Case Law · CJEU EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Lindqvist (CJEU): Publishing personal data on internet is not a transfer to third
Original title: LINDQUIST, 6.11.2003 (“LINDQUIST”)
Judgment
Summary
Transfers to third countries: The publication on the internet does not constitute a transfer, as an internet user would have to connect to the internet and personally carry out the necessary actions to consult those pages where: (i) the internet pages did not contain the technical means to send that information automatically to people who did not intentionally seek access; and, (ii) the internet page is stored with his/her hosting provider in that or another Member State. (¶¶ 60–61, 68, 70)
Full text
summary
Transfers to third countries: The publication on the internet does not constitute a transfer, as an internet user would have to connect to the internet and personally carry out the necessary actions to consult those pages where: (i) the internet pages did not contain the technical means to send that information automatically to people who did not intentionally seek access; and, (ii) the internet page is stored with his/her hosting provider in that or another Member State. (¶¶ 60–61, 68, 70)
¶60 excerpt
It appears from the court file that, in order to obtain the information appearing on the internet pages on which Mrs Lindqvist had included information about her colleagues, an internet user would not only have to connect to the internet but also personally carry out the necessary actions to consult those pages. In other words, Mrs Lindqvist's internet pages did not contain the technical means to send that information automatically to people who did not intentionally seek access to those pages.
¶61 excerpt
It follows that, in circumstances such as those in the case in the main proceedings, personal data which appear on the computer of a person in a third country, coming from a person who has loaded them onto an internet site, were not directly transferred between those two people but through the computer infrastructure of the hosting provider where the page is stored.
¶68 excerpt
Given, first, the state of development of the internet at the time Directive 95/46 was drawn up and, second, the absence, in Chapter IV, of criteria applicable to use of the internet, one cannot presume that the Community legislature intended the expression transfer [of data] to a third country to cover the loading, by an individual in Mrs Lindqvist's position, of data onto an internet page, even if those data are thereby made accessible to persons in third countries with the technical means to access them.
¶70 excerpt
Accordingly, it must be concluded that Article 25 of Directive 95/46 is to be interpreted as meaning that operations such as those carried out by Mrs Lindqvist do not as such constitute a 'transfer [of data] to a third country'. It is thus unnecessary to investigate whether an individual from a third country has accessed the internet page concerned or whether the server of that hosting service is physically in a third country.
How it connects
Related across sources
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design
Guidelines 06/2020 interplay of the Second Payment Services Directive and the GDPR Guidelines on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR Guidelines ·EDPB Dec 15, 2020 International Transfer GDPR Article 5 Principles of Processing Personal Data
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer
Guidelines 10/2020 restrictions under Article 23 GDPR Guidelines ·EDPB Oct 13, 2021 GDPR Subject-Matter and Objectives Right to Restriction Data Portability
2025 hier EDPB 17 jan 2025, Guidelines 01/2025 on Pseudonymisation ➡️ Geef uw mening over deze concept richtsnoeren hier. Deadline : 28 februari 2025. De EDPB werkt ook nog aan Richtsnoeren… EDPB Jan 21, 2025 Pseudonymization Anonymization Security
Guidelines 03/2022 Deceptive design patterns in social media platform interfaces: how to recognise and avoid them Guidelines ·EDPB Feb 24, 2023 Privacy by Design & Default Privacy by Design Privacy by Default