Laws · GDPR ·art-9-par-2 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Paragraph 1 shall not apply if one of the following applies:
How it connects
Cited by
- Belgian DPA: Employer unlawfully disclosed employee health data to colleagues (115/2022)
- Guidelines 05/2020 on consent under Regulation 2016/679
- Guidelines 3/2019 on processing of personal data through video devices
- Guidelines 8/2020 on the targeting of social media users
- Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement
All 116
- Guidelines 02/2021 on virtual voice assistants
- Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR
- Medical centers: Insufficient legal basis for data processing
- School in Skellefteå: Insufficient legal basis for data processing
- Website providing legal information: Insufficient fulfilment of information obligations
- Budapesti Műszaki és Gazdaságtudományi Egyetem (Budapest University of Technology and Economics): Insufficient legal basis for data processing
- Electricity Authority of Cyprus: Insufficient legal basis for data processing
- Norwegian State Pension Fund (SPK): Insufficient legal basis for data processing
- Private individual: Insufficient legal basis for data processing
- Brussels Airport Zaventem: Insufficient legal basis for data processing
- Brussels Airport Charleroi: Insufficient legal basis for data processing
- Ambuce Rescue Team: Insufficient legal basis for data processing
- Istituto Nazionale Assicurazione Infortuni sul Lavoro: Insufficient technical and organisational measures to ensure information security
- Federation of Sports for People with Intellectual Disabilities of Castilla la Mancha-FECAM: Insufficient legal basis for data processing
- Dentist: Insufficient legal basis for data processing
- Comune di Borgia: Insufficient legal basis for data processing
- Comune di Vicchio: Insufficient legal basis for data processing
- Real Federación Española de Tenis de Mesa: Insufficient fulfilment of information obligations
- I&S Limited Kft: Non-compliance with general data processing principles
- Eurocollege Oxford English Institute S.L.: Non-compliance with general data processing principles
- Cappello Giovanni & Figli s.r.l.: Non-compliance with general data processing principles
- Foodinho Srl: Non-compliance with general data processing principles
- GSMA Limited: Insufficient legal basis for data processing
- Primary Health Care in the Capital Area: Insufficient legal basis for data processing
- SATI S.p.A.: Non-compliance with general data processing principles
- Austrian Supreme Court: Meta must give users full access to their data
- Recommendations 1/2025 on the 2027 WADA World Anti-Doping Code
- Study on the secondary use of personal data in the context of scientific research
- Guidelines 02/2025 on processing of personal data through blockchain technologies
- Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH
- Guidelines 3/2025 on the interplay between the DSA and the GDPR
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- Opinion 2/2026 on the Proposal for a Directive amending Directives (EU) 2016/2341 and 2016/97 as regards the strengthening of the framework for occupational retirement provision
- GC and Others v CNIL
- Google LLC v CNIL
- Meta Platforms v noyb
- Court of Justice of the European Union - Case C-422/24 - AB Storstockholms Lokaltrafik.
- 'Principe Umberto di Savoia' State Scientific and Linguistic High School: Insufficient legal basis for data processing
- San Pio Hospital in Benevento: Insufficient legal basis for data processing
- University of Szeged: Insufficient legal basis for data processing
- Elektronikus Egészségügyi Szolgáltatási Tér: Insufficient technical and organisational measures to ensure information security
- Obuda University: Insufficient legal basis for data processing
- EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- AKI (Estonia) - No. 2.1-1/24/397-890-38
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- Reda Naujokaitienė: Insufficient legal basis for data processing
- Generative AI and data protection
- DSB (Austria) - 2026-0.016.479
- DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health
- Personvernnemnda (Norway) - 2018-14 (15/01355)
- Guidelines on processing of personal data through blockchain technologies
- Opinion 14/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR
- Statement 1/2025 on Age Assurance
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- Opinion 12/2024 on the draft decision of the French Supervisory Authority regarding the “Code of Conduct for Service Providers in Clinical Research” submitted by EUCROF
- Statement 2/2024 on the financial data access and payments package
- Report of the work undertaken by the ChatGPT Taskforce
- EDPB Annual Report 2023
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space
- EDPB Annual Report 2021
- Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR – CARPA certification criteria
- Opinion 39/2021 on whether Article 58(2)(g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject
- Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (LED) under Article 62
- EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)
- EDPB Document on response to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research
- Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects
- Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)
- WhatsApp Ireland Ltd v European Data Protection Board
- Integritetsskyddsmyndigheten v AB Storstockholms Lokaltrafik
- CK v Magistrat der Stadt Wien
- Nemzeti Adatvédelmi és Információszabadság Hatóság v UC
- Maximilian Schrems v Meta Platforms Ireland Limited
- Agentsia po vpisvaniyata v OL
- Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság
- État belge v Autorité de protection des données
- ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts
- OQ v Land Hessen
- RK v Ministerstvo zdravotnictví
- European Commission v Republic of Poland
- Criminal proceedings against V.S
- RW v Österreichische Post AG
- VS v Inspektor v Inspektorata kam Visshia sadeben savet
- TU and RE v Google LLC
- Proximus NV v Gegevensbeschermingsautoriteit
- OT v Vyriausioji tarnybinės etikos komisija
- Mircom International Content Management & Consulting (M.I.C.M.) Limited v Telenet BVBA
- Athanassios Oikonomopoulos v European Commission
- The Queen v Minister of Agriculture, Fisheries and Food, ex parte Trevor Robert Fisher and Penny Fisher
- HDPA (Greece) - 12/2026
- NAIH (Hungary) - NAIH-11443-3/2026
- VG Ansbach: Lawyer not required to redact client data when submitting files to court
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- Austrian court reviews postal service selling political affinity data of customers
- Health insurer must disclose aggregated patient treatment data under Free Access to
- DSB (Austria) - 2025-1.049.138
- National court annuls DPA sanction against KFC Spain over website privacy information
- BVwG - W211 2281442-1
- NAIH (Hungary) - NAIH-4462-5-2026
- Austrian DSB: Controller's use of social security number for statutory financial aid was
- DSB (Austria) - DSB-D124.5337
- Garante per la protezione dei dati personali (Italy) - 551/2026
- DSB Austria: disclosure of health data to court-appointed expert in legal dispute lawful
- Medical Student: Insufficient legal basis for data processing
- Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data
- Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
- IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M
- Icelandic DPA: City of Reykjavik cannot request bank statements from NPA disabled service