# Access Controls — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/access-controls
> Sources are cited per item. Verify against the official texts before relying on them.

Access management and authentication

## Overview

## Legal Framework
Access controls fall under the GDPR's security obligations, primarily Article 32(1)(b) GDPR, which requires controllers and processors to implement appropriate technical and organizational measures, including the ability to ensure ongoing confidentiality, integrity, availability, and resilience. Article 5(1)(f) GDPR reinforces this by requiring appropriate security of personal data. Article 25 GDPR mandates data protection by design and by default, meaning access rights must be limited to what is strictly necessary. The AI Act further intersects with access management where biometric data is used for authentication. Recital 14 of the AI Act aligns its definition of biometric data with Article 4(14) GDPR, encompassing data enabling authentication, identification, or categorization of individuals. Recital 15 specifies that biometric identification involves automated recognition of physical, physiological, or behavioral features for establishing identity by comparison to a reference database.

## Key Developments
Enforcement actions demonstrate that inadequate access controls constitute a severe security failure. The French DPA fined Free Mobile €27,000,000 after a data breach caused by insufficient technical and organizational measures. Similarly, the Romanian DPA fined Genpact Romania €10,000 following a cyber attack exploiting insufficient technical safeguards. These cases establish that access management is not merely a best practice but a core compliance requirement with substantial financial exposure.

Dutch case law clarifies the operational standards for access controls during data subject access requests. In cases involving the police and the AIVD, courts upheld searches conducted by personnel with high authorization privileges, emphasizing that the authorization level of the employee performing the search is a critical factor in assessing adequacy. In a university case, the court scrutinized the detailed search plan across multiple systems, requiring clear documentation of which systems were accessed and by whom. In a healthcare context, a court approved the creation of a temporary guest account with full access to a patient dossier for an external expert, illustrating that access controls must accommodate legitimate third-party access while maintaining oversight.

## Practical Guidance
- **Implement role-based access control (RBAC)**: Ensure access rights are strictly limited to the data necessary for each employee's function, consistent with Article 5(1)(c) and Article 32 GDPR. The Free Mobile and Genpact fines show that broad or unmonitored access invites enforcement.
- **Verify authorization for sensitive searches**: When responding to data subject access requests, assign personnel with appropriate authorization levels and document their credentials. Dutch case law confirms that the authorization level of the searcher is a key determinant of search adequacy.
- **Establish documented search protocols**: Create a plan of action for data searches that specifies which systems, databases, and archives will be queried. Courts expect transparency regarding the scope and methodology of searches.
- **Manage third-party access securely**: Where external parties require access to personal data (e.g., medical experts), use dedicated accounts with defined permissions and time-limited access, as demonstrated in the UMCG patient dossier case.
- **Apply heightened scrutiny to biometric authentication**: Where biometric data is used for access control, ensure compliance with both GDPR Article 4(14) and AI Act Recitals 14 and 15, recognizing that biometric authentication triggers specific legal obligations regarding the processing of special category data.

## Legislation (full text of key provisions)

### Recital 15 — biometric identification definition

*Source: AI Act, aiact-rec-15-en, 2024-06-12 — https://overview.legal/posts/93712*

The notion of ‘biometric identification’ referred to in this Regulation should be defined as the automated recognition of physical, physiological and behavioural human features such as the face, eye movement, body shape, voice, prosody, gait, posture, heart rate, blood pressure, odour, keystrokes characteristics, for the purpose of establishing an individual’s identity by comparing biometric data of that individual to stored biometric data of individuals in a reference database, irrespective of whether the individual has given its consent or not. This excludes AI systems intended to be used for biometric verification, which includes authentication, whose sole purpose is to confirm that a specific natural person is the person he or she claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having security access to premises.

### Recital 14 — biometric data definition interpretation

*Source: AI Act, aiact-rec-14-en, 2024-06-12 — https://overview.legal/posts/93710*

The notion of ‘biometric data’ used in this Regulation should be interpreted in light of the notion of biometric data as defined in Article 4, point (14) of Regulation (EU) 2016/679, Article 3, point (18) of Regulation (EU) 2018/1725 and Article 3, point (13) of Directive (EU) 2016/680. Biometric data can allow for the authentication, identification or categorisation of natural persons and for the recognition of emotions of natural persons.

### Recital 54 — high-risk biometric AI classification

*Source: AI Act, aiact-rec-54-en, 2024-06-12 — https://overview.legal/posts/93790*

As biometric data constitutes a special category of personal data, it is appropriate to classify as high-risk several critical-use cases of biometric systems, insofar as their use is permitted under relevant Union and national law. Technical inaccuracies of AI systems intended for the remote biometric identification of natural persons can lead to biased results and entail discriminatory effects. The risk of such biased results and discriminatory effects is particularly relevant with regard to age, ethnicity, race, sex or disabilities. Remote biometric identification systems should therefore be classified as high-risk in view of the risks that they pose. Such a classification excludes AI systems intended to be used for biometric verification, including authentication, the sole purpose of which is to confirm that a specific natural person is who that person claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having secure access to premises. In addition, AI systems intended to be used for biometric categorisation according to sensitive attributes or characteristics protected under Article 9(1) of Regulation (EU) 2016/679 on the basis of biometric data, in so far as these are not prohibited under this Regulation, and emotion recognition systems that are not prohibited under this Regulation, should be classified as high-risk. Biometric systems which are intended to be used solely for the purpose of enabling cybersecurity and personal data protection measures should not be considered to be high-risk AI systems.

### Recital 17 — remote biometric identification system definition

*Source: AI Act, aiact-rec-17-en, 2024-06-12 — https://overview.legal/posts/93716*

The notion of ‘remote biometric identification system’ referred to in this Regulation should be defined functionally, as an AI system intended for the identification of natural persons without their active involvement, typically at a distance, through the comparison of a person’s biometric data with the biometric data contained in a reference database, irrespectively of the particular technology, processes or types of biometric data used. Such remote biometric identification systems are typically used to perceive multiple persons or their behaviour simultaneously in order to facilitate significantly the identification of natural persons without their active involvement. This excludes AI systems intended to be used for biometric verification, which includes authentication, the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having security access to premises. That exclusion is justified by the fact that such systems are likely to have a minor impact on fundamental rights of natural persons compared to the remote biometric identification systems which may be used for the processing of the biometric data of a large number of persons without their active involvement. In the case of ‘real-time’ systems, the capturing of the biometric data, the comparison and the identification occur all instantaneously, near-instantaneously or in any event without a significant delay. In this regard, there should be no scope for circumventing the rules of this Regulation on the ‘real-time’ use of the AI systems concerned by providing for minor delays. ‘Real-time’ systems involve the use of ‘live’ or ‘near-live’ material, such as video footage, generated by a camera or other device with similar functionality. In the case of ‘post’ systems, in contrast, the biometric data has already been captured and the comparison and identification occur only after a significant delay. This involves material, such as pictures or video footage generated by closed circuit television cameras or private devices, which has been generated before the use of the system in respect of the natural persons concerned.

### Recital 57 — data subject identification obligations

*Source: GDPR, gdpr-rec-57-en, 2016-04-27 — https://overview.legal/posts/91629*

If the personal data processed by a controller do not permit the controller to identify a natural person, the data controller should not be obliged to acquire additional information in order to identify the data subject for the sole purpose of complying with any provision of this Regulation. However, the controller should not refuse to take additional information provided by the data subject in order to support the exercise of his or her rights. Identification should include the digital identification of a data subject, for example through authentication mechanism such as the same credentials, used by the data subject to log-in to the on-line service offered by the data controller.

### Recital 51 — special categories of personal data protection

*Source: GDPR, gdpr-rec-51-en, 2016-04-27 — https://overview.legal/posts/91617*

Personal data which are, by their nature, particularly sensitive in relation to fundamental rights and freedoms merit specific protection as the context of their processing could create significant risks to the fundamental rights and freedoms. Those personal data should include personal data revealing racial or ethnic origin, whereby the use of the term ‘racial origin’ in this Regulation does not imply an acceptance by the Union of theories which attempt to determine the existence of separate human races. The processing of photographs should not systematically be considered to be processing of special categories of personal data as they are covered by the definition of biometric data only when processed through a specific technical means allowing the unique identification or authentication of a natural person. Such personal data should not be processed, unless processing is allowed in specific cases set out in this Regulation, taking into account that Member States law may lay down specific provisions on data protection in order to adapt the application of the rules of this Regulation for compliance with a legal obligation or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. In addition to the specific requirements for such processing, the general principles and other rules of this Regulation should apply, in particular as regards the conditions for lawful processing. Derogations from the general prohibition for processing such special categories of personal data should be explicitly provided, inter alia, where the data subject gives his or her explicit consent or in respect of specific needs in particular where the processing is carried out in the course of legitimate activities by certain associations or foundations the purpose of which is to permit the exercise of fundamental freedoms.

### Recital 98 — Promoting encryption for electronic communications security

*Source: NIS2, nis2-rec-98-en, 2022-12-14 — https://overview.legal/posts/96724*

In order to safeguard the security of public electronic communications networks and publicly available electronic communications services, the use of encryption technologies, in particular end-to-end encryption as well as data-centric security concepts, such as cartography, segmentation, tagging, access policy and access management, and automated access decisions, should be promoted. Where necessary, the use of encryption, in particular end-to-end encryption should be mandatory for providers of public electronic communications networks or of publicly available electronic communications services in accordance with the principles of security and privacy by default and by design for the purposes of this Directive. The use of end-to-end encryption should be reconciled with the Member States’ powers to ensure the protection of their essential security interests and public security, and to allow for the prevention, investigation, detection and prosecution of criminal offences in accordance with Union law. However, this should not weaken end-to-end encryption, which is a critical technology for the effective protection of data and privacy and the security of communications.

### Recital 89 — essential entities cyber hygiene and training

*Source: NIS2, nis2-rec-89-en, 2022-12-14 — https://overview.legal/posts/96706*

Essential and important entities should adopt a wide range of basic cyber hygiene practices, such as zero-trust principles, software updates, device configuration, network segmentation, identity and access management or user awareness, organise training for their staff and raise awareness concerning cyber threats, phishing or social engineering techniques. Furthermore, those entities should evaluate their own cybersecurity capabilities and, where appropriate, pursue the integration of cybersecurity enhancing technologies, such as artificial intelligence or machine-learning systems to enhance their capabilities and the security of network and information systems.

### Recital 79 — all-hazards cybersecurity risk management measures

*Source: NIS2, nis2-rec-79-en, 2022-12-14 — https://overview.legal/posts/96686*

As threats to the security of network and information systems can have different origins, cybersecurity risk-management measures should be based on an all-hazards approach, which aims to protect network and information systems and the physical environment of those systems from events such as theft, fire, flood, telecommunication or power failures, or unauthorised physical access and damage to, and interference with, an essential or important entity’s information and information processing facilities, which could compromise the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems. The cybersecurity risk-management measures should therefore also address the physical and environmental security of network and information systems by including measures to protect such systems from system failures, human error, malicious acts or natural phenomena, in line with European and international standards, such as those included in the ISO/IEC 27000 series. In that regard, essential and important entities should, as part of their cybersecurity risk-management measures, also address human resources security and have in place appropriate access control policies. Those measures should be consistent with Directive (EU) 2022/2557.

## Case law

### Council of State upholds €600,000 DPA fine against Enschede for Wi-Fi tracking

*Source: Council of State, 2026-07-29 — https://overview.legal/posts/184682 — original: https://gdprhub.eu/index.php?title=RVS_-_202401622/1/A3*

Facts — The Municipal Executive Board of Enschede, the controller, decided to conduct continuous pedestrian counts to obtain information about visitor numbers in the city centre. From 25 May 2018, at least ten sensors captured the Media Access Control (hereinafter, MAC) addresses of devices with Wi-Fi enabled. When a sensor detected a MAC address, it was temporarily stored and converted into a pseudonymised MAC address using an algorithm. Since all sensors used the same algorithm, the same device received the same pseudonymised identifier across different locations. The resulting data included the sensor that detected the device and the date and time of detection. After several filters were applied, the data was retained for up to six months and used to estimate the number of unique visitors. The controller discontinued the pedestrian-counting system on 1 May 2020. Following an enforcement request, the Autoriteit Persoonsgegevens, the DPA, investigated the processing. It considered that the combination of pseudonymised MAC addresses and location data related to identifiable natural persons. According to the DPA, the data allowed individuals to be distinguished and could reveal lifestyle and behavioural patterns. It also identified three methods through which the controller could potentially determine the identity of device users. On 11 March 2021, the DPA imposed a fine of €600,000 on the controller for processing personal data without a legal basis between 25 May 2018 and 30 April 2020. It considered the controller responsible for determining the purposes and means of the processing and found that no legal basis under Article 6 GDPR had been established. The controller challenged the decision before the District Court of Overijssel. The Court held that the DPA had not sufficiently proven that the information processed by the controller constituted personal data. In particular, the DPA had relied on assumptions regarding the possibility of identifying device users without sufficiently investigating whether those identification methods were realistically available. The Court held that, under Recital 26 GDPR, the DPA should have assessed whether the means allegedly available to identify the individuals were reasonably likely to be used, taking into account the costs, time, available technology and technological developments. It therefore annulled the decision on the objection and revoked the original fine. The DPA appealed the judgment before the Council of State (Appeal Court). Holding — The Appeal Court dismissed the DPA’s appeal and upheld the annulment of the €600,000 fine. The Appeal Court noted that the DPA did not challenge the Court’s finding that it had failed to sufficiently investigate and substantiate the three methods through which the controller could allegedly identify individual device users. During the appeal hearing, the DPA also acknowledged that the applicable standard of proof had not been met regarding those methods. Instead, the DPA argued that natural persons had already been directly identified because the combination of MAC addresses and location data allowed the controller to distinguish and count unique visitors. According to the DPA, the ability to single out unique visitors was itself sufficient for the information to qualify as personal data under Article 4(1) GDPR, irrespective of whether the controller could determine their civil identity. However, the Appeal Court held that the DPA had not relied on this reasoning in its original decision or in its decision on the controller’s objection. In proceedings concerning an administrative fine, the DPA must conclusively establish and substantiate the alleged infringement before completing the administrative decision-making process. This requirement safeguards legal certainty and allows the alleged infringer to defend itself effectively and in a timely manner. The DPA could not wait until the judicial appeal stage to introduce a new argument explaining why the processing concerned personal data and why a punishable infringement had occurred. The Court had therefore not erred by refusing to assess this new argument. Since the DPA had not otherwise challenged the substance of the Court’s finding that the original infringement had not been sufficiently proven, the annulment of the fine remained in effect. The Appeal Court did not determine whether the pseudonymised MAC addresses and location data were, as such, personal data under the GDPR.

### SG Nürnberg - S 5 SF 65/24 DS

*Source: Social Court Nuremberg, 2026-06-10 — https://overview.legal/posts/122874 — original: https://gdprhub.eu/index.php?title=SG_Nürnberg_-_S_5_SF_65/24_DS*

Facts — The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network. On 16 June 2023, the processor informed the controller about the incident. On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents. On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant. Holding — The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles: First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities. Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded. Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take. Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.

### Amsterdam Court of Appeal: Controller may reject watermarked ID copy for verification

*Source: Court of Appeal Amsterdam, 2024-04-30 — https://overview.legal/posts/125642 — original: https://gdprhub.eu/index.php?title=GHAMS_-_200.324.736/01*

Facts — The data subject had a business credit card issued by the controller. In 2021, the controller asked the data subject to identify themselves online by taking a picture of the ID and then taking a selfie of themselves. The data subject wanted to upload a copy of the ID with a watermark on it for fraud prevention purposes (saying, for example: “copy for [the controller]”). The controller, on the other hand, rejected this copy, arguing that the data subject should upload a copy without any writing on it. Therefore, the data subject brought legal proceedings before the District Court of Amsterdam (Rechtbank Amsterdam - Rb. Amsterdam), seeking the court to declare that the controller cannot request an ID copy without the watermark and that the controller should not block the credit card. On 20 April 2022, the District Court of Amsterdam dismissed the data subject’s request. The data subject appealed the decision before the Court of Appeal of Amsterdam (Gerechtshof Amsterdam - GHAMS). They argued that the provisions of the Money Laundering and Terrorist Financing Prevention Act (Wet ter voorkoming van witwassen en financieren van terrorisme – Wwft) do not require that the identification process is performed in the way envisaged by the controller. Therefore, the legal basis provided for by Article 6(1)(c) GDPR cannot be used, since there is no legal obligation to require this kind of identification. Moreover, they argued that the controller should not store the copy of the ID. The controller pointed out that the electronic technique used in the scanning of the ID has currently the highest reliability in the field of authentication and that the use of this technique enables it to recognize high value forgeries of IDs better than with the use of persons trained and educated for this purpose. Holding — First of all, the court noted that the Wwft does not prescribe a way in which the identification should be conducted. Moreover, it pointed out that neither the GDPR nor the Wwft confer the data subject a right to a non-online identification. Secondly, the court noted that Article 13(1)(a) Directive 2015/849 allows the controller to perform the identification through electronic means. Thirdly, the court agreed with the controller’s argument. It held that, since there is an added value in using this ID scanning tool, this use may be considered necessary within the meaning of Article 6(1)(c) GDPR in order to comply with its obligation to conduct a customer due diligence under the Wwft. The court pointed out that, due to the large amount of customers, the controller has a legitimate interest in organizing the identification and verification procedure as uniformly as possible. Fourthly, as for the retention issue, the court noted that the controller is obliged to keep a copy of the proof of identity whose authenticity it has verified by means of the scan pursuant to Article 33(1) Wwft. However, the court highlighted that the controller is obliged to store this data securely. Therefore, the court dismissed the appeal and upheld the judgement of the District Court of Amsterdam.

### Audiencia Nacional upholds €2M AEPD fine against Amazon Flex for criminal-record checks

*Source: National Court, 2026-07-08 — https://overview.legal/posts/184679 — original: https://gdprhub.eu/index.php?title=AN_-_SAN_2996/2026*

Facts — Unión General de Trabajadores (UGT), a trade union, lodged a complaint with the DPA (AEPD) against Amazon Road Transport Spain, S.L., the controller. Applicants wishing to work within the Amazon Flex delivery programme were required to provide a certificate confirming that they had no criminal record. The certificates and other application documents were processed by external processors responsible for the preliminary screening of candidates. The controller considered this requirement necessary to protect its customers and ensure the security of the programme. Delivery drivers transported packages directly to private residences and had access to customers’ addresses, telephone numbers and information that could reveal aspects of their habits. They could also be entrusted with packages of significant value. On 10 February 2022, the DPA imposed a €2 million fine on the controller for an infringement of Article 6(1), in conjunction with Article 10 GDPR, as well as Articles 10 and 71 LOPDGDD. The DPA considered that a certificate showing the absence of criminal convictions still constituted personal data relating to criminal convictions and offences. Consequently, it held that candidates’ consent could not legitimise the processing without a specific authorisation under Union or national law. The controller appealed the decision before the Audiencia Nacional, the appeal court. It argued that a certificate confirming the absence of criminal records did not fall within Article 10 GDPR and referred to previous cases in which the DPA had accepted similar requirements for certain professional activities. Holding — The Court granted the appeal and annulled the DPA’s decision and the €2 million fine. First, the Court held that Article 10 GDPR must be interpreted strictly, particularly in administrative sanctioning proceedings, which are governed by the principle of minimum intervention and the prohibition of extensive interpretations against the alleged infringer. The Court distinguished between processing information concerning existing criminal convictions or offences and processing a certificate confirming that the person has no criminal record. In its view, Article 10 GDPR expressly covers personal data relating to criminal convictions and offences, but not information concerning their absence. The Court considered that a negative criminal record certificate contains favourable information regarding a person’s conduct. Therefore, processing such a certificate does not amount to processing specially protected criminal-offence data under Article 10 GDPR. As a result, the consent provided by candidates was not invalid merely because no Union or national law specifically authorised the processing under that provision. The Court distinguished the case from situations involving direct access to criminal-record databases or the creation of files containing adverse information. It also distinguished previous employment-law judgments concerning employers requesting criminal records. Although requiring such certificates could be unlawful or abusive under employment law, this did not necessarily mean that the conduct was sanctionable under data protection law. Nevertheless, the Court clarified that processing negative criminal record certificates remained subject to the general GDPR requirements, particularly the principles under Article 5 GDPR and the need for a valid legal basis under Article 6(1) GDPR. In this regard, the Court found the controller’s reasons sufficient to consider the processing legitimate. Amazon Flex drivers delivered packages to private homes and had access to customers’ contact details and information capable of revealing their habits. The Court therefore accepted that verifying candidates’ good standing served the security of the recruitment process and the protection of customers. Accordingly, the Court concluded that the processing was legitimate, granted the controller’s appeal and annulled the DPA’s decision without awarding costs.

### French Supreme Admin Court partly upholds challenge to graduated response IP data decree

*Source: Supreme Administrative Court, 2026-04-30 — https://overview.legal/posts/122869 — original: https://gdprhub.eu/index.php?title=CE_-_N._433539*

Facts — Several digital rights organisations asked the Prime Minister to repeal Decree No. 2010-236 of 5 March 2010. The decree regulated an automated personal data processing system used by the French authority for freedom of communications (ARCOM, hereinafter the French authority) for France’s online copyright enforcement mechanism, known as the graduated response procedure. Under this system, the French authority could receive IP addresses linked to alleged copyright infringements and request the corresponding subscriber identity data from electronic communications operators. This data could then be used to send warnings to subscribers and, in repeated cases, refer the matter to the public prosecutor. The applicants argued that the decree allowed the French authority to access personal data linked to IP addresses without sufficient safeguards under EU law. The court had previously referred questions to the CJEU, which ruled in Case C-470/21 that such access may be allowed, but only under strict conditions. Following the CJEU judgment, the court reviewed whether the French decree complied with EU law. Holding — The court partly upheld the action. First, the court held that EU law allows the general and indiscriminate retention of IP addresses for combating criminal offences in general only where serious interference with private life is effectively excluded. This requires strict separation between different categories of retained data, secure technical safeguards and regular monitoring by an independent public authority. The court found that French law did not require electronic communications operators to retain subscriber identity data and IP-related data under these conditions. Therefore, the decree was unlawful insofar as it allowed the French authority to process data that had not necessarily been retained in compliance with EU-law safeguards. Second, the court held that the French authority may access subscriber identity data linked to IP addresses in order to identify persons suspected of online copyright infringements and send the first two warnings under the graduated response procedure. However, the court distinguished the third access to such data. At that stage, the authority is no longer dealing with an isolated identification request: it has already linked the same person’s identity twice with alleged unlawful online activity and with the protected works concerned. A third access therefore allows the authority to build a more detailed picture of the person’s conduct and may reveal sensitive aspects of their private life. It also marks a more serious procedural stage, since it may lead to a registered letter and ultimately to referral to the public prosecutor. For that reason, EU law requires prior authorisation by a court or an independent administrative body before this third access takes place. The decree did not provide for such prior review, so the court held that it was unlawful to that extent. For this third access, EU law requires prior authorisation by a court or an independent administrative body. The decree did not provide for such prior review. The court therefore held that the decree was unlawful to that extent. The court annulled the Prime Minister’s refusal to repeal the unlawful parts of the decree and ordered their repeal. It also held that the French authority must stop applying the unlawful provisions. However, the French authority may still access identity data for the first and second warnings, and may request access in serious copyright offence cases under the conditions set out in the judgment.

### CJEU - C‑178/22 - Procura della Repubblica presso il Tribunale di Bolzano

*Source: GDPRhub, 2024-04-30 — https://overview.legal/posts/158447 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑178/22_-_Procura_della_Repubblica_presso_il_Tribunale_di_Bolzano*

Facts — Two complaints were lodged with the Italian Public Prosecutor's office concerning acts of mobile theft. In order to identify the perpetrators, the Public Prosecutor's office requested an authorisation to obtain the telephone records of the stolen telephones from all the telephone companies. These requests concerned all the data in the possession of the telephone companies, with tracking and localisation methods, in particular the users and International Mobile Equipment Identity (IMEI) codes of the devices called or making the calls, the sites visited and reached, the times and durations of the calls and connections, the details of the cells and/or towers concerned, and the users and IMEI code of senders and receivers of SMS and MMS. These requests were made to the judge responsible for preliminary investigations at the District Court, Bolzano (‘Giudice delle indagini preliminari presso il Tribunale di Bolzano’) on the basis of an Italian National law, Article 132(3) of Legislative Decree n°196/2003. The referring court was uncertain whether Article 132(3) of Legislative Decree n°196/2003 is compatible with Article 15(1) of Directive 2002/58 (‘ePrivacy Directive’) as interpreted by CJEU, 2 March 2021, Prokuratuur, C-746/18. First, according to paragraph 45 of that judgement, national provisions that allow public authorities to access telephone records containing a set of traffic or location data are justifiable if those provisions are intended for the prosecution of serious offences such as threats to public security and other serious crimes. Second, Article 132(3) of Legislative Decree n°196/2003 establishes that if there is sufficient evidence of the commission of an offence for which the penalty is a maximum term of imprisonment of at least three years, the Public Prosecutor may acquire data relevant to the facts, with the prior authorization of the court. According to the referring court, the Italian courts have a very limited margin of discretion to refuse authorisation to obtain telephone records as the authorization must be granted when there is ‘sufficient evidence of the commission of an offence’ and the data requested are ‘relevant to establishing the facts’. The Giudice delle indagini preliminari presso il Tribunale di Bolzano decided to stay the proceedings and referred the following question to the CJEU: Does Article 15(1) of the ePrivacy Directive preclude a national provision which requires a national court to authorise access to a set of traffic or location data for the purposes of investigating a criminal offence with a penalty of a maximum term of imprisonment of at least 3 years, provided that there is sufficient evidence and that those data are relevant to establishing the facts? Holding — Firstly, the CJEU indicated that access to traffic and location data retained by providers of electronic communications services may be granted to public authorities for the purposes of the prevention, investigation, detection and prosecution of criminal offences pursuant to a national law adopted under Article 15(1) ePrivacy Directive. However, a legislative measure cannot allow the general and indiscriminate retention of traffic and location data as a preventative measure (§35 of the Judgement). The CJEU also held that only the objectives of combating serious crime or preventing serious threats to public security are capable of justifying a serious interference with the fundamental rights of Articles 7 and 8 of the Charter (§36 of the Judgement). Secondly, the CJEU assessed the question of whether access to the traffic and location data in the present case may be classified as a serious interference with the fundamental rights guaranteed by Articles 7 and 8 of the Charter. Access to the set of traffic or location data requested in the present case may allow precise conclusions to be drawn concerning the private lives of the persons whose data have been retained, for example the habits of their everyday life, their permanent or temporary places of residence, their daily movements, the activities they carried out, their social relationships and social environments frequented by them. The CJEU found that in such a case, the interference with the fundamental rights guaranteed in Articles 7 and 8 of the Charter would likely to be classified as serious (§39 of the Judgement). The Court considered that for the purposes of assessing the existence of a serious interference with the fundamental rights, it was irrelevant that the access may not concern the data of the owners of the phones, but the data of the persons who communicated with each other after the theft. Indeed, Article 5(1) ePrivacy Directive establishes that the obligation to ensure confidentiality of the traffic data covers communications made by the ‘users’ of that network. The ‘users’ are defined as any natural person using a publicly available electronic communications service, without necessarily having subscribed to that service (§41 of the Judgement). Thirdly, the CJEU added that national law determines the conditions under which providers of electronic communications services grant access to the data in the provider's possession. However, the legislation must lay down clear and precise rules governing the scope and conditions for the application of such access. As a general rule, the CJEU noted that access can be granted in relation to the objective of fighting crime, only for the data of individuals suspected of being implicated in a serious crime. The Court also pointed out that in order to ensure that the interference is limited to what is strictly necessary, the access must be subject to a prior review carried out by a court or an independent administrative body. This does not apply in cases of duly justified emergency (§43 of the Judgement). Regarding the definition of the concept of 'serious offence', the EU has not legislated in that field. This concept reflects social realities and legal traditions, which vary between the Member States and over time. Therefore, it is up to the Member States to define 'serious offences’ for the purposes of applying Article 15(1) ePrivacy Directive (§46 of the Judgement). The CJEU recalled that Article 15(1) ePrivacy Directive is an exception to the obligation to ensure the confidentiality of electronic communications and data and must not become the rule (§48 of the Judgement). Furthermore, the national measures taken by Member States under this provision must comply with the general principles of EU law, in particular the principle of proportionality and ensuring respect for the fundamental rights enshrined in Articles 7, 8 and 11 of the Charter (§49 of the Judgement). Therefore, the Court considered that Member States must not distort the concept of ‘serious offence’ and ‘serious crime’ by including within it, offences which are manifestly not serious offences. In the present case, the CJEU pointed out that Article 132(3) Legislative Decree n°196/2003 defines the offences for which access to data retained by providers of electronic communications services may be granted, by reference to a maximum term of imprisonment of at least three years. Additionally, there must be sufficient evidence to the commission of an offence and the data must be relevant to establishing the facts (§52 of the Judgement). The CJEU held that the definition of ‘serious offence’ cannot cover the vast majority of criminal offences, which would be the case if the maximum term of imprisonment was sent at an excessively low level. The Court considered that a maximum term of imprisonment of three years does not appear excessively low (CJEU, 21 June 2022, Ligue des droits humains, C-817/19, §150). Lastly, the CJEU found that setting a maximum term of imprisonment may create a situation in which the access would be requested for the purposes of prosecuting offences which do not constitute a serious crime. However, the Court held that setting a minimum period above which the maximum term of imprisonment for an offence justifies the classification of that offence as a serious offence is not necessarily contrary to the principle of proportionality (§58 of the Judgement). Thus, the CJEU concluded that Article 15(1) ePrivacy Directive does not preclude a national provision which requires a national court, acting in the context of a prior review, to authorise access to traffic or location data for the purposes of investigating criminal offences punishable under national law by minimum 3 years imprisonment. However, the court must be entitled to refuse such access in the context of investigating an offence which is manifestly not a serious offence in the light of the societal conditions prevailing in the Member State concerned.

### BVwG - W292 2270002-1

*Source: Federal Administrative Court, 2023-07-27 — https://overview.legal/posts/109002 — original: https://gdprhub.eu/index.php?title=BVwG_-_W292_2270002-1*

Facts — On 4 October 2020, the controller sent a non-anonymised court judgement of the Regional Criminal Court (Landesgericht für Strafsachen) as a PDF file to a different recipient via WhatsApp. Less than a year later, on 28 July 2021, the same non-anonymised court judgement was sent to the same recipient again, this time via email. The data subject lodged two complaints with the DPA (DSB) regarding the violation of their right to secrecy under § 1(1) DSG. In the first proceedings (DSB-D124.5125), the DPA ruled on the transmission of the judgement via WhatsApp and notably highlighted that the transmission via email was not the subject of the proceedings. In the second procedure (DSB-D124.0310/22) concerning the transmission via email, the DPA dismissed the complaint on the grounds that the data subject had no legitimate interest of legal protection and referred to its first administrative decision. The data subject appealed against the second decision of the DPA and asked the court to decide in that subject matter. In their opinion, the two transmissions of the judgement at different times represent two separate data processing operations. Holding — First, the court held that, in this specific case, there was no identity of the subject matter in comparison with the first proceedings within the meaning of § 68(1) AVG. In accordance with established legal practice (VwGH 31.07.2006, 2006/05/0158; VwGH 21.06.2007, 2006/10/0093 etc.), the court based its decision on the legal and temporal identity of the case. On the one hand, the data processing operation via email took place at a later date. On the other hand, the resulting time difference could lead to a potentially different legal assessment compared to the previous proceedings. Second, the court ruled that it could only examine the rightfulness of the dismissal of the complaint and therefore could not rule on the subject matter itself (See, for example, VwGH 18.12.2014, Ra 2014/07/0002). Third, the court held that no appeal to the Austrian Supreme Administrative Court (Verwaltungsgerichtshof) was admissible pursuant to Article 133(4) B-VG, as the decision raised no legal questions of fundamental importance. Therefore, the court quashed the DPA's administrative decision DSB-D124.0310/22.

### CJEU - C-101/01 - Lindqvist

*Source: GDPRhub, C-101/01, 2003-11-06 — https://overview.legal/posts/125585 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-101/01_-_Lindqvist*

Facts — The case is about Mrs. Lindqvist who worked as a catechist in the Alseda Parish (Sweden). At the end of 1998, she set up internet pages on her personal computer in order to allow parishioners preparing for their confirmation to obtain any information they needed. She requested the administrator of the Swedish Church’s website to set up a link between those pages and the website. The pages she had set up contained information about Mrs. Lindqvist and 18 of her colleagues in the parish. The pages contained information including their full names, first names, jobs held, hobbies, telephone numbers and medical information on one of her colleagues. She had not informed her colleagues of those pages, obtain their consent or sought approval from the supervisory authority to process the personal data and sensitive personal data. The public prosecutor brought a proceeding against her, that she was in breach of the PUL on grounds that she processed personal data automatically without giving prior written notice to the Supervisory Authority (Datainspektionen). In addition, she processed sensitive personal data and transferred personal data to a third country without authorization or consent from the data subjects. The Royal Court (Göta hovrätt) stayed the national proceedings and referred some question of law to the CJEU. Dispute — The questions brought before the CJEU were: Whether a self-made list, with personal data of others, published on the internet constitute processing of personal data wholly or partly by automatic means as defined under Article 3(1) Directive 95/46/EC. Whether the act of setting up internet home pages for 15 people with links between the pages which make it possible to search the pages using the first name be considered processing of personal data which forms part of a filing system within the meaning under Article 3(1) Directive 95/46/EC? Whether the processing of personal data is covered under the exception to processing under a household activity under Article 3(1) Directive 95/46/EC? Whether the reference made to the health condition of Mrs. Lindqvist colleague amounts to processing of health/medical data under Article 8(1) Directive 95/46/EC? Whether publication of information on the internet, which can be viewed by anyone in the world, amount to transfer of personal data according to Article 25 Directive 95/46/EC. Whether the provisions of Directive 95/46/EC are in conflict with the general principles of freedom of expression under Article 10 ECHR. Lastly, whether a member state can provide more extensive protection for personal data than that provided under Article 13 Directive 95/46/EC. Holding — On the first and second question, the CJEU held that the term personal data defined under Article 2(b) Directive 95/46/EC includes any information relating to an identified or identifiable natural person. Hence, the term covers the name of a person, his telephone number or information relating to his working conditions or hobbies. Regarding the question whether Mrs. Lindqvist was processing personal data using internet pages, the court referred to Article 3(1) Directive 95/46/EC and observed that, according to the definition, the term processing of personal data covers any operation performed on personal data whether or not by automatic means. Thus, the court held that the operation of loading personal data on an internet page must be considered to be processing of personal data. The court also considered the third question, whether the processing falls under the exception stipulated under Article 3(2) Directive 95/46/EC as argued by Mrs. Lindqvist. On this, the court critically examined the exceptions stipulated which include processing by a natural person in the course of a purely household or personal activity. The court interpreted the exception to mean that the exception covers only activities which are carried out in the course of purely private or family life of individuals which clearly is not the case here since the activities carried out by Mrs. Lindqvist were or charitable or religious nature. On the fourth question, the court interpreted widely Article 3(1) Directive 95/46/EC to include information concerning all aspects of physical and mental health state of an individual. Hence, Mrs. Lindqvist's reference to her colleagues health condition constitutes processing of personal data concerning health in line with Article 8(1) Directive 95/46/EC. On the fifth question, the court noted that the term transfer was not defined by Directive 95/46/EC. Hence, in order to determine whether loading personal data on an internet page constitutes transfer within the meaning of transfer envisioned under Article 25 Directive 95/46/EC, the court took into account the technical nature of the internet pages operations. The court noted that, in order for internet users to have access to the internet pages containing the personal data, they had to first connect to the internet and then proceed to carry out a search. Thus, the technical operations in question did not contain the technical means to send that information automatically to people who did not seek to access those pages. The court held that Mrs. Lindqvist did not transfer personal data as enumerated under Article 25 Directive 95/46/EC. On the sixth question, the court noted that Member states have an obligation to ensure that national laws are harmonized to ensure free flow of information between member states and also safeguard individuals’ rights and freedoms. Thus, there must be balancing of rights of individuals and economic and social integration. Mrs. Lindqvist's freedom of expression in her work to contribute to religious life had to be weighed against the protection of individual rights. To balance these two, the court emphasized on the importance of respecting the principle of proportionality that means taking into account all the circumstances of the case before it before making a decision. The court held that the provisions of Directive 95/46/EC do not necessarily bring a restriction which conflicts with the general principles of freedom of expression, but it is up to the national courts to ensure a fair balance between the rights and interests in question. On the seventh question, the court addressed the question with reference to the provisions of Recital 8 Directive 95/46/EC and Recital 10 Directive 95/46/EC. In the harmonization of laws by member states, the court reiterated the importance of having a complete harmonization of laws. The court noted that Directive 95/46 allows room for manoeuvres in certain cases, but such manoeuvres should ensure that there is a balance between the free movement of personal data and protection of private life. In conclusion, the court held that measures taken by member states to ensure the protection of personal data must be consistent with the provisions of Directive 95/46/EC. However, nothing prevents a member state from extending the scope of national legislation to areas not included in the scope of Directive 95/46/EC.

### Rotterdam Court: DPA did not err in finding ING contactless chip payments GDPR-compliant

*Source: District Court Rotterdam, 2026-06-24 — https://overview.legal/posts/96826 — original: https://gdprhub.eu/index.php?title=Rb._Rotterdam_-_ROT_25/7371*

Facts — ING Bank N.V. (the controller) is a bank. In 2022, several data subjects brought a complaint to the DPA regarding the controller’s contactless payments. The data subjects requested the controller to issue debit cards without a chip that would enable contactless payments. The controller stated that this was not possible, however, the contactless payment feature could be disabled on the data subjects’ cards. The data subjects later filed a complaint because the debit cards contained the chips even if the contactless feature was disabled. The DPA dismissed the complaint in 2024, on the grounds that further investigation would be needed to determine whether the controller violated the GDPR or not. The DPA stated that it had limited capacity and such an investigation would place a heavy burden on it. The data subjects appealed this decision to the court, who determined that the DPA had wrongfully failed to hear the data subjects during the objection phase. The DPA issued a new decision in 2025 and concluded that the controller had not violated the GDPR. The data subjects appealed this decision, arguing that the DPA had again not investigated the case sufficiently. In addition, the data subjects argued that the controller processed personal data through the debit card chip without a valid legal basis. This is because the chip allowed payments made with blocked or expired cards, meaning Article 6(1)(b) GDPR did not apply. The controller could also not rely on consent (Article 6(1)(a) GDPR) to process the data. The DPA argued that the GDPR does not require controllers to completely eliminate a risk. In addition, disabling contactless payments or blocking cards were related to the contract between the data subject and the controller; the DPA argued that this did not remove the basis to process personal data. Holding — The court found that the DPA investigated the complaint to an appropriate extent and was not required to conduct a further investigation. According to the court, the data subjects did not provide sufficient evidence that the controller’s statements were incorrect or that the DPA lacked the technical knowledge during its investigations. The court upheld the DPA’s reasoning that Article 32 GDPR does not require a security risk to be completely eliminated, and concluded that the DPA could reasonably decide that there was no violation of the GDPR. Similarly, the court upheld the DPA’s reasoning and concluded that the controller had a valid legal basis to process the data subjects’ personal data. The court saw no need to assess potential violations of other laws (e.g. fraud or forgery) or consumer law issues, on the grounds that the DPA’s investigation is limited to compliance with the GDPR. The DPA is also not required to coordinate or refer the case to other competent authorities. The court dismissed the appeal.

### GC - T-318/24

*Source: Gereral Court, T-318/24, 2025-12-03 — https://overview.legal/posts/122878 — original: https://gdprhub.eu/index.php?title=GC_-_T-318/24*

Facts — An applicant (the data subject) participated in several EU staff selection procedures administered by the European Personnel Selection Office (EPSO), acting as controller, and created an EPSO account in the Talent system. After he successfully passed one selection procedure, EPSO also stored his data in its recruitment portal. EPSO managed recruitment through two IT systems, both of which generated access logs, although those logs contained limited technical information regarding the purpose of each access. Between 2022 and 2024, the data subject submitted several requests to EPSO under Article 17 of Regulation (EU) 2018/1725, seeking access to all personal data concerning him. He requested, in particular, full access logs, minutes of meetings, internal and external communications containing his personal data, information on data recipients, and the restoration of personal data deleted after the expiry of retention periods. EPSO stated that certain data did not exist, that it could not restore lawfully deleted data, and that it had already disclosed all available log data. After the data subject lodged a complaint, the European Data Protection Supervisor (EDPS) reconsidered the matter in light of the CJEU’s judgment in Pankki. The EDPS ordered EPSO to provide all available log data relating to consultations of the data subject’s profile. EPSO complied with that order by disclosing the available logs but withheld the identities of individual staff members who had accessed the data. EPSO later rejected further access requests submitted by the data subject. As a result, the data subject brought two actions before the General Court (Cases T-318/24 and T-362/24), seeking the annulment of EPSO’s decisions. The General Court joined the two cases and examined together all the pleas in law raised by the data subject. Holding — The General Court dismissed both actions in their entirety. It held that the controller did not infringe Article 17(1) or (3) of Regulation 2018/1725, as the right of access concerns personal data undergoing processing and not documents as such, nor does it require the controller to restore lawfully deleted data. The Court confirmed that Regulation 2018/1725 contains no obligation for a controller to reinstate personal data once deleted in compliance with applicable retention rules. The Court further held that the controller had no obligation to disclose additional log data, meeting minutes, or communications where it credibly asserted that no such personal data existed. The data subject failed to rebut the presumption of legality attaching to the controller’s statements regarding the non-existence of further data. Moreover , The Court held that access logs constitute personal data to which a data subject is entitled, as they reveal the existence, frequency and purpose of processing. However, employees of a controller acting under its authority are not “recipients” within the meaning of the GDPR or Regulation 2018/1725, and controllers are not required to log or disclose their identities. Disclosure of such identities is only required if strictly necessary for the effective exercise of data protection rights and subject to safeguarding employees’ rights. Since the data subject had already been informed of the purposes and recipients of processing, the absence of staff identities or detailed purposes in the logs did not infringe the right of access. It is not further apparent from the Pankki that Article 15 GDPR requires the controller to set up a logging mechanism containing information on the identity of employees who have carried out consultation operations in respect of the personal data of a person. In addition, the Court found no infringement of the principles of lawfulness, fairness, transparency, accuracy, integrity, confidentiality, or accountability under Article 4 of Regulation 2018/1725. The deletion of the data subject’s data after the expiry of retention periods was lawful and the data subject’s rights to restriction of processing and objection under Articles 20 and 23 were not applicable, as the deletion was based on a legal obligation rather than consent or legitimate interests.

### VG Düsseldorf - 29 K 3490/24

*Source: Administrative Court Düsseldorf, 2026-06-22 — https://overview.legal/posts/108992 — original: https://gdprhub.eu/index.php?title=VG_Düsseldorf_-_29_K_3490/24*

Facts — A district (the controller), acting as the lower water authority, initiated administrative proceedings after identifying unauthorised riverbank works and a private jetty on two riverside properties. One property belonged to a water utility company, while the other belonged to a municipality and was leased to the data subjects. During those proceedings, the controller shared the data subjects' personal data with various participants, including the owners of the affected properties, other public authorities and a lawyer who claimed to represent the data subjects. The data subjects lodged a complaint with the competent supervisory authority (LDI NRW), alleging that the controller had unlawfully processed and disclosed their personal data. They argued that their personal data had been shared with uninvolved third parties, that the controller had communicated with a lawyer whom they had not authorised, recorded a telephone conversation with an unknown person, and transmitted personal data by unencrypted email. The controller's data protection officer addressed each allegation and provided additional factual information concerning the disputed processing operations. The DPA initially informed the data subjects that no GDPR infringement was apparent, invited them to provide any additional factual information, and explained that it would obtain extracts from the controller's administrative file if there were concrete indications that it contained relevant facts not already available. The data subjects did not identify any additional facts and instead reiterated their legal position that the controller had breached its GDPR accountability obligations. The DPA rejected the complaint, concluding that no GDPR infringement could be established. The data subjects then brought an action before the Verwaltungsgericht Düsseldorf (Administrative Court Düsseldorf), seeking a fresh decision on their complaint on the basis that the DPA had failed to adequately investigate the complaint because it had not obtained the controller's administrative file before reaching its decision. Holding — The court held that Articles 57(1)(f) and 77(1) GDPR give rise to an enforceable right requiring a supervisory authority to investigate a complaint to the extent appropriate in the circumstances before determining whether a GDPR infringement has occurred. Recital 141 GDPR requires the investigation to extend as far as is appropriate in light of the circumstances of the individual case, including the significance of the complaint and the seriousness of the alleged infringement. Applying these principles, the court held that the DPA had adequately investigated the complaint. It had considered each allegation together with the detailed response provided by the controller's data protection officer, invited the data subjects to provide any additional factual information, and explained that it would obtain extracts from the administrative file if concrete indications emerged that further relevant facts required clarification. As the data subjects did not provide any additional facts and there were no objective indications that the information already available was inaccurate or incomplete, the court held that the DPA was not required to obtain the controller's administrative file or undertake further investigations in the absence of concrete indications that additional factual clarification was necessary. The court further held that the DPA had correctly concluded that no GDPR infringement had occurred. The court held that the disputed processing was lawful under Article 6(1)(e) GDPR, read together with Article 6(3) GDPR and § 88 of the German Water Resources Act (WHG), which provided the legal basis for the processing. The court also held that the transmission of personal data by email did not infringe Article 5(1)(f) GDPR because, in the circumstances of the case, transport encryption provided an appropriate level of security.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

## Guidance

### Guidelines 01/2021

*Source: EDPB, edpb-guidelines-on-examples-regarding-personal-data-breach-notification, 2022-01-03 — https://overview.legal/posts/38047 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012021-on-examples-regarding-personal-data-breach-notification_en*

The European Data Protection Board (EDPB) adopted Guidelines 01/2021 on December 14, 2021, providing practical examples and analysis regarding personal data breach notification obligations under Articles 33 and 34 of the GDPR. The guidelines present hypothetical scenarios covering ransomware attacks and data exfiltration incidents, illustrating how controllers should assess risk to determine whether notification to supervisory authorities and communication to data subjects are required. The document serves as interpretive guidance for controllers evaluating breach severity, appropriate mitigation measures, and notification decisions, and does not impose any fines or sanctions.

### Guidelines 3/2019 on processing of personal data through video devices

*Source: EDPB, edpb-guidelines-on-processing-of-personal-data-through-video-devices, 2020-01-30 — https://overview.legal/posts/38059 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-32019-on-processing-of-personal-data-through-video-devices_en*

The European Data Protection Board (EDPB) adopted Guidelines 3/2019 to provide comprehensive guidance on the processing of personal data through video devices,including CCTV and smart camera systems, under the GDPR. The guidelines address key issues such as the scope of application, the household exemption, lawfulness of processing under Article 6(1)(f) GDPR (legitimate interests), data subjects' rights, and obligations of controllers, while also clarifying the boundary with the Law Enforcement Directive (EU 2016/680). The guidelines were adopted on 29 January 2020 following public consultation and do not impose fines but serve as interpretative guidance for controllers and supervisory authorities.

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### Statement 1/2025 on Age Assurance

*Source: EDPB, statement-12025-on-age-assurance-en, 2025-02-12 — https://overview.legal/posts/125696 — original: https://www.edpb.europa.eu/documents/statement/statement-12025-on-age-assurance_en*

1 Statement 1/2025 on Age Assurance Adopted on 11 February 2025 1 The European Data Protection Board has adopted the following statement: 1. BACKGROUND AND PURPOSE OF THIS STATEMENT 1. The European regulatory framework calls for the increased protection of children in the digital environment. For example, the Audiovisual Media Services Directive 2 , which Member States have transposed into their national laws, highlights the possibility to implement age verification measures (Articles 6a and…

### Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive

*Source: EDPB, edpb-guidelines-on-technical-scope-of-art-53-of-eprivacy-directive, 2024-10-16 — https://overview.legal/posts/38063 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22023-on-technical-scope-of-art-53-of-eprivacy-directive_en*

The European Data Protection Board (EDPB) issued Guidelines 2/2023 to clarify the technical scope of Article 5(3) of the ePrivacy Directive, focusing on its application to emerging tracking technologies that operate as alternatives to cookies. The guidelines establish three key elements—information, terminal equipment, and gaining access/storage—to determine whether specific technical operations require user consent. The document applies this framework to common use cases such as URL and pixel tracking, local processing, IP-based tracking, intermittent IoT reporting, and the use of unique identifiers.

### Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement

*Source: EDPB, edpb-guidelines-on-the-use-of-facial-recognition technology-in-the-area-of-law-enforcement, 2023-05-17 — https://overview.legal/posts/38075 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052022-on-the-use-of-facial-recognition-technology-in-the-area-of_en*

More  and  more  law  enforcement  authorities  (LEAs)  apply  or  intend  to  apply  facial  recognition technology (FRT). It may be used to authenticate or to identify a person and can be applied on videos (e.g. CCTV) or  photographs. It may be used for various purposes, including to search for persons  in police watch lists or to monitor a person's movements in the public space. FRT is  built on the processing of biometric data , therefore, it encompasses the processing of special categories ...

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### Opinion 13/2019 on the draft list of the competent supervisory authority of France regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR)

*Source: EDPB, opinion-132019-on-the-draft-list-of-the-competent-supervisory-en, 2019-07-12 — https://overview.legal/posts/126218 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-132019-on-the-draft-list-of-the-competent-supervisory_en*

Adopted 1 Opinion 13 /2019 on the draft list of the com petent supervisory authority of France regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35( 5 ) GDPR) Adopted on 10 July 2019 Adopted 2 Adopted 3 The European Data Protection Board Having r egard to Article 63, Article 64 (2)and Article 35( 1), (5), (6) of the Regulation 2016/679/E U of the European Parliament and of the Council of 27 April 2016 on the protection of natural…

## Enforcement decisions

### VDAI (Lithuania) - 3R-1143

*Source: VDAI (Lithuania), 2026-06-19 — https://overview.legal/posts/53896 — original: https://gdprhub.eu/index.php?title=VDAI_(Lithuania)_-_3R-1143*

Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other personal data of patients (the data subjects). The first breach potentially concerned 63 data subjects, whereas the latter breach affected approximately 10,000 employees and 383,000 data subjects. The DPA initiated two separate investigations against the controllers in September 2024 and November 2025 respectively and later combined the cases. Holding — The DPA imposed a fine of €450,000 on the first controller it investigated as this company was also the legal successor of the other controller. It held that the controllers had failed to implement appropriate technical and organisational measures to ensure the security of processing and compliance with the principles of integrity and confidentiality. The controller had violated Articles 5(1)(f), 24(1), and 32(1)(b) GDPR. When assessing the GDPR infringements, the DPA took into account that the controllers processed sensitive categories of personal data. The DPA held the controllers lacked adequate security measures for protecting against unauthorised access to an IT system, such as access control and authentication. For instance, passwords used by employees did not reach a certain level of complexity, and multi-factor authentication was not used.

### Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023

*Source: Tietosuojavaltuutetun toimisto (Finland), 2026-07-22 — https://overview.legal/posts/184713 — original: https://gdprhub.eu/index.php?title=Tietosuojavaltuutetun_toimisto_(Finland)_-_TSV/4630/2023*

Facts — A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022. The data subject made an access request in November 2022 – they suspected the misuse of their personal data as they had not submitted the loan application themselves. The data subject provided their name, phone number, and email address as identifying information in connection with the access request. The controller did not provide the requested information; instead, it asked the data subject to disclose their residential address and personal identification number as well as to sign the access request electronically using strong authentication in order to verify their identity. The data subject refused to comply with this request and filed a complaint with the DPA, stating that the controller’s procedure for verifying the identity of the data subject in connection with an access request violated Articles 5(1)(c), 12(2) and (6), and 25(2) GDPR. The controller considered the additional information necessary to identify the correct individual and avoid providing the data subject’s information to an unauthorised third party. Holding — The DPA found no GDPR violation and held that the controller was entitled to request the data subject to provide additional information necessary to verify their identity pursuant to Article 12(6) GDPR. The controller’s procedure was also in line with the principle of data minimisation laid down in Article 5(1)(c) GDPR. According to the DPA, the personal data originally provided by the data subject when making the access request could not be considered sufficient identifying information since several people might have the same name and the email address and the phone number of the data subject could also be known to third parties. The DPA considered that the controller had a legitimate reason to request that the data subject provide additional information to verify their identity, as the controller processes personal data concerning the financial status of its customers.

### AEPD (Spain) - EXP202306354 (PS/00312/2024)

*Source: AEPD (Spain), 2026-02-11 — https://overview.legal/posts/52464 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202306354_(PS/00312/2024)*

Facts — The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested a duplicate SIM card for the mobile line of a data subject. The request was made through Vodafone’s internal telephone support channel for retail stores. The caller impersonated staff and provided several data elements, including the store user code, the data subject’s identification number, the mobile phone number and digits of the ICC number of the new SIM card. Vodafone processed the request and activated the duplicate SIM card. On the same day, the data subject’s phone stopped working. Shortly afterwards, four unauthorised transactions totalling €1,996 were carried out from their bank account. The data subject contacted Vodafone, their bank and the police. Vodafone confirmed that a duplicate SIM card had been issued through a physical point of sale. After the data subject presented a complaint, during the investigation, Vodafone explained that its internal policy required store staff to call a dedicated support channel and provide identifying information before a duplicate SIM could be issued. Vodafone stated that the fraudster had provided the required information and that the security protocol in force at the time had been followed. The controller also informed the AEPD that it later adopted additional measures to reinforce the security of the duplicate SIM procedure. On the basis of these facts, the AEPD opened sanctioning proceedings against Vodafone for an alleged infringement of Article 6(1) GDPR. Holding — The AEPD found that Vodafone infringed Article 6(1) GDPR by processing the personal data of the data subject without a valid legal basis. The AEPD held that the issuance and activation of a duplicate SIM card involved the processing of personal data. Vodafone carried out this processing without the knowledge or consent of the data subject and without any other legal basis under Article 6(1) GDPR. As a result, the processing was unlawful. The AEPD rejected the controller’s argument that it had complied with its internal security protocols. The DPA stated that the existence of internal procedures did not remove the obligation to ensure that processing had a valid legal basis. The intervention of a criminal third party did not exempt the controller from responsibility where the unlawful processing occurred within its own systems and procedures. The AEPD considered that Vodafone acted at least negligently. It took into account the nature of the infringement and the link between the processing and the controller’s core business activity. The DPA imposed an administrative fine of €150,000 on Vodafone for the infringement of Article 6(1) GDPR.

### AEPD sanctions 23andMe for security failures in credential-stuffing breach

*Source: AEPD (Spain), 2025-10-10 — https://overview.legal/posts/158429 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00140-2025*

Facts — 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In October 2023, the controller suffered a personal data breach following a credential-stuffing attack. Attackers accessed customer accounts by using login credentials that customers had reused on other services previously compromised. The breach affected 2,642 customers residing in Spain and exposed identity, contact and location data, images, genetic data, health data and data revealing ethnic origin. A sample of the data was published on an online forum, while a file containing the compromised data was offered for sale on the dark web. At the time of the breach, customers accessed their accounts using a username and password. Multi-factor authentication was available but optional. The controller had not established specific password-strength requirements or periodic password changes and had not implemented limits on access requests or downloads based on IP addresses. Once an account had been accessed, there were no additional controls limiting the viewing or downloading of sensitive data, including information relating to potential relatives. On 1 October 2023, the controller detected a Reddit post offering information allegedly belonging to its customers. On 5 October, it confirmed that one of the published records belonged to a customer. It published an alert on its website on 6 October, reported the incident to US authorities on 7 October and required customers to reset their passwords on 9 October. The controller informed all customers about the incident on 10 October. It identified 799 affected customers residing in Spain on 12 October and notified them on 13 October. It subsequently identified and notified another 1,843 customers residing in Spain on 24 October. However, the controller did not notify the DPA until 17 October 2023 and submitted additional information on 30 October. Holding — The DPA held that the GDPR applied pursuant to Article 3(2) GDPR because the controller, although not established in the EU, offered genetic testing and analysis services to data subjects in the Union. First, the DPA found a violation of Article 5(1)(f) GDPR. The controller had failed to process personal data in a manner ensuring appropriate integrity and confidentiality. The adequacy of its security measures had to be assessed in light of Articles 24(1) and 32 GDPR and the risk-based approach established by the GDPR. The DPA emphasised that the affected information included genetic data, health data and data revealing ethnic origin, which constitute special categories of personal data under Article 9 GDPR. Given the sensitivity of this information and the potential consequences of unauthorised disclosure, the controller was required to implement particularly robust security measures. Nevertheless, the controller did not impose specific password-strength requirements or require passwords to be changed periodically. Although it had implemented multi-factor authentication, its use remained optional. Moreover, it had not introduced additional controls or limits concerning account access, access requests or the downloading of sensitive information. These deficiencies made unauthorised access more difficult to detect and facilitated the extraction of the compromised data. The DPA rejected the suggestion that responsibility could be shifted to customers because they had reused their credentials. Although customers were responsible for using their credentials appropriately, the controller remained responsible for assessing the risks and implementing security measures appropriate to the nature of the processing. Credential theft was a well-known attack vector, particularly relevant where account access allowed users to view or download genetic and health information. Second, the DPA found a violation of Article 33 GDPR. It considered that the controller became aware of the personal data breach on 5 October 2023, when it confirmed that one of the records published online belonged to one of its customers. At that point, it had a reasonable degree of certainty that a security incident involving personal data had occurred. The controller’s subsequent actions, including publishing an alert, notifying US authorities and requiring password resets, further demonstrated that it was already aware of the breach. However, it did not notify the DPA until 17 October, substantially exceeding the 72-hour deadline. The DPA stressed that notification cannot be postponed until all affected individuals and all details of the incident have been identified. Article 33(4) GDPR expressly permits information to be provided in phases when it cannot be submitted simultaneously. The controller’s need to assess its notification obligations across several jurisdictions therefore did not justify the delay, particularly because the breach involved sensitive data posing a high risk to the affected individuals. The DPA imposed a total administrative fine of €2,400,000: - €2,000,000 for the violation of Article 5(1)(f) GDPR; - €400,000 for the violation of Article 33 GDPR.

### Datatilsynet (Denmark) - 2022-63-0003

*Source: Datatilsynet (Denmark), 2022-10-28 — https://overview.legal/posts/6329 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2022-63-0003*

Facts — A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that the personal data was accessed by unauthorized persons, with a potential for harm to the data subjects. In March 2020, the law firm notified the Danish DPA of the data breach. Holding — The Danish DPA held that the law firm lacked basic security measures, especially considering the fact that its processing involved special categories of personal data. The DPA emphasized that in such cases a data breach would almost certainly entail a high risk to the data subjects' rights. Therefore, the controller must have especially strict security measures in place to avoid unauthorised accesses. Hence, when creating remote access to such IT systems, the controller could, for instance, implement multifactor authentication. Consequently, the DPA reported the firm to the police. The DPA assessed the appropriate sanctions in accordance with Article 83(2) GDPR and suggested a fine of approximately €67,000 (DKK 500,000).

### ANSPDCP (Romania) - Fine against Homelux SRL

*Source: ANSPDCP (Romania), 2026-08-11 — https://overview.legal/posts/187378 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_Homelux_SRL*

Facts — HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform that had not been updated to the latest version released by the software provider. The website subsequently suffered a cyberattack affecting the security of the personal data processed through it. This incident was further facilitated by weak password requirements for user accounts, a deficiency that remained unremedied after the breach. As a result, the security of personal data processed by the controller, including names, surnames, addresses, email addresses and passwords, was compromised. During the investigation, the DPA also found that the controller stored non-essential cookies on users' devices and accessed this information without obtaining the users' prior consent. Holding — First, the DPA found that the controller infringed Article 32(1)(d) and 32(2) GDPR by failing to implement adequate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing. The DPA considered these shortcomings insufficient to ensure a level of security appropriate to the risk. It also found that the controller had failed to establish a process for regularly testing, assessing, and evaluating the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 78,570 (€15,000). Second, the DPA found that the controller infringed Article 4(5) of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector by placing non-essential cookies on users' devices without obtaining prior consent. The DPA noted that these cookies were not technically necessary for the operation of the website and therefore could not be deployed without user consent. For this infringement, the DPA imposed a fine of RON 30,000 (€5,715). In addition, as corrective measures, the DPA ordered the controller to implement a procedural plan for the regular testing, evaluation and assessment of its IT systems and subsequent modifications. The DPA also required the controller to strengthen access controls by introducing stronger password requirements, multi-factor authentication, the deactivation of inactive accounts and limiting each user to only the access rights necessary for their role according to the principle of least privilege. Furthermore, the DPA required the controller to implement measures aimed at reducing vulnerabilities, including mechanisms to detect and block cyberattacks and restrictions on access to administrative interfaces. Finally, the DPA ordered the controller to ensure compliance with Article 4(5) of Law No. 506/2004 on its website.

### ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026

*Source: ANSPDCP (Romania), 2026-07-29 — https://overview.legal/posts/144034 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_Orange_Romania_SA_of_July_17,_2026*

Facts — The investigation was initiated after Orange Romania SA (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR, related to its mobile application. A customer (the data subject) of the controller was able to access and download invoices belonging to other customers. As a result, personal data such as names, addresses, delivery addresses, ID document details, and invoice information were disclosed. The incident was caused by a mismatch between two interconnected applications, which incorrectly linked the data subject's account to an employee account. During the investigation, another vulnerability was identified in the controller's ticketing application. The platform was publicly accessible and lacked adequate security measures, such as VPN protection, multi-factor authentication, and IP-based access restrictions. This vulnerability enabled a cyberattack that resulted in the theft of a large volume of personal data, including names, contact details, national identification numbers, copies of identity documents, banking-related information, login credentials, customer codes, and IBAN numbers. Holding — First, the DPA found that the controller infringed Article 25 GDPR by failing to implement appropriate technical and organisational measures when designing and operating its digital platforms. The DPA considered that these shortcomings enabled unauthorised access to personal data and failed to adequately protect data subjects' rights. For this infringement, the DPA imposed a fine of RON 104,780 (€20,000). Second, the DPA found that the controller infringed Article 32 GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The DPA noted that the controller had not adequately secured its platforms and had failed to regularly test and assess the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 419,120 (€80,000). In addition, as a corrective measure, the DPA ordered the controller to implement a monitoring and testing process for all IT applications used in its activities. The process must include controls over software changes and vulnerability testing.

### UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security

*Source: Autoriteit Persoonsgegevens, 2019-10-31 — https://overview.legal/posts/46222 — original: https://www.enforcementtracker.com/ETid-107*

As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online employer portal, security was inadequate. Employers and health and safety services were able to collect and display health data from employees in an absence system.

## Recent developments

### Data brokers: Identification possible to sell ads, not to exercise fundamental rights

*Source: noyb - European Center for Digital Rights, 2023-02-28 — https://overview.legal/posts/53249 — original: https://noyb.eu/en/data-brokers-identification-possible-sell-ads-not-exercise-fundamental-rights*

Today, noyb filed a series of complaints against websites and data brokers that did not correctly address access requests using cookies as an authentication factor. The companies had shown obstructive approaches when authenticating users; ranging from denying the right to access, to requiring additional information, unnecessary to authenticate the user. Complaint against data broker: machine translated EN [PDF] Complaint against website: machine translated EN [PDF] Exercising fundamental rights

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

### De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming).

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/51791*

De GDPR-risicoanalyse is bedoeld om controllers en verwerkers te helpen bij het identificeren van de risicofactoren voor de rechten en vrijheden van de betrokkenen, wiens gegevens worden verwerkt. Het doel is om een eerste inschatting te maken van het inherente risico, inclusief de noodzaak om een Privacy Impact Assessment (DIA) uit te voeren, en om het resterende risico te schatten als maatregelen en beveiligingsmechanismen worden gebruikt om specifieke risicofactoren te verminderen.

### Het EDPB en het EDPS: Het voorstel om online seksueel misbruik van kinderen te bestrijden, brengt serieuze risico's met zich mee voor fundamentele rechten.

*Source: EDPS, 2022-07-29 — https://overview.legal/posts/51845*

De Europese Autoriteit voor gegevensbescherming (EDPB) en de Europese Toezichthouder op het gebied van gegevensbescherming (EDPS) hebben een gezamenlijk advies aangenomen over het voorstel voor een verordening ter bestrijding van seksueel misbruik van kinderen.

### Want your Grindr data? Show your ID and take a selfie!

*Source: noyb - European Center for Digital Rights, 2021-11-11 — https://overview.legal/posts/53301 — original: https://noyb.eu/en/want-your-grindr-data-show-your-id-and-take-selfie*

Identification & Authentication Want your Grindr data? Show your ID and take a selfie! Today, noyb filed a GDPR complaint against Grindr – a dating app for gay, bi, trans and queer people, where many users share very personal and even explicit sexual details. Instead of authenticating against the data that users have provided, like the email and password – Grindr requires users to identify in maybe the most grotesque way imaginable: Users have to hold up a piece of paper with their email address

## Literature

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how

*Source: Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza, 2023-12-30 — https://overview.legal/posts/132546 — original: https://doi.org/10.14746/ppuam.2023.15.09*

The data subject’s right to access information on data processing has a very broad meaning. Considering the latest developments in this field (mainly the CJEU ruling on Austrian posts and EDPB guidelines) one can draw the conclusion that the controller’s right to protect its confidential in-formation is limited and less valuable than the data subject’s rights. However, this may lead to unfair and unequal treatment of companies and data subjects. When looking at this right in a more systematic pe

### GDPR - General Data Protection Regulation on Sites Requiring Accessibility

*Source: Innovative STEM Education, 2021-06-29 — https://overview.legal/posts/132420 — original: https://doi.org/10.55630/stem.2021.0305*

The paper describes what GDPR - General Data Protection Regulation is and why it matters for business, institutions and other legal entities, who need to collect personal data in order to provide and deliver services or products. They have to apply and describe to consumers’ principles and general rules to protect their data. Rules include reasons why personal data collection is necessary, transparency how and by who it will be used and stored and for how long, as well as safety measures to not

### Challenges of Cloud Data Privacy in Surveillance: Legal, Technical, and Ethical Implications

*Source: IJARCCE, 2026-07-07 — https://overview.legal/posts/83508 — original: https://doi.org/10.17148/ijarcce.2026.15701*

The migration of surveillance systems to cloud infrastructure has improved scalability and analytics capabilities but introduces distinct privacy challenges: jurisdictional conflicts between GDPR and the CLOUD Act, expanded attack surfaces from third-party integrations, mandatory retention that conflicts with data minimization, and function creep enabled by centralized data lakes.Using case law from Schrems II, breach reports from ENISA, and technical evaluations of federated learning and differ

### Cookies, privacidade e proteção de dados

*Source: J², 2026-04-04 — https://overview.legal/posts/53837 — original: https://doi.org/10.29073/j2.v8i1.1124*

This paper aims to analyze issues related to cookies, privacy, and data protection, providing a critical overview of relevant literature and regulatory frameworks. It examines the implications of cookie usage in the context of the General Data Protection Regulation (GDPR), highlights current challenges, and discusses emerging trends such as the decline of third-party cookies and the rise of alternative tracking technologies. The paper concludes by proposing measures that organizations should ado

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Identification** — https://overview.legal/topics/identificatie
  Methods and processes for identifying individuals
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Security** — https://overview.legal/topics/beveiliging
  Technical and organizational measures to protect personal data

---
Generated by overview.legal · https://overview.legal/topics/access-controls · 2026-08-22
