Case Law · CJEU EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
CJEU Weltimmo: establishment under EU data protection law is broad, not based solely on
Establishment: The concept of establishment must be interpreted broadly.
Original title: WELTIMMO S.R.O. V. NEMZETI A DATVEDELMI ES INFORMACIOSZABADSAGH ATOSAG (HUNGARIAN DPA), 1.10.15 (“WELTIMMO”)
Judgment
Summary
The legal form of such establishment (e.g. branch, subsidiary etc) is not the determining factor. The formalist approach whereby organizations are considered to be established solely in the place in which they are registered is not the correct approach. There is a 3-pronged test: (i) Is there an exercise of real and effective activity — even a minimal one? (ii) Is the activity through stable arrangements? and (iii) Is perso
Full text
summary
Establishment: The concept of establishment must be interpreted broadly. The legal form of such establishment (e.g. branch, subsidiary etc) is not the determining factor. The formalist approach whereby organizations are considered to be established solely in the place in which they are registered is not the correct approach. There is a 3-pronged test: (i) Is there an exercise of real and effective activity — even a minimal one? (ii) Is the activity through stable arrangements? and (iii) Is personal data processed in the context of the activity? (¶41)
¶41 excerpt
In the light of all the foregoing considerations, the answer to the first to sixth questions is as follows:
excerpt
– Article 4(1)(a) of Directive 95/46 must be interpreted as permitting the application of the law on the protection of personal data of a Member State other than the Member State in which the controller with respect to the processing of those data is registered, in so far as that controller exercises, through stable arrangements in the territory of that Member State, a real and effective activity — even a minimal one — in the context of which that processing is carried out;
excerpt
– in order to ascertain, in circumstances such as those at issue in the main proceedings, whether that is the case, the referring court may, in particular, take account of the fact (i) that the activity of the controller in respect of that processing, in the context of which that processing takes place, consists of the running of property dealing websites concerning properties situated in the territory of that Member State and written in that Member State’s language and that it is, as a consequence, mainly or entirely directed at that Member State, and (ii) that that controller has a representative in that Member State, who is responsible for recovering the debts resulting from that activity and for representing the controller in the administrative and judicial proceedings relating to the processing of the data concerned;
excerpt
– by contrast, the issue of the nationality of the persons concerned by such data processing is irrelevant.
How it connects
Related across sources
Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Apr 4, 2023 Notification Obligation Data Breaches Personal Data
Guidelines 10/2020 restrictions under Article 23 GDPR Guidelines ·EDPB Oct 13, 2021 GDPR Subject-Matter and Objectives Right to Restriction Data Portability
Guidelines 04/2021 Codes of Conduct as tools for transfers Guidelines on codes of conduct and monitoring bodies Guidelines ·EDPB Feb 22, 2022 International Transfer Processing Agreement Codes of Conduct
€158,000 Garante · 487/2026 Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Art. 3, 5, 12 +7 Jul 3, 2026 Child Consent Personal Data Right to Object
Opinion 14/2026 Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR Opinion ·EDPB Apr 16, 2026 Certification Notified Body Reporting and Notification Obligations Accountability
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Art. 3, 5, 6 +2 Jul 14, 2026 Personal Data IP Address Legitimate Interest