Case Law · CJEU EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Jehovah’s Witnesses
Summary
Access: Exercise of the right to access cannot be systematically denied on the basis of privacy violations without analyzing the specific circumstances. (¶¶ 89-94)
How it connects
References
Related across sources
Guidance Guidelines 10/2020 on restrictions under Article 23 GDPR Guidance Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them News AEPD publishes GDPR Risk Assessment Guidance Guidelines 8/2020 on the targeting of social media users Guidance Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom Guidance Guidelines 01/2022 on data subject rights - Right of access
Full text
summary
Access: Exercise of the right to access cannot be systematically denied on the basis of privacy violations without analyzing the specific circumstances. (¶¶ 89-94)
excerpt
71. As to the question whether the data controller must necessarily have access to that data, I note once more that such a requirement is not included in the definition given by Directive 95/46. That is also the view of the ‘Article 29’ Working Party, according to which inability to fulfil directly all the obligations of a controller, such as right of access, does not exclude the possibility of being a controller(66) It is even precisely for that type of situation that Directive 95/46 expressly provides that control may be exercised jointly. (67) I therefore fully concur here with the view expressed by Advocate General Bot that ‘any interpretation which focuses on the existence of complete control over all aspects of data processing is likely to result in serious lacunae in the protection of personal data’. (68)
excerpt
72. I shall therefore conclude the analysis by stating that, in the context of the case in the main proceedings, any finding of control by the religious community in no way excludes a parallel finding of shared control by the members of that community, since ‘the assessment of this joint control should mirror the assessment of “single” control, by taking a substantive and functional approach and focusing on whether the purposes and the essential elements of the means are determined by more than one party. The participation of parties in the determination of purposes and means of processing in the context of joint control may take different forms and does not need to be equally shared.’ (69) However, it seems apparent from the facts as presented to the Court by the referring court that members of the religious community can have a practical effect on the means of processing (in targeting the persons who will be visited, deciding whether to take notes, choosing the medium for those notes, determining the extent of the data collected, etc.).
Original document at the source eur-lex.europa.eu