Case Law · CJEU EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
CJEU Worten: Controllers must implement appropriate technical and organizational security
Original title: WORTEN-EQUIPAMENTOS PARA O LAR SA V. ACT (AUTHORITY FOR WORKING CONDITIONS), 30.5.2013 (“WORTEN”)
Judgment
Summary
Security: Data protection law requires controllers (not Member States) to adopt technical and organizational measures which, having regard to the state of the art and cost of their implementation, are to ensure a level of security appropriate to the risks represented. Controller must ensure that only those persons duly authorized have access. (¶¶ 24–25, 28–29)
Full text
summary
Security: Data protection law requires controllers (not Member States) to adopt technical and organizational measures which, having regard to the state of the art and cost of their implementation, are to ensure a level of security appropriate to the risks represented. Controller must ensure that only those persons duly authorized have access. (¶¶ 24–25, 28–29)
¶24 excerpt
It must be recalled that, in accordance with Article 17(1) of Directive 95/46 concerning security of processing, Member States are to provide that the controller must implement appropriate technical and organisational measures which, having regard to the state of the art and the cost of their implementation, are to ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected (see, to that effect, Rijkeboer, paragraph 62).
¶25 excerpt
It follows that, contrary to the premiss on which the second and third questions are based, Article 17(1) of Directive 95/46 does not require Member States, except where they act as controllers, to adopt those technical and organisational measures, as the obligation to adopt such measures concerns solely the controller; namely, in the present case, the employer. Article 17(1) of Directive 95/46 does, however, require the Member States to adopt a provision in their national law providing for that obligation.
¶28 excerpt
That line of argument cannot succeed. Contrary to the premiss on which it is based, the obligation for an employer, as a controller of personal data, to provide the national authority responsible for monitoring working conditions immediate access to the record of working time in no way implies that the personal data contained in that record must necessarily, on that ground alone, be made accessible to persons not authorised for that purpose. As the Portuguese government rightly pointed out, all controllers of personal data must, under Article 17(1) of Directive 95/46, implement appropriate technical and organisational measures to ensure that only those persons duly authorised to access the personal data in question are entitled to respond to a request for access from a third party.
¶29 excerpt
Accordingly, it does not appear that Article 17(1) of Directive 95/46 is relevant for the purposes of resolving the dispute in the main proceedings.
How it connects
Related across sources
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design
AEPD: Data subject entitled to identity of professionals who accessed medical records Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of… pd-00055-2026 ·Spain ·Art. 5, 12, 15 +2 Sep 15, 2026 Personal Data Healthcare Right of Access
2020 EDPB Annual Report 2019 EDPB Annual Report 2019 1 EDPB Annual Report 2019 1 European Data Protection Board 2019 Annual Report WORKING TOGETHER FOR STRONGER RIGHTS An Executive Summary of this report,… May 18, 2020 Privacy by Design & Default Privacy by Default Supervision
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer
Opinion 04/2021 EDPB-EDPS Joint Opinion 04/2021 on the Proposal for a Regulation of the European Parliament and of the Council on a framework for the issuance, verification and acceptance of interoperable certificates on vaccination, testing and recovery Opinion Mar 31, 2021 Personal Data Privacy by Design & Default Accountability
2024 EDPB Annual Report 2023 EDPB Annual Report 2023 1 2023 ANNUAL REPORT SAFEGUARDING INDIVIDUALS' DIGITAL RIGHTS 2 FOREWORD 4 HIGHLIGHTS 2023 6 1. THE EDPB SECRETARIAT 8 1.1. MISSION AND ACTIVITIES IN 2023… Apr 23, 2024 Privacy Shield Privacy by Design & Default Privacy by Design