# Authority Powers for Fundamental Rights Protection — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/authority-powers-fundamental-rights-protection
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed because the content specifically addresses the powers and authorities granted to competent authorities to protect fundamental rights in AI systems, including inspection, intervention, and corrective action powers that are not adequately covered by existing topics.

## Overview

## Legal Framework

Authority powers for fundamental rights protection operate at the intersection of the GDPR and the AI Act. Under Article 58(2) GDPR, supervisory authorities wield corrective powers including the ability to impose temporary or definitive processing bans, order suspension of data flows to third countries, and initiate judicial proceedings. Article 58(1) GDPR confers extensive investigative powers to handle complaints and conduct inquiries. These powers are framed as discretionary competencies rather than mandatory obligations — a distinction confirmed by the CJEU and Dutch administrative courts, which have held that Recital 148 GDPR does not compel authorities to sanction every infringement with at minimum a reprimand.

The AI Act reinforces this architecture. Article 20 of the AI Act obliges providers of high-risk AI systems to implement corrective measures and notification duties when systems fail to comply with requirements. Article 27 of the AI Act introduces a fundamental rights impact assessment specific to high-risk AI deployments, requiring organizations to evaluate impacts on rights and freedoms before and during operation. Recital 155 of the AI Act underscores the need for post-market monitoring systems to detect and address emerging risks, including interactions between AI systems and other software or devices.

Article 82(4) GDPR establishes the liability regime underpinning these enforcement powers, ensuring data subjects can exercise rights against any joint controller — a principle that predates the GDPR under the 1995 Data Protection Directive and was affirmed by the Article 29 Working Party in Opinion 1/2010.

## Key Developments

The CJEU's ruling in *Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems* (C-362/14) established that national supervisory authorities are independently responsible for verifying whether data transfers to third countries comply with EU requirements, regardless of Commission adequacy decisions. The Court emphasized that this responsibility is of paramount importance for fundamental rights protection. *Schrems II* further reinforced that Article 58(2)(f) and (j) GDPR empower authorities to impose processing bans and suspend data flows when third-country protection is inadequate.

Dutch jurisprudence (ECLI:NL:RVS:2021:1407) clarified that corrective measures under Article 58(2) GDPR constitute a discretionary power, not a duty — meaning authorities may calibrate enforcement responses proportionally rather than mechanically penalizing every violation. A subsequent Dutch case confirmed that complainants cannot compel authorities to adopt specific corrective measures, reinforcing the discretionary nature of enforcement.

Enforcement practice demonstrates the scale of these powers. The Croatian DPA imposed a €4.5 million fine on a telecommunications operator for multiple GDPR violations, while the Spanish DPA has exercised corrective powers even for relatively minor infractions, showing authorities' willingness to act across the full spectrum of non-compliance.

## Practical Guidance

- **Maintain a post-market monitoring system for high-risk AI systems** that includes analysis of interactions with other AI systems, devices, and software, as required by Recital 155 of the AI Act and Article 20 of the AI Act. Document corrective actions taken and their outcomes.

- **Conduct a fundamental rights impact assessment** under Article 27 of the AI Act before deploying high-risk AI systems, identifying specific risks to data subject rights and documenting mitigation measures.

- **Prepare for authority inspections by maintaining an up-to-date processing activity register** that can be produced on request, recognizing that supervisory authorities may investigate complaints and exercise corrective powers including processing bans and data flow suspensions under Article 58(2) GDPR.

- **Establish clear internal escalation procedures** for responding to authority inquiries, including designated points of contact for representatives under Article 27 GDPR who must cooperate with supervisory authorities on all compliance measures.

- **Do not assume proportionality in enforcement will shield non-compliance**: while authorities exercise discretion under Article 58(2) GDPR, the Schrems line of cases confirms that authorities must act when fundamental rights are at risk, and complainants' complaints trigger investigative obligations under Article 58(1) GDPR.

## Legislation (full text of key provisions)

### Fundamental rights impact assessment for high-risk AI systems

*Source: AI Act, aiact-art-27-en, 2024-06-12 — https://overview.legal/posts/92424*

### Recital 96 — fundamental rights impact assessment deployers

*Source: AI Act, aiact-rec-96-en, 2024-06-12 — https://overview.legal/posts/93874*

In order to efficiently ensure that fundamental rights are protected, deployers of high-risk AI systems that are bodies governed by public law, or private entities providing public services and deployers of certain high-risk AI systems listed in an annex to this Regulation, such as banking or insurance entities, should carry out a fundamental rights impact assessment prior to putting it into use. Services important for individuals that are of public nature may also be provided by private entities. Private entities providing such public services are linked to tasks in the public interest such as in the areas of education, healthcare, social services, housing, administration of justice. The aim of the fundamental rights impact assessment is for the deployer to identify the specific risks to the rights of individuals or groups of individuals likely to be affected, identify measures to be taken in the case of a materialisation of those risks. The impact assessment should be performed prior to deploying the high-risk AI system, and should be updated when the deployer considers that any of the relevant factors have changed. The impact assessment should identify the deployer’s relevant processes in which the high-risk AI system will be used in line with its intended purpose, and should include a description of the period of time and frequency in which the system is intended to be used as well as of specific categories of natural persons and groups who are likely to be affected in the specific context of use. The assessment should also include the identification of specific risks of harm likely to have an impact on the fundamental rights of those persons or groups. While performing this assessment, the deployer should take into account information relevant to a proper assessment of the impact, including but not limited to the information given by the provider of the high-risk AI system in the instructions for use. In light of the risks identified, deployers should determine measures to be taken in the case of a materialisation of those risks, including for example governance arrangements in that specific context of use, such as arrangements for human oversight according to the instructions of use or, complaint handling and redress procedures, as they could be instrumental in mitigating risks to fundamental rights in concrete use-cases. After performing that impact assessment, the deployer should notify the relevant market surveillance authority. Where appropriate, to collect relevant information necessary to perform the impact assessment, deployers of high-risk AI system, in particular when AI systems are used in the public sector, could involve relevant stakeholders, including the representatives of groups of persons likely to be affected by the AI system, independent experts, and civil society organisations in conducting such impact assessments and designing measures to be taken in the case of materialisation of the risks. The European Artificial Intelligence Office (AI Office) should develop a template for a questionnaire in order to facilitate compliance and reduce the administrative burden for deployers.

### Recital 159 — biometric AI surveillance authority powers

*Source: AI Act, aiact-rec-159-en, 2024-06-12 — https://overview.legal/posts/94000*

Each market surveillance authority for high-risk AI systems in the area of biometrics, as listed in an annex to this Regulation insofar as those systems are used for the purposes of law enforcement, migration, asylum and border control management, or the administration of justice and democratic processes, should have effective investigative and corrective powers, including at least the power to obtain access to all personal data that are being processed and to all information necessary for the performance of its tasks. The market surveillance authorities should be able to exercise their powers by acting with complete independence. Any limitations of their access to sensitive operational data under this Regulation should be without prejudice to the powers conferred to them by Directive (EU) 2016/680. No exclusion on disclosing data to national data protection authorities under this Regulation should affect the current or future powers of those authorities beyond the scope of this Regulation.

### Recital 93 — deployers role fundamental rights protection

*Source: AI Act, aiact-rec-93-en, 2024-06-12 — https://overview.legal/posts/93868*

Whilst risks related to AI systems can result from the way such systems are designed, risks can as well stem from how such AI systems are used. Deployers of high-risk AI system therefore play a critical role in ensuring that fundamental rights are protected, complementing the obligations of the provider when developing the AI system. Deployers are best placed to understand how the high-risk AI system will be used concretely and can therefore identify potential significant risks that were not foreseen in the development phase, due to a more precise knowledge of the context of use, the persons or groups of persons likely to be affected, including vulnerable groups. Deployers of high-risk AI systems listed in an annex to this Regulation also play a critical role in informing natural persons and should, when they make decisions or assist in making decisions related to natural persons, where applicable, inform the natural persons that they are subject to the use of the high-risk AI system. This information should include the intended purpose and the type of decisions it makes. The deployer should also inform the natural persons about their right to an explanation provided under this Regulation. With regard to high-risk AI systems used for law enforcement purposes, that obligation should be implemented in accordance with Article 13 of Directive (EU) 2016/680.

### Recital 153 — fundamental rights protection and proportionality

*Source: DSA, dsa-rec-153-en, 2022-10-19 — https://overview.legal/posts/95703*

This Regulation respects the fundamental rights recognised by the Charter and the fundamental rights constituting general principles of Union law. Accordingly, this Regulation should be interpreted and applied in accordance with those fundamental rights, including the freedom of expression and of information, as well as the freedom and pluralism of the media. When exercising the powers set out in this Regulation, all public authorities involved should achieve, in situations where the relevant fundamental rights conflict, a fair balance between the rights concerned, in accordance with the principle of proportionality.

### Recital 122 — tiered supervisory regimes for entities

*Source: NIS2, nis2-rec-122-en, 2022-12-14 — https://overview.legal/posts/96772*

In order to strengthen the supervisory powers and measures that help ensure effective compliance, this Directive should provide for a minimum list of supervisory measures and means through which the competent authorities can supervise essential and important entities. In addition, this Directive should establish a differentiation of supervisory regime between essential and important entities with a view to ensuring a fair balance of obligations on those entities and on the competent authorities. Therefore, essential entities should be subject to a comprehensive ex ante and ex post supervisory regime, while important entities should be subject to a light, ex post only, supervisory regime. Important entities should therefore not be required to systematically document compliance with cybersecurity risk-management measures, while the competent authorities should implement a reactive ex post approach to supervision and, hence, not have a general obligation to supervise those entities. The ex post supervision of important entities may be triggered by evidence, indication or information brought to the attention of the competent authorities considered by those authorities to suggest potential infringements of this Directive. For example, such evidence, indication or information could be of the type provided to the competent authorities by other authorities, entities, citizens, media or other sources or publicly available information, or could emerge from other activities conducted by the competent authorities in the fulfilment of their tasks.

### Recital 129 — supervisory authorities tasks and powers

*Source: GDPR, gdpr-rec-129-en, 2016-04-27 — https://overview.legal/posts/91773*

In order to ensure consistent monitoring and enforcement of this Regulation throughout the Union, the supervisory authorities should have in each Member State the same tasks and effective powers, including powers of investigation, corrective powers and sanctions, and authorisation and advisory powers, in particular in cases of complaints from natural persons, and without prejudice to the powers of prosecutorial authorities under Member State law, to bring infringements of this Regulation to the attention of the judicial authorities and engage in legal proceedings. Such powers should also include the power to impose a temporary or definitive limitation, including a ban, on processing. Member States may specify other tasks related to the protection of personal data under this Regulation. The powers of supervisory authorities should be exercised in accordance with appropriate procedural safeguards set out in Union and Member State law, impartially, fairly and within a reasonable time. In particular each measure should be appropriate, necessary and proportionate in view of ensuring compliance with this Regulation, taking into account the circumstances of each individual case, respect the right of every person to be heard before any individual measure which would affect him or her adversely is taken and avoid superfluous costs and excessive inconveniences for the persons concerned. Investigatory powers as regards access to premises should be exercised in accordance with specific requirements in Member State procedural law, such as the requirement to obtain a prior judicial authorisation. Each legally binding measure of the supervisory authority should be in writing, be clear and unambiguous, indicate the supervisory authority which has issued the measure, the date of issue of the measure, bear the signature of the head, or a member of the supervisory authority authorised by him or her, give the reasons for the measure, and refer to the right of an effective remedy. This should not preclude additional requirements pursuant to Member State procedural law. The adoption of a legally binding decision implies that it may give rise to judicial review in the Member State of the supervisory authority that adopted the decision.

### Recital 124 — risk-based supervisory prioritisation and methodologies

*Source: NIS2, nis2-rec-124-en, 2022-12-14 — https://overview.legal/posts/96776*

In the exercise of ex ante supervision, the competent authorities should be able to decide on the prioritisation of the use of supervisory measures and means at their disposal in a proportionate manner. This entails that the competent authorities can decide on such prioritisation based on supervisory methodologies which should follow a risk-based approach. More specifically, such methodologies could include criteria or benchmarks for the classification of essential entities into risk categories and corresponding supervisory measures and means recommended per risk category, such as the use, frequency or types of on-site inspections, targeted security audits or security scans, the type of information to be requested and the level of detail of that information. Such supervisory methodologies could also be accompanied by work programmes and be assessed and reviewed on a regular basis, including on aspects such as resource allocation and needs. In relation to public administration entities, the supervisory powers should be exercised in line with the national legislative and institutional frameworks.

### Recital 34 — responsible use of real-time biometric identification

*Source: AI Act, aiact-rec-34-en, 2024-06-12 — https://overview.legal/posts/93750*

In order to ensure that those systems are used in a responsible and proportionate manner, it is also important to establish that, in each of those exhaustively listed and narrowly defined situations, certain elements should be taken into account, in particular as regards the nature of the situation giving rise to the request and the consequences of the use for the rights and freedoms of all persons concerned and the safeguards and conditions provided for with the use. In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement should be deployed only to confirm the specifically targeted individual’s identity and should be limited to what is strictly necessary concerning the period of time, as well as the geographic and personal scope, having regard in particular to the evidence or indications regarding the threats, the victims or perpetrator. The use of the real-time remote biometric identification system in publicly accessible spaces should be authorised only if the relevant law enforcement authority has completed a fundamental rights impact assessment and, unless provided otherwise in this Regulation, has registered the system in the database as set out in this Regulation. The reference database of persons should be appropriate for each use case in each of the situations mentioned above.

## Case law

### Judgment of the Court (First Chamber) of 26 September 2024.#TR v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(a) and (f) – Tasks of the supervisory authority – Article 58(2) – Corrective powers – Administrative fine – Discretion of the supervisory authority – Limits.#Case C-768/21.

*Source: Court of Justice of the European Union, C-768/21, 2024-09-26 — https://overview.legal/posts/132245 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0768*

In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of the Hessischer Beauftragte für Datenschutz und Informationsfreiheit (HBDI) for declining to exercise corrective powers against Sparkasse X following a personal data breach complaint. The Court clarified the limits of supervisory authorities' discretion under GDPR Articles 57(1) and 58(2), holding that while authorities retain discretion in selecting corrective measures, they are legally obliged to exercise those powers when an infringement is established, and complainants have a right to an effective remedy under Article 77 even where no enforcement action was taken. No fine was imposed in this proceeding, as the ruling addressed the supervisory authority's enforcement obligations rather than penalizing a controller.

### Judgment of the Court (Fifth Chamber) of 14 March 2024.#Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 58(2)(d) and (g) – Powers of the supervisory authority of a Member State – Paragraph 17(1) – Right to e

*Source: Court of Justice of the European Union, C-46/23, 2024-03-14 — https://overview.legal/posts/132267 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0046*

In a preliminary ruling requested by the Budapest High Court, the Court of Justice interpreted whether Article 58(2)(d) and (g) of the GDPR permits a national supervisory authority to order a controller to erase unlawfully processed personal data without a prior request from the data subject. The case arose from a dispute between the Budapest District IV (Újpest) municipal administration and the Hungarian National Data Protection and Freedom of Information Authority (NAIH), which had ordered the municipality to erase unlawfully processed data. The Court held that GDPR provisions do not require a prior data subject request for a supervisory authority to exercise its corrective power to order erasure of unlawfully processed personal data, as such a requirement would undermine the consistent and effective protection of fundamental rights under the GDPR.

### HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)

*Source: Hof van Justitie EU, 2020-07-16 — https://overview.legal/posts/1 — original: https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62018CJ0311*

Het Hof van Justitie verklaart het Privacy Shield-akkoord ongeldig wegens onvoldoende waarborgen voor Europese burgers tegen toegang door Amerikaanse inlichtingendiensten.

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/5945 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311*

“the national supervisory authorities are responsible for monitoring compliance with the EU rules concerning the protection of natural persons with regard to the processing of personal data. Each of those authorities is therefore vested with the power to check whether a transfer of personal data from its own Member State to a third country complies with the requirements laid down in that regulation” / “The exercise of that responsibility is of particular importance where personal data is tra

### Spanish court reviews DPA decision on KFC Spain website privacy information and DPO

*Source: National Court, 2026-07-16 — https://overview.legal/posts/184690 — original: https://gdprhub.eu/index.php?title=AN_-_SAN_3154/2026*

Facts — In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website. The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer. The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented corrective measures. Holding — The Court dismissed the appeal and upheld the total fine of €25,000. Regarding Article 13 GDPR, the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding Article 37(1)(b) GDPR, the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.

### Deutsche Wohnen SE v Staatsanwaltschaft Berlin

*Source: CJEU, C-807/21, 2023-12-05 — https://overview.legal/posts/51487 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0807*

Fines can be imposed directly on legal persons without identifying responsible natural person.

### NSA - III OSK 5037/21

*Source: Supreme Administrative Court, 2025-04-29 — https://overview.legal/posts/125644 — original: https://gdprhub.eu/index.php?title=NSA_-_III_OSK_5037/21*

Facts — In March 2020, the Ombudsman requested the DPA to initiate proceedings regarding several laws that introduced an obligation for judges and prosecutors to declare their membership in an association, which would then be included in a Public Information Bulletin. The declarations of membership included associations to churches, religions, political parties, and functions similar to trade unions. The Ombudsman argued that the law was unconstitutional. In addition, the Ombudsman requested that the DPA issue an order restricting the processing of this data, specifically to prohibit the publication in the bulletin until proceedings were complete. The DPA dismissed the case in April 2020. The DPA stated that Article 6(1) GDPR provided a legal basis for the processing based on a legal obligation (Article 6(1)(c) GDPR) and necessity for the public interest (Article 6(1)(e) GDPR). Finally, the DPA stated that it did not have the competence under Article 57 GDPR to decide on the issue of constitutionality; this was a matter the Ombudsman should have taken to the Constitutional Court. The Ombudsman appealed the decision to the Court of First Instance, arguing that the DPA should have also considered whether the law fulfilled the requirements of public interest and proportionality under Article 6(3) GDPR. The Court upheld the reasoning of the DPA, stating that law has a legal basis in accordance with the GDPR. According to the Court, GDPR does not give the DPA broader powers, since the this was not foreseen by the EU legislator or provided by national law. The Ombudsman appealed the case to the Provincial Administrative Court, who dismissed the case. The Ombudsman requested the Court to reconsider, or alternatively, the Supreme Administrative Court. In addition, the Ombudsman requested the Supreme Administrative Court to refer a preliminary question to the EU Court of Justice (CJEU). The Provincial Administrative Court referred the case to the Supreme Administrative Court. In its complaint, the Ombudsman argued there was a violation of EU and national law due to the DPA’s and Court’s failure to act, as well as the law restricting the judges and prosecutor’s freedom of religion and assembly. The Ombudsman cited CJEU Case C-204/21 (European Commission v. Republic of Poland). In this case, the CJEU found that national legislation requiring judges to submit written declarations of membership in a political party violated Article 7 CFR and Article 8 CFR, as well as Article 6(1)(c) GDPR and Article 6(3) GDPR. In addition, the CJEU stated that it was insufficient for a national law to meet the formal criteria (e.g. by specifying the data processed and the storage period), it also needed to meet the qualitative criteria (public interest purpose and proportionality). Holding — The Supreme Administrative Court first dismissed the request of the Ombudsman to refer a preliminary question to the CJEU, on the basis that the case C-204/21 made the question irrelevant. Nonetheless, the Court stated that it had the obligation to take the CJEU case into account in assessing whether a national law is compatible with EU law, regardless of the issues raised in the appeal. Article 260(1) TFEU obliges the Court to take measures to ensure the implementation of a CJEU judgment stating that a Member State has not complied with its obligations under the Treaties. The Court considered that the Court of First Instance had misinterpreted Article 6(1)(c) GDPR and Article 6(1)(e) GDPR by limiting its interpretation to national laws. According to the Court, the decision did not consider the Constitution or the CFREU (Article 8 CFR and Article 10(1) CFR) and the European Convention of Human Rights (ECHR) (Article 8 ECHR and Article 9(1) ECHR and Article 9(2) ECHR ). The Court followed the reasoning of the CJEU in Case C-204/21 and concluded that the Polish law requiring judges and prosecutors to disclose their affiliation with religious, trade union and political organisations was a serious interference of their rights under the CFREU. The Polish law also violated Article 6(1)(c) GDPR and Article 6(1)(e) GDPR and Article 6(3) GDPR. The Court referred to the CJEU's reasoning in stating that the processing and publishing of judges' and prosecutors' personal data is likely to reveal their worldview and religious beliefs. This data belongs to the special category of personal data that has additional protections in accordance with Article 9(1) GDPR. The Court overturned the decision by the lower courts and the DPA.

### Judgment of the Court (Grand Chamber) of 7 May 2024.#SO.#Request for a preliminary ruling from the Unabhängige Schiedskommission Wien.#Reference for a preliminary ruling – Admissibility – Article 267 TFEU – Concept of ‘court or tribunal’ – National arbitration committee competent to combat doping in sport – Criteria – Independence of the body making the reference – Principle of effective judicial protection – Inadmissibility of the request for a preliminary ruling.#Case C-115/22.

*Source: Court of Justice of the European Union, C-115/22, 2024-05-07 — https://overview.legal/posts/132258 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0115*

The Court of Justice of the European Union (Grand Chamber) ruled on a preliminary ruling request from the Unabhängige Schiedskommission Wien concerning the interpretation of GDPR Articles 5, 6, 9, and 10 in the context of NADA's decision to publish anti-doping sanctions against athlete SO. The Court found the request inadmissible because the national anti-doping arbitration committee does not qualify as a "court or tribunal" under Article 267 TFEU, as it lacks the requisite independence and does not provide effective judicial protection. No fine was imposed.

### Judgment of the Court (Third Chamber) of 25 January 2024.#BL v MediaMarktSaturn Hagen-Iserlohn GmbH.#Request for a preliminary ruling from the Amtsgericht Hagen.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Interpretation of Articles 5, 24, 32 and 82 – Assessment of the validity of Article 82 – Inadmissibility of the request for an assessment of validity – Right to compensation for damage caused by

*Source: Court of Justice of the European Union, C-687/21, 2024-01-25 — https://overview.legal/posts/132272 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0687*

In Case C-687/21, the Court of Justice of the European Union interpreted Articles 5, 24, 32, and 82 of the GDPR in response to a preliminary ruling request from the Amtsgericht Hagen in proceedings between data subject BL and MediaMarktSaturn Hagen-Iserlohn GmbH concerning alleged non-material damage from personal data transmitted to an unauthorized third party due to employee error. The Court held that a controller's infringement of GDPR security obligations through employee error can give rise to a right to compensation under Article 82, that the severity of the infringement may be relevant to assessing both the appropriateness of protective measures and the existence of damage, and that the concept of non-material damage should be interpreted broadly without requiring a minimum threshold of severity. No fine was imposed, as the ruling addresses interpretation of GDPR provisions rather than administrative penalties.

### BVwG - W256 2227693-1

*Source: Federal Administrative Court, 2023-09-28 — https://overview.legal/posts/125664 — original: https://gdprhub.eu/index.php?title=BVwG_-_W256_2227693-1*

Facts — On 05.09.2019, the Austrian DPA (DSB) notified the controller of a customer loyalty program that they were initiating an ex officio investigation. The controller responded by answering the provided questionnaire and submitting further documents. On 23.10.2019, the DPA ruled that the investigation was justified and that the declaration of consent for profiling using certain registration methods (website, app, partner company store, flyer) did not comply with the requirements of Article 4(11) GDPR and Article 7 GDPR, nor were they provided in an intelligible way. If a contract covers several aspects, the declaration of consent must be clearly distinguishable. Regarding the website and flyer, the following was found: The website says 'Enjoy your personal benefits' without providing clear information that 'personal benefits' involves profiling. In an embedded box, the relevant points were merely referred to. Information regarding profiling was only accessible by scrolling down further. Concerning the flyer, the following information was provided under the signature field: 'This signature only applies to the declaration of consent and is voluntary. Your registration [...] is also valid without a signature.' Thus, it conveyed the impression that a signature was required to confirm the registration. Consequently, the controller was required to amend the declaration and to cease using any obtained consents for the purpose of profiling prior to 01.05.2020. The controller lodged a complaint. In addition to other information, the controller stated that the data processing was in accordance with Article 6(1)(a) GDPR, and that they had a legitimate interest under Article 6(1)(f) GDPR. The DPA ruled a preliminary decision on the complaint, thereby changing the ruling that the website and flyer did not meet the requirements under Article 6(1)(a) GDPR, and thus, the processing of personal data, collected in that cases, was forbidden. The other methods ensured that the consent was clearly separated from the rest of the registration process. The controller then filed a request for referral to the court, arguing that the DPA had exceeded their corrective powers by prohibiting the processing of the data. Furthermore, the data processing for profiling would be used to manage customer memberships under Article 6(1)(b) GDPR. Following their view, processing under Article 6(4) GDPR was applicable. Additionally, the controller denied the DPA's view that a violation of the principle of good faith would foreclose a weighing of interests under Article 6(1)(f) GDPR. The court quashed the preliminary decision as the DPA had not examined the other grounds of justification for data processing under Article 6(1) GDPR in their initial decision. The DPA then lodged an appeal to the Austrian Supreme Administrative Court (Verwaltungsgerichtshof), which overturned the court's ruling (VwGH 08.02.2022, Ro 2021/04/0033). It was the court's responsibility to examine the potential legal bases, rather than overturning the DPA's decision. Therefore, the case was returned to the court. In the meantime, the controller complied with the preliminary decision by deleting the affected personal data in 2021 and changing their registration process in 2020. Holding — First, the court found that they had to formally rule on whether the DPA's decision was lawful at the time it was ruled. It is not to be considered that the controller complied with the administrative decision and fulfilled the required steps (VwGH 28.04.2022, Ra 2022/06/0056). Second, the court held that the controller did not comply with the transparency requirements regarding the layout of their declaration of consent under Article 7(2) GDPR in both cases (website, flyer). Third, the court ruled that they could not agree with DPA's view, that an invalid declaration of consent always constitutes unlawful data processing and that a review of other grounds of justification would not be necessary (CLEU in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537). Further on, the Supreme Administrative Court ruled that both, the DPA and the court are required to examine the presence of other grounds (VwGH 08.02.2022, Ro 2021/04/0033). Fourth, the court held that the controller could not base their appeal on Article 6(4) GDPR as the data processing did not satisfy the grounds of justification, nor were other grounds apparent. Inter alia, following the CLEU's preliminary ruling in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537, three cumulative requirements must be met for data processing under Article 6(1)(f) GDPR: (1) The controller or a third party must have a legitimate interest, (2) which requires the processing of that personal data, (3) and 'the fundamental rights and freedoms of the data subject' must not outweigh those interests. There were no doubts about the controller's legitimate interest in processing the personal data in question for targeted marketing purposes, as this was both necessary and reasonable. However, the data subject should have been notified about profiling. The wording 'only if the member consents' did not constitute such a notification, and therefore the data subjects were not to be expected that their personal data was used for profiling purposes. Furthermore, the controller explicitly excluded it in their general terms and conditions. Hence, the data subject's right to secrecy overrode the controller's legitimate interest. In summary, the court dismissed the controller's complaint. Last, the court held that an appeal to the Supreme Administrative Court was admissible under Article 133(4) B-VG, as no prevailing case law concerning the implementation of a declaration of consent existed. Hence, the decision relied on a legal question of fundamental importance.

### BVwG - W292 2270002-1

*Source: Federal Administrative Court, 2023-07-27 — https://overview.legal/posts/109002 — original: https://gdprhub.eu/index.php?title=BVwG_-_W292_2270002-1*

Facts — On 4 October 2020, the controller sent a non-anonymised court judgement of the Regional Criminal Court (Landesgericht für Strafsachen) as a PDF file to a different recipient via WhatsApp. Less than a year later, on 28 July 2021, the same non-anonymised court judgement was sent to the same recipient again, this time via email. The data subject lodged two complaints with the DPA (DSB) regarding the violation of their right to secrecy under § 1(1) DSG. In the first proceedings (DSB-D124.5125), the DPA ruled on the transmission of the judgement via WhatsApp and notably highlighted that the transmission via email was not the subject of the proceedings. In the second procedure (DSB-D124.0310/22) concerning the transmission via email, the DPA dismissed the complaint on the grounds that the data subject had no legitimate interest of legal protection and referred to its first administrative decision. The data subject appealed against the second decision of the DPA and asked the court to decide in that subject matter. In their opinion, the two transmissions of the judgement at different times represent two separate data processing operations. Holding — First, the court held that, in this specific case, there was no identity of the subject matter in comparison with the first proceedings within the meaning of § 68(1) AVG. In accordance with established legal practice (VwGH 31.07.2006, 2006/05/0158; VwGH 21.06.2007, 2006/10/0093 etc.), the court based its decision on the legal and temporal identity of the case. On the one hand, the data processing operation via email took place at a later date. On the other hand, the resulting time difference could lead to a potentially different legal assessment compared to the previous proceedings. Second, the court ruled that it could only examine the rightfulness of the dismissal of the complaint and therefore could not rule on the subject matter itself (See, for example, VwGH 18.12.2014, Ra 2014/07/0002). Third, the court held that no appeal to the Austrian Supreme Administrative Court (Verwaltungsgerichtshof) was admissible pursuant to Article 133(4) B-VG, as the decision raised no legal questions of fundamental importance. Therefore, the court quashed the DPA's administrative decision DSB-D124.0310/22.

### Judgment of the Court (Fifth Chamber) of 4 May 2023.#UZ v Bundesrepublik Deutschland.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to processing – Controllership – Article 6 – Lawfulness of processing – Electronic file compiled by an administrative authority relating to an asylum application – Tra

*Source: Court of Justice of the European Union, C-60/22, 2023-05-04 — https://overview.legal/posts/132289 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0060*

In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik Deutschland regarding the processing of personal data in an asylum application file. The Court held that an administrative authority transmitting an electronic asylum file to a competent national court via an electronic mailbox constitutes processing under the GDPR, and that where both the authority and the court determine the purposes and means of processing, they are joint controllers under Article 26, requiring an arrangement allocating responsibility and maintaining records of processing activities under Article 30. The Court further clarified that transmission of personal data without the data subject's consent constitutes unlawful processing, triggering the right to erasure under Article 17(1)(d) and the right to restriction under Article 18(1)(b), and that national courts must disregard such unlawfully processed data. No fine was imposed.

## Guidance

### Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework

*Source: EDPB, statement-32024-on-data-protection-authorities-role-in-the-en, 2024-07-16 — https://overview.legal/posts/125732 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32024-on-data-protection-authorities-role-in-the_en*

Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPO SE OF THIS STATEMENT 1. On 12 July 2024, Regulation (EU) 2024/1689 laying down harmonised rules on a rtificial i ntelligence (Artificial Intelligence Act, hereinafter the “ AI Act ”) and amending certain Union Legislative Acts was published in the Official Journal 1 . 2.…

### EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

*Source: EDPB, edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the-en, 2021-06-18 — https://overview.legal/posts/126016 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the_en*

1 Adopted EDPB - EDPS Joint Opinion 5 /2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmo nised rules on artificial i ntelligence (Artificial Intelligence Act) 18 June 2021 2 Adopted Executive Summary On 2 1 April 2021, the European Commission presented its Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (hereinafter “the Proposal”) . The EDPB and the EDPS welcome…

### Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom

*Source: EDPB, edpb-opinion-202527-united-kingdom-adequacy-led-en, 2025-10-16 — https://overview.legal/posts/51407 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-272025-regarding-the-european-commission-draft-implementing-decision_en*

Adopted 1 Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom Adopted 16 October 2025 Adopted 2 Executive summary The European Commission endorsed its draft implementing decision on the adequate protection of personal data by the United Kingdom pursuant to the Law Enforcement Directive on 22 July 2025. On the same date, as part of the procedure towards the formal…

### Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation

*Source: EDPB, edpb-opinion-202507-epo-adequacydecision-en, 2025-05-06 — https://overview.legal/posts/50823 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-072025-regarding-the-european-commission-draft-implementing-decision_en*

EDPB, Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation, 2025.

### Opinion 39/2021 on whether Article 58(2)(g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject

*Source: EDPB, opinion-392021-on-whether-article-582g-gdpr-could-serve-as-a-en, 2021-12-14 — https://overview.legal/posts/125971 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-392021-on-whether-article-582g-gdpr-could-serve-as-a_en*

Adopted 1 Opinion 39 /2021 on whether Article 58(2) ( g) GDPR coul d serve as a legal basis for a s upervisory a uthority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject Adopted on 14 December 2021 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63 and Article 64 (2) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural…

### Guidelines 01/2023 on Article 37 Law Enforcement Directive

*Source: EDPB, guidelines-012023-on-article-37-law-enforcement-directive-en, 2024-06-19 — https://overview.legal/posts/125738 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012023-on-article-37-law-enforcement-directive_en*

Adopted 1 Guidelines 0 1 / 2023 on Article 37 Law Enforcement Directive V ersion 2 . 1 Adopted on 19 June 2024 Adopted 2 Version history Version 1.0 27 September 2023 Adoption of the Guidelines for public consultation Version 2.0 19 June 2024 Adoption of the Guidelines after public consultation Version 2.1 30 September 2024 Minor corrections in footnotes 10 and 57 Adopted 3 Executive summary These guidelines provide guidance on the application of Article 37 LED, in particular on the legal…

### EDPB Strategy 2024-2027

*Source: EDPB, edpb-strategy-2024-2027-en, 2024-04-18 — https://overview.legal/posts/125760 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-strategy-2024-2027_en*

The mission and legal task of the European Data Protection Board (EDPB) is to ensure the consistent application of EU data protection rules and to promote effective cooperation among data protection authorities throughout the European Economic Area (EEA). Since their entries into application in 2018, the General Data Protection Regulation (GDPR) and the Law Enforcement Directive (LED) have strengthened, modernised and harmonised data protection across the European Economic Area (EEA). Awareness…

### Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-032023-on-the-draft-decision-of-the-competent-en, 2023-02-17 — https://overview.legal/posts/125871 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-032023-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 3 February 2023 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3)-(8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

## Enforcement decisions

### EDPS finds Commission infringed purpose limitation and data transfer rules in Microsoft

*Source: EDPS, 2024-03-08 — https://overview.legal/posts/125645 — original: https://gdprhub.eu/index.php?title=EDPS_-_2021-0518*

Facts — Following an investigation in 2019-2020, the EDPS issued recommendations and the Commission modified the ILA. The EDPS investigated whether these modifications were sufficient to bring processing in compliance with data protection requirements and found infringements. Data accessed by Microsoft include identity and contact data of users (when signing on to the service and when checking the licenses), data generated by the users while using the software and data generated by Microsoft based on the usage of the software. The EDPS found that the processing presents significant risks as it monitors the behaviour of users, combines datasets and uses artificial intelligence. Reference date is the 12th May 2021, the date when the investigation was launched. Some measures were taken meanwhile by the Commission, which were taken into account in the recommendations issued. Holding — The EDPS found infringements with regards to purpose limitation, transfers to a third country and further, unathorised disclosure of personal data. Purpose limitation: The EDPS found that it was not sufficiently defined in the International License Agreement (ILA) which types of personal data are to be processed for which purposes. Instead, there was only a list of purposes stating that Microsoft uses these data for: troubleshooting billing remunerating Microsoft staff, internal reporting and business modelling, financial reporting following the use of the system for own reasons (analytics) to improve the service security risk management protection of intellectual property These stated purposes were considered to be too vague and general pursuant to the Art 29 WP. The Commission and Microsoft could not demonstrate that all these data were necessary and that a less intrusive collection of data would be insufficient to achieve the purposes cited. In addition, some of these purposes were actually not in the interest of the Commission but for purposes of individual to Microsoft (like remuneration of their personnel). In this case, the processor acts as controller; thus, these purposes and the data used for this purposes should have been precisely defined. Also, if data were used for purposes other than for which they were collected, the compatibility of these new purposes with the original ones should have been assessed. As a processor, Microsoft should have processed the personal data on documented instructions by the Commission. This was not ensured as the Commission did not issue sufficiently clear documented instructions to Microsoft. For example, though the Commission gave instructions for analytics and improvement of the service, these instructions were not sufficiently detailed and precise and did not exclusively concern uses of data for the purposes of the controller. Some instructions were given orally, but this was not enabled by the ILA and the oral instructions were not documented. The Commission did not assess whether it is necessary and proportionate to transmit data to Microsoft Ireland and its sub-processors. Further details of this infringement are given under the part on further unauthorised disclosure or personal data. Transfer to third countries : The Commission transferred personal data to Microsoft, a company established in the US. This raises questions about adequacy for such transfers to a third country. After the reference date, the Commission adopted the Transatlantic Data Privacy Framework (TDPF), which is an adequacy decision in respect of recipients in the US who register under this framework. The EDPS found that even when the software and data storage is property of Microsoft, it is directly transferred to these subcontractors and cannot therefore be covered by the TDPF to Microsoft US and onward transfer from Microsoft US to other subcontractors under SCCs. The EDPS found that in was not clearly specified in the ILA what types of personal data can be transferred to which recipients in which third country. The Commission also did not appraise the transfers and therefore could not determine whether any supplementary measures are necessary. In addition, the Commission should have performed a data transfer impact assessment and (as there are no SCCs applicable by EUIs as exporters) should have submitted the DPAs with these processors or subprocessors in third countries to the EDPS for approval. Because it failed to do this, the Commission did not implement effective supplementary measures for these transfers. Another issue was that the “EU storage guarantee” offered by Microsoft did not cover all types of data. Some data may be accessible to recipients in third countries. The “EU Data Boundary” also has numerous exceptions and exclusions which cover customer data, service generated data, diagnostic data and professional services data. Further unauthorised disclosure or personal data: A specific reference was made to Article 9 Regulation (EU) 2018/1725, which concerns transmission of personal data by EU institutions to recipients established in the EU. According to the EDPS, this article is also applicable to transmission of personal data to processors of EUIs. Therefore all transmission of personal data should be in the public interest and if the data subject’s legitimate interests may be prejudiced, the controller has to weigh the competing interests and establish that it is proportionate to transmit the personal data. The purpose of management and functioning of the Commission, use of products the staff is familiar with etc. was not found to be the purpose of processing of the personal data by MS. As long as the purposes are not specified, specific and explicit, it is not possible to do this balancing. In addition, the EDPS found that the Commission did not ensure that transfers take place “solely to allow tasks within the competence of the controller to be carried out”. The EDPS determined that organisational and contractual measures to restrict/prevent access of third country authorities were not sufficient, and that further technical measures are thus necessary. The EDPS also found that the organisational measures applied are only limiting transfers but does not ensure that transfers are protected. Further, the encryption is only found to be an adequate measure if the controller is in control of the encryption key. In this case, customers control the keys, but Microsoft has access to the encryption key, and thus, even when law does not oblige it to decrypt the data on an authority request, it may do it voluntarily. Also, the ILA does not detail encryption of data other than “customer data”, i.e. diagnostic data, service generated data or professional services data. The contract also enabled the processor not to notify the Commission about a request of disclosure also when EU or Member State law did not prohibit this notification and enabled recipients in third countries not to notify requests for disclosure also when the law prohibiting it did not constitute a necessary and proportionate measure in a democratic society respecting the essence of the fundamental rights and freedoms recognised by the Charter.

### IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border

*Source: IMY (Sweden), 2026-07-03 — https://overview.legal/posts/57263 — original: https://gdprhub.eu/index.php?title=IMY_(Sweden)_-_IMY-2024-2904*

Facts — The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of the personal data of travellers arriving from third countries (the data subjects). During border control, the controller scanned the data subjects’ passports, and some travellers were required to provide fingerprints. The data collected was then possibly checked against various border control systems, such as the Schengen Information System (SIS) and the Visa Information System (VIS). There were no signs, brochures, or other written information on the processing of personal data available directly in the arrival hall. The only information available could be found on the controller’s website. Holding — The DPA issued the controller a reprimand for the infringement of Article 13 GDPR. It held that the controller had not provided the data subjects sufficient information about the processing of personal data during border controls. According to the DPA, the data subjects had not been able to easily access information regarding, among other things, what personal data is collected, how it is processed, and what rights data subjects have. The DPA took into account that not all travellers arriving from third countries could be expected to know which national authority is responsible for border controls, let alone be able to find and understand the information on the controller’s website without any guidance in the arrivals hall. It concluded that the lack of easily accessible information on this matter constituted a significant shortcoming: the border control operations included the processing of sensitive data, including biometric data, of a large number of travellers on a daily basis. On the other hand, the investigation was limited to one arrivals hall. The controller had also obtained signs with tailored information regarding the processing of personal data during border control since the beginning of the investigation. Based on an overall assessment, the DPA held that the lack of information required by Article 13 in the arrivals hall constituted a minor GDPR violation.

### EDPS - 2020-1013

*Source: EDPS, 2022-01-05 — https://overview.legal/posts/122849 — original: https://gdprhub.eu/index.php?title=EDPS_-_2020-1013*

Facts — In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The issues raised were: confusing and unclear cookie banners, vague and unclear data protection notices, and the illegal transfer of data to the US. Holding — On data controllership — According to the EDPS, the processor may enjoy a considerable degree of autonomy in providing its services and may identify the ‘non-essential’ elements of the processing operation. Furthermore, the processor may advise or propose certain measures in this respect, but it is up to the controller to decide whether to accept such advice or proposals. The analysis of the EDPS shows that the European Parliament (EP) delegated some aspects on the setting up and functioning of the website to Ecolog. The EDPS considers the EP acts as the sole data controller for the processing in question (i.e. the operation of the Parliament’s dedicated website) whereas Ecolog acts as a processor. After having assessed the instructions given by the EP to the processor, the EDPS concluded that the EP did not show the necessary diligence required from a data controller and, ultimately, failed to comply with the Regulation on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data 2018/1725 (hereafter Regulation 2018/1725), in particular with Articles 26(1) and 29(1). Moreover, the EDPS considered that the EP failed to provide the necessary detailed instructions to Ecolog for the setting up of the website, including the drafting of the data protection notice. The absence of documented instructions is therefore in violation of Article 29(3) Regulation 2018/1725. Transparency and information requirements — The EDPS confirmed that the data protection notice published at the time of the complaint did not reflect the processing done by the EP, since it merely consisted of a copy of the testing center of Zaventem's airport. Moreover, the reference made in the document to Article 6(1)(f) GDPR was wrong since it stems from the same error. The EDPS confirmed that the EP did not meet its transparency requirements. The EDPS also analysed the updated version of the data protection notice during the procedure and raised several remaining -and even new- inconsistencies and issues. Among other things, the following problems persisted after the data protection notice was updated: a mere reference to Article 15 and 16 Regulation 2018/1725 is misleading as it should apply in its entirety; the reference to the processing of health data is not correct since no such data are processed in the case at hand; the retention period mentioned is not precise enough; the sections of the data protection notices relating to the recipients of the personal data fail to make any reference to the processor; inconsistencies between the different linguistic versions of the data protection notices were still observed: The English and German versions refer to Ecolog and the Laboratory van Poucke as processors under Article 29 Regulation 2018/1725, whereas the French version refers to them as controllers (‘responsables du traitement’). Moreover, the DPO’s contact details on the website refer to Ecolog in all three linguistic versions of the website, when they should be referring to the Parliament Cookies and transfers of personal data to the US — The EDPS confirmed that tracking cookies, such as the Stripe and the Google analytics cookies, are considered personal data, even if the traditional identity parameters of the tracked users are unknown or have been deleted by the tracker after collection. In the same vein, the EDPS rejected the EP's argument and confirmed that upon installation on a device, a cookie cannot be considered ‘inactive’. Every time a user visited Ecolog’s website, personal data was transferred to Stripe through the Stripe cookie, which contained an identifier. The EDPS reached the conclusion that a transfer of data was taking place to the US, via the use of Google and Stripe cookies, since Google Analytics is hosted in the US and the data protection notice referred to a Standard Contractual Clause (SCC) for the transfer of data outside of the EU. However, the Parliament provided no documentation, evidence or other information regarding the contractual, technical or organisational measures in place to ensure an essentially equivalent level of protection to the personal data transferred to the US in the context of the use of cookies on the website. Cookie banner on the Parliament’s dedicated website — The EDPS reminded that: before setting cookies or any other technology falling within the scope of Article 5(3) ePrivacy Directive 2002/58/EC (hereafter ePrivacy Directive), the EU institution must provide the user with adequate information on what is accessed or stored on the user’s terminal equipment, on the purposes of this action and the means for expressing their consent; no action may be performed before the consent is collected. In addition, users must be enabled to withdraw their consent at any time; ‘cookie walls’ are not in line with Regulation 2018/1725, meaning that for consent to be freely given, access to the website’s service and functionalities should not depend on the users’ consent for cookies that are not strictly necessary in the sense described above; in case personal data collected through the cookies are shared with third parties such as analytics partners, the cookie banner should draw the user's attention to it. The EDPS reached the conclusion that the cookie banners in all three languages were not in line with the definition of consent under Article 3(15) Regulation 2018/1725, nor did they meet the requirements of Article 37 Regulation 2018/1725 and Article 5(3) ePrivacy Directive. The cookie banner further failed to provide transparent information regarding the processing of personal data in relation to the cookies on the website. Request for access to personal data — The Parliament was aware that the complainants’ personal data had been processed through the cookies, which were present on the website for the period between 30 September to 4 November 2020, since transfers of personal data had taken place. Consequently, and especially following the EDPS’ inquiry on the matter, the Parliament should have replied to the complainants’ access to personal data request. The Parliament should have provided the relevant information even if it was aware that the processing of the personal data in question was unlawful, as the main purpose of the right of access under Article 15 GDPR is precisely to enable data subjects to become aware of the processing and verify the lawfulness thereof, or exercise other data subject rights. Conclusion — The EDPS concludes that the Parliament has infringed the following articles of Regulation 2018/1725: Articles 26(1) and 29(1) due to its failure to fulfil its responsibilities as controller and use a processor providing sufficient guarantees to implement appropriate technical and organisational measures; Article 29(3) due to its failure to provide documentation relating to the detailed instructions given to the processor for the setting up and functioning of the website; Articles 4(1)(a) and 14, 4(2), and 15 due to its failure to respect the principle of transparency, accountability and the data subjects’ right to information because of the inaccurate data protection notice and cookie banner on the dedicated website; Article 46 and Article 48(2)(b) of the Regulation, due to its reliance on the Standard Contractual Clauses in the absence of a demonstration that data subjects’ personal data transferred to the US were provided an essential equivalent level of protection; Article 37 read in the light of Article 5(3) of the ePrivacy Directive, due to its failure to protect information (the cookies) transmitted to, stored in, related to, processed by and collected from the users’ terminal equipment; Articles 17 and 14(4) due to its failure to reply to the data subjects’ request for access to their personal data. On the basis of the above, the EDPS decides: to issue a reprimand to the Parliament in accordance with Article 58(2)(b) Regulation 2018/1725 for the above infringements; to order the Parliament, pursuant to Article 58(2)(b) Regulation 2018/1725:, to update its data protection notices in the dedicated website in order to provide all relevant information relating to the processing of personal data. The Parliament should address this order within one month from the date of the decision.

### APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender

*Source: APDCAT (Catalonia), 2026-07-17 — https://overview.legal/posts/184715 — original: https://gdprhub.eu/index.php?title=APDCAT_(Catalonia)_-_PS-0036/2026*

Facts — On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing lease. The documents expressly disclosed the identities of the applicants. On 9 May 2025, the controller replaced the original documents with revised versions in which the applicants’ names and surnames were partially redacted, leaving only their initials visible. However, the redaction was performed manually and did not effectively conceal the information, as it remained possible to infer the length of the names and surnames and to identify some of their letters. In addition to the applicants’ identifying information, the documents disclosed detailed financial data, including the exact annual net income of each household. They also revealed information concerning particularly sensitive personal circumstances, including dependency, gender-based violence and addiction, which had been used to calculate the applicants’ respective scores. No adequate anonymisation or redaction measures had been implemented. In July and November 2025, the DPA requested that the controller provide specific information concerning certain aspects of the processing. The controller’s failure to respond or cooperate hindered the DPA’s ability to exercise its investigative powers. Holding — The DPA held that the controller violated Article 5(1)(c) GDPR by publishing personal data that were not necessary for the purpose pursued. The DPA acknowledged that publishing information about the procedure could serve the objective of administrative transparency. However, transparency did not justify disclosing identifying data together with detailed financial information and sensitive personal or family circumstances. The controller had to limit the processing to data that were necessary and proportionate to that objective and consider less intrusive alternatives. The DPA found that the controller’s subsequent redaction did not amount to effective anonymisation. Although most of the characters had been concealed, the applicants could still potentially be reidentified from their initials, the length of their names and surnames and other contextual information. This risk was particularly significant because the municipality had only 277 inhabitants. The controller should therefore have applied complete anonymisation or a pseudonymisation method preventing direct or indirect identification. The DPA also held that the controller violated Article 5(1)(f) GDPR and the duty of confidentiality under Article 5 LOPDGDD. The published documents disclosed the applicants’ exact household income, household composition and scores linked to circumstances such as dependency, addiction, gender-based violence, single-parent status and age. Although this information was relevant to assessing the applications, it was unnecessary to make it publicly accessible in a form linked to identifiable individuals. The DPA considered that the violations of the data-minimisation and confidentiality principles constituted a medial concurrence of infringements. The failure to anonymise the applicants’ identities was the necessary means through which their sensitive personal and family circumstances were disclosed. Nevertheless, the DPA formally declared separate violations of Articles 5(1)(c) and 5(1)(f) GDPR. Additionally, the DPA held that the controller violated Article 31 GDPR by failing to respond to two information requests. This failure breached the controller’s duty to cooperate with the supervisory authority and obstructed the exercise of the DPA’s investigative powers.

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

### ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN: Onvoldoende samenwerking met de toezichthoudende instantie.

*Source: Spanish Data Protection Authority (aepd), 2025-11-05 — https://overview.legal/posts/51984*

De Spaanse gegevensbeschermingsautoriteit (DPA) heeft een boete van 750 euro opgelegd aan de ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN. De verantwoordelijke partij heeft nagelaten om aan te tonen dat aan de door de DPA opgelegde corrigerende maatregelen is voldaan, wat heeft geleid tot het opleggen van de boete.

### DPC (Ireland) - 06/SIU/2018

*Source: DPC (Ireland), 2023-08-22 — https://overview.legal/posts/125614 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_06/SIU/2018*

Facts — The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance technologies deployed by state authorities, including the Galway County Council and by the An Garda Síochána (the Irish police). More specifically, the Galway County Council Officials make use of CCTV systems, body-worn cameras and automated number plate recognition (ANPR) technologies for various purposes including law enforcement purposes. The DPC carried out its assessment both on the basis of the GDPR and of the Law Enforcement Directive (LED) for activities meant to prevent, investigate, detect and prosecute crime or for the execution of criminal penalties. Holding — In its inquiry, the DPC assessed the legitimacy of processing activities by the controller in light of both the GDPR and the Irish Data Protection Act and the LED, as different processing activities pursued different purposes. The DPC held with respect to body-worn cameras and ANPR systems that the GDPR applies to these processing activities as they mainly serve health and safety and traffic management purposes respectively, thus no law enforcement purposes. Making reference to the strict interpretation in CJEU jurisprudence, the DPC held that in order for a processing activity to fall under the scope of the LED, it must be specifically and concretely used for law enforcement purposes and it does not suffice that the data could potentially (emphasis added) be processed for law enforcement purposes. Firstly, as regards ANPR cameras used for traffic management, the DPC held that the latter enable identification of data subjects within the vehicle and thus constitutes processing of personal data. The legal basis referred to by the Council is Article 6(1)(e) GDPR. The DPC held that processing ex Article 6(1)(e) GDPR, read in light of Article 6(3) GDPR and Recital 41 GDPR requires a legal basis to set out the conditions for processing clearly, precisely and in a foreseeable way. In this case, the DPC held that the use of ANPR cameras does aid to the traffic management function of officials but it may also have significant impacts on the rights and freedoms of data subjects. The DPC concluded that the national provisions relied on by the controller to make use of such cameras are too broad and cannot constitute a legal basis for the Council to deploy APNR cameras for traffic management purposes. Hence, the DPC found the Council had acted in violation of Article 5(1)(a) GDPR. In addition to this, the DPC considered whether the controller complied with its Article 24(1) GDPR obligation to adopt appropriate technical and organizational measures to ensure and demonstrate GDPR-compliant processing activities, also by means of a data protection policy as per Article 24(2) GDPR. The DPC held that the controller failed to comply with its obligation under Article 24(1) GDPR with respect to the use of ANPR cameras for traffic management purposes as it failed to demonstrate compliance with the GDPR. Further, the DPC also found the controller had failed to comply with its obligation to carry out a Data Protection Impact Assessment by virtue of Article 35(1) GDPR for the use of APNR cameras for the systematic monitoring, tracking and observing of individuals. Secondly, the DPC considered the use of a body-worn camera by a Housing Tenacy Officer who had been threatened while conducting official activities. The legal basis relied upon by the Council in this case was Article 6(1)(d) GDPR, which allows for processing activities that are necessary to protect the vital interest of an individual. Further the Council also relied on Article 6(1)(e) GDPR as it is required to comply with health and safety obligations towards its employees set out in two specific Acts. As regards the use of body-worn cameras on the basis of Article 6(1)(d) GDPR, the DPC held that the controller failed to carry out a test for proving the necessity of the use of such cameras before their actual use. Hence, the controller failed to prove that such measure was necessary to protect the vital interest of the officer or to perform a task in the public interest. As for the use of such cameras on the basis of Article 6(1)(e) GDPR, the DPC held that again the controller did not rely on a clear, precise and foreseeable provision in the law allowing specifically for the body-worn cameras to be used. In this case too, the DPC held that the Council had infringed Article 5(1)(a) GDPR. Lastly, the DPC held that the controller infringed Article 24(1) GDPR to the extent that it failed to raise staff awareness on the principles of data processing, which counts as an organizational measure to be adopted by the controller under Article 24(1) GDPR. With respect to all the above mentioned violations, the DPC decided to adopt the following corrective powers: it provisionally banned the use of body-worn cameras and APNR cameras until a valid legal basis is identified and issued a reprimand concerning the violation of Article 24 GDPR. The rest of the activities carried out by the Galway County Council were assessed in light of the provisions of the LED, and the DPC found several violations in that respect too.

### DPC (Ireland) - 05/SIU/2018

*Source: DPC (Ireland), 2023-01-16 — https://overview.legal/posts/125613 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_05/SIU/2018*

Facts — This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special Investigations Unit of the DPC were authorised to conduct a range of inquiries pertaining to surveillance technologies deployed by state authorities, including An Garda Síochána (the national police) and various local authorities, including Kildare County Council. These inquiries sought to determine whether the data processing was lawful, and also to ensure that full accountability measures for the collection and processing of personal data were in place, in advance of further investment in and deployment of newer surveillance technology. The investigation into Kildare County Council focused on the following: the legal basis for surveillance technology employed for the purposes of preventing, investigating, detecting or prosecuting crime; the legal basis for surveillance tech deployed for purposes other than preventing, investigating, detecting, or prosecuting crime; appropriate signage and general transparency; and the question of a joint controller agreement between the council and the national police. Furthermore, the authority sought to examine the security measures for traffic management CCTV; housing department CCTV; and the transmission of CCTV footage to An Garda Síochána. Holding — Issuing its final decision, the DPC began by establishing that not all of the processing of personal data in question is regulated by the GDPR. Any processing of personal data for the purposes of prevention, investigation, detection, or prosecution of criminal offences is regulated by the Law Enforcement Directive (LED) supplemented into Irish law by the Irish Data Protection Act 2018 (“the 2018 Act”). The other personal data processing at issue here is covered by the GDPR. For further information and relevant legal provisions, please see Article 2(2)(d) GDPR, Articles 1 and 2 LED, and Part 5 and 6 of the 2018 Act. The first issue addressed in the DPC’s decision was the legal basis for the surveillance technologies employed for the purposes of preventing, investigating, detecting or prosecuting crime. In particular, this concerned CCTV systems deployed in a number of housing estates and Traveller caravan parks in the area. While the County Council initially submitted that the lawful basis for this processing was Article 6(1)(c) and 6(1)(d) GDPR, after clarifying that the relevant regime is the LED, the DPC sought to examine the justification for processing in light of this Directive and the 2018 Act. The controller sought to rely on its ‘estate management functions’ as set out in domestic housing legislation, and the powers to combat anti-social behaviour afforded therein. In accordance with the 2018 Act, personal data must be processed lawfully and fairly (Section 71(1)(a)) and the processing will only be lawful where the subject has given their consent, or where the processing is necessary for the performance of a function of the controller for a purpose specified in Section 70(1)(a) and the function has a legal basis in the law of the EU or Ireland (Section 71(2)). Furthermore, for special category data, one of the additional nine conditions in Article 73(1)(b) must be met. After examining the case, the DPC found no requirement to support the development of CCTV cameras in the estates as described above. The cited Irish legislation places no requirement upon the local authority to monitor in this way, and makes no reference to CCTV cameras. Furthermore, given that Irish Travellers are an ethnic group, and their accommodation has a distinct design and layout, the activities also represented the illegal processing of special category data. The DPC found an infringement of Sections 71(1)(a) and 73 of the 2018 Act. With regards to CCTV cameras located on the grounds of 2 supermarkets for the purpose of detecting illegal dumping. The investigation found that these cameras had not been operational before, during or after the investigation, and accordingly the DPC found no violation of the 2018 Act. Thereafter the DPC decision addressed the second issue: the legal basis for the surveillance technologies employed for purposes other than for preventing, investigating, detecting or prosecuting crime. In particular, the authority investigated CCTV used for: traffic management; the sharing of live feed traffic with An Garda Síochána; and the use of ANPR cameras, which recognise and digitise number plates. With regard to processing for traffic management, the Council sought to rely on the Irish Roads Act 1993, which places obligations upon public authorities to, among other things, provide for the safety or convenience of road users. Accordingly, the council argued they had a lawful basis for processing was in the public interest (Article 6(1)(e) GDPR). The DPC held that, given the significant potential impact to fundamental rights of a widespread video surveillance system, the Roads Act is not sufficiently clear, precise or foreseeable to constitute a valid legal basis for the processing of personal data in accordance with Article 6(1)(e) GDPR. There was also a complete lack of legal basis for the sharing of a live traffic feed with An Garda Síochána. Furthermore, for the use of ANPR cameras to be lawful under Article 6(1)(e) GDPR, it would be necessary for the legislature to specifically grant power to the local authority to carry out such processing in a manner which is clear, precise and foreseeable for the data subjects. As the Roads Act does not explicitly permit such processing, the Council does not have a lawful basis to operate ANPR cameras. In light of the above, the DPC found that the Council had violated Article 5(1)(a) GDPR in all 3 respects. The third question investigated was the presence of appropriate signage and general transparency. The investigation found that no appropriate signage had been installed to inform data subjects of the use of CCTV for traffic management purposes. Accordingly, the DPC held there had been a violation of Article 13 GDPR. Regarding the fourth issue, the DPC investigated the question of whether the Kildare County Council could be considered “joint controllers” with respect to Article 26 GDPR. The Decision finds that while An Garda Síochána used the CCTV footage for the prevention of crime, there is no evidence that the two entities “jointly” determined the purposes of processing. In other words, there is no connection between the Council’s decision to use the cameras for traffic management purposes and An Garda Síochána’s decision to then use the live feed for monitoring and preventing crime. Accordingly, the Council has not violated Article 26 GDPR. The DPC also made a number of findings regarding the security measures implemented by the Council. The Council failed to maintain a data log that recorded which users had accessed the CCTV cameras, thereby infringing Article 32(1) GDPR. The Council also violated Sections 71(1)(f), 72(1) and 78 of the 2018 Act by failing to implement appropriate technical or organisational security measures when installing the CCTV cameras. Furthermore, by failing to keep a data log, the Council also violated Section 82(2) of the 2018 Act. The Council also infringed Section 71(1)(c) and Section 76(2) of the 2018 Act by recording CCTV of private properties, in the absence of any privacy masking technology. Additionally, the Council infringed Section 71(10) of the 2018 Act by failing to be in a position to demonstrate that its processing of personal data via CCTV cameras at one location was not excessive to its purpose of preventing anti-social behaviour. Finally, The Council infringed its obligations under Sections 71(1)(f), 72(1) and 78 of the 2018 Act in connection with arrangements surrounding the transfer of personal data to An Garda Síochána using unencrypted USB sticks. Exercising its corrective powers, the DPC imposed a temporary ban on the processing of personal data with CCTV for the purposes of criminal law enforcement and traffic management, until a legal basis can be identified. Furthermore, they imposed an order for Kildare County Council to bring its processing into compliance with the legislation, and imposed an administrative fine of €50,000.

## Recent developments

### De FRIA voor AI-systemen komt eraan: bereid u voor

*Source: Autoriteit Persoonsgegevens, 2026-08-17 — https://overview.legal/posts/291285 — original: https://autoriteitpersoonsgegevens.nl/actueel/de-fria-voor-ai-systemen-komt-eraan-bereid-u-voor*

Bent u een overheidsorganisatie of een private organisatie die publieke diensten levert? En bent u van plan een AI-systeem met een hoog risico te gaan gebruiken? Of gaat u als publieke of private organisatie een beoordelingssysteem voor financiële risico’s gebruiken? Dan moet u vanaf december 2027 vooraf beoordelen welke gevolgen dit AI-systeem kan hebben voor de grondrechten van mensen. Zo’n beoordeling heet een ‘fundamental rights impact assessment’ (FRIA), oftewel een ‘grondrechteneffectbeoor

### De AI-wet is niet voldoende: we moeten de gevaarlijke hiaten dichten die misbruik mogelijk maken en de rechten van mensen schenden.

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/51727*

Hoewel de AI-wetgeving van de EU tot doel heeft om AI-systemen met een hoog risico te reguleren, wordt deze ondermijnd door belangrijke uitzonderingen die hun ongecontroleerde toepassing mogelijk maken in de context van nationale veiligheid en handhaving van de wet. Deze uitzonderingen riskeren onder meer het mogelijk maken van grootschalige surveillance van protesten en discriminerende migratiepraktijken. Om dit te voorkomen, heeft de EDRi-partner Danes je nov dan aanbevelingen gepubliceerd voor Slovenië om strengere nationale beschermingsmaatregelen en transparante toezichtsmechanismen in te voeren. De post "De AI-wetgeving is niet..."

### Council spells out possible new powers for AI Office

*Source: EURactiv, 2026-02-13 — https://overview.legal/posts/52650 — original: https://www.euractiv.com/news/council-spells-out-possible-new-powers-for-ai-office/*

Second compromise text for the AI simplification package, obtained by Euractiv, details beefed up inspection powers

### Reopening GDPR and ePrivacy through the Digital Omnibus: a risky path for EU digital rights

*Source: European Digital Rights, 2026-02-11 — https://overview.legal/posts/52496 — original: https://edri.org/our-work/reopening-gdpr-and-eprivacy-through-the-digital-omnibus-a-risky-path-for-eu-digital-rights/*

EDRi has assessed the Digital Omnibus proposals affecting the General Data Protection Regulation (GDPR) and the ePrivacy framework. While presented as simplification, the changes amount to deregulation in effect, weakening fundamental rights safeguards, increasing legal uncertainty, and advancing through a process that falls short of democratic lawmaking standards.

### Europa ondermijnt haar eigen digitale rechten van binnenuit.

*Source: European Digital Rights, 2025-11-27 — https://overview.legal/posts/51714*

De nieuwe "Digital Omnibus" van de Europese Commissie wordt gepresenteerd als een eenvoudige "vereenvoudiging", maar in de praktijk ondermijnt het belangrijke beschermingsmaatregelen in de GDPR, de ePrivacy-regels en de AI-wet. Het zou de toegang tot apparaatgegevens gemakkelijker maken, de beperkingen op geautomatiseerde besluitvorming verzwakken en de bescherming tegen discriminerende AI verminderen. Het artikel "Europa ondermijnt haar digitale rechten van binnenuit" verscheen oorspronkelijk op European Digital Rights (EDRi).

## Literature

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects

*Source: Law and Economy, 2026-02-25 — https://overview.legal/posts/132619 — original: https://doi.org/10.63593/le.2788-7049.2026.03.004*

The Italian Artificial Intelligence Act, enacted on September 17, 2025, represents the first comprehensive national implementation of the European Union’s AI Act. This study examines the Italian legislation through the theoretical lens of multi-level governance, analyzing its dual function as both a “bridging legislation” that translates EU framework into domestic practice and a site of significant regulatory innovation. Through detailed textual analysis and case studies, particularly in healthc

### A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance

*Source: International Journal of Computer Applications, 2024-09-26 — https://overview.legal/posts/132613 — original: https://doi.org/10.5120/ijca2024923954*

International Journal of Computer Applications (0975 – 8887) Volume 186 – No. 38 , September 2024 23 A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance Mayur Jariwala School of Computer and Information Sciences, University of the Cumberlands, Williamsburg, KY, USA ABSTRACT This comparative study examines the EU AI Act and the Colorado AI Act, focusing on their regulatory approaches to artificial intelligence. The EU AI Act provides a comprehensive framework with a risk - based classification, emphasizing transparency, accountability, and the protection of fundamental rights across diverse sectors. It aims to set a global benchmark for AI governance, influencing international standards. The Colorado AI Act targets high - risk AI systems, prioritizing consumer protection, fairness, and the prevention of algorithmic discrimination. It mandates detailed documentation, ri sk management, and transparency measures to ensure ethical AI deployment. This analysis explores the impacts of each act on innovation, industry practices, and consumer protection, as well as their potential global influence. The findings highlig

### Balancing Security and Privacy: Analyzing the Effectiveness of EU Digital Surveillance Laws in Criminal Proceedings

*Source: International Journal of Law and Societal Studies, 2025-09-26 — https://overview.legal/posts/53859 — original: https://doi.org/10.61424/ijlss.v2i1.445*

This research examines the complex balance between privacy and law enforcement in EU digital surveillance laws during criminal proceedings. It analyzes how these laws protect individual rights while ensuring security through case studies and legal analysis. Landmark cases like Digital Rights Ireland, Schrems decisions, and Tele2 Sverige illustrate the European courts' preference for targeted surveillance over mass data collection, highlighting tensions between privacy and security. Although thes

## Related topics

- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Processors** — https://overview.legal/topics/processors
  Entities that process data on behalf of controllers

---
Generated by overview.legal · https://overview.legal/topics/authority-powers-fundamental-rights-protection · 2026-08-22
