# Archiving — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/archiving
> Sources are cited per item. Verify against the official texts before relying on them.

Archiving in the public interest

## Overview

## Legal Framework

Article 89 GDPR establishes the governing framework for processing personal data for archiving purposes in the public interest, as well as for scientific and historical research and statistical purposes. It requires Member States to provide appropriate safeguards for the rights and freedoms of data subjects, and permits derogations from certain data subject rights — specifically Articles 15, 16, 18, and 21 — when such derogations are necessary for the archiving purpose and likely to render the processing impossible or seriously impair its achievement.

Recital 52 elaborates that the prohibition on processing special categories of personal data under Article 9 may be lifted where Union or Member State law provides for it and appropriate safeguards are established, particularly when processing serves the public interest. The Dutch UAVG Article 45 implements these provisions at the national level, specifying the conditions under which public-interest archiving may proceed.

The rationale is straightforward: archiving in the public interest serves a legitimate societal function — preserving records of enduring value for future generations — but must be balanced against individuals' fundamental rights. The framework therefore permits controlled derogations from certain data subject rights while mandating technical and organizational safeguards to mitigate privacy risks.

## Key Developments

Case law has begun clarifying the practical boundaries of archiving obligations. Dutch administrative courts have addressed the scope of search obligations in access requests, holding that where a request is formulated in general terms, a public body may discharge its obligation by conducting a general search across the most common personal data systems. More specific requests demand correspondingly more targeted searches. This distinction directly affects how archived data must be retrieved and disclosed.

Police data retention rules illustrate the layered approach to archiving. Under the relevant Dutch police data provisions, data deleted from active police registers is retained for an additional five years for complaint handling and accountability purposes before destruction. During this retention period, certain data subject rights do not apply — a model that mirrors the Article 89 derogation structure.

The *Schrems* litigation before the CJEU reinforces that any transfer of archived personal data to third countries requires an adequacy decision or appropriate safeguards under Article 45 GDPR, absent which the processing risks unlawful interference with fundamental rights. The *V & EDPS v. European Parliament* ruling further establishes that transferring sensitive data — even between EU institutions — constitutes an interference with Article 8 ECHR rights, requiring justification regardless of the final use to which the data is put.

Enforcement actions by the Italian Garante (Verisure, €400,000) and the Spanish AEPD (GSMA, €600,000) demonstrate that retention and archiving practices face significant scrutiny, particularly where retention periods are excessive or purposes are insufficiently circumscribed.

## Practical Guidance

- **Establish a legal basis under Member State law**: Article 89 processing for public-interest archiving requires a specific national legal mandate. Verify that your archiving activity is grounded in applicable Member State legislation implementing Article 89.

- **Implement appropriate safeguards before relying on derogations**: Technical and organizational measures — pseudonymization, access controls, encryption — must be in place before derogating from data subject rights under Articles 15, 16, 18, and 21 GDPR.

- **Document retention periods with precision**: The police data model — five-year post-deletion retention for accountability, then destruction — illustrates the level of specificity required. Define clear start dates, durations, and destruction triggers for each archive category.

- **Calibrate search responses to request specificity**: When responding to access requests involving archived data, match the breadth of your search to the specificity of the request. General requests permit general searches; specific demands require targeted retrieval.

- **Assess international transfers of archived data separately**: Transferring archived personal data to third countries triggers Article 45 adequacy requirements. Ensure appropriate safeguards are in place, as the *Schrems* framework applies equally to archived data.

## Case law

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

### Meta Platforms v noyb

*Source: CJEU, C-252/21, 2023-01-12 — https://overview.legal/posts/51484 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0252*

GDPR consent requirements and lead supervisory authority mechanism.

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)

*Source: Hof van Justitie EU, 2020-07-16 — https://overview.legal/posts/1 — original: https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62018CJ0311*

Het Hof van Justitie verklaart het Privacy Shield-akkoord ongeldig wegens onvoldoende waarborgen voor Europese burgers tegen toegang door Amerikaanse inlichtingendiensten.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

### Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV

*Source: CJEU, C-40/17, 2019-07-29 — https://overview.legal/posts/51478 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0040*

Website operators using Facebook Like button are joint controllers for data collection.

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

### VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”)

*Source: CJEU, 2010-11-09 — https://overview.legal/posts/6180 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6180*

Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their consent. (¶ 54)

### CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is

*Source: CJEU, 2010-06-29 — https://overview.legal/posts/6182 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62008CJ0028&ref=6182*

Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69)

### USR - Us I-755/2025-8

*Source: Administrative Court in Rijeka, 2025-11-11 — https://overview.legal/posts/49225 — original: https://gdprhub.eu/index.php?title=USR_-_Us_I-755/2025-8*

Facts — The data subject was a member of the management board of Zagrebački holding, a company owned by the City of Zagreb, from 3 September 2021 until 31 March 2023. A television broadcaster published several pieces, including a video on its YouTube channel, reporting on the data subject’s resignation. The publications mentioned his name, role, employer, salary, and information on the brand of his private car. The data subject filed a complaint with the Croatian Personal Data Protection Agency (AZOP), claiming that the publication constituted unlawful processing under the GDPR because the media lacked a valid legal basis under Article 6, the reporting was inaccurate and excessive, and it did not serve any genuine public interest. He latter further claimed during the lawsuit against AZOP's decision that the authority had incorrectly and incompletely established the facts, misapplied substantive law, and breached procedural rules. He emphasized that the published personal data was unrelated to transparency in public administration, that he was neither a public figure nor a political actor, and that any public interest ended once he left office on 31 March 2023. He invoked his right to erasure under Article 17 GDPR and sought removal of the content, annulment of AZOP’s decision, or alternatively, a remittal for a new procedure. AZOP contested the lawsuit in full, maintaining that it had acted in accordance with Article 34 of the Croatian GDPR Implementation Act and Article 77 GDPR. It argued that the publication fell within a justified public interest under Article 8 of the Croatian Media Act and that it had properly carried out a balancing test between privacy (Article 8 ECHR) and freedom of expression (Article 10 ECHR). According to AZOP, the reporting was necessary, proportionate, and not sensationalistic, and did not excessively intrude on the data subject’s privacy. It added that consent was not required because the processing relied on legitimate interest under Article 6(1)(f) GDPR. Holding — The Administrative Court dismissed the action and upheld AZOP’s decision. Because Zagrebački holding is a city-owned and publicly funded company, the court considered information about the data subject’s salary, compensation for using his private vehicle in official duties, and his managerial role to be directly connected to the use of public resources. This placed the publication within the legitimate public interest in transparency recognised by Article 8 of the Media Act. In its proportionality assessment, the court accepted AZOP's application of Article 5 and 6 GDPR, emphasizing that the published data did not touch upon the data subject’s family or intimate life but related solely to his public functions. Publication was therefore limited to what was necessary to inform the public about the management of a publicly owned company. The data subject’s claims that the publication was false or harmful to his reputation did not alter the outcome, as AZOP is not empowered to determine the truthfulness or tone of journalistic content, particularly under the journalistic exemption in Article 85 GDPR. Issues of accuracy or reputational harm must instead be pursued through media-law mechanisms such as requests for correction or civil actions. On the erasure request, the court held that the right to be forgotten under Article 17 GDPR cannot override freedom of expression and information where media reporting is involved. Although the data subject no longer served on the board, the publication continued to contribute to public understanding of how a major public entity was run during his tenure, thus the public interest persisted and erasure was not justified. Finally, the court reiterated that consent was not required because Article 6 GDPR offers alternative lawful bases for processing. Since Article 6(1)(f) was satisfied, the absence of consent was irrelevant. Concluding that AZOP had properly applied the law and that the interference with the data subject’s privacy was proportionate, the court upheld the decision and denied the data subject’s claim and costs.

### Privacy International v Secretary of State

*Source: CJEU, C-623/17, 2020-10-06 — https://overview.legal/posts/51481 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0623*

General and indiscriminate transmission of traffic data to security agencies incompatible with EU law.

### Peter Nowak v Data Protection Commissioner

*Source: CJEU, C-434/16, 2017-12-20 — https://overview.legal/posts/51480 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0434&ref=51480*

Examination scripts constitute personal data of the candidate.

## Guidance

### Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH

*Source: EDPB, edpb-opinion-202515-dbo-certificationcriteria-en, 2025-07-14 — https://overview.legal/posts/51079 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-152025-on-the-draft-decision-of-the-austrian_en*

Adopted 1 Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority ( AT SA) regarding the certificat ion criteria of BDO Consulting GmbH Adopted on 8 July 2025 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of…

### Guidelines 02/2024 on Article 48 GDPR

*Source: EDPB, edpb-guidelines-022024-on-article-48-gdpr, 2025-06-05 — https://overview.legal/posts/38045 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022024-on-article-48-gdpr_en*

Article  48  GDPR  provides  that:  ' Any  judgment  of  a  court  or  tribunal  and  any  decision  of  an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data  may  only  be  recognised  or  enforceable  in  any  manner  if  based  on  an  international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer...

### Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria

*Source: EDPB, opinion-152023-on-the-draft-decision-of-the-dutch-supervisory-en, 2023-09-19 — https://overview.legal/posts/125831 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-152023-on-the-draft-decision-of-the-dutch-supervisory_en*

Adopted 1 Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria Adopted on 19 09 2023 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Guidelines 06/2022 on the practical implementation of amicable settlements

*Source: EDPB, edpb-guidelines-on-the-practical-implementation-of-amicable-settlements, 2022-05-12 — https://overview.legal/posts/38072 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-062022-on-the-practical-implementation-of-amicable-settlements_en*

The EDPB adopted Guidelines 06/2022 to provide practical guidance on the implementation of amicable settlements between supervisory authorities and controllers or processors under the GDPR. The guidelines address the scope and definition of amicable settlements, the legal basis for this power, and its procedural operation within the one-stop-shop mechanism, including the roles of the complaint-receiving competent supervisory authority and the lead supervisory authority. No fines are imposed as this is a guidance document rather than an enforcement decision.

### Guidelines 02/2022 on the application of Article 60 GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-60-gdpr, 2022-03-14 — https://overview.legal/posts/38066 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022022-on-the-application-of-article-60-gdpr_en*

With the introduction of the GDPR, the concept of the one-stop shop was established as one of the main innovations. In cross-border processing cases, the supervisory authority in the Member State of the controller's or processor's main establishment is the authority leading the  enforcement of the GDPR for the respective cross-border processing activities, in cooperation with all the authorities which may face the effects of the processing activities at stake: be it  through  the establishments ...

### Guidelines 10/2020 on restrictions under Article 23 GDPR

*Source: EDPB, edpb-guidelines-on-restrictions-under-article-23-gdpr, 2021-10-13 — https://overview.legal/posts/38062 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the scope and application of Article 23 of the GDPR, which allows Member States to restrict certain data subject rights and controller obligations. The guidelines outline the necessary conditions and safeguards, emphasizing that any restrictions must respect the essence of fundamental rights and be implemented via foreseeable, proportionate legislative measures. This document serves as authoritative guidance for interpreting the specific grounds and requirements under which Member States may legally impose such limitations.

### Guidelines 07/2020 on the concepts of controller and processor in the GDPR

*Source: EDPB, edpb-guidelines-on-the-concepts-of-controller-and-processor-in-the-gdpr, 2021-07-07 — https://overview.legal/posts/38069 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en*

The concepts of controller, joint controller and processor play a crucial role in the application of the General Data Protection Regulation 2016/679 (GDPR), since they determine who shall be responsible for compliance with different data protection rules, and how data subjects can exercise their rights in practice. The precise meaning of these concepts and the criteria for their correct interpretation must be sufficiently clear and consistent throughout the European Economic Area (EEA). The conc...

## Enforcement decisions

### Verisure Italy s.r.l.: Niet-naleving van algemene principes voor gegevensverwerking.

*Source: Italian Data Protection Authority (Garante), 2025-11-27 — https://overview.legal/posts/51925*

De Italiaanse gegevensbeschermingsautoriteit heeft Verisure Italy s.r.l. een boete van 400.000 euro opgelegd. De verantwoordelijke partij was actief met direct marketingactiviteiten. De verantwoordelijke partij heeft nagelaten te waarborgen dat de toestemming die door de betrokkenen was verstrekt, geldig was. Bovendien heeft de verantwoordelijke partij nagelaten om adequate bewaartermijnen voor de verwerkte gegevens in te stellen. Ten slotte heeft de verantwoordelijke partij niet adequaat gereageerd op de verzoeken van de betrokkenen om hun rechten uit te oefenen, en heeft zij hen niet voldoende geïnformeerd over de verwerking van hun gegevens.

### APD/GBA (Belgium) - 115/2022

*Source: APD/GBA (Belgium), 2022-07-19 — https://overview.legal/posts/6317 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_115/2022*

Facts — During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor, stating that she was unfit to work and would leave the company. This statement was also included in the minutes of that meeting. When the data subject discovered this, she filed a complaint against the controller with the Belgian DPA for unlawfully disclosing health related personal data to third parties. She added that the minutes were then saved on the controller´s server, freely accessible to all its staff, including from other departments. Holding — The DPA noted that the data subject did not dispute the lawfulness of processing of the information that she was unfit to work, but the subsequent communication about her health to her colleagues and other staff members. The DPA noted that it was not able to verify whether the minutes were actually made available on the controller's server. However if that were the case, this would amount to an additional processing activity and the following findings of the infringement also apply. The DPA first assessed whether the further processing was compatible with the purpose of the original processing (Article 5(1)(b) GDPR). It found that the purpose of the original processing was personnel management. The DPA held that the data subject could not reasonably expect that the same data would be communicated widely beyond the persons authorised for personnel management. Especially considering the sensitive nature of the data. Therefore the DPA held that the further processing was incompatible with the purpose of the original processing. As the further processing was incompatible with the purpose of the original processing, the DPA noted that it could only be lawful if it had its own legal basis pursuant to Article 9(2) juncto Article 6(1). However the DPA found that this was also not present. Therefore, the DPA held that the controller did not have a proper legal basis for processing the data subject's health related data and thereby violated Article 5(1)(b) juncto Article 6(4) and Article 9(2). The DPA issued a reprimand against the controller. The DPA noted that it was not competent to issue a fine as the controller was a public authority.

### AEPD (Spain) - EXP202203606

*Source: AEPD (Spain), 2022-04-22 — https://overview.legal/posts/125657 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202203606*

Facts — Resolution No. R/00665/2022 is highlighted by a case concerning a claimant (namely A.A.A) and a respondent party (namely Securitas Direct España, S.A). The claimant filed against the respondent party for not having been duly attended to his right of access and deletion enshrined in Articles 15 to 22 GDPR, Articles 13 to 18 LOPDGDD and Article 17 GDPR respectively. The conflict of law arose in this case when a sufficiently legally established response was not generated by the respondent to the claimants request. Furthermore, the claim was transferred to the respondent so that the entity could proceed with its analysis and provide a response to the claimant within a period of one month. The Director of the Spanish Data Protection Agency agreed to admit the claim for processing and the parties concerned were informed of the maximum term for resolution, that being six months. The competence of the Spanish Data Protection Agency is refined by Article 55 GDPR in the promotion of an obligation between controllers and processors to deal with complaints issued by data subjects. The result of the said transfer did not allow the claimants issues to be understood as satisfied. Consequently, due to the lack of attention delegated to the claimants rights further set forth in Article 15 GDPR, Article 16 GDPR, Article 17 GDPR, Article 18 GDPR, Article 19 GDPR, Article 20 GDPR, Article 21 GDPR and Article 22 GDPR, an agreement to admit for processing was initiated. Holding — The Director of the Spanish Data Protection Agency went on to note that considering the purpose of the outlined procedure was to ensure that the rights of affected parties were fully restored, the complaint that gave rise to this procedure should be upheld on formal grounds due to the fact that the right of access had been complied with and the right of erasure had been duly denied (on the applicable grounds of Article 17 GDPR).

### GSMA Limited: Insufficient legal basis for data processing

*Source: Spanish Data Protection Authority (aepd), 2024-05-31 — https://overview.legal/posts/48660 — original: https://www.enforcementtracker.com/ETid-2545*

The Spanish DPA has imposed a fine of EUR 600,000 on GSMA Limited. In 2022, GSMA Limited required employees of its suppliers to register on an online platform and upload proof of vaccination against COVID-19. One of the data subjects filed a complaint with the DPA as they considered the data processing to be unlawful. GSMA referred to a legal obligation and public interest, but could not provide a specific legal basis. The DPA found that less invasive safeguards would have been possible and that

### Brussels Airport Charleroi: Insufficient legal basis for data processing

*Source: Belgian Data Protection Authority (APD), 2022-04-04 — https://overview.legal/posts/47232 — original: https://www.enforcementtracker.com/ETid-1117*

The Belgian DPA has fined Brussels Airport Charleroi EUR 100,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of persons at the airport. Due to the Covid-19 pandemic the airport used thermal imaging cameras to filter out people with body temperatures above 38 degrees. Those filtered out were then required to answer questions about possible coronavirus symptoms. The DPA particularly noted that the airport did not have a valid lega

### Brussels Airport Zaventem: Insufficient legal basis for data processing

*Source: Belgian Data Protection Authority (APD), 2022-04-04 — https://overview.legal/posts/47231 — original: https://www.enforcementtracker.com/ETid-1116*

The Belgian DPA has fined Brussels Airport Zaventem EUR 200,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of persons at the airport. Due to the Covid-19 pandemic the airport used thermal imaging cameras to filter out people with body temperatures above 38 degrees. Those filtered out were then required to answer questions about possible coronavirus symptoms. The DPA particularly noted that the airport did not have a valid legal

### Ambuce Rescue Team: Insufficient legal basis for data processing

*Source: Belgian Data Protection Authority (APD), 2022-04-04 — https://overview.legal/posts/47233 — original: https://www.enforcementtracker.com/ETid-1118*

The Belgian DPA has fined Ambuce Rescue Team EUR 20,000. The fine is related to the fines against Brussels Airport Charleroi and Brussels Airport Zaventem. Due to the Covid 19 pandemic, the airports used thermal imaging cameras to filter out people with body temperatures above 38 degrees. Those filtered out were then asked to answer questions about possible coronavirus symptoms. In this process, Ambuce Rescue Team provided the questionnaires. Specifically, the DPA found that there was no valid l

### Deutsche Wohnen SE: Non-compliance with general data processing principles

*Source: Data Protection Authority of Berlin, 2021-02-23 — https://overview.legal/posts/46213 — original: https://www.enforcementtracker.com/ETid-98*

Originally, a fine in the amount of EUR 14.500.000 was issued against Deutsche Wohnen SE for using an archiving system for the storage of personal data of tenants that, according to the data protection authority, did not provide for the possibility of removing data that was no longer required. According to the data protection authority, personal data of tenants were stored without checking whether storage was permissible or even necessary and it was therefore possible to access personal data of

## Recent developments

### EU-Hof: gegevens waaruit indirect de seksuele geaardheid van een persoon kan worden afgeleid vormen gevoelige gegevens in de zin van de AVG

*Source: NL EU Court Expert, 2022-08-17 — https://overview.legal/posts/6290 — original: https://ecer.minbuza.nl/-/eu-hof-gegevens-waaruit-indirect-de-seksuele-geaardheid-van-een-persoon-kan-worden-afgeleid-vormen-gevoelige-gegevens-in-de-zin-van-de-avg?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-300*

The processing of personal data that may indirectly reveal sensitive information about an individual, such as information about their sexual orientation, may qualify as processing of "special categories of personal data" within the meaning of the AVG. The processing of such sensitive data is prohibited in principle. This is the EU Court's answer to questions from a Lithuanian judge.

### HvJ: De PNR-richtlijn is geldig, mits deze beperkt blijft tot wat "strikt noodzakelijk" is.

*Source: eucrim, 2022-08-04 — https://overview.legal/posts/51841*

Op 21 juni 2022 heeft het Gerechtshof van de Europese Unie (Groot Beschouwingscollege) een baanbrekende uitspraak gedaan waarin het het EU-regime voor het verzamelen en gebruiken van gegevens van reizigers bevestigde, mits dit strikt wordt geïnterpreteerd in overeenstemming met de fundamentele rechten van de EU. Bovendien is het zonder onderscheid verwerken van deze gegevens bij vluchten die uitsluitend binnen de EU plaatsvinden verboden, tenzij er een dreiging van terrorisme bestaat. Over het algemeen moeten de gegevens van de passagiers ook binnen zes maanden worden verwijderd.

### EU-wetgeving inzake datagovernance definitief vastgesteld

*Source: NL EU Court Expert, 2022-06-08 — https://overview.legal/posts/6302 — original: https://ecer.minbuza.nl/-/eu-wetgeving-inzake-datagovernance-definitief-vastgesteld?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-303*

The new data governance regulation sets out the conditions for the reuse of certain government data. In addition, the regulation provides a notification and oversight framework for the provision of data mediation services. Furthermore, the regulation contains a framework for the voluntary registration of entities that collect and process data made available for altruistic purposes. The rules will apply from September 2023.

### A-G: rechtmatig verzamelde en opgeslagen persoonsgegevens mogen onder voorwaarden tijdelijk in een extra interne databank worden bewaard

*Source: NL EU Court Expert, 2022-04-09 — https://overview.legal/posts/6307 — original: https://ecer.minbuza.nl/-/a-g-rechtmatig-verzamelde-en-opgeslagen-persoonsgegevens-mogen-onder-voorwaarden-tijdelijk-in-een-extra-interne-databank-worden-bewaard?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-306*

Lawfully collected and stored personal data may be retained in an additional internal database, to the extent that it pursues the same data processing purposes as the original data collection. That is the opinion of Advocate General Pikamäe to the EU Court in response to questions from a Hungarian judge.

### EU-Hof: een belastingautoriteit die bij een marktaanbieder van  internetdiensten gegevens opvraagt moet de AVG in acht nemen

*Source: NL EU Court Expert, 2022-03-02 — https://overview.legal/posts/6309 — original: https://ecer.minbuza.nl/-/eu-hof-een-belastingautoriteit-die-bij-een-marktaanbieder-van-internetdiensten-gegevens-opvraagt-moet-de-avg-in-acht-nemen?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-308*

The collection by the tax authority of a Member State of personal data concerning the advertisements for the sale of vehicles placed on the website of an economic operator falls within the material scope of the General Data Protection Regulation (AVG). Thus, that authority will also have to comply with the principles on the processing of personal data laid down in the AVG. However, a tax authority can derogate from the AVG in certain cases, even if the right to derogate is not granted by nationa

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Public Authority** — https://overview.legal/topics/overheid
  Government bodies and their data processing activities
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes

---
Generated by overview.legal · https://overview.legal/topics/archiving · 2026-08-22
