Case Law · CJEU EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
CJEU: Website operator embedding social plugin is joint controller limited to data
Original title: FASHION ID GmbH & Co. KG v. VERBRAUCHERZENTRALE NRW eV
Judgment
Summary
Concept of joint-controllers: The operator of a website, such as Fashion ID, that embeds on that website a social plugin causing the browser of a visitor to that website to request content from the provider of that plugin and, to that end, to transmit to that provider the personal data of the visitor can be considered to be a controller. That liability is, however, limited to the operation or set of operations involving the processing of personal data in respect of which it actually determines t
Full text
summary
Concept of joint-controllers: The operator of a website, such as Fashion ID, that embeds on that website a social plugin causing the browser of a visitor to that website to request content from the provider of that plugin and, to that end, to transmit to that provider the personal data of the visitor can be considered to be a controller. That liability is, however, limited to the operation or set of operations involving the processing of personal data in respect of which it actually determines the purposes and means, that is to say, the collection and disclosure by transmission of the data at issue. (¶85)
¶85 excerpt
In the light of the findings above, the answer to the second question is that the operator of a website, such as Fashion ID, that embeds on that website a social plugin causing the browser of a visitor to that website to request content from the provider of that plugin and, to that end, to transmit to that provider the personal data of the visitor can be considered to be a controller, within the meaning of Article 2(d) of Directive 95/46. That liability is, however, limited to the operation or set of operations involving the processing of personal data in respect of which it actually determines the purposes and means, that is to say, the collection and disclosure by transmission of the data at issue.
How it connects
Related across sources
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines Jul 7, 2021 Controllers Processors IP Address
Guidelines 9/2022 personal data breach notification under GDPR Guidelines Apr 4, 2023 Notification Obligation Data Breaches Personal Data
Guidelines 01/2022 data subject rights - Right of access Guidelines Apr 17, 2023 Right of Access Personal Data Right to Rectification
Guidelines 10/2020 restrictions under Article 23 GDPR Guidelines Oct 13, 2021 GDPR Subject-Matter and Objectives Right to Restriction Data Portability
Guidelines 03/2022 Deceptive design patterns in social media platform interfaces: how to recognise and avoid them Guidelines Feb 24, 2023 Privacy by Design & Default Privacy by Design Privacy by Default