# Accountability — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/accountability
> Sources are cited per item. Verify against the official texts before relying on them.

Principle of demonstrating GDPR compliance

## Overview

## Legal Framework

Accountability under the GDPR is anchored in [Article 5(2)](/laws/gdpr/art-5#par-2), which requires controllers to be responsible for and demonstrate compliance with the data protection principles set out in Article 5(1). This is operationalised through [Article 24]((/laws/gdpr/art-24), which obliges controllers to implement appropriate technical and organisational measures both to ensure and to demonstrate that processing complies with the Regulation. [Article 25](/laws/gdpr/art-25) extends this into design and default obligations, while [Article 28]((/laws/gdpr/art-28) imposes parallel accountability requirements on processor relationships.

The dual function of Article 24 is critical: controllers must not only comply but also maintain the evidence to prove compliance. As the Regulation states:

> "the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation"
> — [GDPR Art. 24(1)](/laws/gdpr/art-24#par-3)

Article 24(3) further provides that adherence to approved codes of conduct or certification mechanisms may serve as an element to demonstrate compliance, giving controllers concrete tools to discharge their accountability burden.

## Key Developments

Dutch courts have begun applying the accountability principle in enforcement actions. In a recent administrative fine case, the Rechtbank confirmed that the controller bears an affirmative duty to account for its processing decisions:

> "De verwerkingsverantwoordelijke is verantwoordelijk voor de naleving van deze beginselen en heeft ten aanzien van die naleving een verantwoordingsplicht."
> — [Rechtbank, AVG Handhaving ¶8.3](/posts/50406#seg-8.3)

In a separate case concerning a data subject access request, the court accepted the controller's accountability documentation where it had adequately motivated the purpose basis for retaining personal data after termination of employment, finding the explanation sufficient to discharge the verantwoordingsplicht ([Rechtbank ¶11](/posts/50892#seg-11)).

The EDPB has reinforced that accountability is not confined to processing principles but permeates the entire regulatory architecture. In the context of consent:

> "the burden of proof in Article 7(4) is on the controller. 25 This specific rule reflects the general principle of accountability, which runs throughout the GDPR."
> — [EDPB Guidelines 05/2020 §36](/posts/38053#seg-36)

The EDPB has also linked accountability to breach response preparedness, recommending that controllers maintain pre-established breach handling documentation to meet their obligations without undue delay ([EDPB Guidelines 01/2021 §13](/posts/38047#seg-13)).

## Status of the Debate

The accountability principle itself is well-established at the level of the legal text. However, its operational boundaries remain contested in court. The core tension concerns the evidentiary threshold: what quantum and quality of documentation suffices to "demonstrate" compliance under Article 24(1). Courts have diverged on whether a controller's ex post reasoning can cure a documentation deficit, or whether contemporaneous records are required. The Schrems II ruling and subsequent CJEU case law have intensified scrutiny of accountability in cross-border transfer contexts, where demonstrating compliance involves complex assessments of third-country safeguards. No definitive CJEU ruling has yet set a uniform evidentiary standard for the verantwoordingsplicht. A preliminary reference clarifying whether retroactive justification can satisfy Article 24(1) would resolve the principal open question.

## Practical Guidance

- **Maintain contemporaneous documentation**: Article 24(1) requires the ability to demonstrate compliance at the time of processing, not merely after the fact. Record processing decisions, lawful basis assessments, and necessity analyses as they are made.
- **Implement data protection policies proportionate to processing scale**: Article 24(2) requires formal policies where proportionate — for high-volume or high-risk processing, written policies are not optional.
- **Leverage certification and codes of conduct**: Article 24(3) explicitly permits these as compliance evidence. Pursuing certification under [Article 42](/laws/gdpr/art-25#par-3) provides a defensible posture in enforcement proceedings.
- **Embed accountability in processor contracts**: Article 28(3) requires binding contractual terms specifying processing scope, instructions, and security obligations — these contracts are your primary evidence of processor oversight.
- **Pre-establish breach response procedures**: The EDPB recommends advance preparation of breach handling documentation so that accountability obligations are met without undue delay when incidents occur.

## Legislation (full text of key provisions)

### Data protection by design and by default

*Source: GDPR, gdpr-art-25-en, 2016-04-27 — https://overview.legal/posts/90530*

### Records of processing activities

*Source: GDPR, gdpr-art-30-en, 2016-04-27 — https://overview.legal/posts/90594*

### Recital 82 — records of processing activities

*Source: GDPR, gdpr-rec-82-en, 2016-04-27 — https://overview.legal/posts/91679*

In order to demonstrate compliance with this Regulation, the controller or processor should maintain records of processing activities under its responsibility. Each controller and processor should be obliged to cooperate with the supervisory authority and make those records, on request, available to it, so that it might serve for monitoring those processing operations.

### Recital 112 — competent authorities independence and accountability

*Source: DSA, dsa-rec-112-en, 2022-10-19 — https://overview.legal/posts/95621*

The competent authorities designated under this Regulation should also act in complete independence from private and public bodies, without the obligation or possibility to seek or receive instructions, including from the government, and without prejudice to the specific duties to cooperate with other competent authorities, the Digital Services Coordinators, the Board and the Commission. On the other hand, the independence of those authorities should not mean that they cannot be subject, in accordance with national constitutions and without endangering the achievement of the objectives of this Regulation, to proportionate accountability mechanisms regarding the general activities of the Digital Services Coordinators, such as their financial expenditure or reporting to the national parliaments. The requirement of independence should also not prevent the exercise of judicial review, or the possibility to consult or regularly exchange views with other national authorities, including law enforcement authorities, crisis management authorities or consumer protection authorities, where appropriate, in order to inform each other about ongoing investigations, without affecting the exercise of their respective powers.

### Recital 118 — supervisory authority independence and accountability

*Source: GDPR, gdpr-rec-118-en, 2016-04-27 — https://overview.legal/posts/91751*

The independence of supervisory authorities should not mean that the supervisory authorities cannot be subject to control or monitoring mechanisms regarding their financial expenditure or to judicial review.

### Recital 85 — personal data breach notification requirements

*Source: GDPR, gdpr-rec-85-en, 2016-04-27 — https://overview.legal/posts/91685*

A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons such as loss of control over their personal data or limitation of their rights, discrimination, identity theft or fraud, financial loss, unauthorised reversal of pseudonymisation, damage to reputation, loss of confidentiality of personal data protected by professional secrecy or any other significant economic or social disadvantage to the natural person concerned. Therefore, as soon as the controller becomes aware that a personal data breach has occurred, the controller should notify the personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the controller is able to demonstrate, in accordance with the accountability principle, that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where such notification cannot be achieved within 72 hours, the reasons for the delay should accompany the notification and information may be provided in phases without undue further delay.

### Recital 78 — data protection by design and default

*Source: GDPR, gdpr-rec-78-en, 2016-04-27 — https://overview.legal/posts/91671*

The protection of the rights and freedoms of natural persons with regard to the processing of personal data require that appropriate technical and organisational measures be taken to ensure that the requirements of this Regulation are met. In order to be able to demonstrate compliance with this Regulation, the controller should adopt internal policies and implement measures which meet in particular the principles of data protection by design and data protection by default. Such measures could consist, inter alia, of minimising the processing of personal data, pseudonymising personal data as soon as possible, transparency with regard to the functions and processing of personal data, enabling the data subject to monitor the data processing, enabling the controller to create and improve security features. When developing, designing, selecting and using applications, services and products that are based on the processing of personal data or process personal data to fulfil their task, producers of the products, services and applications should be encouraged to take into account the right to data protection when developing and designing such products, services and applications and, with due regard to the state of the art, to make sure that controllers and processors are able to fulfil their data protection obligations. The principles of data protection by design and by default should also be taken into consideration in the context of public tenders.

### Recital 177 — Transitional provisions existing high-risk AI systems

*Source: AI Act, aiact-rec-177-en, 2024-06-12 — https://overview.legal/posts/94036*

In order to ensure legal certainty, ensure an appropriate adaptation period for operators and avoid disruption to the market, including by ensuring continuity of the use of AI systems, it is appropriate that this Regulation applies to the high-risk AI systems that have been placed on the market or put into service before the general date of application thereof, only if, from that date, those systems are subject to significant changes in their design or intended purpose. It is appropriate to clarify that, in this respect, the concept of significant change should be understood as equivalent in substance to the notion of substantial modification, which is used with regard only to high-risk AI systems pursuant to this Regulation. On an exceptional basis and in light of public accountability, operators of AI systems which are components of the large-scale IT systems established by the legal acts listed in an annex to this Regulation and operators of high-risk AI systems that are intended to be used by public authorities should, respectively, take the necessary steps to comply with the requirements of this Regulation by end of 2030 and by 2 August 2030.

### Recital 114 — systemic risk AI model obligations

*Source: AI Act, aiact-rec-114-en, 2024-06-12 — https://overview.legal/posts/93910*

The providers of general-purpose AI models presenting systemic risks should be subject, in addition to the obligations provided for providers of general-purpose AI models, to obligations aimed at identifying and mitigating those risks and ensuring an adequate level of cybersecurity protection, regardless of whether it is provided as a standalone model or embedded in an AI system or a product. To achieve those objectives, this Regulation should require providers to perform the necessary model evaluations, in particular prior to its first placing on the market, including conducting and documenting adversarial testing of models, also, as appropriate, through internal or independent external testing. In addition, providers of general-purpose AI models with systemic risks should continuously assess and mitigate systemic risks, including for example by putting in place risk-management policies, such as accountability and governance processes, implementing post-market monitoring, taking appropriate measures along the entire model’s lifecycle and cooperating with relevant actors along the AI value chain.

### Recital 27 — ethics guidelines for trustworthy AI

*Source: AI Act, aiact-rec-27-en, 2024-06-12 — https://overview.legal/posts/93736*

While the risk-based approach is the basis for a proportionate and effective set of binding rules, it is important to recall the 2019 Ethics guidelines for trustworthy AI developed by the independent AI HLEG appointed by the Commission. In those guidelines, the AI HLEG developed seven non-binding ethical principles for AI which are intended to help ensure that AI is trustworthy and ethically sound. The seven principles include human agency and oversight; technical robustness and safety; privacy and data governance; transparency; diversity, non-discrimination and fairness; societal and environmental well-being and accountability. Without prejudice to the legally binding requirements of this Regulation and any other applicable Union law, those guidelines contribute to the design of coherent, trustworthy and human-centric AI, in line with the Charter and with the values on which the Union is founded. According to the guidelines of the AI HLEG, human agency and oversight means that AI systems are developed and used as a tool that serves people, respects human dignity and personal autonomy, and that is functioning in a way that can be appropriately controlled and overseen by humans. Technical robustness and safety means that AI systems are developed and used in a way that allows robustness in the case of problems and resilience against attempts to alter the use or performance of the AI system so as to allow unlawful use by third parties, and minimise unintended harm. Privacy and data governance means that AI systems are developed and used in accordance with privacy and data protection rules, while processing data that meets high standards in terms of quality and integrity. Transparency means that AI systems are developed and used in a way that allows appropriate traceability and explainability, while making humans aware that they communicate or interact with an AI system, as well as duly informing deployers of the capabilities and limitations of that AI system and affected persons about their rights. Diversity, non-discrimination and fairness means that AI systems are developed and used in a way that includes diverse actors and promotes equal access, gender equality and cultural diversity, while avoiding discriminatory impacts and unfair biases that are prohibited by Union or national law. Social and environmental well-being means that AI systems are developed and used in a sustainable and environmentally friendly manner as well as in a way to benefit all human beings, while monitoring and assessing the long-term impacts on the individual, society and democracy. The application of those principles should be translated, when possible, in the design and use of AI models. They should in any case serve as a basis for the drafting of codes of conduct under this Regulation. All stakeholders, including industry, academia, civil society and standardisation organisations, are encouraged to take into account, as appropriate, the ethical principles for the development of voluntary best practices and standards.

## Case law

### Spanish court reviews DPA decision on KFC Spain website privacy information and DPO

*Source: National Court, 2026-07-16 — https://overview.legal/posts/184690 — original: https://gdprhub.eu/index.php?title=AN_-_SAN_3154/2026*

Facts — In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website. The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer. The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented corrective measures. Holding — The Court dismissed the appeal and upheld the total fine of €25,000. Regarding Article 13 GDPR, the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding Article 37(1)(b) GDPR, the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.

### VwGH - VwGH Ro 2025/04/0007-7

*Source: Austrian Administrative Supreme Court, 2026-06-24 — https://overview.legal/posts/184547 — original: https://gdprhub.eu/index.php?title=VwGH_-_VwGH_Ro_2025/04/0007-7*

Facts — The controller was an address publisher and direct advertising company that operated a data application to provide advertisers with personal data for targeted marketing measures. In 2019, following media reports concerning the alleged sale of personal data, particularly information about natural persons’ political party affinity, the Austrian DPA (DSB) initiated an ex officio investigation against the controller. Based on its investigation, the DPA found that the controller had unlawfully processed political party affinity data and unlawfully further processed parcel-frequency data, and had infringed its obligations concerning the DPIA and record of processing activities. It consequently imposed a fine of €18,000,000. The controller appealed to the Federal Administrative Court (BVwG), arguing that the commission of an infringement by a legal person was not, in itself, sufficient for a fine to be imposed under the GDPR. It claimed that since a legal person could not act on its own, the culpable conduct of a natural person had to be identified and attributed to it. The controller argued that the DPA had failed to establish such attribution. The court agreed and, on 26 November 2020, annulled the fine. It found that the DPA had failed to establish that natural persons acting on behalf of the controller had engaged in culpable conduct. The DPA filed an extraordinary official appeal against this judgment with the Austrian Supreme Administrative Court (VwGH). The court stayed the proceedings pending the CJEU’s preliminary ruling in Case C-807/21 (Deutsche Wohnen SE), as the questions referred in that case were also relevant to the appeal proceedings. The CJEU published its judgement on this matter on 5 December 2023. The CJEU held that a fine under Article 83(4) GDPR, Article 83(5) GDPR and Article 83(6) GDPR may be imposed on anyone who qualifies as a controller where it is established that the controller committed the relevant infringement intentionally or negligently. A controller may be sanctioned where it could not have been unaware of the infringing nature of its conduct, regardless of whether it knew that its conduct infringed the GDPR. The CJEU further clarified that, where the controller is a legal person, the application of Article 83 GDPR does not require any action or knowledge on the part of its governing body. Member States may not impose additional substantive requirements for the imposition of fines beyond those laid down in Article 83 GDPR. For the determination of the fine, the controller may also constitute an undertaking within the meaning of EU competition law, with the turnover of the relevant economic unit being taken into account. Following the CJEU judgment, the Supreme Administrative Court annulled the Federal Administrative Court’s judgment on 1 February 2024. The Federal Administrative Court issued a new judgment on 27 December 2024, largely upholding the infringements but reducing the fine to €16,000,000. The controller appealed this decision before the Supreme Administrative Court. Holding — The court found that the controller gathered information concerning the political party affinity of the Austrian population based on anonymous surveys conducted by commissioned polling institutes. These surveys included specific questions concerning interest in election advertising, together with sociodemographic information such as age, level of education and income, place of residence and interest in advertising from political parties. Marketing groups were subsequently formed based on the sociodemographic data and place of residence. For each group, calculations were made to determine the likelihood that an individual with particular sociodemographic characteristics and religious affiliation would be interested in advertising from the political parties concerned. By assigning an identifiable individual to a particular marketing group, the controller linked that person to the probability values calculated for the group and the resulting political party affinity. The court held that the controller did not obtain consent from the data subjects to whom these probability scores were assigned. In total, political party affinity was attributed to approximately 2,200,000 individuals. The court reiterated that political party affinity scores attributed to identifiable individuals constituted personal data revealing political opinions within the meaning of Article 9(1) GDPR. It therefore upheld the finding that the controller had infringed Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. In assessing the controller’s culpability, the court relied heavily on the CJEU’s judgment in Deutsche Wohnen SE. It held that the fact that the controller believed it had complied with the GDPR because it had established a quality-assured organisation was not decisive. It pointed out that under GDPR, a legal person’s fault does not require knowledge or awareness on the part of the management body. The establishment of a data protection compliance system, like the obtaining of legal advice, did not in itself exculpate the controller. It stated that the decisive question was whether the controller could have been aware of the unlawfulness of the processing of political party affinity data during the relevant period. The court ruled that the controller had incorrectly assessed that political party affinity scores did not constitute personal data and that it had consequently failed to examine whether they constituted special categories of personal data under Article 9 GDPR. The court rejected the controller’s argument that political party affinity was processed only in relation to groups rather than in relation to specific identifiable individuals. It also rejected the argument that marketing classifications used for political advertising posed no risk to data subjects. The court concluded that given the controller’s resources and its ability to examine the applicable legal position, that legal assessment amounted to gross negligence concerning the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. Furthermore, the court ruled that the controller’s incorrect assessment that political party affinity scores did not constitute personal data or special categories of personal data also led it to conclude in its Data Protection Impact Assessment (DPIA) that the processing did not pose a high risk and that the scope of Article 35(3)(a) GDPR was therefore not applicable. The court held that the DPIA-related infringement was therefore absorbed from the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. It found no separate element of wrongdoing. The court additionally ruled that the same incorrect legal assessment resulted in the controller’s failure to include political party affinity as a separate category of personal data in its record of processing activities under Article 30(1)(c) GDPR. The court similarly found that these documentation failures did not contain a separate element of wrongdoing beyond that already covered by the infringement of Article 5(1)(a) GDPR and Article 9(1) GDPR. The court therefore discontinued the proceedings concerning the separate DPIA and record-of-processing infringements. It further held that, where a controller commits multiple GDPR infringements, a single aggregate fine must be imposed under Article 83(3) GDPR, the total amount of which may not exceed the amount applicable to the most serious infringement. The court reassessed the penalty and reduced it to €13,000,000, because the DPIA and record of processing infringements were no longer to be taken into account in determining the fine.

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) –

*Source: Court of Justice of the European Union, C-492/23, 2025-12-02 — https://overview.legal/posts/132130 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0492*

In Case C-492/23, the Court of Justice of the European Union (Grand Chamber) addressed a preliminary reference from the Curtea de Apel Cluj concerning whether an online marketplace operator (Russmedia Digital SRL and Inform Media Press SRL) qualifies as a data "controller" under Article 4(7) GDPR for personal data contained in advertisements published by user advertisers. The Court examined the allocation of controller responsibility, including potential joint control with user advertisers, and analyzed whether the operator's obligations under Articles 5(2), 9, 24, 25, and 32 GDPR—including prior identification of sensitive data and advertisers, refusal of unlawful advertisements, and implementation of security measures—preclude reliance on the intermediary liability exemptions under Articles 12 to 15 of Directive 2000/31/EC (E-Commerce Directive). No fine was imposed, as the ruling is an interpretive preliminary reference rather than an enforcement action.

### French Supreme Court upholds €8M CNIL fine against Apple for App Store ad tracking

*Source: Supreme Administrative Court, 2025-10-10 — https://overview.legal/posts/122852 — original: https://gdprhub.eu/index.php?title=CE_-_473833*

Facts — The DPA imposed an €8 million administrative fine on Apple (the controller) in 2022 (CNIL - SAN-2022-025). The DPA found that Apple used identifiers stored on users’ devices to enable personalized advertising in the App Store without first obtaining valid user consent, as required by Article 82 of the French Data Protection Act, which implements Article 5(3) of the ePrivacy Directive. Apple challenged the sanction before the Supreme Administrative Court (Conseil d’État), arguing that the DPA lacked jurisdiction, that the investigation violated Apple’s procedural rights, that the advertising-related processing did not fall within the scope of Article 82, and that the case should be referred to the Court of Justice of the EU. Apple also claimed that the fine was disproportionate. Holding — The court held that reading identifiers stored on user devices for the purpose of delivering personalised advertising constitutes access to information under Article 5(3) of the ePrivacy Directive, requiring the controller to obtain the user’s prior consent. It reasoned that since this operation was to implement personalized advertising it could not fall within the exemptions to the consent requirement. The court found that the national authority was competent because the controller’s establishment within the country contributed to the advertising operations in question. It did so by marketing devices pre-equipped with the App Store where personalized advertising appears and by providing Search Ads Specialists who helped monetize and optimize that advertising space. It also rejected the controller’s claim that the authority had violated its procedural rights, finding that the right to remain silent did not apply during CNIL investigations and that the authority had lawfully carried out the investigation providing sufficient opportunity for the controller to respond. Additionally, the court rejected Apple's request to reference the case to the Court of Justice of the EU stating that there wasn't any reasonable doubt Finally, it held that the €8 million fine was proportionate, noting the scale of the processing, the number of affected users, and the economic significance of the advertising activity.

### X - BA-6S/221/2019

*Source: Regional Administrative Court Bratislava, 2025-06-25 — https://overview.legal/posts/132105 — original: https://gdprhub.eu/index.php?title=X_-_BA-6S/221/2019*

Facts — Sociálna poisťovňa, the social insurance agency (the controller), processes applications for foreign invalidity pensions and forwards related documents to the social insurance institutions of other EU Member States. A data subject applied for a Danish invalidity pension. On 22 October 2018, the controller sent the data subject's sensitive personal data (including health data, personal identification number and a Danish personal identifier) to the Danish social insurance institution by ordinary (uninsured, untracked) second-class mail rather than by registered mail. The data subject could not confirm delivery and, in November 2018, filed a request with the Slovak DPA alleging that sending sensitive data by ordinary mail, without any proof of dispatch or protection against loss, violated their data protection rights. The controller resent the documents by the same method in December 2018. The DPA's first-instance decision (13 June 2019) found that the controller had violated Article 24(1) in conjunction with Article 32(1) and (2) GDPR, because sending sensitive personal data by ordinary rather than registered mail did not ensure a level of security appropriate to the risk. The DPA ordered the controller to use registered mail for such dispatches going forward and imposed a fine of €50,000. The controller's appeal was rejected, and the Slovak DPA president upheld the first-instance decision. The controller then brought an action before the Regional Administrative Court Bratislava, arguing among other things that: the parcel had in fact been delivered (as confirmed by the Danish institution by email), registered mail offers no greater protection against loss of confidentiality than ordinary mail, only one data subject was concerned and no damage had occurred and the decision's operative part improperly referred to the data of pension applicants generally, not just the individual data subject who had filed the complaint. Holding — The court did not rule on the substance of the security measures dispute, since it found the DPA's decision unreviewable on procedural grounds. First, the court held that the operative part of the DPA's decision was contradictory and imprecise. The administrative proceedings had been triggered by, and the evidence had concerned, an alleged violation of rights of one specific data subject (loss of their parcel). However, the decision extended the finding of violation to the controller's general practice of sending all pension applicants' data by ordinary mail. The court noted that a systemic pattern affecting other data subjects could, at most, be taken into account as an aggravating circumstance when setting the fine, but it could not itself form part of the sanctioned conduct in a proceeding limited to one individual's complaint. Second, the court found that the DPA had failed to properly assess evidence submitted by the controller showing that the parcel had actually been delivered to the Danish institution. The DPA only addressed this evidence for the first time in its written observations in the court proceedings, not in the administrative decision itself, even though the decision's entire reasoning rested on the (contested) premise that the parcel had been lost. Third, the court observed that the fine had been imposed under a provision of the national Data Protection Act that only permits fines for breaches of Articles 25 to 32 GDPR, whereas the DPA's decision had also relied on Article 24(1) GDPR, which is not covered by that provision. Because of these defects, the court annulled the DPA's decision and remanded the case for further proceedings, without addressing the parties' remaining arguments on the merits . The court instructed the DPA to first clearly establish the specific conduct underlying the alleged offence and then decide the case again, addressing all evidence submitted by the controller. The court awarded the controller full reimbursement of costs.

### Judgment of the Court (Third Chamber) of 11 April 2024.#GP v juris GmbH.#Request for a preliminary ruling from the Landgericht Saarbrücken.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 82 – Right to compensation for damage caused by data processing that infringes that regulation – Concept of ‘non-material damage’ – Impact of the seriousness of the damage suffered – Liability of the controlle

*Source: Court of Justice of the European Union, C-741/21, 2024-04-11 — https://overview.legal/posts/132262 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0741*

In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject GP and juris GmbH concerning GP's claim for compensation under Article 82 GDPR after the company processed his personal data for marketing purposes despite his objections. The Court held that "non-material damage" under Article 82(1) GDPR must be interpreted broadly and is not subject to a seriousness threshold, that a controller may be exempt from liability under Article 82(3) if it proves it was not in any way responsible for the infringement (including where a person acting under its authority under Article 29 was at fault), and that the criteria for administrative fines under Article 83 GDPR do not apply to the assessment of compensation amounts.

### Judgment of the Court (First Chamber) of 22 June 2023.#Proceedings brought by J.M.#Request for a preliminary ruling from the Itä-Suomen hallinto-oikeus.#Reference for a preliminary ruling – Processing of personal data – Regulation (EU) 2016/679 – Articles 4 and 15 – Scope of the right of access to information referred to in Article 15 – Information contained in log data – Article 4 – Definition of ‘personal data’ – Definition of ‘recipients’ – Temporal application.#Case C-579/21.

*Source: Court of Justice of the European Union, C-579/21, 2023-06-22 — https://overview.legal/posts/132284 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0579*

In Case C-579/21, the Court of Justice of the European Union ruled on a preliminary reference from the Itä-Suomen hallinto-oikeus (Administrative Court of Eastern Finland) concerning a dispute between J.M. and Pankki S, a Finnish bank, after the Apulaistietosuojavaltuutettu (Assistant Data Protection Supervisor) rejected J.M.'s request for access to certain log data. The core issue was the scope of the right of access under Article 15 of the GDPR, specifically whether log data containing information about who accessed personal data and when constitutes "personal data" and whether the controller must communicate the identities of recipients. The Court held that log data relating to consultations of a data subject's personal data constitutes personal data under Article 4(1) of the GDPR, and that a data subject is entitled to obtain the identities of recipients of their data, subject only to exceptions expressly provided by law or overriding rights of third parties. No fine was imposed as this was a preliminary ruling proceeding.

### Judgment of the Court (Fifth Chamber) of 4 May 2023.#UZ v Bundesrepublik Deutschland.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to processing – Controllership – Article 6 – Lawfulness of processing – Electronic file compiled by an administrative authority relating to an asylum application – Tra

*Source: Court of Justice of the European Union, C-60/22, 2023-05-04 — https://overview.legal/posts/132289 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0060*

In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik Deutschland regarding the processing of personal data in an asylum application file. The Court held that an administrative authority transmitting an electronic asylum file to a competent national court via an electronic mailbox constitutes processing under the GDPR, and that where both the authority and the court determine the purposes and means of processing, they are joint controllers under Article 26, requiring an arrangement allocating responsibility and maintaining records of processing activities under Article 30. The Court further clarified that transmission of personal data without the data subject's consent constitutes unlawful processing, triggering the right to erasure under Article 17(1)(d) and the right to restriction under Article 18(1)(b), and that national courts must disregard such unlawfully processed data. No fine was imposed.

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

### CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is

*Source: CJEU, 2010-06-29 — https://overview.legal/posts/6182 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62008CJ0028&ref=6182*

Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69)

## Guidance

### Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)

*Source: EDPB, opinion-222024-on-certain-obligations-following-from-the-en, 2024-10-09 — https://overview.legal/posts/125715 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-222024-on-certain-obligations-following-from-the_en*

A dopted 1 Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub - processor(s) Adopted on 7 October 2024 Adopted 2 Executive summary The Danish SA requested the EDPB to issue an opinion on matters of general application pursuant to Article 64(2) GDPR. The opinion contributes to a harmonised interpretation by the national supervisory authorities of certain aspects of Article 28 GDPR, whe re appropriate in conjunction with Chapter V GDPR. In particular, the…

### Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-codes-of-conduct-and-monitoring-bodies, 2019-06-04 — https://overview.legal/posts/38051 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-12019-on-codes-of-conduct-and-monitoring-bodies-under-regulation_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the framework for codes of conduct and monitoring bodies under Articles 40 and 41 of the GDPR. The guidelines address the admissibility, content, and approval requirements for draft codes of conduct, as well as the criteria and accreditation process for monitoring bodies responsible for verifying compliance with such codes. This version (2.0) was adopted on 4 June 2019 following public consultation.

### Position Paper on the derogations from the obligation to maintain records of processing activities pursuant to Article 30(5) GDPR

*Source: EDPB, position-paper-on-the-derogations-from-the-obligation-to-maintain-records-en, 2018-04-19 — https://overview.legal/posts/126338 — original: https://www.edpb.europa.eu/documents/other-guidance/position-paper-on-the-derogations-from-the-obligation-to-maintain-records_en*

Position Paper on the derogations from the obligation to maintain records of processing activities pursuant to Article 30(5) GDPR Други насоки 19 April 2018 During its first plenary meeting the European Data Protection Board endorsed the GDPR related WP29 Guidelines. Position Paper on the derogations from the obligation to maintain records of processing activities pursuant to Article 30(5) GDPR Related topics: #Accountability Related documents Съвместно становище 01/2025 на ЕКЗД и ЕНОЗД във връзка с Предложението за регламент относно мерките за опростяване на процедурите за МСП и МПСПК и по-специално задължението за водене на регистър съгласно член 30, параграф 5 от ОРЗД Законодателно становище09 July 2025#Controller/processor#ОтчетностRead more about Съвместно становище 01/2025 на ЕКЗД и…

### Opinion 14/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR

*Source: EDPB, opinion-142026-on-the-europrivacy-certification-criteria-en, 2026-04-16 — https://overview.legal/posts/125682 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-142026-on-the-europrivacy-certification-criteria_en*

Opinion 14 / 2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR Adopted on 15 April 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64 (2) and Article 42 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free…

### Opinion 34/2025 on the draft decision of the Greek Supervisory Authority regarding C.E.C.L certification criteria

*Source: EDPB, edpb-opinion-202534-el-sacertificationcriteriacecl-en, 2025-12-02 — https://overview.legal/posts/51416 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-342025-on-the-draft-decision-of-the-greek-supervisory_en*

Adopted Opinion 34/ 2025 on the draft decision of the Greek Supervisory Authority regarding C.E.C.L certification criteria Adopted on 02 December 2025 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Opinion 16/2025 regarding the draft decision of the German North Rhine Westphalia Supervisory Authority regarding Trusted Site Data Privacy (TÜV IT) certification criteria

*Source: EDPB, edpb-opinion-202516-tuv-certificationcriteria-en-0, 2025-07-14 — https://overview.legal/posts/51080 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-162025-regarding-the-draft-decision-of-the-german_en*

Adopted 1 Opinion 16 /2025 regarding the draft decision of the German North Rhine Westphalia Supervisory Authority regarding Trusted Site Data Privacy (TÜV IT) certification criteria Adopted on 8 July 2025 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data…

### Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH

*Source: EDPB, edpb-opinion-202515-dbo-certificationcriteria-en, 2025-07-14 — https://overview.legal/posts/51079 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-152025-on-the-draft-decision-of-the-austrian_en*

Adopted 1 Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority ( AT SA) regarding the certificat ion criteria of BDO Consulting GmbH Adopted on 8 July 2025 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of…

### Opinion 3/2025 on the draft decision of the French Supervisory Authority (FR SA) regarding the “Lexing GDPR certification criteria”

*Source: EDPB, edpb-opinion-202523-lexingcertificationcriteria-en, 2025-04-14 — https://overview.legal/posts/50756 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-32025-on-the-draft-decision-of-the-french-supervisory_en*

EDPB, Opinion 3/2025 on the draft decision of the French Supervisory Authority (FR SA) regarding the “Lexing GDPR certification criteria”, 2025.

## Enforcement decisions

### AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator

*Source: AEPD (Spain), 2026-07-13 — https://overview.legal/posts/109001 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202310345*

Facts — On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data subject) The duplicate SIM card was delivered to an impersonator after they passed the established protocols for verifying the applicant's identity. The controller appealed the decision by the Spanish DPA to impose a fine because they claimed that they had appropriate security measures. The controller claims that, by focusing on the result, the Spanish DPA is acting under strict liability. The mere fact that identity theft occurred does not equal a lack of due diligence on the part of the controller. The controller also requested a reduction of the fine on the basis of Article 83(5)(a) GDPR because there were no aggravating circumstances and no special categories of data were processed Holding — The Spanish DPA found a violation of Article 6(1) GDPR because issuing a duplicate SIM card and delivering it to a person other than the telephone line holder constitutes the processing of personal data within the meaning of Article 4(1) GDPR without a legal basis because the data subject did not give consent. The DPA ruled that the controller violated their duty of care because the security measures lacked the dilligence required. According to Article 5(2) GDPR (principle of proactive responsibility) the controller must demonstrate compliance to the GDPR. Proactive responsibility means that the measures are compliant to the GDPR under normal circumstances. The controller must also demonstrate that the measures are compliant with the GDPR and that they are effective in the specific context and purposes of processing (Article 24 en 25 GDPR). The controller had a higher standard of care because of a documented risk to SIM swap attacks and the high scale of processing. Recital 74 GDPR states that the controller’s must implement effective and appropriate measures that take into account the nature, scope and context, and purposes of processing. The card allows an impersonator to access additional data through which they can carry out actions with grave consequences. The controller did not demonstrate that their security measures sufficiently protected the data subject. Factual circumstances should have alerted DIGI to the fraud: the SIM card replacement was processed at a physical store in a different province from where the data subject resided. The Spanish DPA flagged that the controller did not ask the reason for issuing the card and they did not verify whether the old SIM card was functioning. Therefore the security measures were not appropriate to prevent'SIM swap attacks' that are prevalent in the telecom context. With regard to to the height of the fine, the Spanish DPA found that no new legal arguments were made that would lead to the reduction of the fine.

### NAIH fines online store HUF 10M for missing and inadequate privacy notice

*Source: NAIH (Hungary), 2026-04-30 — https://overview.legal/posts/262255 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-4462-5-2026*

Facts — The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The controller’s main business activity was the wholesale distribution of beverages. The personal data of the data subjects was processed on the website of the online store for registration, placing orders, billing, communication, delivery, creation of user accounts, and newsletter subscription. During the period under review, i.e. between January 2020 and October 2025, no standalone privacy notice was available on the website. The previously archived privacy notice and the data processing section included in the general terms and conditions described the processing operations in a rather brief and general manner. The controller argued that the inaccessibility of the privacy notice followed from a technical error that was corrected upon discovery. Holding — The DPA found that the controller had violated Articles 5(1)(a), 5(2), 12(1), 13(1)(a), (c), and (e) as well as 13(2)(a)–(e) GDPR and issued it a fine of HUF 10,000,000 (€27,300). When issuing the fine, the DPA took into account that the identified infringements followed from systemic inadequacies of the privacy notice and were of continuous nature. In addition, the DPA ordered the controller to develop and publish a uniformly structured privacy notice that is aligned with its actual processing operations. First, the DPA identified a violation of the principle of transparency laid down in Article 5(1)(a) GDPR: the information provided to data subjects about the processing of their personal data was either incomplete or completely absent, and changes could not be tracked. Second, the DPA held that the controller had violated the principle of accountability set forth in Article 5(2) GDPR, as it had failed to submit appropriate documentation covering the period under review. In addition, the controller’s data processing practices could not be continuously monitored or subsequently verified based on the documentation it had provided. Finally, the DPA confirmed that the controller had not complied with the requirements laid down in Articles 12(1), 13(1)(a), (c) and (e), and 13(2)(a)–(e) GDPR. Due to the lack of a privacy notice, the controller could not demonstrate that it had provided data subjects with the information required under Article 13 GDPR apart from brief, general statements in the archived privacy notice and the general terms and conditions. The controller had thus failed to provide the data subjects clear and differentiated information regarding the purpose and legal basis for each processing operation. Furthermore, the controller had not adequately identified the recipients or the storage period of personal data or information on the data subjects' rights. Due to the form and scope of the information provided, the controller had also infringed Article 12(1) GDPR.

### UODO (Poland) - DKN.5131.7.2022

*Source: UODO (Poland), 2026-04-13 — https://overview.legal/posts/53109 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.7.2022*

Facts — An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone application between July 2020 and March 2021 to send pictures of customer contracts containing the personal data of individuals residing at addresses visited during door-to-door sales (the data subjects). The controller had not authorised this practice, and former employees of the sub-processor could still access the personal data through the app. The controller identified the use of the app as a data breach and notified the supervisory authority about it in April 2021. The DPA initiated administrative proceedings in March 2022. Holding — First, the DPA held that the controller had violated the principles of integrity and confidentiality enshrined in Article 5(1)(f) and the principle of accountability laid down in Article 5(2) GDPR. It had also violated Articles 24(1), 25(1), 28(1), 32(1) and 32(2) GDPR, which specify these principles. The DPA issued the controller a reprimand. The DPA found the controller had failed to implement appropriate technical and organisational measures itself and also failed to properly verify whether the (sub-)processors had provided sufficient guarantees that they had implemented such measures. The data protection agreements required in Article 28(1) GDPR were very general in nature, and none of the parties in the chain of contracts had conducted a risk analysis to select appropriate security measures. In addition, the controller had not continuously monitored the processing activities. Second, the DPA held that the two processor and the sub-processor had violated Articles 32(1) and 32(2) GDPR read in conjunction with Article 28(4) GDPR. They had all failed to implement appropriate technical and organisational measures to ensure the security of personal data processing. The sub-processor was largely held responsible for the data breach – it had started using the app to process customers’ personal data without authorisation from the controller or the processors. Furthermore, the DPA pointed out the sub-processor should have verified whether the application would allow access to the personal data through it even after the termination of the employment relationship. The DPA reprimanded the processors and fined the sub-processor €2,415.

### Datatilsynet (Denmark) - 2020-422-0026

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6312 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-422-0026*

Facts — The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data processing agreements and processor audit practices. Holding — The DPA first held that, based on the information provided by the controller, there were no indications that the controller's assessment of the legal bases for the processing were incorrect. The DPA then held that the use of processors had been lawful and that the relevant data processing agreements satisfied the requirements of Article 28 GDPR. However, the DPA reprimanded the controller, partly for its lack of clear auditing procedures, and partly for not actually conducting audits in line with the routines that did exist. The DPA held that the accountability principle in Article 5 GDPR entails an obligation for the controller to oversee the security of the data processing operations performed by a processor. The DPA highlighted that entering into a data processing agreement that contains security obligations is not sufficient, and that the controller must also oversee that the processor actually adheres to the agreement. The fact that the controller had auditing procedures in place was not good enough if these auditing procedures were not being followed in practice.

### UODO (Poland) - DKN.5131.12.2022

*Source: UODO (Poland), 2026-06-11 — https://overview.legal/posts/144031 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.12.2022*

Facts — The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor). The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022. Holding — The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated Article 28(1) GDPR: while the controller had concluded a data processing agreement with the processor, it had failed to verify whether the processor provided sufficient guarantees to implement appropriate technical and organisational measures. Second, the DPA found that the controller had infringed Articles 24(1), 25(1), and 32(1) and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of processing via the email system. The DPA took into account that the controller had not taken any measures to minimise the risks identified. In addition, the DPA pointed out that the breach involved sensitive health data, and the passwords used by the controller did not meet the usual security requirements. As a consequence of the previous violations, the controller had infringed the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR as well. Finally, the DPA found a violation of Article 35(1) GDPR in conjunction with Article 35(3) GDPR due to the controller’s failure to conduct a data protection impact assessment. The DPA also reprimanded the processor for the failure to implement appropriate technical and organisational measures to ensure the security of processing – the processor had failed to conduct a risk analysis and to implement adequate security measures, such as blocking a user’s account after a certain amount of login attempts. The DPA held that the processor had violated Articles 32(1) and 32(2) GDPR in conjunction with Article 28(3)(c) GDPR.

### UODO (Poland) - DKN.5131.5.2025

*Source: UODO (Poland), 2026-05-25 — https://overview.legal/posts/184680 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.5.2025*

Facts — A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’) personal data to a specialised entity established for this purpose (the processor). In January 2023, a work laptop belonging to an employee of the processor was stolen from the trunk of a car parked in a parking garage. This resulted in a breach of confidentiality of the data subjects’ personal data, including names, addresses, ID numbers, and land registry numbers. The controller notified this data breach to the DPA later in January 2023. The DPA conducted an investigation and initiated administrative proceedings regarding the GDPR compliance of the processing operations carried out by the controller and the processor in March 2025. Holding — The DPA issued the controller a fine of PLN 21,000 (€4,900) and the processor a fine of PLN 12,500 (€2,900). First, the DPA held that the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of personal data processing – the controller had failed to demonstrate that it had conducted a thorough risk assessment in a manner that would have allowed for the selection of adequate security measures. These infringements resulted in the violations of the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR. Second, the DPA found that the controller had also violated Article 28(1) GDPR: it had failed to verify the adequacy of the technical and organisational measures implemented by the processor. Finally, the DPA came to the conclusion that the processor had infringed Articles 32(1) and 32(2) GDPR in conjunction with Articles 28(3)(c) and 28(3)(f) GDPR. The DPA held that the processor had failed to assist the controller in fulfilling its obligations and contributed to the controller’s GDPR violations. Unlike the controller, the processor had conducted a risk assessment covering the processing operations at issue; however, the processor had not implemented security measures to protect data stored on laptops used outside of its office premises, such as encryption.

### UODO (Poland) - DKN.5131.27.2023

*Source: UODO (Poland), 2026-05-19 — https://overview.legal/posts/83471 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.27.2023*

Facts — A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information regarding whether certain individuals were subject to mandatory quarantine to prevent and combat the SARS-COV-2 virus. An employee of the controller posted a file containing this information on a private server in November 2020. An automated search engine indexing bot subsequently accessed the file and made its full contents available in search results to any Internet user. The supervisory authority received an electronic report concerning a potential data breach in February 2021. The controller had not notified the DPA or the data subjects of this incident, as it concluded it had not acted as a controller in the context of the processing operations at issue. The DPA launched an investigation into the unauthorised disclosure of personal data and initiated administrative proceedings against the controller in August 2023. Holding — The DPA issued the controller three separate fines amounting to PLN 33,700 (€7,800) in total, as it considered its GDPR violations were the result of three separate courses of conduct. It held that the social welfare unit had clearly determined the means and purposes of processing and acted as controller within the meaning of Article 4(7) GDPR – the employee responsible for the processing operations had acted with the unit’s authorisation, at its instruction, and on its behalf. First, the DPA held the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures and imposed a fine of PLN 15,000 (€3,460) on the controller. This resulted in violations of the principles of integrity, confidentiality and accountability set out in Articles 5(1)(f) and 5(2) GDPR. There was an internal document in effect during the data breach that identified the risk level of processing as high. However, the DPA pointed out this document did not include, among other things, the number of data subjects, the periods for data storage, and the duration of the processing. The measures implemented were not reviewed or updated and also proved to be ineffective. Second, the DPA issued the controller a fine of PLN 5,500 (€1,270) for an infringement of Article 33(1) GDPR due to a failure to report the data breach to the supervisory authority. Finally, the DPA held that the controller had violated Article 34(1) GDPR by failing to notify the data subjects of the data breach and imposed a fine of PLN 13,200 (€3,060) on the controller. In addition, it ordered the controller to notify the data subjects of the breach in question.

### Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-14 — https://overview.legal/posts/184678 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542/2026*

Facts — Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

## Recent developments

### DPC (Ireland) - IN-19-9-4

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291263 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_IN-19-9-4*

The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR.The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR. English Summary. English Summary On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the

### What Happened to the Risk-Based Approach to Data Transfers?

*Source: Future of Privacy Forum, 2022-09-27 — https://overview.legal/posts/6271 — original: https://fpf.org/blog/what-happened-to-the-risk-based-approach-to-data-transfers/#entry-912*

The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute principles), the RBA of Article 24 therefore applies. Other than the DPAs assume, this is not contradicted by the ECJ in Schrems II nor by the EDPB recommendations on additional measures following the Schrems II judgment, according to Lokke Moerel, Professor of Global ICT Law at Tilburg University and a Dutch Cyber Security

### EDPB and EDPS support streamlining AI Act implementation but call for stronger safeguards to protect fundamental rights

*Source: European Data Protection Board, 2026-01-21 — https://overview.legal/posts/52417 — original: https://www.edpb.europa.eu/news/news/2026/edpb-and-edps-support-streamlining-ai-act-implementation-call-stronger-safeguards_en*

Brussels, 21 January - The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted a Joint Opinion on the European Commission’s Proposal for the ‘Digital Omnibus on AI’. The Proposal seeks to simplify the implementation of certain harmonised rules under the AI Act to ensure their effective application.The EDPB and the EDPS support the objective of addressing practical challenges relating to the implementation of the AI Act. Administrative simplificat

### UK data protection reform: How the UK's GDPR may change

*Source: Hogan Lovells, 2022-09-06 — https://overview.legal/posts/6285 — original: https://www.engage.hoganlovells.com/knowledgeservices/news/uk-data-protection-reform-how-the-uk-gdpr-may-change#entry-214*

> The current version of the Bill seeks to maintain the majority of key principles that underpin the UK data protection law framework, while at the same time modifying certain key provisions in relation to accountability, lawful grounds for processing, data subject access requests and cookies, amongst others.

A [consolidated redline version of the UK GDPR by Hogan Lovells](https://www.engage.hoganlovells.com/knowledgeservices/attachment_dw.action?attkey=FRbANEucS95NMLRN47z%2BeeOgEFCt8EGQJsWJiCH

### Third noyb "Advent Reading" from Facebook/DPC Documents

*Source: noyb - European Center for Digital Rights, 2021-12-12 — https://overview.legal/posts/53295 — original: https://noyb.eu/en/third-noyb-advent-reading-facebookdpc-documents*

noyb's third "Advent Reading": Facebook's laughable Record of Processing Activities (ROPA) In its third "Advent Reading" (in protest of the DPC unlawfully removing noyb from a pending procedure) noyb is publishing Facebook's main GDPR compliance document: Facebook's "Record of Processing Activities" under Article 30 GDPR (short: "ROPA"). Such legally required document should allow to easily assess Facebook's compliance with the GDPR, but in fact it only has a laughable four pages. Usually such d

## Literature

### All Talk, No Action? The Effect of the GDPR Accountability Principle on the EU Data Protection Paradigm

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132554 — original: https://doi.org/10.21552/edpl/2022/1/6*

ED P L 1 | 2 0 2 2 1 9 A l l T al k, N o A ct i o n ? T h e Ef f ect o f t h e G D P R A cco u n t ab i l i t y P r i n ci p l e o n t h e EU D at a P r o t ect i o n P ar ad i gm T u u l i a K a r j a l a i n e n * T h e G e n e r a l D a t a P r o t e c t i o n R e g u l a t i o n ( 679/ 201 6, ’ G D P R ’ ) i n t r o d u c e d t h e a c c o u n t a b i l i t y p r i n c i p l e t o t h e f i e l d o f E U d a t a p r o t e c t i o n l a w . T h e p r i n c i p l e a i m s t o i n c r e a s e t h e c o n t r o l l e r ’ s r e s p o n s i b i l i t y f o r i t s p e r s o n a l d a t a p r o c e s s i n g a n d t o p r o m o t e a r i s k - b a s e d a p p r o a c h t o d a- t a p r o t e c t i o n . H o w e v e r , a c c o u n t a b i l i t y , a s i m p l e m e n t e d i n t h e G D P R , f a i l s t o m e e t t h e s e o b- j e c t i v e s . A c c o u n t a b i l i t y i s s o m e t i m e s s e e n a s a s i g n i f i c a n t p a r a d i g m s h i f t – a s a m o v e a w a y f r o m t r a n s p a r e n c y a n d c h o i c e - b a s e d d a t a s u b j e c t c o n t r o l t o w a r d s c o m p a n y l i a b i l i t y . H o w- e v e r , t h e p r i n c i p l e d o e s n o t t r u

### General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain

*Source: SCRIPTed A Journal of Law Technology & Society, 2026-06-30 — https://overview.legal/posts/132370 — original: https://doi.org/10.2218/scrip.12300*

This article examines how the final version of the EU Artificial Intelligence Act (“AI Act”, adopted 2024) allocates obligations across the AI value chain, with a focus on general-purpose AI (“GPAI”) or foundation models. It proposes a taxonomy of key actors – foundation model providers, fine-tuners, integrators, and deployers – and analyses the interfaces between them, including documentation tools (model cards, system cards) and logging requirements. Building on principles of control, foreseea

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation”

*Source: Athens Journal of Law, 2025-01-02 — https://overview.legal/posts/132443 — original: https://doi.org/10.30958/ajl.11-1-3*

The recent Regulation that sets down harmonised rules on Artificial Intelligence in the European Union, known as the "AI Act," includes a significant requirement for human oversight in high-risk AI systems during their use (art. 14). This requirement embodies the "human-in-command" approach, ensuring both legal and ethical compliance. The AI Act is intended to complement the General Data Protection Regulation (hereinafter GDPR), thereby forming a consistent and comprehensive legal framework. Thi

## Tools

### CNIL record of processing activities template

*Source: CNIL, 2026-07-17 — https://overview.legal/posts/125621 — original: https://www.cnil.fr/en/record-processing-activities*

The French DPA's explanation of the Article 30 record-keeping obligation with a simplified downloadable register template aimed at SMEs: one sheet per processing activity covering purposes, data categories, recipients, transfers, retention and security measures.

### ICO documentation templates (records of processing, Article 30)

*Source: ICO, 2026-07-17 — https://overview.legal/posts/125620 — original: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/documentation/*

Guidance plus downloadable controller and processor documentation templates for the Article 30 record of processing activities: what must be recorded, who is exempt, and spreadsheet templates organisations can adopt directly.

### GDPR.eu compliance checklist

*Source: GDPR.eu (Proton), 2026-07-17 — https://overview.legal/posts/125625 — original: https://gdpr.eu/checklist/*

Widely used plain-language GDPR compliance checklist covering lawful basis, data inventory, accountability documents, data subject rights, security and transfer requirements. Published by Proton as part of the GDPR.eu resource site (an unofficial but well-maintained companion to the Regulation).

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals

---
Generated by overview.legal · https://overview.legal/topics/accountability · 2026-08-22
