Skip to content
Topic Contested in court

Access Controls

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Access management and authentication

210 linked items 9 Laws25 Case Law45 Guidance106 Enforcement10 News

Overview

24 sources · Jul 23, 2026

Legal Framework

Access controls fall under the GDPR's security obligations, primarily Article 32(1)(b) GDPR, which requires controllers and processors to implement appropriate technical and organizational measures, including the ability to ensure ongoing confidentiality, integrity, availability, and resilience. Article 5(1)(f) GDPR reinforces this by requiring appropriate security of personal data. Article 25 GDPR mandates data protection by design and by default, meaning access rights must be limited to what is strictly necessary. The AI Act further intersects with access management where biometric data is used for authentication. Recital 14 of the AI Act aligns its definition of biometric data with Article 4(14) GDPR, encompassing data enabling authentication, identification, or categorization of individuals. Recital 15 specifies that biometric identification involves automated recognition of physical, physiological, or behavioral features for establishing identity by comparison to a reference database.

Key Developments

Enforcement actions demonstrate that inadequate access controls constitute a severe security failure. The French DPA fined Free Mobile €27,000,000 after a data breach caused by insufficient technical and organizational measures. Similarly, the Romanian DPA fined Genpact Romania €10,000 following a cyber attack exploiting insufficient technical safeguards. These cases establish that access management is not merely a best practice but a core compliance requirement with substantial financial exposure.

Dutch case law clarifies the operational standards for access controls during data subject access requests. In cases involving the police and the AIVD, courts upheld searches conducted by personnel with high authorization privileges, emphasizing that the authorization level of the employee performing the search is a critical factor in assessing adequacy. In a university case, the court scrutinized the detailed search plan across multiple systems, requiring clear documentation of which systems were accessed and by whom. In a healthcare context, a court approved the creation of a temporary guest account with full access to a patient dossier for an external expert, illustrating that access controls must accommodate legitimate third-party access while maintaining oversight.

Practical Guidance

  • Implement role-based access control (RBAC): Ensure access rights are strictly limited to the data necessary for each employee's function, consistent with Article 5(1)(c) and Article 32 GDPR. The Free Mobile and Genpact fines show that broad or unmonitored access invites enforcement.
  • Verify authorization for sensitive searches: When responding to data subject access requests, assign personnel with appropriate authorization levels and document their credentials. Dutch case law confirms that the authorization level of the searcher is a key determinant of search adequacy.
  • Establish documented search protocols: Create a plan of action for data searches that specifies which systems, databases, and archives will be queried. Courts expect transparency regarding the scope and methodology of searches.
  • Manage third-party access securely: Where external parties require access to personal data (e.g., medical experts), use dedicated accounts with defined permissions and time-limited access, as demonstrated in the UMCG patient dossier case.
  • Apply heightened scrutiny to biometric authentication: Where biometric data is used for access control, ensure compliance with both GDPR Article 4(14) and AI Act Recitals 14 and 15, recognizing that biometric authentication triggers specific legal obligations regarding the processing of special category data.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 9
Art. 3(36) ‘biometric verification’ means the automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their… AI Act Art. 21(2)(i) human resources security, access control policies and asset management; NIS2 Art. 21(2)(j) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency comm… NIS2 rec 15 Recital 15 — biometric identification definition AI Act Jun 2024 rec 14 Recital 14 — biometric data definition interpretation AI Act Jun 2024 rec 54 Recital 54 — high-risk biometric AI classification AI Act Jun 2024 rec 17 Recital 17 — remote biometric identification system definition AI Act Jun 2024 rec 57 Recital 57 — data subject identification obligations GDPR Apr 2016 rec 51 Recital 51 — special categories of personal data protection GDPR Apr 2016 rec 98 Recital 98 — Promoting encryption for electronic communications security NIS2 Dec 2022 rec 89 Recital 89 — essential entities cyber hygiene and training NIS2 Dec 2022 rec 79 Recital 79 — all-hazards cybersecurity risk management measures NIS2 Dec 2022
Case Law 25
¶97 Thus, in order to assess the proportionality of a rejection of the disputed list as evidence, the referring court must examine whether its national le… Judgment of the Court (Second Chamber) of 27 September 2017.#Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy.#Request for a preliminary ruling from the Najvyšší súd Slovenskej republiky.#Reference for a preliminary ruling — Charter of Fundamental Rights of the European Union — Articles 7, 8 and 47 — Directive 95/46/EC — Articles 1, 7 and 13 — Processing of personal data — Article 4(3) TEU — Drawing up of a list of personal data — Subject matter — Ta ¶6 Costs (Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – … Meta Platforms v noyb ¶27 In the second place, when the applicant signed in to the Commission’s user authentication service, EU Login, on 30 March 2022, using his Facebook acco… Judgment of the General Court (Sixth Chamber, Extended Composition) of 8 January 2025.#Thomas Bindl v European Commission.#Processing of personal data – Protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies – Regulation (EU) 2018/1725 – Concept of ‘transfer of personal data to a third country’ – Transfer of data when visiting a website – EU Login – Action for annulment – Act not open to challenge – Inadmissibility – A ¶165 The applicant claims that, on 30 March 2022, when he registered for the ‘GoGreen’ event available on the CFE website, his IP address and information a… Judgment of the General Court (Sixth Chamber, Extended Composition) of 8 January 2025.#Thomas Bindl v European Commission.#Processing of personal data – Protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies – Regulation (EU) 2018/1725 – Concept of ‘transfer of personal data to a third country’ – Transfer of data when visiting a website – EU Login – Action for annulment – Act not open to challenge – Inadmissibility – A 203/22 Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor Court of Justice of the European Union Feb 2025 252/21 Meta Platforms v noyb CJEU Jan 2023 670/22 Judgment of the Court (Grand Chamber) of 30 April 2024.#Criminal proceedings against M.N.#Request for a preliminary ruling from the Landgericht Berlin.#Reference for a preliminary ruling – Judicial cooperation in criminal matters – Directive 2014/41/EU – European Investigation Order (EIO) in criminal matters – Obtaining of evidence already in the possession of the competent authorities of the executing State – Conditions for issuing an EIO – Encrypted telecommunications service – EncroChat – Nee Court of Justice of the European Union Apr 2024 349/21 Judgment of the Court (Third Chamber) of 16 February 2023.#HYA and Othersprokuratura.#Request for a preliminary ruling from the Spetsializiran nakazatelen sad.#Reference for a preliminary ruling – Telecommunications sector – Processing of personal data and the protection of privacy – Directive 2002/58 – Article 15(1) – Restriction of the confidentiality of electronic communications – Judicial decision authorising the interception, recording and storage of telephone conversations of persons suspe Court of Justice of the European Union Feb 2023 GDPRhub CJEU - C‑178/22 - Procura della Repubblica presso il Tribunale di Bolzano GDPRhub Apr 2024 229/23 Judgment of the Court (Tenth Chamber) of 13 June 2024.#Criminal proceedings against HYA and Others.#Request for a preliminary ruling from the Sofiyski gradski sad.#Reference for a preliminary ruling – Telecommunications sector – Processing of personal data and the protection of privacy – Directive 2002/58/EC – Article 15(1) – Restriction of the confidentiality of electronic communications – Judicial decision authorising listening, tapping and storage in respect of telephone conversations of pers Court of Justice of the European Union Jun 2024 768/21 Judgment of the Court (First Chamber) of 26 September 2024.#TR v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(a) and (f) – Tasks of the supervisory authority – Article 58(2) – Corrective powers – Administrative fine – Discretion of the supervisory authority – Limits.#Case C-768/21. Court of Justice of the European Union Sep 2024 102/20 Judgment of the Court (Third Chamber) of 25 November 2021.#StWL Städtische Werke Lauf a.d. Pegnitz GmbH v eprimo GmbH.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Directive 2002/58/EC – Processing of personal data and the protection of privacy in the electronic communications sector – Article 2(h) – Concept of ‘electronic mail’ – Article 13(1) – Concept of ‘use of … electronic mail for the purposes of direct marketing’ – Directive 2005/29/EC Court of Justice of the European Union Nov 2021 Administrative Court Düsseldorf VG Düsseldorf - 29 K 3490/24 Administrative Court Düsseldorf Jun 2026 District Court Rotterdam Rotterdam Court: DPA did not err in finding ING contactless chip payments GDPR-compliant District Court Rotterdam Jun 2026 Supreme Administrative Court French Supreme Admin Court partly upholds challenge to graduated response IP data decree Supreme Administrative Court Apr 2026 CJEU PARLIAMENT V. COUNCIL (PNR) CJEU May 2006 Council of State Council of State upholds €600,000 DPA fine against Enschede for Wi-Fi tracking Council of State Jul 2026 Social Court Nuremberg SG Nürnberg - S 5 SF 65/24 DS Social Court Nuremberg Jun 2026 Court of Appeal Amsterdam Amsterdam Court of Appeal: Controller may reject watermarked ID copy for verification Court of Appeal Amsterdam Apr 2024 National Court Audiencia Nacional upholds €2M AEPD fine against Amazon Flex for criminal-record checks National Court Jul 2026 Federal Administrative Court BVwG - W292 2270002-1 Federal Administrative Court Jul 2023 101/01 CJEU - C-101/01 - Lindqvist GDPRhub Nov 2003 318/24 GC - T-318/24 Gereral Court Dec 2025 Administrative Court Stuttgart VG Stuttgart - 1 K 12737/25 Administrative Court Stuttgart Jul 2026 Show 5 more →
Guidance 45
§49 Advisable measures: (The list of the following measures is by no means exclusive or comprehensive. Rather, the goal is to provide prevention ideas and… Guidelines 01/2021 §51 The security of the data controller's environment is extremely important, as the majority of these breaches can be prevented by ensuring that all syst… Guidelines 01/2021 §62 Also, it is strongly advisable to communicate a breach involving passwords to data subjects in any case even when the passwords were stored using a sa… Guidelines 01/2021 §67 The controller's measures mentioned in the case description are adequate. In the wake of the breach it also corrected the vulnerability of the website… Guidelines 01/2021 guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 guidelines on processing of personal data through video devices Guidelines 3/2019 on processing of personal data through video devices EDPB Jan 2020 guidelines on technical scope of art 53 of eprivacy directive Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive EDPB Oct 2024 guidelines on the use of facial recognition technology in the area of law enforcement Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement EDPB May 2023 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 on processing of personal data through blockchain technologies Guidelines on processing of personal data through blockchain technologies EDPB Jul 2026 guidelines on virtual voice assistants Guidelines 02/2021 on virtual voice assistants EDPB Jul 2021 012020 on processing personal data in the context of connected Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Mar 2021 042020 on the use of location data and contact tracing tools in the Guidelines 04/2020 on the use of location data and contact tracing tools in the context of the COVID-19 outbreak EDPB Apr 2020 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 22020 on articles 46 2 a and 46 3 b of regulation 2016679 for Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies EDPB Dec 2020 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 032020 on the processing of data concerning health for the purpose Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak EDPB Apr 2020 guidelines on processing personal data in the context of connected vehicles and mobility rel Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Jan 2020 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 052021 on the interplay between the application of article 3 and the Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR EDPB Feb 2023 132019 on the draft list of the competent supervisory Opinion 13/2019 on the draft list of the competent supervisory authority of France regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR) EDPB Jul 2019 012021 on the adequacy referential under the law Recommendations 01/2021 on the adequacy referential under the Law Enforcement Directive EDPB Feb 2021 022020 on the european essential guarantees for Recommendations 02/2020 on the European Essential Guarantees for surveillance measures EDPB Nov 2020 Show 25 more →
Enforcement 106
Tietosuojavaltuutetun toimisto (Finland) Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 Tietosuojavaltuutetun toimisto (Finland) Jul 2026 VDAI (Lithuania) VDAI (Lithuania) - 3R-1143 VDAI (Lithuania) Jun 2026 ANSPDCP (Romania) ANSPDCP (Romania) - Fine against Homelux SRL ANSPDCP (Romania) Aug 2026 ANSPDCP (Romania) ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026 ANSPDCP (Romania) Jul 2026 French Data Protection Authority (CNIL) ONVOLDRAAGLIJK: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. French Data Protection Authority (CNIL) Jan 2026 NL Garante per la protezione dei dati personali (Italy) Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful Garante per la protezione dei dati personali (Italy) May 2026 French Data Protection Authority (CNIL) FREE MOBILE: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. French Data Protection Authority (CNIL) Jan 2026 NL French Data Protection Authority (CNIL) FREE: Insufficient technical and organisational measures to ensure information security French Data Protection Authority (CNIL) Jan 2026 French Data Protection Authority (CNIL) FREE MOBILE: Insufficient technical and organisational measures to ensure information security French Data Protection Authority (CNIL) Jan 2026 Data Protection Authority of Ireland Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland May 2026 AEPD (Spain) AEPD (Spain) - EXP202306354 (PS/00312/2024) AEPD (Spain) Feb 2026 Persónuvernd (Island) Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive Persónuvernd (Island) Jul 2026 AEPD (Spain) AEPD: No fine for surveillance cameras facing public road; no evidence of rights AEPD (Spain) Jul 2026 AEPD (Spain) AEPD (Spain) - E/03783/2020 AEPD (Spain) Jul 2026 HDPA (Greece) HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens HDPA (Greece) May 2026 HDPA (Greece) HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers HDPA (Greece) Jun 2026 AEPD (Spain) AEPD (Spain) - PS/00421/2020 AEPD (Spain) Jul 2026 Garante per la protezione dei dati personali (Italy) Garante: Piaggio violated GDPR by accessing former employees' emails in disciplinary probe Garante per la protezione dei dati personali (Italy) Jun 2026 AEPD (Spain) AEPD sanctions 23andMe for security failures in credential-stuffing breach AEPD (Spain) Oct 2025 Garante per la protezione dei dati personali (Italy) Italian DPA fines butcher €1,500 for unlawful video surveillance lacking information signs Garante per la protezione dei dati personali (Italy) Jan 2026 Show 86 more →
News 10
noyb - European Center for Digital Rights Data brokers: Identification possible to sell ads, not to exercise fundamental rights noyb - European Center for Digital Rights Feb 2023 AEPD AEPD publishes GDPR Risk Assessment AEPD Oct 2022 AEPD De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming). AEPD Oct 2022 NL EDPS Het EDPB en het EDPS: Het voorstel om online seksueel misbruik van kinderen te bestrijden, brengt serieuze risico's met zich mee voor fundamentele rechten. EDPS Jul 2022 NL noyb - European Center for Digital Rights Want your Grindr data? Show your ID and take a selfie! noyb - European Center for Digital Rights Nov 2021 noyb - European Center for Digital Rights Three GDPR Complaints filed against Grindr, Twitter and the AdTech companies Smaato, OpenX, AdColony and AT&T’s AppNexus noyb - European Center for Digital Rights Jan 2020 EDPS Gezamenlijk document van de AEPD en de EDPS: 10 misverstanden over machine learning. EDPS Sep 2022 NL GDPRhub De Deense toezichthouder (SA) heeft een boete van ongeveer 67.000 euro opgelegd aan een advocatenkantoor dat getroffen was door ransomware, vanwege ontoereikende beveiligingsmaatregelen. GDPRhub Oct 2022 NL noyb - European Center for Digital Rights NCC & noyb GDPR complaint: "Grindr" fined € 6.3 Mio over illegal data sharing noyb - European Center for Digital Rights Dec 2021 noyb - European Center for Digital Rights Gay Dating App "Grindr" to be fined almost € 10 Mio noyb - European Center for Digital Rights Jan 2021
Literature 15
Journal Scientific and Applied Research HOW GDPR TREATS AUTOMATED DECISION-MAKING Journal Scientific and Applied Research Nov 2025 Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza Dec 2023 Innovative STEM Education GDPR - General Data Protection Regulation on Sites Requiring Accessibility Innovative STEM Education Jun 2021 IJARCCE Challenges of Cloud Data Privacy in Surveillance: Legal, Technical, and Ethical Implications IJARCCE Jul 2026 Cookies, privacidade e proteção de dados Apr 2026 Awang Long Law Review PROTECTION OF DATA SUBJECT RIGHTS IN THE TRANSFER OF PERSONAL DATA BETWEEN DATA CONTROLLERS IN INDONESIA: A COMPARATIVE ANALYSIS OF THE PDP LAW AND THE EU GDPR Awang Long Law Review Jan 2026 Journal of Computer Science and Technology Studies Event-Driven Compliance: Reconciling Privacy Regulation with Real-Time Advertising Infrastructure Journal of Computer Science and Technology Studies Nov 2025 Athens Journal of Law Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation” Athens Journal of Law Jan 2025 Journal of Information Technology Building data management capabilities to address data protection regulations: Learnings from EU-GDPR Journal of Information Technology Jan 2023 European Journal of Risk Regulation The Court of Justice on the Excessiveness of Access Requests under the GDPR European Journal of Risk Regulation Jul 2026 Requirements Engineering Understanding the GDPR from a requirements engineering perspective—a systematic mapping study on regulatory data protection requirements Requirements Engineering Jul 2024 Electronics Comparative Analysis of Passkeys (FIDO2 Authentication) on Android and iOS for GDPR Compliance in Biometric Data Protection Electronics Oct 2025 International Journal of Latest Technology in Engineering Management & Applied Science The Right to Be Forgotten in The Context of Mobile Number Recycling International Journal of Latest Technology in Engineering Management & Applied Science Sep 2025 Law and Economy Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects Law and Economy Feb 2026 International Journal of Law and Societal Studies Balancing Security and Privacy: Analyzing the Effectiveness of EU Digital Surveillance Laws in Criminal Proceedings International Journal of Law and Societal Studies Sep 2025