# Accuracy — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/accuracy
> Sources are cited per item. Verify against the official texts before relying on them.

Principle that personal data must be accurate and up to date

## Overview

## Legal Framework

Article 5(1)(d) GDPR establishes the accuracy principle, requiring that personal data be accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that data which are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay. This principle is operationalized through Article 16 GDPR, which grants data subjects the right to obtain from the controller rectification of inaccurate personal data without undue delay. Article 16 also provides the right to have incomplete personal data completed, including by means of a supplementary statement, taking into account the purposes of processing.

The accuracy principle does not impose an absolute guarantee of factual correctness. Rather, it requires proportionate measures appropriate to the processing context. For processing under archiving, scientific research, or statistical purposes, Recital 156 indicates that appropriate safeguards—including data minimization—must be applied, which indirectly supports accuracy by limiting the scope of data processed.

## Key Developments

Dutch administrative case law has drawn a critical boundary on the scope of Article 16. The Afdeling bestuursrechtspraak has consistently held that the rectification right is not intended to alter or remove impressions, opinions, research findings, or conclusions with which the data subject disagrees (e.g., ECLI:NL:RVS:2024:243). This means a medical professional's assessment in a patient file, even if contested, generally falls outside the rectification mechanism unless it contains objectively demonstrable factual errors.

The CJEU's ruling in *Minister voor Immigratie v. M* (17 July 2014) established that the right of access under Article 15 serves as a prerequisite for exercising rectification rights. The controller satisfies the access requirement by providing a full summary of the data in an intelligible form that allows the data subject to verify accuracy—a literal copy of every document is not required.

The *Rechtbank Den Haag* (C/09/608204 / HA RK 21-96) addressed rectification requests in the context of fraud registers, clarifying that proceedings under Article 35 UAVG are limited to granting or denying requests under Articles 15–22 GDPR. Claims for damages or financial compensation fall outside that procedural scope and must be pursued through separate civil action.

Enforcement actions confirm that accuracy failures carry financial consequences. The Spanish DPA fined Vodafone España €5,000 after a customer was wrongfully charged due to incorrect data handling, and the Croatian DPA (AZOP) imposed a €20,000 fine on a telecommunications company following a complaint about inaccurate personal data processing.

## Practical Guidance

- **Distinguish factual errors from contested opinions.** Before processing a rectification request, assess whether the challenged data constitutes an objectively verifiable fact or a professional judgment. Article 16 does not require controllers to amend subjective assessments, research conclusions, or interpretive findings that the data subject simply disputes.

- **Ensure access mechanisms enable accuracy verification.** Provide data subjects with a comprehensive, intelligible summary of their processed data so they can identify potential inaccuracies. This satisfies the access prerequisite identified in *Minister v. M* and facilitates efficient rectification handling.

- **Establish internal rectification workflows with defined timelines.** Article 16 requires rectification "without undue delay." Implement procedures that triage incoming requests, verify factual claims, and execute corrections or supplementary statements within a documented, reasonable period.

- **Maintain accuracy in fraud and risk registers with particular care.** Registrations in incident registers, FSV entries, or similar databases must be factually substantiated. Courts scrutinize whether recorded inaccuracies were deliberate or negligent, and wrongful registrations can trigger both rectification obligations and separate liability claims.

- **Account for sector-specific accuracy obligations.** Police data, insurance records, and financial sector registrations each carry additional accuracy requirements beyond the GDPR baseline. Verify that processing in these contexts meets both the general accuracy standard and any applicable sectoral rules.

## Legislation (full text of key provisions)

### Right to rectification

*Source: GDPR, gdpr-art-16-en, 2016-04-27 — https://overview.legal/posts/90424*

The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

### Recital 51 — Innovative technology for cybersecurity

*Source: NIS2, nis2-rec-51-en, 2022-12-14 — https://overview.legal/posts/96630*

Member States should encourage the use of any innovative technology, including artificial intelligence, the use of which could improve the detection and prevention of cyberattacks, enabling resources to be diverted towards cyberattacks more effectively. Member States should therefore encourage in their national cybersecurity strategy activities in research and development to facilitate the use of such technologies, in particular those relating to automated or semi-automated tools in cybersecurity, and, where relevant, the sharing of data needed for training users of such technology and for improving it. The use of any innovative technology, including artificial intelligence, should comply with Union data protection law, including the data protection principles of data accuracy, data minimisation, fairness and transparency, and data security, such as state-of-the-art encryption. The requirements of data protection by design and by default laid down in Regulation (EU) 2016/679 should be fully exploited.

## Case law

### BVwG - W254 2321912-1

*Source: Federal Administrative Court, 2026-04-14 — https://overview.legal/posts/125597 — original: https://gdprhub.eu/index.php?title=BVwG_-_W254_2321912-1*

Facts — The data subject, an Austrian citizen residing in Vienna, was enrolled in a distance-learning programme at a German university (the controller). When the data subject enrolled, the controller registered them under the official name shown on their identity document. The data subject experienced gender dysphoria and had chosen a gender-neutral name for themselves which was a different to their legal name. They requested the controller to rectify and replace their official name with their chosen name. They stated that the chosen name reflected better their gender identity. The controller refused the change because the data subject had not provided either an official document proving a legal name change or a dgti supplementary ID card. This is a German supplementary identity document issued by Deutsche Gesellschaft für Trans*- und Inter*geschlechtlichkeit e.V. (dgti e.V.), a German association supporting trans and intersex persons, which may certify, among other things, a chosen first name, pronouns, gender and a current photo. The controller claimed that such a document would allow it to record changes concerning pronouns and first name in its administrative system. On 6 May 2024 the data subject lodged a complaint with the Austrian DPA. They argued that the controller failed to comply with their rectification request under Article 16 GDPR. The data subject also relied on the CJEU’s judgement in Deldits case(C-247/23), which concerned the rectification of gender identity data under Article 16 GDPR. As the controller was established in Germany, the Austrian DPA considered that the Thuringian DPA was the lead supervisory authority for the cross-border processing. The Thuringian DPA held that the controller had not violated Article 16 GDPR. Because the complaint had been lodged with the Austrian DPA and the outcome was a dismissal of the complaint, Article 60(8) GDPR required the supervisory authority with which the complaint had been lodged to adopt the decision and notify the data subject. The data subject then appealed that decision before the Austrian Federal Administrative Court. They argued that the continued use of the official name resulted in misidentification and systematic misgendering. They also stated that the prerequisite to submit further documents proving the name change was excessive and disproportionate. Moreover, the data subject requested that the chosen name should at least be used in non-legally binding university systems, such as the learning platform, email address, campus card and attendance lists. The controller noted that it was legally obligated to identify students and process their data based on official identification documents. This applied, on the one hand, to the transcripts addressed in the administrative proceedings, but also to other academic achievements by students, such as individual coursework, seminar work, or work within interdisciplinary study teams. Holding — The court first confirmed that the cooperation procedure under Article 56 GDPR and Article 60 GDPR had been correctly applied. The Thuringian DPA acted as the lead supervisory authority because the controller was established in Germany. However, since the complaint was dismissed, the Austrian DPA, as the authority with which the complaint had been lodged, adopted the rejection decision pursuant to Article 60(8) GDPR. The court held that there was no violation of Article 16 GDPR. It emphasised that the accuracy of personal data must be assessed in relation to the purpose of the processing. The controller processed the official name in order to identify the student, administer the study programme, issue certificates and academic degrees that aim to be recognized outside the university and certify the student's completion of the program to third parties. The court held that in light of these processing purposes, the processed data of the data subject should be regarded as accurate within the meaning of Article 16 GDPR. Since the data subject had not officially changed their name and had not submitted any official document, the court found that the official name was not inaccurate for the controller’s stated processing purposes. It further stated that the requirement to provide proof of a name change or to present a supplementary identification document was proportionate. The court acknowledged that gender identity is protected as part of private life under Article 8 ECHR. However, it distinguished the case from Deldits. In Deldits, the issue concerned the rectification of gender data in a public register and CJEU held that a data subject requesting the correction of gender identity data may be required to provide relevant and sufficient evidence, taking into account the circumstances of the individual case, in order to establish the inaccuracy of such data. By contrast, this case concerned university administration and academic documents whose effects extend beyond the university and there was no official change of the data subject’s name. Therefore, the court maintained that the controller could continue to use the official name unless the data subject provided official proof of name change. The court further noted that the request to use the chosen name only in non-legally binding systems went beyond the original complaint.

### BVwG - W291 2298748-1

*Source: Federal Administrative Court, 2025-10-31 — https://overview.legal/posts/49235 — original: https://gdprhub.eu/index.php?title=BVwG_-_W291_2298748-1*

Facts — A data subject wished to be addressed in a gender-neutral way and claimed they were misgendered by two companies (the controllers) in profile settings, tickets, and train announcements. They initially sent a tweet to one of the involved controllers asking whether gender-neutral options would be available and later filed a complaint with the Equal Treatment Commission and the Austrian Data Protection Authority (DSB), claiming a violation of their right under Article 16 GDPR. The DPA rejected the complaint, arguing that the data subject had not submitted a formal request for rectification to the controllers. The complainant then appealed to the Federal Administrative Court. Holding — The Court dismissed the appeal, holding that there was no violation of the GDPR because the data subject had not submitted a formal request for rectification. Article 16 GDPR requires a clear and specific request for correction, and vague or indirect statements, such as tweets or general demands for a change of the controller’s practice, do not satisfy this requirement. During the proceedings, it became clear that the data subject’s statements, primarily concerned the implementation of a future change of the controller’s practice to allow a gender-neutral option for all users, rather than a concrete request to correct their own personal data. In addition, some corrections had already been made to the data subject’s profile and invoices, while oral misgendering in trains and via loudspeaker announcements was found to fall outside the scope of the GDPR, as such statements were not stored in any personal data filing system. Finally, the Court noted that the minutes of the Equal Treatment Commission hearing could not be relied upon as full proof, as the hearing had been recorded only in audio form and not documented in accordance with the requirements of Austrian administrative procedure law (AVG). Statements made during the Equal Treatment Commission proceedings therefore did not constitute a formal exercise of the right to rectification under Article 16 GDPR.

### OVG Saarlouis - 2 A 165/24

*Source: Superior Administrative Court Saarlouis, 2025-05-13 — https://overview.legal/posts/125590 — original: https://gdprhub.eu/index.php?title=OVG_Saarlouis_-_2_A_165/24*

Facts — The data subject was an employee, the controller was the employer. On 14 January 2022, the data subject requested access to personal data from the controller under Article 15 GDPR. They did not respond. On 28 January 2022, the controller terminated the employment. On 17 February 2022, the data subject lodged a complaint with the Data Protection Authority (DPA) under Article 77 GDPR. The data subject alleged that the controller had failed to answer the access request, had taken unauthorised photographs, and had a copy of their vaccination certificate. On 24 February 2022, the employment relationship ended by a court settlement before the Labour Court. The settlement stated that all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, were settled, except for employment documents. By entering the settlement, the data subject agreed to not pursue further claims. After the settlement, the controller informed the DPA that it had not received an access request from the data subject, had not taken photographs, and had destroyed the vaccination certificate after the employee left. The data subject continued to raise issues with the DPA, including access to time-tracking data and alleged inaccuracies in the controller’s provided documents. The controller later provided partially redacted time-tracking data. On 26 July 2022, the DPA closed the administrative procedure, as it considered that the data subject no longer had a right of access under Article 15 GDPR because the settlement didn't allow for this claim. The data subject challenged the DPA’s decision before the Administrative Court. On 10 July 2024, the court dismissed the action. The data subject appealed. Holding — First, the court held that the right of access under Article 15 GDPR was, in principle, waivable. Although Article 8(2) CFR protects the right of access, the court noted that data protection law is based on self-determination, including the possibility to consent to processing under Article 7 GDPR. From this, the court inferred that a data subject could also waive the exercise of the right of access. Second, the court clarified that a waiver could not generally cover unknown future data processing. However, a waiver relating to past processing was permissible, especially after the end of an employment relationship, where the imbalance between employee and employer no longer existed. Third, the court held that the specific settlement covered the right of access under Article 15 GDPR. The clause settling all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, also included secondary claims linked to the employment relationship, such as access rights concerning employee data. The court considered the wording sufficiently clear and found no requirement to explicitly mention data protection rights. Fourth, the court noted that the data subject already knew about the access request and had raised it before concluding the settlement. Any internal intention not to waive data protection rights was legally irrelevant. Finally, the court upheld the DPA’s decision to close the procedure. Since the data subject had waived the right of access under Article 15 GDPR for past processing through the settlement, the DPA had no obligation to continue enforcement action against the employer.

### CJEU - C-247/23 - Deldits

*Source: GDPRhub, C-247/23, 2025-03-13 — https://overview.legal/posts/125591 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-247/23_-_Deldits*

Facts — The data subject is a trans person who was granted refugee status in Hungary. When applying for this status, they pointed out that they identified as male and relied on their transsexuality as the ground for their recognition as a refugee. However, the Hungarian National Directorate-General for Immigration Policing (Országos Idegenrendészeti Főigazgatóság, the controller) recorded them in the register as female. In 2022, the data subject, pursuant to Article 16 GDPR, submitted a request to the controller to rectify the asylum register in two particulars: a change of the name under which they had been registered and a change of gender from female to male. On 11 October 2022, the controller rejected the request, arguing that the documents provided by the data subject did not prove that they had undergone gender reassignment surgery and that the applicant’s gender had changed. Therefore, the data subject brought proceedings before the Budapest High Court (Fővárosi Törvényszék). This court, having doubts regarding the interpretation of Article 16 GDPR, stayed the proceedings and referred the following questions to the CJEU: Must Article 16 GDPR be interpreted as meaning that, in connection with the exercise of the rights of the data subject, the authority responsible for keeping registers under national law is required to rectify the personal data relating to the gender of that data subject recorded by that authority, where those data have changed after they were entered in the register and therefore do not comply with the principle of accuracy established in Article 5(1)(d) GDPR? If the answer to the first question referred is in the affirmative, must Article 16 GDPR be interpreted as meaning that it requires the person requesting rectification of the data relating to his or her gender to provide evidence in support of the request for rectification? If the answer to the second question referred is in the affirmative, must Article 16 GDPR be interpreted as meaning that the person making the request is required to prove that he or she has undergone gender reassignment surgery?’ The data subject argued that, pursuant to Article 5(1)(d) GDPR, the accuracy of data must be assessed having regard to the purposes for which they are processed. In this case, the purpose of the asylum register is to identify refugees. On this point, the data subject pointed out that where the gender of a transgender person as recorded does not reflect the identity by which they are recognised in public, that record does not facilitate their identification and may even expose them to discrimination and harassment. The Hungarian Government submitted that, according to Article 6(2) GDPR and Article 6(3) GDPR, the data subject’s right to have an entry in an official record, such as the asylum register, rectified may be exercised under the law of a Member State only and not by direct reliance upon Article 16 GDPR. Advocate General Opinion — First question First, Advocate General Collins (AG) noted that the question asked by the referring court does not reflects the facts if the case. While the question seems to imply that the data subject’s change of gender identity occurred after the recognition of their refugee status in 2014, facts suggest that this occurred prior to it, since the change of gender identity appears to have been the basis upon which Hungary recognised the data subject’s refugee status. Therefore, the AG suggested the CJEU to take these facts into account and consider that the rectification request aimed at correcting an original error and not to amend that record in order to reflect a change in circumstances. Secondly, the AG recalled that the right to rectification is enshrined both in Article 16 GDPR but also in Article 8(2) CFR. Thirdly, the AG pointed out that since the accuracy of personal data may vary depending on the context in which it is processed, the purpose of the collection of data has a direct bearing upon an assessment of its accuracy. In the case at hand, one of the purposes of the asylum register is to identify a person and gender is considered to be one of the identifiers. On this point, the AG noted that when Hungary recognised the data subject’s refugee status, they identified as a transgender male. Therefore, the AG opined that the entry of the data subject’s gender as “female” in the asylum register thus appears to have been inaccurate for the purposes of Article 5(1)(d) GDPR. Fourthly, the AG acknowledged that the right to rectification is not absolute and could be limited under certain conditions, according to Article 23 GDPR. In particular, Article 23(1)(e) GDPR relates to the “keeping of public registers kept for reasons of general public interest”. Therefore, according to the AG, a Member State could theoretically rely on Article 23(1)(e) GDPR to partially restrict the right to rectification in order to ensure the reliability and consistency of public records, including records of civil status. However, nothing in the case at hand suggests that such a law has been implemented in Hungary. Moreover, this cannot on itself be an obstacle to granting an application to rectify the gender in an asylum register so as to record their gender identity as it was at the time it was entered therein, since this type of application only serves to enhance the reliability of that register and the accuracy of the data recorded therein. Therefore, the AG advised the Court to answer that Article 16 GDPR, read in the light of Article 5(1)(d) GDPR, is to be interpreted as meaning that a national authority responsible for keeping a register of refugees is, upon application, required to rectify personal data on the gender of a refugee which that authority had incorrectly recorded at the time they were entered in that register. Second and third questions According to the AG, the second and third questions seek to know which evidence a data subject should submit in support to their gender rectification request under Article 16 GDPR and whether that person may be required to furnish proof of having undergone gender reassignment surgery. First, the AG noted that Article 16 GDPR does not specify anything about the evidence a data subject should provide. Therefore, this needs to be assessed on a case-by-case basis. This means that, in certain cases, the data subject might be required to produce evidence that may be reasonably necessary to establish the inaccuracy of that data in the light of the purposes for which they were collected or processed. However, the AG emphasised that the data subject does not have to claim or to demonstrate a particular interest in the rectification of inaccurate data or that the alleged inaccuracy causes any harm. In the case at hand, the AG opined that it is sufficient for the data subject to prove that Hungary recognised their refugee status in 2014 on the basis of their pre-existing transgender identity and that the asylum register does not accurately record that identity. Finally, as for the necessity to have undergone gender reassignment surgery, the AG noted that the European Court of Human Rights has repeatedly hold that imposing this requirement goes against the ECHR. Therefore, imposing such a requirement would have the effect of negating the right to rectify inaccurate data on the gender of a transgender data subject. Therefore, the AG suggested the CJEU to answer that a national authority responsible for keeping a register of refugees may require a data subject requesting rectification of data to produce evidence to establish the inaccuracy of that data in the light of the purposes for which they were collected or processed but may not be required to prove they have undergone gender reassignment surgery. Holding — First question: Article 16 GDPR demands rectification of data on gender identity — The Court observed that under Article 16 GDPR in conjunction with the principle of accuracy (Article 5(1)(d) GDPR) and Article 8(2) CFR, the data subject has the right to obtain from the controller, without undue delay, the rectification of inaccurate personal data concerning him or her. The court recalled that it had laid out in Nowak that the purpose for which data were collected, was to be considered when assessing the accuracy of data. Thus, the court indicated, that if the purpose of collecting those data was to identify the data subject, those data would appear to refer to that person’s lived gender identity, and not to the identity assigned to them at birth. In that context, the court clarified that a Member State cannot limit the exercise of the right to rectification based on the absence of a national procedure to proof a transgender identity but only on legislative measures adopted under Article 23 GDPR. However, even if such a legislative measure existed, the court held, that although EU law does not detract from the Member States’ competence in the legal recognition of person's gender identity, those States must comply with EU law, including the GDPR, read in the light of the CFR. The court held, that national legislation preventing a transgender person from fulfilling a requirement which must be met to rectify their data on gender identity by not recognizing such identity must be regarded as being incompatible with Article 8(2) CFR and its specific expression in Article 16 GDPR. Consequently, the Court concluded that Article 16 GDPR must be interpreted as requiring a national authority responsible for keeping a public register to rectify the personal data relating to the gender identity where those data are inaccurate. Second and third question: No requirement to proof of gender reassignment surgery — The court found that, for the purposes of exercising their right to rectification under Article 16 GDPR, a person may be required to provide relevant and sufficient evidence that may reasonably be required in order to establish that those data are inaccurate. The court further stated, that any limitation of the rights under the GDPR pursuant to Article 23 GDPR must respect the essence of the fundamental rights and freedoms and be laid down by law. First, the court found that the evidential requirement for rectification limiting Article 16 GDPR seems to have no basis in Hungarian law. Secondly, the court found, that Article 8 ECHR (corresponding to Article 7 CFR) includes the right of transgender persons to personal development and physical and moral integrity, as well as to respect for and recognition of their gender identity. Additionally, the court referenced the European Court of Human Right's ruling, that recognition of a transgender identity could not be made conditional on the performance of surgical treatment not desired by that person. Thirdly, the court held, that in any event, a requirement of evidence of gender reassignment surgery is neither necessary nor proportionate to ensure the reliability and consistency of a public register such as the asylum register, since a medical certificate, including a psychiatric diagnosis, may constitute relevant and sufficient evidence in that regard. Thus, the court held, that a Member State may never make the exercise of the right to rectification conditional upon the production of evidence of gender reassignment surgery because such a requirement would undermine the essence of the right to the integrity of the person and the right to respect for private life, referred to in Article 3 CFR and Article 7 CFR.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

### BVwG - W252 2247042-1

*Source: Federal Administrative Court, 2024-01-22 — https://overview.legal/posts/132104 — original: https://gdprhub.eu/index.php?title=BVwG_-_W252_2247042-1*

Facts — The controller, an Public Employment Service Austria, processed the personal data of the data subject in connection with his file. On 21 February 2019, 15 March 2019 and 25 November 2020, the data subject sent access requests to the controller by fax, each time explicitly insisting on delivery of the response by registered post, addressed personally and refusing delivery by email. With the November 2020 request, he also sent a blank DVD-R by post, asking the controller to copy the data onto it. The controller responded to each request with a printed access response sent by registered letter, the responses were substantially identical and the DVD-R was returned unused. The controller's usual practice is to provide access electronically through an online account. The access responses included the data subject's basic data, insurance and benefit periods and a chronological log of case notes "Informationen/Gesprächsnotizen/Vermerke", which listed attachments where relevant but did not include copies of entire documents. The data subject was aware of the content of the documents listed as attachments, since he himself had submitted them to the controller. None of the three responses referred to a specific case note dated 17 October 2018, recording a phone call between the controller and the data subject's family doctor about his health. The data subject repeatedly and specifically requested this note. The controller only produced it during the proceedings before the Federal Administrative Court, in a submission of 29 June 2023, which the Court forwarded to the data subject in July 2023. The data subject lodged a complaint with the Austrian DPA in February 2020, arguing that the access provided was deficient because copies of documents were missing, unexplained abbreviations were used, the response was not delivered in a common electronic format and it contained incorrect data. The DPA partially upheld the complaint (ordering the controller to explain certain abbreviations) but rejected the remainder, holding that the right of access does not include a right to copies of documents. The data subject appealed only the rejecting part of the DPA's decision to the Federal Administrative Court. Holding — First, the court held that the data subject was entitled, in the specific circumstances, to receive a copy of the case note of 17 October 2018. Citing CJEU case-law, the court noted that "personal data" must be interpreted broadly and that a "copy" means a faithful reproduction, not a mere general description or reference to categories of data. Because the data subject had specifically identified and requested this particular note as early as February 2019, the controller's asserted practice of a staged, multi-step access process could not be relied on to justify withholding it. However, the court held that this part of the complaint became moot once the controller supplied the missing note during the court proceedings, since the data subject's interest in access was thereby satisfied, even though the note reached him via the court rather than directly from the controller. Referring to national case-law, the court noted that there is no separate right to a formal declaration that a past infringement of the right of access occurred, once the substantive right has been satisfied. It also stated that any dispute about the accuracy of the date shown on the note was a matter for the right to rectification, not the right of access. Second, the court held that the right of access does not, in general, entitle a data subject to copies of entire documents or file attachments. Reproduction of extracts or whole documents is only necessary where needed to make the disclosed personal data intelligible. Since the data subject already knew the content of the referenced attachments (he had submitted them himself and had annotated copies of the responses identifying their content), the court held that further disclosure of the attachments was not necessary for comprehensibility and the access already given was complete. Third, the court rejected the data subject's argument that the access responses should have been delivered in a "common electronic format." While the GDPR provides that a request submitted electronically should, in principle, be answered electronically unless the data subject indicates otherwise, the court held that the data subject himself had explicitly and repeatedly requested delivery by registered post rather than email and this constituted "otherwise" within the meaning of that provision. The court also held that there is no obligation on a controller to use a physical data carrier (such as the data subject's own DVD-R) to provide access. It rejected the argument that paper delivery was designed to prevent the data being machine-searchable, noting that the right of access, unlike the right to data portability, does not guarantee a right to further processing of the data. The appeal was dismissed and the court declared that an appeal on points of law (Revision) was not admissible, since the relevant questions were already settled by existing CJEU and national supreme administrative court case-law.

### Österreichische Datenschutzbehörde v CRIF

*Source: CJEU, C-487/21, 2023-10-26 — https://overview.legal/posts/51486 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0487*

Right of access includes obtaining a copy in commonly used electronic form.

### Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C

*Source: Court of Justice of the European Union, C-154/21, 2023-01-12 — https://overview.legal/posts/132299 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0154*

The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article 15(1)(c) GDPR in proceedings between data subject RW and Österreichische Post AG regarding the scope of the right of access to information about recipients or categories of recipients of personal data. The Court held that controllers must provide the actual identities of specific recipients to whom personal data have been or will be disclosed, rather than merely naming categories of recipients, unless a further specification is impossible. The Court clarified that while the right of access under Article 15(1)(c) is not absolute and may be balanced against the rights and freedoms of others, including trade secrets, such restrictions must not result in a refusal to provide all information to the data subject.

### Judgment of the Court (Grand Chamber) of 8 December 2022.#TU and RE v Google LLC.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Directive 95/46/EC – Article 12(b) – Point (a) of the first paragraph of Article 14 – Regulation (EU) 2016/679 – Article 17(3)(a) – Operator of an internet search engine – Research carried out on the basis of a person’s name – Displaying a l

*Source: Court of Justice of the European Union, C-460/20, 2022-12-08 — https://overview.legal/posts/132301 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0460*

In Case C-460/20, the Court of Justice (Grand Chamber) ruled on a preliminary reference from the Bundesgerichtshof (Germany) concerning two individuals' request that Google de-reference search results containing allegedly inaccurate articles about them and remove thumbnail images from image search results. The Court held that the right to erasure under Article 17(3)(a) GDPR does not extend to requiring a search engine operator to de-reference links to articles whose content the requester claims is inaccurate, as that exception addresses the balance between data protection and freedom of expression rather than data accuracy. The Court further ruled that the requester bears the burden of providing relevant evidence to substantiate the alleged inaccuracy of the information.

### Judgment of the Court (Fourth Chamber) of 27 October 2022.#Proximus NV v Gegevensbeschermingsautoriteit.#Request for a preliminary ruling from the Hof van beroep te Brussel.#Reference for a preliminary ruling – Processing of personal data and protection of privacy in the electronic communications sector – Directive 2002/58/EC – Article 12 – Public telephone directories and directory enquiry services – Subscriber’s consent – Obligations of the provider of directories and of directory enquiry serv

*Source: Court of Justice of the European Union, C-129/21, 2022-10-27 — https://overview.legal/posts/132304 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0129*

In a preliminary ruling requested by the Brussels Court of Appeal, the Court of Justice of the European Union addressed the interpretation of Article 12 of Directive 2002/58/EC (ePrivacy Directive) and several GDPR provisions in proceedings between Proximus NV and the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit). The core issue concerned the obligations of providers of public telephone directories regarding subscriber consent, information requirements, and the right to erasure under the GDPR, following the DPA's imposition of a EUR 20,000 fine and remedial orders against Proximus. The Court clarified the interplay between the ePrivacy Directive's consent regime for directory inclusion and the GDPR's broader data protection obligations, including the controller's responsibility to ensure erasure of subscriber data upon withdrawal of consent.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

### Google LLC v CNIL

*Source: CJEU, C-507/17, 2019-09-24 — https://overview.legal/posts/51476 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0507&ref=51476*

Right to delisting does not require global de-referencing under EU law.

## Guidance

### Guidelines on processing of personal data through blockchain technologies

*Source: EDPB, guidelines-on-processing-of-personal-data-through-blockchain-technologies-en, 2026-07-07 — https://overview.legal/posts/125668 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-on-processing-of-personal-data-through-blockchain-technologies_en*

Guidelines 02/2025 on processing of personal data through blockchain technologies Version 2.0 Adopted on 07 July 2026 1 | Adopted Version history Version Date Adoption information version 1.1 08 April 2025 adoption of the guidelines before public consultation version 2.0 07 July 2026 adoption of the guidelines after public consultation 3 | Adopted 4 | Adopted The European Data Protection Board Having regard to Article 70 (1)(e) of the Regulation 2016/679/EU of the European Parliament and of the…

### Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation

*Source: EDPB, edpb-opinion-202507-epo-adequacydecision-en, 2025-05-06 — https://overview.legal/posts/50823 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-072025-regarding-the-european-commission-draft-implementing-decision_en*

EDPB, Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation, 2025.

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Guidelines 10/2020 on restrictions under Article 23 GDPR

*Source: EDPB, edpb-guidelines-on-restrictions-under-article-23-gdpr, 2021-10-13 — https://overview.legal/posts/38062 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the scope and application of Article 23 of the GDPR, which allows Member States to restrict certain data subject rights and controller obligations. The guidelines outline the necessary conditions and safeguards, emphasizing that any restrictions must respect the essence of fundamental rights and be implemented via foreseeable, proportionate legislative measures. This document serves as authoritative guidance for interpreting the specific grounds and requirements under which Member States may legally impose such limitations.

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)

*Source: EDPB, edpb-guidelines-on-the-criteria-of-the-right-to-be-forgotten-in-the-search-engines-cases-under-th, 2020-07-07 — https://overview.legal/posts/38070 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-52019-on-the-criteria-of-the-right-to-be-forgotten-in-the-search_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the criteria and grounds for exercising the right to erasure (right to be forgotten) specifically in the context of search engine cases under the GDPR. The document details the six grounds under Article 17(1) that allow data subjects to request delisting, alongside the relevant exceptions, such as the right to freedom of expression and information. As a guidance instrument, it does not impose administrative fines but instead aims to harmonize how search engine providers handle and balance delisting requests across the EU.

### Statement on restrictions on data subject rights in connection to the state of emergency in Member States

*Source: EDPB, statement-on-restrictions-on-data-subject-rights-in-connection-to-the-state-of-en, 2020-06-02 — https://overview.legal/posts/126146 — original: https://www.edpb.europa.eu/documents/statement/statement-on-restrictions-on-data-subject-rights-in-connection-to-the-state-of_en*

1 Statement on restrictions on data subject rights in connection to the state of emergency 1 in Member States Adopted on 2 June 2020 The European Data Protection Board has adopted the following statement: 1. The EDPB has been informed of the adoption by the Hungarian government of the Decree 179/2020 of 4 May 2020 on the derogations from certain data protection and access to information provisions during the state of danger 2 . Under Article 1, this Decree provides that, with respect to…

### Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria

*Source: EDPB, opinion-152023-on-the-draft-decision-of-the-dutch-supervisory-en, 2023-09-19 — https://overview.legal/posts/125831 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-152023-on-the-draft-decision-of-the-dutch-supervisory_en*

Adopted 1 Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria Adopted on 19 09 2023 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

## Enforcement decisions

### CNIL fines energy supplier for mishandling data subject access and objection requests

*Source: CNIL (France), 2026-07-17 — https://overview.legal/posts/125641 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2022-011*

Facts — The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French DPA (CNIL) that they had encountered difficulties in exercising their rights of access to personal information about them, and objection to receiving commercial prospecting telephone calls from the controller. The complaints concerned data subject requests for rectification of personal data, late, erroneous, or no response to access to personal data and access to the origin of personal data, failure to cease processing of personal data after objection to the processing of data for commercial prospecting (marketing) purposes, and request for personal data deletion. The DPA appointed a rapporteur that carried out an audit of the website of the controller and investigated the various complaints of the data subjects. The controller in its defence argued that 1) the data subjects' access requests were not sent by the data subjects to the controller’s dedicated unit and that the person who received the requests did not know how to identify their purpose; 2) the procedures it had put in place were not respected because of human error; 3) there were a large number of requests received in 2020 during the health crisis and this was impeded by the disruptions that followed; 4) there were difficulties in obtaining the necessary information from its business partners, thus unable to properly inform data subjects about the source of their data; 3) It had taken steps to modify its processing activities to comply with the relevant applicable laws; 4) The breach affected barely a fraction of its customers. Beyond the direct complaints made by the data subjects, the DPA in its investigation noted that when subscribing online on the controller's website, the subscription form had no option for users to object to the use of their personal data for marketing purposes. The subscription form informed users that their personal data may be used by the controller to present offers to them at a later date. On this point, the controller argued that 5) the CPCE did not apply to the online subscription form, since the collection of personal data through the form was not intended to promote the company's products or services, but to offer assistance to the user in order to help them finalize the current subscription. Holding — The DPA held that the lack of an option for a user to object to the processing of their personal data for marketing purposes, at the time of collection, constitutes a breach of the provisions of article L. 34-5 of the French Post and Electronic Telecommunications Code (CPCE). The DPA observed that, in certain cases, the data subjects contacted for marketing purposes were not provided with any information required in Article 14 GDPR, such as the purposes of the processing or the existence of the various rights. They were not informed that the call was being recorded, nor of their right to object to it. The DPA observed that the controller had failed to respond, supplied erroneous responses, or responded late to several data subject requests, beyond the deadlines set by Article 12 GDPR, often after several reminders from the data subject. The DPA observed that the controller failed to process the various data subject’s requests for access to personal data, their origin, as well as access to recordings of telephone conversations concerning the data subjects within the time limit set with the obligations of Article 15 GDPR. The DPA finally observed that the controller continued to process the personal data of data subjects after objections from the data subjects to the processing of their personal data in breach of Article 21 GDPR. The DPA held that the controller cannot rely on its difficulties in obtaining information from its commercial partners to justify its failure to provide a response to the applicants in accordance with the applicable provisions. It is the duty of the controller to organize itself in such a way as to be able to ensure that requests for access are processed in accordance with the applicable provisions and, in particular, to provide information on the origin of the data. The DPA further held that although data subjects did not send their access requests directly to the unit in charge of responding to them, it is up to the controller, as long as the requests, one of which was directly addressed to the data protection officer, were received in clear terms by the controller, to process them within the time limits provided for and to ensure that they were transmitted to the competent department responsible for handling such requests. For these violations, the DPA fined the controller €1,000,000. The controller argued against the publication of the penalty decision, on the ground that publication would be disproportionate in light of the limited nature of the alleged breaches and its compliance. It also claimed that publication of the penalty would have a significant impact on the controller’s image and that it would be favorable to its main competitors, in a very competitive market. The DPA also decided to make its decision public on the CNIL website and on the Légifrance website and held that the controller will no longer be identified by name after a period of two years from its publication. The DPA noted that the company has taken measures to bring its processing into compliance with the applicable laws, and the efforts made by the company to comply throughout the procedure. The DPA also noted that the controller’s agents have had to attend awareness training on the subjects of the complaints.

### APD/GBA: Controller failed to provide copies of service sheets for GDPR access request

*Source: APD/GBA (Belgium), 2026-05-06 — https://overview.legal/posts/144020 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_97/2026*

Facts — The data subject was a technician employed by the controller. The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained the technician’s working hours, journeys, services performed and the clients visited. On 10 May 2021, the data subject requested copies of their service sheets covering the previous five years in order to verify whether the hours they had reported corresponded to those recorded by the controller. The controller provided only the sheet concerning the week of 3 May 2021 to 9 May 2021 and subsequently proposed that the data subject arrange an appointment to consult the records at its premises. The data subject reiterated the request on 17 January 2022 and again in 2023, but never received the requested copies. On 27 July 2023, the data subject lodged a complaint with the Belgian DPA. The DPA issued the prima facie Decision 14/2025, where it ordered the controller to comply with the data subject’s access request and warned it of potential violations of Article 15(3) GDPR and Article 12(3) GDPR. The controller requested an examination on the merits. The controller argued that the data subject’s request had not clearly distinguished between the handwritten service sheets and a computer-generated statement. It further claimed that the request was excessive under Article 12(5) GDPR because the documents were stored by date rather than by employee in several dozen binders. Locating, copying and scanning the relevant records would therefore require considerable workload. For that reason, it had invited the data subject to inspect the binders in its premises and identify the relevant documents to be copied. The data subject maintained that their request had always been clear, that the computer-generated statement was incomplete and unintelligible and that the practical difficulties relied upon by the controller resulted from its own archiving practices. Holding — The DPA ruled that the data subject had made a sufficiently clear request for access and a copy under Article 15(1) GDPR and Article 15(3) GDPR. It further pointed out that the controller’s response demonstrated that it had understood that the data subject sought copies of the service sheets themselves. The DPA further held that the computer-generated statement did not satisfy the request. It noted that the data subject needed the handwritten records in order to compare the hours they had reported with those subsequently recorded by the controller. It referred to C-487/21 (Österreichische Datenschutzbehörde) and recalled that the copy provided must constitute a faithful and intelligible reproduction of the personal data and may require copies of documents where this is necessary for the effective exercise of the data subject’s rights. The DPA therefore determined that the controller’s invitation to inspect the documents at its premises therefore did not constitute an adequate response to the data subject’s request for a copy. It stated that if the controller had genuinely been uncertain about the scope of the request, it should have sought clarification in accordance with Article 12(2) GDPR. Moreover, it rejected the controller’s reliance on Article 12(5) GDPR. The DPA held that the request was neither manifestly unfounded nor excessive as was clearly expressed and properly understood by the controller. It found that the controller did not demonstrate the excessiveness but relied exclusively on the workload resulting from its own archiving system. The DPA also relied on C-526/24 (Brillen Rottler) and applied the abuse of rights test. It found that neither its objective nor its subjective element was established. It reasoned that the request pursued the purpose of Article 15 GDPR, since the data subject sought to access and verify the accuracy of personal data concerning them, nor was there any evidence that the data subject had artificially created the conditions for obtaining an advantage under the GDPR. It further referred to EDPB Guidelines 01/2022 on the right of access, emphasizing that the time and effort required for a controller to fulfil an access request cannot, in itself, make the request excessive, particularly since the burden resulted from organisational choices made by the controller. It also emphasized that the data subject was also not required to justify the reasons for the request. The right of access under Article 15 GDPR does not include any general proportionality reservation regarding the controller’s efforts. Additionally, the term "appropriate" in Article 12(1) GDPR should not be used to limit the scope of data covered by the right of access. The DPA concluded that the alleged burden could not justify a refusal, especially since it stemmed from self-imposed organizational and administrative constraints related to the controller’s archiving system. A refusal may only apply if there is proven abusive intent, as defined by applicable requirements. Any other interpretation would undermine Article 15 GDPR and conflict with Article 12(2) GDPR and Article 25 GDPR, which require controllers to facilitate access requests and implement technical and organizational measures from the outset to ensure effective exercise of this right. The DPA further held that the controller had violated Article 12(2) GDPR, Article 12(3) GDPR and Article 12(4) GDPR. It had neither responded within the applicable time limit nor formally notified the data subject of a reasoned refusal. It further emphasized that the controller by requiring the data subject to attend its premises and identify the relevant records, it improperly transferred to them a task that belonged to it. Moreover, it noted that on-site consultation of the records could have exposed the data subject to personal data relating to the controller’s clients. The DPA held that under Article 15(4) GDPR, the controller was required to assess whether measures, such as partial anonymisation of third-party information, were necessary and that provision could not justify a blanket refusal to provide a copy. The DPA reprimanded the controller for violating Article 12(2) GDPR, Article 12(3) GDPR, Article 12(4) GDPR, Article 15(1) GDPR and Article 15(3) GDPR and ordered it to provide copies of the timesheets within one month.

### Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-14 — https://overview.legal/posts/184678 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542/2026*

Facts — Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

### DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific

*Source: DSB (Austria), 2025-11-24 — https://overview.legal/posts/158460 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-0.950.759*

Facts — On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders either as guests or through an optional customer account. During the registration process, the data subject's personal data was collected, including a gender-specific title. The only options provided for the title were "Mr." and "Ms.", with no option to select no title. The data subject selected “Ms.” during the registration process. The data subject then informed the controller about this situation and requested that it should refrain from using gender-specific forms of address regarding them. The controller initially assured the data subject that it would inform the relevant department. Later, the controller communicated that implementing the requested adjustment was currently not technically feasible, but that a solution was being worked on. On 14 May 2025, the data subject received a newsletter from the controller in which a gender specific salutation (specifically "Ms.") was used. On 16 May 2025, the data subject lodged a complaint with the Austrian DPA against the controller. The data subject argued that the controller had infringed their rights regarding the principles of data processing under Article 5 GDPR, the rights to rectification under Article 16 GDPR, to erasure under Article 17 GDPR and to data protection by design and by default under Article 25 GDPR. Τhe controller stated in its privacy notice that it was necessary to process customers’ personal data for registration purposes under Article 6(1)(b) GDPR. Moreover, the controller also claimed reliance on Article 6(1)(f) GDPR. During the proceedings before the DPA, the controller restructured its IT system. On 8 September 2025, the controller announced that it had implemented gender-neutral forms of address in its online shop and requested for the complaint to be dismissed. Holding — The DPA first noted that, during the proceedings, the controller had implemented the requested changes by removing gender-specific forms of address from the registration process. Since the data subject did not contest this, the DPA considered the alleged infringements of the rights to rectification and erasure to have been remedied and ended that part of the proceedings. However, it continued to examine whether the past processing had violated Article 5 GDPR and Article 25 GDPR. Regarding the processing of salutation data for the personalisation of business communications, the DPA relied on the CJEU judgment in Case C-394/23 (Mousse). In this case, the CJEU had ruled that the processing of salutation data for the personalization of business communications is neither necessary for the performance of a contract pursuant to Article 6(1)(b) GDPR nor consistent with the principle of data minimization pursuant to Article 5(1)(c) GDPR, because such processing is not required for the stated purposes. The DPA concluded that using gender-specific salutations for contract fulfilment, order processing, internal correspondence, contests, newsletters, user account registration, and delivery of goods was not strictly necessary, even under a broad interpretation. It backed this conclusion by the fact that the controller had already stopped using gender-specific salutations in direct communications, newsletters, contests, contact forms, delivery notifications, invoices, and order confirmations. The DPA therefore held that neither Article 6(1)(b) GDPR nor Article 6(1)(f) GDPR could serve as a legal basis for processing gender-specific salutations during the registration process, since the processing was not necessary. In relation to Article 6(1)(f) GDPR , the DPA accepted that the controller could in principle have a legitimate economic interest in personally addressing customers, but found that the necessity requirement was not met. The DPA found that the processing operation violated the principles of purpose limitation and data minimisation under Article 5(1)(b) GDPR and Article 5(1)(c) GDPR due to the lack of necessity of the gender-specific salutation and the availability of less intrusive alternatives. The DPA also referred to the Austrian Constitutional Court’s (Verfassungsgerichtshof) decision GZ G 77/2018, according to which a restriction to only two gender categories is incompatible with Article 8 ECHR. Regarding data protection by design and by default, the DPA held that Article 25 GDPR imposes obligations on the controller, but does not grant the data subject a subjective right to demand a specific privacy-friendly technical setting. It pointed out that while privacy-unfriendly default settings might lead to a violation of confidentiality or of the data protection principles, the data subject could not require the controller to implement specific privacy-friendly settings.

### Greek DPA: Google breached Art. 17 GDPR erasure right over outdated criminal case links

*Source: HDPA (Greece), 2023-06-29 — https://overview.legal/posts/125608 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_54/2024*

Facts — In 2020, the data subject filed a complaint with the DPA against Google LLC (the controller) for failing to fulfill their right to erasure (Article 17 GDPR) concerning links - referring to criminal charges - appearing in search results based on their name. The data subject argued that these results contained outdated information about a closed criminal case involving them. The controller partially complied with the request but retained one link. The data subject then identified additional publications that required deletion. However, the controller failed to act within the 30-day deadline stipulated by Article 12(3) GDPR. Instead, it responded with an automated message, attributing the delay to the Covid-19 pandemic and claiming that the erasure request was incomplete because it lacked the court judgment clearing the data subject of charges. Before the DPA, the data subject argued that the pandemic is not a valid justification for delays and that the erasure request form does not allow attachments, preventing them from submitting supporting documents. The controller stated that it provides multiple channels for data subjects to request data erasure, including direct email contact with its DPO and the retained link in question referred to a comment, which allegedly did not meet the criteria for erasure or contain any information directly linking it to the data subject. Holding — The DPA found Google LLC to be the controller as it is responsible for the deletion process not Google Hellas/Athens. The DPA found, that contrary to the controller's statement the remaining link could be associated with the data subject’s identity and past criminal cases. Thus, the DPA held, that the erasure request must be fulfilled unless the controller demonstrates compelling and lawful reasons for continuing processing (Article 21(1) GDPR), which the DPA found lacking. The DPA held that the lack of an attachment option hinders the effective exercise of data subjects' rights, as they are forced to seek alternative communication methods. Thus, the controller fails to facilitate the erasure request process. Additionally the court found, that the controller did not comply with Article 12(3) GDPR, as a general, automated response does not meet it’s requirements and the contact link for the controller’s DPO did not include any contact details, making direct communication impossible in breach of Article 37(7) GDPR. Based on these findings, the DPA ordered the controller to: Provide an attachment option in the erasure request submission form. Stop sending automated responses to submitted requests. Publish the contact details of its DPO. Delete the remaining link, as requested by the data subject.

### EDPS - 2020-1013

*Source: EDPS, 2022-01-05 — https://overview.legal/posts/122849 — original: https://gdprhub.eu/index.php?title=EDPS_-_2020-1013*

Facts — In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The issues raised were: confusing and unclear cookie banners, vague and unclear data protection notices, and the illegal transfer of data to the US. Holding — On data controllership — According to the EDPS, the processor may enjoy a considerable degree of autonomy in providing its services and may identify the ‘non-essential’ elements of the processing operation. Furthermore, the processor may advise or propose certain measures in this respect, but it is up to the controller to decide whether to accept such advice or proposals. The analysis of the EDPS shows that the European Parliament (EP) delegated some aspects on the setting up and functioning of the website to Ecolog. The EDPS considers the EP acts as the sole data controller for the processing in question (i.e. the operation of the Parliament’s dedicated website) whereas Ecolog acts as a processor. After having assessed the instructions given by the EP to the processor, the EDPS concluded that the EP did not show the necessary diligence required from a data controller and, ultimately, failed to comply with the Regulation on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data 2018/1725 (hereafter Regulation 2018/1725), in particular with Articles 26(1) and 29(1). Moreover, the EDPS considered that the EP failed to provide the necessary detailed instructions to Ecolog for the setting up of the website, including the drafting of the data protection notice. The absence of documented instructions is therefore in violation of Article 29(3) Regulation 2018/1725. Transparency and information requirements — The EDPS confirmed that the data protection notice published at the time of the complaint did not reflect the processing done by the EP, since it merely consisted of a copy of the testing center of Zaventem's airport. Moreover, the reference made in the document to Article 6(1)(f) GDPR was wrong since it stems from the same error. The EDPS confirmed that the EP did not meet its transparency requirements. The EDPS also analysed the updated version of the data protection notice during the procedure and raised several remaining -and even new- inconsistencies and issues. Among other things, the following problems persisted after the data protection notice was updated: a mere reference to Article 15 and 16 Regulation 2018/1725 is misleading as it should apply in its entirety; the reference to the processing of health data is not correct since no such data are processed in the case at hand; the retention period mentioned is not precise enough; the sections of the data protection notices relating to the recipients of the personal data fail to make any reference to the processor; inconsistencies between the different linguistic versions of the data protection notices were still observed: The English and German versions refer to Ecolog and the Laboratory van Poucke as processors under Article 29 Regulation 2018/1725, whereas the French version refers to them as controllers (‘responsables du traitement’). Moreover, the DPO’s contact details on the website refer to Ecolog in all three linguistic versions of the website, when they should be referring to the Parliament Cookies and transfers of personal data to the US — The EDPS confirmed that tracking cookies, such as the Stripe and the Google analytics cookies, are considered personal data, even if the traditional identity parameters of the tracked users are unknown or have been deleted by the tracker after collection. In the same vein, the EDPS rejected the EP's argument and confirmed that upon installation on a device, a cookie cannot be considered ‘inactive’. Every time a user visited Ecolog’s website, personal data was transferred to Stripe through the Stripe cookie, which contained an identifier. The EDPS reached the conclusion that a transfer of data was taking place to the US, via the use of Google and Stripe cookies, since Google Analytics is hosted in the US and the data protection notice referred to a Standard Contractual Clause (SCC) for the transfer of data outside of the EU. However, the Parliament provided no documentation, evidence or other information regarding the contractual, technical or organisational measures in place to ensure an essentially equivalent level of protection to the personal data transferred to the US in the context of the use of cookies on the website. Cookie banner on the Parliament’s dedicated website — The EDPS reminded that: before setting cookies or any other technology falling within the scope of Article 5(3) ePrivacy Directive 2002/58/EC (hereafter ePrivacy Directive), the EU institution must provide the user with adequate information on what is accessed or stored on the user’s terminal equipment, on the purposes of this action and the means for expressing their consent; no action may be performed before the consent is collected. In addition, users must be enabled to withdraw their consent at any time; ‘cookie walls’ are not in line with Regulation 2018/1725, meaning that for consent to be freely given, access to the website’s service and functionalities should not depend on the users’ consent for cookies that are not strictly necessary in the sense described above; in case personal data collected through the cookies are shared with third parties such as analytics partners, the cookie banner should draw the user's attention to it. The EDPS reached the conclusion that the cookie banners in all three languages were not in line with the definition of consent under Article 3(15) Regulation 2018/1725, nor did they meet the requirements of Article 37 Regulation 2018/1725 and Article 5(3) ePrivacy Directive. The cookie banner further failed to provide transparent information regarding the processing of personal data in relation to the cookies on the website. Request for access to personal data — The Parliament was aware that the complainants’ personal data had been processed through the cookies, which were present on the website for the period between 30 September to 4 November 2020, since transfers of personal data had taken place. Consequently, and especially following the EDPS’ inquiry on the matter, the Parliament should have replied to the complainants’ access to personal data request. The Parliament should have provided the relevant information even if it was aware that the processing of the personal data in question was unlawful, as the main purpose of the right of access under Article 15 GDPR is precisely to enable data subjects to become aware of the processing and verify the lawfulness thereof, or exercise other data subject rights. Conclusion — The EDPS concludes that the Parliament has infringed the following articles of Regulation 2018/1725: Articles 26(1) and 29(1) due to its failure to fulfil its responsibilities as controller and use a processor providing sufficient guarantees to implement appropriate technical and organisational measures; Article 29(3) due to its failure to provide documentation relating to the detailed instructions given to the processor for the setting up and functioning of the website; Articles 4(1)(a) and 14, 4(2), and 15 due to its failure to respect the principle of transparency, accountability and the data subjects’ right to information because of the inaccurate data protection notice and cookie banner on the dedicated website; Article 46 and Article 48(2)(b) of the Regulation, due to its reliance on the Standard Contractual Clauses in the absence of a demonstration that data subjects’ personal data transferred to the US were provided an essential equivalent level of protection; Article 37 read in the light of Article 5(3) of the ePrivacy Directive, due to its failure to protect information (the cookies) transmitted to, stored in, related to, processed by and collected from the users’ terminal equipment; Articles 17 and 14(4) due to its failure to reply to the data subjects’ request for access to their personal data. On the basis of the above, the EDPS decides: to issue a reprimand to the Parliament in accordance with Article 58(2)(b) Regulation 2018/1725 for the above infringements; to order the Parliament, pursuant to Article 58(2)(b) Regulation 2018/1725:, to update its data protection notices in the dedicated website in order to provide all relevant information relating to the processing of personal data. The Parliament should address this order within one month from the date of the decision.

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

### Vodafone España, S.A.U.: Non-compliance with general data processing principles

*Source: Spanish Data Protection Authority (aepd), 2025-12-30 — https://overview.legal/posts/49094 — original: https://www.enforcementtracker.com/ETid-46*

The spanish telecommunications and informations agancy (SETSI) decided Vodafone had to reimburse a customer for costs he was wrongfully charged for. Nevertheless, Vodafone reported personal data of this respective customer to a solvency registry (BADEXCUG). The AEPD found this behaviour violated the principle of accuracy.

## Recent developments

### AI hallucinations: ChatGPT created a fake child murderer

*Source: noyb - European Center for Digital Rights, 2025-03-20 — https://overview.legal/posts/53159 — original: https://noyb.eu/en/ai-hallucinations-chatgpt-created-fake-child-murderer*

Artificial Intelligence OpenAI’s highly popular chatbot, ChatGPT, regularly gives false information about people without offering any way to correct it. In many cases, these so-called “hallucinations” can seriously damage a person’s reputation: In the past, ChatGPT falsely accused people of corruption, child abuse – or even murder. The latter was the case with a Norwegian user. When he tried to find out if the chatbot had any information about him, ChatGPT confidently made up a fake story that p

### HvJ: De PNR-richtlijn is geldig, mits deze beperkt blijft tot wat "strikt noodzakelijk" is.

*Source: eucrim, 2022-08-04 — https://overview.legal/posts/51841*

Op 21 juni 2022 heeft het Gerechtshof van de Europese Unie (Groot Beschouwingscollege) een baanbrekende uitspraak gedaan waarin het het EU-regime voor het verzamelen en gebruiken van gegevens van reizigers bevestigde, mits dit strikt wordt geïnterpreteerd in overeenstemming met de fundamentele rechten van de EU. Bovendien is het zonder onderscheid verwerken van deze gegevens bij vluchten die uitsluitend binnen de EU plaatsvinden verboden, tenzij er een dreiging van terrorisme bestaat. Over het algemeen moeten de gegevens van de passagiers ook binnen zes maanden worden verwijderd.

### A-G: rechtmatig verzamelde en opgeslagen persoonsgegevens mogen onder voorwaarden tijdelijk in een extra interne databank worden bewaard

*Source: NL EU Court Expert, 2022-04-09 — https://overview.legal/posts/6307 — original: https://ecer.minbuza.nl/-/a-g-rechtmatig-verzamelde-en-opgeslagen-persoonsgegevens-mogen-onder-voorwaarden-tijdelijk-in-een-extra-interne-databank-worden-bewaard?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-306*

Lawfully collected and stored personal data may be retained in an additional internal database, to the extent that it pursues the same data processing purposes as the original data collection. That is the opinion of Advocate General Pikamäe to the EU Court in response to questions from a Hungarian judge.

### SO Warszawa - C 310/23

*Source: GDPRhub, 2026-01-13 — https://overview.legal/posts/51627*

Vaste link: De verantwoordelijke partij reageerde niet adequaat en verstrekte onduidelijke informatie of verwees de betrokkene naar derden. Hierdoor heeft de betrokkene een klacht ingediend bij de Autoriteit Persoonsgegevens. De verantwoordelijke partij reageerde niet adequaat en verstrekte onduidelijke informatie of verwees de betrokkene naar derden. Hierdoor heeft de betrokkene een klacht ingediend bij de Autoriteit Persoonsgegevens. De Autoriteit Persoonsgegevens heeft een definitief besluit uitgevaardigd waarin de verantwoordelijke partij wordt gewaarschuwd voor het overtreden van artikel 6(1) van de AVG en artikel 5(1).

### SO Warszawa - Case C 310/23

*Source: GDPRhub, 2026-01-13 — https://overview.legal/posts/51906*

Permanent link: The responsible party did not respond adequately and provided unclear information or referred the individual to third parties. As a result, the individual filed a complaint with the Data Protection Authority. The responsible party did not respond adequately and provided unclear information or referred the individual to third parties. As a result, the individual filed a complaint with the Data Protection Authority. The Data Protection Authority has issued a final decision in which the responsible party is warned for violating Article 6(1) of the GDPR and Article 5(1).

## Literature

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132426 — original: https://doi.org/10.21552/edpl/2019/4/11*

### GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132478 — original: https://doi.org/10.21552/edpl/2018/3/15*

### GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132479 — original: https://doi.org/10.21552/edpl/2018/3/16*

### Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132504 — original: https://doi.org/10.21552/edpl/2022/4/8*

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Public Authority** — https://overview.legal/topics/overheid
  Government bodies and their data processing activities
- **Scientific Research** — https://overview.legal/topics/scientific-research
  Processing for scientific research purposes
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data

---
Generated by overview.legal · https://overview.legal/topics/accuracy · 2026-08-22
