly Facebook Ireland Ltd v European Commission
- UZ v Bundesrepublik Deutschland
- RW v Österreichische Post AG
- WhatsApp Ireland Ltd v European Data Protection Board
- WM and Sovim SA v Luxembourg Business Registers
- Proximus NV v Gegevensbeschermingsautoriteit
- Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság
- Tele2 (Netherlands) BV and Others v Autoriteit Consument en Markt (ACM)
- LSG-Gesellschaft zur Wahrnehmung von Leistungsschutzrechten GmbH v Tele2 Telecommunication GmbH
- Garante per la protezione dei dati personali (Italy) - 10254256
- CA - EWCA Civ 899 Vince v. Associated Newspapers Limited
- Garante per la protezione dei dati personali (Italy) - 457/2026
- EDPB - Binding Decision 1/2026
- DSB (Austria) - 2026-0.043.390
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- HDPA (Greece) - 7/2026
- Garante per la protezione dei dati personali (Italy) - 483/2026
- Garante per la protezione dei dati personali (Italy) - 462/2026
- Austrian court reviews postal service selling political affinity data of customers
- Garante per la protezione dei dati personali (Italy) - 484/2026
- Garante fines Lusha Systems Inc. over unauthorized B2B contact database
- DSB (Austria) - 2025-1.049.138
- Austrian FAC rules on publishing full court judgment naming witness on social media
- NAIH (Hungary) - NAIH-450-7-2026
- Garante per la protezione dei dati personali (Italy) - 476/2026
- NAIH (Hungary) - NAIH-4462-5-2026
- Garante per la protezione dei dati personali (Italy) - 10273026
- VG Berlin - 42 K 73/25
- MEDE S.A.: Non-compliance with general data processing principles
- Austrian DSB: Employee who shared customer's phone number acted as GDPR controller
- DSB: Retailer must grant full access and delete data after third-party fraud order
- DSB: No processor access violation under Art. 15 GDPR when controller deleted data
- UODO reprimands mayor for disclosing data subject's data to company without legal basis
- Finnish DPA examines anti-doping organization's GDPR compliance over public suspension
- Federal Administrative Court: retention of job applicant data for potential legal claims
- Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car
- Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on
- Italian DPA finds Cerved Group failed to disclose creditworthiness scores in Art. 15
- Garante per la protezione dei dati personali (Italy) - 577/2026
- Dr. Guzzo: Insufficient legal basis for data processing
- Persónuvernd (Iceland) - 2025010364
- Ministry of Justice: Insufficient legal basis for data processing
- Francesco Gagliardi: Non-compliance with general data processing principles
- FeGi M&A Services s.r.l.: Non-compliance with general data processing principles
- Pianeta S.r.l.: Non-compliance with general data processing principles
- APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients
- AEPD: Data subject entitled to identity of professionals who accessed medical records
- OGH - 6Ob148/25w
- Italian DPA sanctions Top Secret Investigazioni for unjustified email forwarding after
- VG Hannover: Controller appeals DPA reprimand over unlawful workplace video surveillance
- BVwG - W292 2298015-1
- Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive
- BVwG - W298 2314952-1
- Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste
- Cyprus Court upholds DPA finding that Sigma TV unlawfully disclosed financial data
- Ristorante Carlo Menta s.r.l.: Insufficient fulfilment of information obligations
- Rosetta Trastervere s.r.l.s.: Insufficient fulfilment of information obligations
- Autonomous Region of Sardinia: Insufficient legal basis for data processing
- University of Pisa: Insufficient technical and organisational measures to ensure information security
- Cerved Group S.p.A.: Insufficient fulfilment of data subjects rights
- Municipality of Villaputzu: Insufficient legal basis for data processing
- FTT upholds UKIPO's FOIA withholding of copyright exception documents under s.27
- FTT: Kent County Council FOIA refusal of Kent Test scores and DOB upheld
- European Commission v Hungary
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- CJEU - C-458/25
- Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to
- Top Secrert Investigazioni e sicurezza s.r.l.: Non-compliance with general data processing principles
- Austrian Federal Administrative Court: address publisher's data transfer and Article 15
- Italian DPA: Municipality of Aprilia unlawfully disclosed whistleblower data to employer
- Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools
- Icelandic DPA opens formal proceedings against Isavia over ANPR parking cameras at
- Icelandic DPA: City of Reykjavik cannot request bank statements from NPA disabled service