Laws · GDPR ·art-5-par-1-pnt-b EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);
How it connects
Cited by
- Belgian DPA: Employer unlawfully disclosed employee health data to colleagues (115/2022)
- Guidelines 05/2020 on consent under Regulation 2016/679
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020
- Guidelines 01/2022 on data subject rights - Right of access
- Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them
All 63
- Guidelines 8/2020 on the targeting of social media users
- Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications
- Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR
- Company: Insufficient legal basis for data processing
- hier
- Study on the secondary use of personal data in the context of scientific research
- EDPB Annual Report 2024
- Guidelines 3/2025 on the interplay between the DSA and the GDPR
- SO Warszawa: Controller warned for violating GDPR Arts. 5(1), 6(1), and 15(1)
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- Garante per la protezione dei dati personali (Italy) - 382/2026
- Generative AI and data protection
- DSB (Austria) - 2026-0.016.479
- Garante per la protezione dei dati personali (Italy) - 10128005
- Garante per la protezione dei dati personali (Italy) - 419/2026
- GC T-318/24: EPSO access logs and Article 17 access requests under Regulation 2018/1725
- Greek HDPA: Classroom video surveillance at school unlawful; oral notice insufficient
- EDPS - 2021-0518
- Statement 1/2025 on Age Assurance
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- Opinion 12/2024 on the draft decision of the French Supervisory Authority regarding the “Code of Conduct for Service Providers in Clinical Research” submitted by EUCROF
- Report of the work undertaken by the ChatGPT Taskforce
- EDPB Annual Report 2023
- Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms
- Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- EDPB Annual Report 2022
- EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)
- EDPB Document on response to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research
- Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak
- Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects
- Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)
- X v Russmedia Digital SRL and Inform Media Press SRL
- Maximilian Schrems v Meta Platforms Ireland Limited
- Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V
- Norra Stockholm Bygg AB v Per Nycander AB
- VS v Inspektor v Inspektorata kam Visshia sadeben savet
- WM and Sovim SA v Luxembourg Business Registers
- Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság
- SIA 'SS' v Valsts ieņēmumu dienests
- Deutsche Post AG v Hauptzollamt Köln
- Data Protection Regulation and International Arbitration: Can There Be Harmonious Coexistence (with the GDPR Requirements Concerning Cross-Border Data Transfer)?
- Hoge Raad - ECLI:NL:PHR:2023:935
- DSB (Austria) - 2025-0.950.759
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- HDPA (Greece) - 7/2026
- Garante per la protezione dei dati personali (Italy) - 483/2026
- Austrian court reviews postal service selling political affinity data of customers
- Garante per la protezione dei dati personali (Italy) - 484/2026
- Garante per la protezione dei dati personali (Italy) - 476/2026
- Austrian DSB: Employee who shared customer's phone number acted as GDPR controller
- DSB (Austria) - DSB-D124.5337
- Federal Administrative Court: retention of job applicant data for potential legal claims
- Supreme Court: CRIF illegally collected data of millions in Austria. Way clear for class action!
- Persónuvernd (Iceland) - 2025010364
- CJEU - C-798/24 - Jautiva
- OGH - 6Ob148/25w
- Austrian Federal Administrative Court: address publisher's data transfer and Article 15
- Italian DPA: Municipality of Aprilia unlawfully disclosed whistleblower data to employer
Related across sources
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
Guidelines 5/2019 criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) Guidelines ·EDPB Jul 7, 2020 Right to be Forgotten Personal Data Right to Rectification
C-77/21 Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority… CJEU ·First Chamber Oct 20, 2022 Retention Period Storage Limitation Personal Data
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… CJEU ·Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design
HvJ EU 9 januari 2025, C‑394/23 (Mousse) Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20… HvJ EU 9 januari 2025, C‑394/23 (Mousse). ·CJEU Jan 9, 2025 IP Address Retention Period Identification