Skip to content
Case Law · CJEU EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

CJEU Worten: Controllers must implement appropriate technical and organizational security

Original title: WORTEN-EQUIPAMENTOS PARA O LAR SA V. ACT (AUTHORITY FOR WORKING CONDITIONS), 30.5.2013 (“WORTEN”)

Judgment

security
Summary

Security: Data protection law requires controllers (not Member States) to adopt technical and organizational measures which, having regard to the state of the art and cost of their implementation, are to ensure a level of security appropriate to the risks represented. Controller must ensure that only those persons duly authorized have access. (¶¶ 24–25, 28–29)

Full text

summary
Security: Data protection law requires controllers (not Member States) to adopt technical and organizational measures which, having regard to the state of the art and cost of their implementation, are to ensure a level of security appropriate to the risks represented. Controller must ensure that only those persons duly authorized have access. (¶¶ 24–25, 28–29)
¶24 excerpt
It must be recalled that, in accordance with Article 17(1) of Directive 95/46 concerning security of processing, Member States are to provide that the controller must implement appropriate technical and organisational measures which, having regard to the state of the art and the cost of their implementation, are to ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected (see, to that effect, Rijkeboer, paragraph 62).
¶25 excerpt
It follows that, contrary to the premiss on which the second and third questions are based, Article 17(1) of Directive 95/46 does not require Member States, except where they act as controllers, to adopt those technical and organisational measures, as the obligation to adopt such measures concerns solely the controller; namely, in the present case, the employer. Article 17(1) of Directive 95/46 does, however, require the Member States to adopt a provision in their national law providing for that obligation.
¶28 excerpt
That line of argument cannot succeed. Contrary to the premiss on which it is based, the obligation for an employer, as a controller of personal data, to provide the national authority responsible for monitoring working conditions immediate access to the record of working time in no way implies that the personal data contained in that record must necessarily, on that ground alone, be made accessible to persons not authorised for that purpose. As the Portuguese government rightly pointed out, all controllers of personal data must, under Article 17(1) of Directive 95/46, implement appropriate technical and organisational measures to ensure that only those persons duly authorised to access the personal data in question are entitled to respond to a request for access from a third party.
¶29 excerpt
Accordingly, it does not appear that Article 17(1) of Directive 95/46 is relevant for the purposes of resolving the dispute in the main proceedings.

GDPR Articles Cited (1)

How it connects

AEPD: Data subject entitled to identity of professionals who accessed medical records Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of… pd-00055-2026 ·Spain ·Art. 5, 12, 15 +2 Sep 15, 2026 Personal Data Healthcare Right of Access
2020 EDPB Annual Report 2019 EDPB Annual Report 2019 1 EDPB Annual Report 2019 1 European Data Protection Board 2019 Annual Report WORKING TOGETHER FOR STRONGER RIGHTS An Executive Summary of this report,… May 18, 2020 Privacy by Design & Default Privacy by Default Supervision
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer
2024 EDPB Annual Report 2023 EDPB Annual Report 2023 1 2023 ANNUAL REPORT SAFEGUARDING INDIVIDUALS' DIGITAL RIGHTS 2 FOREWORD 4 HIGHLIGHTS 2023 6 1. THE EDPB SECRETARIAT 8 1.1. MISSION AND ACTIVITIES IN 2023… Apr 23, 2024 Privacy Shield Privacy by Design & Default Privacy by Design