Laws · GDPR ·art-6-par-4 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Where the processing for a purpose other than that for which the personal data have been collected is not based on the data subject's consent or on a Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23(1), the controller shall, in order to ascertain whether processing for another purpose is compatible with the purpose for which the personal data are initially collected, take into account, inter alia:
How it connects
Cited by
- Belgian DPA: Employer unlawfully disclosed employee health data to colleagues (115/2022)
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020
- Guidelines 3/2019 on processing of personal data through video devices
- Guidelines 8/2020 on the targeting of social media users
- Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications
All 43
- Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR
- Unnamed financial institution: Insufficient fulfilment of data subjects rights
- hier
- Recommendations 1/2025 on the 2027 WADA World Anti-Doping Code
- Study on the secondary use of personal data in the context of scientific research
- Opinion 3/2025 on the draft decision of the French Supervisory Authority (FR SA) regarding the “Lexing GDPR certification criteria”
- Guidelines 3/2025 on the interplay between the DSA and the GDPR
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- Opinion 2/2026 on the Proposal for a Directive amending Directives (EU) 2016/2341 and 2016/97 as regards the strengthening of the framework for occupational retirement provision
- EDPB-EDPS Joint opinion 1/2026 on the Proposal for a Regulation as regards the simplification of the implementation of harmonised rules on artificial intelligence
- EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (
- Generative AI and data protection
- Belgian DPA: Roularta Media Group violated cookie consent rules
- EDPS - 2021-0518
- Austrian FAC: DPA rightly found loyalty program consent for profiling invalid under GDPR
- Rb. Midden-Nederland - UTR 21/3403
- EDPB Annual Report 2025
- Statement 1/2025 on Age Assurance
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- Opinion 26/2024 on the draft decision of the DE Bremen Supervisory Authority regarding the “Catalogue of Criteria for the Certification of IT-supported processing of Personal Data pursuant to art 42 GDPR (‘GDPR – information privacy standard’)” presented
- Report of the work undertaken by the ChatGPT Taskforce
- EDPB Annual Report 2021
- EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)
- Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR – CARPA certification criteria
- EDPB contribution to the 6th round of consultations on the draft Second Additional Protocol to the Council of Europe Budapest Convention on Cybercrime
- EDPB-EDPS Joint Opinion 04/2021 on the Proposal for a Regulation of the European Parliament and of the Council on a framework for the issuance, verification and acceptance of interoperable certificates on vaccination, testing and recovery
- EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)
- Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications
- EDPB Document on response to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research
- Statement 02/2021 on new draft provisions of the second additional protocol to the Council of Europe Convention on Cybercrime (Budapest Convention)
- Norra Stockholm Bygg AB v Per Nycander AB
- Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság
- Ligue des droits humains ASBL v Conseil des ministres
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- Austrian court reviews postal service selling political affinity data of customers
- BVwG - W214 2235505-1
- OGH - 6Ob148/25w
- Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools