Laws · GDPR ·art-6-par-1-pnt-f EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
How it connects
Cited by
- Record fine for Instagram following EDPB intervention
- LfD (Lower Saxony) - Fine EUR 900,000 against bank
- Guidelines 02/2024 on Article 48 GDPR
- Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them
- Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679
All 114
- Guidelines 3/2019 on processing of personal data through video devices
- Guidelines 8/2020 on the targeting of social media users
- Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR
- Website providing legal information: Insufficient fulfilment of information obligations
- Company: Insufficient legal basis for data processing
- Rijeka Court: AZOP decision on media reporting of former Zagrebački Holding board
- hier
- Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Study on the secondary use of personal data in the context of scientific research
- Guidelines 02/2025 on processing of personal data through blockchain technologies
- EDPB Annual Report 2024
- Guidelines 3/2025 on the interplay between the DSA and the GDPR
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- Opinion 2/2026 on the Proposal for a Directive amending Directives (EU) 2016/2341 and 2016/97 as regards the strengthening of the framework for occupational retirement provision
- Meta Platforms v noyb
- BGH - I ZR 97/25 (This appears to be a legal citation and doesn't require translation.)
- USR - Reference number I-755/2025-8
- FTT allows appeal: NMC should have neither confirmed nor denied holding nurse's data
- OLG Köln - 15 W 55/26
- EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (
- Coordinated Enforcement Action,
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- Can the GPC standard eliminate consent banners in the EU?
- Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU
- BGH - VI ZR 375/2
- Generative AI and data protection
- DSB (Austria) - 2026-0.016.479
- Garante per la protezione dei dati personali (Italy) - 487/2026
- BVwG: Separate WhatsApp and email transmissions of same judgment are distinct data
- APD/GBA (Belgium) - 11/2022
- LG Rostock: Pre-ticked cookie consent boxes invalid under Art 6(1)(a) GDPR
- EDPS: European Parliament is sole controller for COVID testing website and failed
- BVwG - W 108 2284491-1
- Italy Garante: TikTok switch to legitimate interest for personalized ads violates
- Belgian DPA finds MediaHuis violated GDPR fairness over cookie banner design
- Court rejects DFW request for Ziggo customer IP addresses due to insufficient transparency
- Greek HDPA: Classroom video surveillance at school unlawful; oral notice insufficient
- German Supreme Court: GDPR non-material damages need no severity threshold
- CNIL (France) - SAN-2022-011
- Personvernnemnda (Norway) - 2018-14 (15/01355)
- Norwegian Supreme Court: Legelisten.no has Art. 6(1)(f) legal basis for doctor reviews
- Norwegian DPA: Legelisten.no may process healthcare reviews without prior consent
- Austrian FAC: DPA rightly found loyalty program consent for profiling invalid under GDPR
- Guidelines on processing of personal data through blockchain technologies
- EDPB Annual Report 2025
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- Report of the work undertaken by the ChatGPT Taskforce
- Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms
- EDPB Annual Report 2022
- Report of the work undertaken by the Cookie Banner Taskforce
- EDPB Annual Report 2021
- Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects
- Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)
- Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens
- IAB Europe v Gegevensbeschermingsautoriteit
- UF and AB v Land Hessen
- OQ v Land Hessen
- VS v Inspektor v Inspektorata kam Visshia sadeben savet
- Mircom International Content Management & Consulting (M.I.C.M.) Limited v Telenet BVBA
- Commercial, but Legitimate Interest: The Court of Justice Calls the Dutch Data Protection Authority to Order
- CJEU - C‑209/23 - RRC Sports
- NAIH (Hungary) - NAIH-11443-3/2026
- APD/GBA (Belgium) - 74/2024
- VG Ansbach: Lawyer not required to redact client data when submitting files to court
- AEPD (Spain) - PS-00480-2025
- DSB (Austria) - 2025-0.950.759
- OLG München - 36 U 1054/25 e
- AEPD fines El Español for publishing video of minor assailant without anonymization
- HDPA (Greece) - 7/2026
- Garante per la protezione dei dati personali (Italy) - 483/2026
- Garante per la protezione dei dati personali (Italy) - 462/2026
- Austrian court reviews postal service selling political affinity data of customers
- BGH - VI ZR 54/21
- Garante fines Lusha Systems Inc. over unauthorized B2B contact database
- DSB (Austria) - 2025-1.049.138
- National court annuls DPA sanction against KFC Spain over website privacy information
- Austrian FAC rules on publishing full court judgment naming witness on social media
- NAIH (Hungary) - NAIH-450-7-2026
- Austrian VwGH: hotel listings and user reviews on travel platform serve legitimate
- DSB (Austria) - 2025-0.960.016
- Garante per la protezione dei dati personali (Italy) - 476/2026
- Bulgarian SAC: criminal record check for bank counsel role lawful under GDPR Art. 6(1)(c)
- AEPD fines MÁS SOL ENERGÍA for marketing call to Robinson List subscriber
- DSB Austria: Publishing companies-register data on free ad-funded platform unlawful
- NAIH (Hungary) - NAIH-4462-5-2026
- BVwG - W214 2235505-1
- Austrian DSB: Employee who shared customer's phone number acted as GDPR controller
- VG Berlin: DPA correctly found residential video surveillance for property protection
- Datatilsynet ordered Lab Pharma AS to erase influencer's personal data used after
- DSB: Retailer must grant full access and delete data after third-party fraud order
- DSB (Austria) - DSB-D124.5337
- Federal Administrative Court: retention of job applicant data for potential legal claims
- BVwG - W137 2334047-1
- EWCA (UK) - 2026 EWCA Civ 1130
- BVwG - W605 2289290-2/18E
- BVwG - W292 2292202-1
- Francesco Gagliardi: Non-compliance with general data processing principles
- Medical Student: Insufficient legal basis for data processing
- OGH - 6Ob148/25w
- VG Hannover: Controller appeals DPA reprimand over unlawful workplace video surveillance
- BVwG - W292 2298015-1
- AEPD: CaixaBank requested excessive inheritance documentation from heirs
- FTT upholds UKIPO's FOIA withholding of copyright exception documents under s.27
- FTT: Kent County Council FOIA refusal of Kent Test scores and DOB upheld
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary
- Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to
- IndaNext Hungary Kft. (legal successor of Blikk Kft.): Insufficient legal basis for data processing
Related across sources
CJEU Google Spain: data subject may require search engine to remove links to outdated Legitimate interest balancing test: Legitimate interest requires balancing of the interest of the controller and third party with the interest of the data subject. In this… May 13, 2014 Personal Data Legitimate Interest Right to Rectification
CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69) Jun 29, 2010 Personal Data Legitimate Interest Right to Restriction
W137 2333649-1 Federal Administrative Court: retention of job applicant data for potential legal claims The data subject applied for a job with the association and provided additional documents, regarding the use of their personal data. Among other things, it was stated that the… Jul 8, 2026 Storage Limitation Retention Period Right to be Forgotten
Guidelines 2/2018 derogations of Article 49 under Regulation 2016/679 Guidelines on derogations of Article 49 Guidelines ·EDPB May 25, 2018 Privacy Shield Lawful Basis Legitimate Interest
Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Jan 30, 2020 Personal Data Processing Material scope (GDPR)
Guidelines 02/2024 Article 48 GDPR Article 48 GDPR provides that: ' Any judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to… Guidelines ·EDPB Jun 5, 2025 Controllers Privacy Shield International Transfer