# Security — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/beveiliging
> Sources are cited per item. Verify against the official texts before relying on them.

Technical and organizational measures to protect personal data

## Overview

## Legal Framework

Security obligations under the GDPR are anchored in Article 32, which mandates that controllers and processors implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures must protect against unauthorized or unlawful processing and against accidental loss, destruction, or damage. Article 25 reinforces this through data protection by design and by default, requiring that security be built into processing systems from the outset. Article 5(1)(f) establishes integrity and confidentiality as a core principle, meaning personal data must be processed in a manner ensuring appropriate security. Recital 29 specifically incentivizes pseudonymization as a security-enhancing measure, encouraging controllers to separate additional identifying information from the processed data. The constitutional underpinning derives from Article 8 ECHR and Article 7 of the EU Charter of Fundamental Rights, which require that any interference with private life through data processing be accompanied by sufficient safeguards.

## Key Developments

The CJEU's ruling in *Digital Rights Ireland* established a critical baseline: technical and organizational measures must be specific and adapted to the volume, sensitivity, and risk profile of the data involved. The Court struck down the Data Retention Directive partly because its security provisions were insufficiently tailored — they permitted economic considerations to dilute the required level of protection and failed to ensure irreversible destruction of data at the end of retention periods. This sets a clear precedent: cost considerations cannot serve as the primary determinant of security standards when sensitive or large-scale data is at stake.

Enforcement actions confirm that DPAs apply these principles rigorously. The Romanian ANSPDCP fined Poșta Română €5,000 for insufficient technical measures, while the Polish UODO imposed a €23,540 fine on the Minister of Justice for inadequate technical and organizational safeguards. Both decisions signal that public-sector entities face scrutiny equal to private operators. The EDPB's Guidelines 4/2019 on Article 25 further clarify that data protection by design is not optional architecture — it is a binding obligation requiring demonstrable, documented decisions about security configurations from the earliest stages of system development.

## Practical Guidance

- **Conduct and document risk assessments** tied to Article 32, evaluating the risks of varying likelihood and severity for the rights and freedoms of data subjects. The level of encryption, access controls, and logging must correspond to identified risks, not to budgetary convenience.

- **Implement pseudonymization** where feasible, as explicitly encouraged by Recital 29. Separate the additional information needed to re-identify individuals and restrict access to it under strict controls.

- **Embed security into system design** from inception under Article 25. The EDPB Guidelines 4/2019 require demonstrable evidence that privacy-protective defaults and security features were selected during development, not retrofitted.

- **Establish data retention and destruction protocols** that ensure irreversible deletion at the end of the retention period. *Digital Rights Ireland* makes clear that failure to guarantee irreversible destruction renders security measures deficient per se.

- **Review and update measures continuously.** Article 32 requires ongoing evaluation. Static security configurations that are not reassessed against evolving threats constitute non-compliance, as reflected in the UODO enforcement against the Polish Minister of Justice.

## Legislation (full text of key provisions)

### Processing of personal data relating to criminal convictions and offences

*Source: GDPR, gdpr-art-10-en, 2016-04-27 — https://overview.legal/posts/90322*

Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.

### Recital 83 — data security risk assessment and mitigation

*Source: GDPR, gdpr-rec-83-en, 2016-04-27 — https://overview.legal/posts/91681*

In order to maintain security and to prevent processing in infringement of this Regulation, the controller or processor should evaluate the risks inherent in the processing and implement measures to mitigate those risks, such as encryption. Those measures should ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the costs of implementation in relation to the risks and the nature of the personal data to be protected. In assessing data security risk, consideration should be given to the risks that are presented by personal data processing, such as accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed which may in particular lead to physical, material or non-material damage.

### Recital 98 — Promoting encryption for electronic communications security

*Source: NIS2, nis2-rec-98-en, 2022-12-14 — https://overview.legal/posts/96724*

In order to safeguard the security of public electronic communications networks and publicly available electronic communications services, the use of encryption technologies, in particular end-to-end encryption as well as data-centric security concepts, such as cartography, segmentation, tagging, access policy and access management, and automated access decisions, should be promoted. Where necessary, the use of encryption, in particular end-to-end encryption should be mandatory for providers of public electronic communications networks or of publicly available electronic communications services in accordance with the principles of security and privacy by default and by design for the purposes of this Directive. The use of end-to-end encryption should be reconciled with the Member States’ powers to ensure the protection of their essential security interests and public security, and to allow for the prevention, investigation, detection and prosecution of criminal offences in accordance with Union law. However, this should not weaken end-to-end encryption, which is a critical technology for the effective protection of data and privacy and the security of communications.

### Recital 51 — Innovative technology for cybersecurity

*Source: NIS2, nis2-rec-51-en, 2022-12-14 — https://overview.legal/posts/96630*

Member States should encourage the use of any innovative technology, including artificial intelligence, the use of which could improve the detection and prevention of cyberattacks, enabling resources to be diverted towards cyberattacks more effectively. Member States should therefore encourage in their national cybersecurity strategy activities in research and development to facilitate the use of such technologies, in particular those relating to automated or semi-automated tools in cybersecurity, and, where relevant, the sharing of data needed for training users of such technology and for improving it. The use of any innovative technology, including artificial intelligence, should comply with Union data protection law, including the data protection principles of data accuracy, data minimisation, fairness and transparency, and data security, such as state-of-the-art encryption. The requirements of data protection by design and by default laid down in Regulation (EU) 2016/679 should be fully exploited.

### Recital 69 — privacy and data protection lifecycle

*Source: AI Act, aiact-rec-69-en, 2024-06-12 — https://overview.legal/posts/93820*

The right to privacy and to protection of personal data must be guaranteed throughout the entire lifecycle of the AI system. In this regard, the principles of data minimisation and data protection by design and by default, as set out in Union data protection law, are applicable when personal data are processed. Measures taken by providers to ensure compliance with those principles may include not only anonymisation and encryption, but also the use of technology that permits algorithms to be brought to the data and allows training of AI systems without the transmission between parties or copying of the raw or structured data themselves, without prejudice to the requirements on data governance provided for in this Regulation.

### Recital 115 — systemic risk management for general-purpose AI

*Source: AI Act, aiact-rec-115-en, 2024-06-12 — https://overview.legal/posts/93912*

Providers of general-purpose AI models with systemic risks should assess and mitigate possible systemic risks. If, despite efforts to identify and prevent risks related to a general-purpose AI model that may present systemic risks, the development or use of the model causes a serious incident, the general-purpose AI model provider should without undue delay keep track of the incident and report any relevant information and possible corrective measures to the Commission and national competent authorities. Furthermore, providers should ensure an adequate level of cybersecurity protection for the model and its physical infrastructure, if appropriate, along the entire model lifecycle. Cybersecurity protection related to systemic risks associated with malicious use or attacks should duly consider accidental model leakage, unauthorised releases, circumvention of safety measures, and defence against cyberattacks, unauthorised access or model theft. That protection could be facilitated by securing model weights, algorithms, servers, and data sets, such as through operational security measures for information security, specific cybersecurity policies, adequate technical and established solutions, and cyber and physical access controls, appropriate to the relevant circumstances and the risks involved.

### Recital 95 — continuity with existing national security guidelines

*Source: NIS2, nis2-rec-95-en, 2022-12-14 — https://overview.legal/posts/96718*

Where appropriate and in order to avoid unnecessary disruption, existing national guidelines adopted for the transposition of the rules related to security measures laid down in Articles 40 and 41 of Directive (EU) 2018/1972 should be taken into account in the transposition of this Directive, thereby building on the knowledge and skills already acquired under Directive (EU) 2018/1972 concerning security measures and incident notifications. ENISA can also develop guidance on security requirements and on reporting obligations for providers of public electronic communications networks or of publicly available electronic communications services to facilitate harmonisation and transition and to minimise disruption. Member States can assign the role of the competent authorities for electronic communications to the national regulatory authorities under Directive (EU) 2018/1972 in order to ensure the continuation of current practices and to build on the knowledge and experience gained as a result of the implementation of that Directive.

### Recital 104 — cybersecurity obligations for electronic communications providers

*Source: NIS2, nis2-rec-104-en, 2022-12-14 — https://overview.legal/posts/96736*

Providers of public electronic communications networks or of publicly available electronic communications services should implement security by design and by default, and inform their service recipients of significant cyber threats and of measures they can take to protect the security of their devices and communications, for example by using specific types of software or encryption technologies.

### Recital 75 — personal data processing risks to individuals

*Source: GDPR, gdpr-rec-75-en, 2016-04-27 — https://overview.legal/posts/91665*

The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from personal data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage; where data subjects might be deprived of their rights and freedoms or prevented from exercising control over their personal data; where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, and the processing of genetic data, data concerning health or data concerning sex life or criminal convictions and offences or related security measures; where personal aspects are evaluated, in particular analysing or predicting aspects concerning performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, in order to create or use personal profiles; where personal data of vulnerable natural persons, in particular of children, are processed; or where processing involves a large amount of personal data and affects a large number of data subjects.

### Recital 49 — network and information security processing

*Source: GDPR, gdpr-rec-49-en, 2016-04-27 — https://overview.legal/posts/91613*

The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, by public authorities, by computer emergency response teams (CERTs), computer security incident response teams (CSIRTs), by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned. This could, for example, include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping ‘denial of service’ attacks and damage to computer and electronic communication systems.

## Case law

### Audiencia Nacional upholds €2M AEPD fine against Amazon Flex for criminal-record checks

*Source: National Court, 2026-07-08 — https://overview.legal/posts/184679 — original: https://gdprhub.eu/index.php?title=AN_-_SAN_2996/2026*

Facts — Unión General de Trabajadores (UGT), a trade union, lodged a complaint with the DPA (AEPD) against Amazon Road Transport Spain, S.L., the controller. Applicants wishing to work within the Amazon Flex delivery programme were required to provide a certificate confirming that they had no criminal record. The certificates and other application documents were processed by external processors responsible for the preliminary screening of candidates. The controller considered this requirement necessary to protect its customers and ensure the security of the programme. Delivery drivers transported packages directly to private residences and had access to customers’ addresses, telephone numbers and information that could reveal aspects of their habits. They could also be entrusted with packages of significant value. On 10 February 2022, the DPA imposed a €2 million fine on the controller for an infringement of Article 6(1), in conjunction with Article 10 GDPR, as well as Articles 10 and 71 LOPDGDD. The DPA considered that a certificate showing the absence of criminal convictions still constituted personal data relating to criminal convictions and offences. Consequently, it held that candidates’ consent could not legitimise the processing without a specific authorisation under Union or national law. The controller appealed the decision before the Audiencia Nacional, the appeal court. It argued that a certificate confirming the absence of criminal records did not fall within Article 10 GDPR and referred to previous cases in which the DPA had accepted similar requirements for certain professional activities. Holding — The Court granted the appeal and annulled the DPA’s decision and the €2 million fine. First, the Court held that Article 10 GDPR must be interpreted strictly, particularly in administrative sanctioning proceedings, which are governed by the principle of minimum intervention and the prohibition of extensive interpretations against the alleged infringer. The Court distinguished between processing information concerning existing criminal convictions or offences and processing a certificate confirming that the person has no criminal record. In its view, Article 10 GDPR expressly covers personal data relating to criminal convictions and offences, but not information concerning their absence. The Court considered that a negative criminal record certificate contains favourable information regarding a person’s conduct. Therefore, processing such a certificate does not amount to processing specially protected criminal-offence data under Article 10 GDPR. As a result, the consent provided by candidates was not invalid merely because no Union or national law specifically authorised the processing under that provision. The Court distinguished the case from situations involving direct access to criminal-record databases or the creation of files containing adverse information. It also distinguished previous employment-law judgments concerning employers requesting criminal records. Although requiring such certificates could be unlawful or abusive under employment law, this did not necessarily mean that the conduct was sanctionable under data protection law. Nevertheless, the Court clarified that processing negative criminal record certificates remained subject to the general GDPR requirements, particularly the principles under Article 5 GDPR and the need for a valid legal basis under Article 6(1) GDPR. In this regard, the Court found the controller’s reasons sufficient to consider the processing legitimate. Amazon Flex drivers delivered packages to private homes and had access to customers’ contact details and information capable of revealing their habits. The Court therefore accepted that verifying candidates’ good standing served the security of the recruitment process and the protection of customers. Accordingly, the Court concluded that the processing was legitimate, granted the controller’s appeal and annulled the DPA’s decision without awarding costs.

### BVwG - W137 2327171-1

*Source: Federal Administrative Court, 2026-07-08 — https://overview.legal/posts/184712 — original: https://gdprhub.eu/index.php?title=BVwG_-_W137_2327171-1*

Facts — The controller, an assistant professor at a private university (the appellant), was engaged in an employment dispute with her university employer before a labour and social court. The data subject, a senior legal counsel employed by the university gave testimony as a witness in that employment proceeding. On 23 January 2025, the labour and social court ruled in the controller's favour, finding that her employment relationship continued beyond the university's purported termination date. The judgment referred to the data subject several times by her academic title and surname in connection with her witness testimony. In April 2025, the controller published the unredacted judgment in full, including the data subject's title and surname on social media. She shared a downloadable link (first via Dropbox, later via Adobe) on her public Facebook profile and in a closed Facebook group of around 230 members connected to the university community. The files were later removed by Dropbox and Adobe after the data subject reported them. The data subject's full first name and additional details could also be found by combining her academic title and surname with the university's name in a Google search, which surfaced her LinkedIn profile. The data subject filed a complaint with the Austrian DPA, arguing that the controller had no justification for naming her and had drawn her into a public dispute with her employer. The controller argued that the judgment concerned matters of wider relevance to university staff, that the Facebook group was closed and that the data subject's name and role were already public via the university directory and LinkedIn. On 15 October 2025, the DPA upheld the complaint, finding that the controller had violated the data subject's right to secrecy under §1(1) of the Austrian Data Protection Act (DSG) by publishing the judgment without a legal basis. The DPA found that a legitimate interest existed in principle, but that both publications were excessive as the judgment was made accessible to an uninvolved and disproportionately wide audience and that disclosing the data subject's name was not necessary to achieve the controller's stated purpose of informing colleagues in similar situations. The DPA noted that publishing the judgment with the data subject's name redacted would have been an equally effective, less intrusive alternative. The controller appealed, arguing that the data subject had no protectable secrecy interest because she had participated in the proceeding in a public professional capacity and had made comparable information about herself public on LinkedIn and that the DPA had failed to weigh her freedom of expression rights under Article 10 ECHR against the data subject's secrecy interest. Holding — The court dismissed the appeal in full and confirmed the DPA's decision. First, the court rejected the controller's argument that no protectable secrecy interest existed because the data subject had acted in a professional capacity. It held that, under settled national case-law, appearing in a professional role does not by itself remove a person's right to secrecy under §1(1) DSG. Second, applying the three-part test for legitimate interest under Article 6(1)(f) GDPR, the court accepted that the controller had, in principle, a legitimate interest in informing colleagues in comparable employment situations about the judgment. However, it held that publishing the data subject's surname failed the necessity requirement under this test and therefore also breached the data minimisation principle under Article 5(1)(c) GDPR. The court noted that the data subject was a witness testifying about legal matters, not the person responsible for the controller's employment contract and that naming her added nothing to the comprehensibility or persuasive value of the information the controller sought to share. Because necessity was lacking, the court found it unnecessary to conduct any further balancing of the parties' respective rights. Third, the court rejected the controller’s argument that her freedom of expression justified the full disclosure of the judgment, for which she relied on the CJEU’s judgment in Case C-345/17 (Buivids). The court held that Buivids concerned whether processing could be regarded as being carried out solely for journalistic purposes, whereas there was no indication of journalistic activity in the present case. It further held that §9 DSG, which implements Article 85 GDPR in relation to journalistic activity, was therefore inapplicable. In any event, the court stated that §9 DSG does not entirely override the principle of proportionality but establishes a different standard for balancing the competing interests. Finally, the court agreed with the DPA that redacting the data subject's name and title would have been an equally effective and only minimally burdensome alternative that would not have undermined the controller's informational purpose and held that the controller had not plausibly explained why such redaction would have been insufficient. The court accordingly found no unlawfulness in the DPA's decision and dismissed the appeal. It declared that an appeal on points of law (Revision) was not admissible, since the case did not raise a legal question of fundamental importance and was consistent with existing case-law.

### VwGH - VwGH Ro 2025/04/0007-7

*Source: Austrian Administrative Supreme Court, 2026-06-24 — https://overview.legal/posts/184547 — original: https://gdprhub.eu/index.php?title=VwGH_-_VwGH_Ro_2025/04/0007-7*

Facts — The controller was an address publisher and direct advertising company that operated a data application to provide advertisers with personal data for targeted marketing measures. In 2019, following media reports concerning the alleged sale of personal data, particularly information about natural persons’ political party affinity, the Austrian DPA (DSB) initiated an ex officio investigation against the controller. Based on its investigation, the DPA found that the controller had unlawfully processed political party affinity data and unlawfully further processed parcel-frequency data, and had infringed its obligations concerning the DPIA and record of processing activities. It consequently imposed a fine of €18,000,000. The controller appealed to the Federal Administrative Court (BVwG), arguing that the commission of an infringement by a legal person was not, in itself, sufficient for a fine to be imposed under the GDPR. It claimed that since a legal person could not act on its own, the culpable conduct of a natural person had to be identified and attributed to it. The controller argued that the DPA had failed to establish such attribution. The court agreed and, on 26 November 2020, annulled the fine. It found that the DPA had failed to establish that natural persons acting on behalf of the controller had engaged in culpable conduct. The DPA filed an extraordinary official appeal against this judgment with the Austrian Supreme Administrative Court (VwGH). The court stayed the proceedings pending the CJEU’s preliminary ruling in Case C-807/21 (Deutsche Wohnen SE), as the questions referred in that case were also relevant to the appeal proceedings. The CJEU published its judgement on this matter on 5 December 2023. The CJEU held that a fine under Article 83(4) GDPR, Article 83(5) GDPR and Article 83(6) GDPR may be imposed on anyone who qualifies as a controller where it is established that the controller committed the relevant infringement intentionally or negligently. A controller may be sanctioned where it could not have been unaware of the infringing nature of its conduct, regardless of whether it knew that its conduct infringed the GDPR. The CJEU further clarified that, where the controller is a legal person, the application of Article 83 GDPR does not require any action or knowledge on the part of its governing body. Member States may not impose additional substantive requirements for the imposition of fines beyond those laid down in Article 83 GDPR. For the determination of the fine, the controller may also constitute an undertaking within the meaning of EU competition law, with the turnover of the relevant economic unit being taken into account. Following the CJEU judgment, the Supreme Administrative Court annulled the Federal Administrative Court’s judgment on 1 February 2024. The Federal Administrative Court issued a new judgment on 27 December 2024, largely upholding the infringements but reducing the fine to €16,000,000. The controller appealed this decision before the Supreme Administrative Court. Holding — The court found that the controller gathered information concerning the political party affinity of the Austrian population based on anonymous surveys conducted by commissioned polling institutes. These surveys included specific questions concerning interest in election advertising, together with sociodemographic information such as age, level of education and income, place of residence and interest in advertising from political parties. Marketing groups were subsequently formed based on the sociodemographic data and place of residence. For each group, calculations were made to determine the likelihood that an individual with particular sociodemographic characteristics and religious affiliation would be interested in advertising from the political parties concerned. By assigning an identifiable individual to a particular marketing group, the controller linked that person to the probability values calculated for the group and the resulting political party affinity. The court held that the controller did not obtain consent from the data subjects to whom these probability scores were assigned. In total, political party affinity was attributed to approximately 2,200,000 individuals. The court reiterated that political party affinity scores attributed to identifiable individuals constituted personal data revealing political opinions within the meaning of Article 9(1) GDPR. It therefore upheld the finding that the controller had infringed Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. In assessing the controller’s culpability, the court relied heavily on the CJEU’s judgment in Deutsche Wohnen SE. It held that the fact that the controller believed it had complied with the GDPR because it had established a quality-assured organisation was not decisive. It pointed out that under GDPR, a legal person’s fault does not require knowledge or awareness on the part of the management body. The establishment of a data protection compliance system, like the obtaining of legal advice, did not in itself exculpate the controller. It stated that the decisive question was whether the controller could have been aware of the unlawfulness of the processing of political party affinity data during the relevant period. The court ruled that the controller had incorrectly assessed that political party affinity scores did not constitute personal data and that it had consequently failed to examine whether they constituted special categories of personal data under Article 9 GDPR. The court rejected the controller’s argument that political party affinity was processed only in relation to groups rather than in relation to specific identifiable individuals. It also rejected the argument that marketing classifications used for political advertising posed no risk to data subjects. The court concluded that given the controller’s resources and its ability to examine the applicable legal position, that legal assessment amounted to gross negligence concerning the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. Furthermore, the court ruled that the controller’s incorrect assessment that political party affinity scores did not constitute personal data or special categories of personal data also led it to conclude in its Data Protection Impact Assessment (DPIA) that the processing did not pose a high risk and that the scope of Article 35(3)(a) GDPR was therefore not applicable. The court held that the DPIA-related infringement was therefore absorbed from the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. It found no separate element of wrongdoing. The court additionally ruled that the same incorrect legal assessment resulted in the controller’s failure to include political party affinity as a separate category of personal data in its record of processing activities under Article 30(1)(c) GDPR. The court similarly found that these documentation failures did not contain a separate element of wrongdoing beyond that already covered by the infringement of Article 5(1)(a) GDPR and Article 9(1) GDPR. The court therefore discontinued the proceedings concerning the separate DPIA and record-of-processing infringements. It further held that, where a controller commits multiple GDPR infringements, a single aggregate fine must be imposed under Article 83(3) GDPR, the total amount of which may not exceed the amount applicable to the most serious infringement. The court reassessed the penalty and reduced it to €13,000,000, because the DPIA and record of processing infringements were no longer to be taken into account in determining the fine.

### BVwG - W258 2227269-1/39E

*Source: Federal Administrative Court, 2024-12-27 — https://overview.legal/posts/184564 — original: https://gdprhub.eu/index.php?title=BVwG_-_W258_2227269-1/39E*

Facts — On the 8 January 2019, the Austrian DPA (Datenschutzbehörde – DSB) launched an investigation into the actions of the Austrian postal service as it also had a business license for address publishing and direct marketing. Media reports had claimed that the postal service (the controller) sold data concerning the political affinities of data subjects to third parties. The controller ran a platform entitled “Adress Shop” on which it sold personal data to legal entities. The datasets included names and addresses but more importantly it included data subjects’ affinities to certain things such as an affinity to moving house, an affinity to organic products or how frequently a data subject receives packages. The purpose of the data processing was to sell this data to third parties who would use it for marketing purposes and therefore could avoid scattering losses. In order to create this database, the controller abused its position as postal service provider. In the postal service contract provided to data subjects the controller had included a notice stating that data subject are agreeing to their personal data being processed for marketing purposes. The contract however also included a box which could be ticked in order to refuse the data processing for marketing purposes. One of these affinities was concluded through an affinity score concerning the main political parties in Austria. For example, data subjects would be assessed with either a “very low”, “low”, “high” or “very high” affinity towards the SPÖ (the Socialist Party of Austria), the ÖVP (the Conservative Party of Austria) or any other major political party. The controller calculated this score through combing anonymous survey results, socio-demographic data (e.g., age or level of income and education) and voting results of particular region. On the 20 Febuary 2019, the DSB alleged that the controller had unlawfully processed sensitive data under Article 9 GDPR. The DSB found that the controller could not rely on a legal basis for the processing of this data and that the controller had sold the data to third parties. The DSB issued a fine of fine of €18,000,000 for the processing of sensitive data and other violations. The full details can be found here. On the 25 November 2019, the controller appealed the decision of the DSB to the Austrian Federal Administrative Court (Bundesverwaltungsgericht – BVwG) and alleged that the DSB had inadequately assessed the situation. On the 26 November, the BVwG annulled the decision of the DSB stating that the DSB had failed to name a natural person to whom the actions of the controller could be attributed to. Based on an Austrian provision, namely paragraph 45(1)(3) of the Administrative Penal Code (Verwaltungsstrafgesetz - VStG), in order to fine a legal person for a violation of the GDPR all necessary requirements for the penalization of a natural person must be fulfilled. This finding was however annulled by the Supreme Administrative Court (Verwaltungsgerichtshof – VwGH) on the 1 February 2024. The VwGH explained that although the BVwG correctly applied the national provision, the CJEU case C-807/21 Deutsche Wohnen showed that Article 58(2)(i) GDPR and Article 83 GDPR are excluded from national derogations. Therefore, the BVwG should not have applied the national provision. The case was therefore reverted back to the BVwG. Holding — The BVwG reassessed the case and partly upheld the DSB decision but made the following alterations. Article 9 GDPR data related to political affinities The BVwG confirmed that the controller had at no point in time obtained the consent of the data subject and therefore was processing data in violation of Article 9(1) GDPR since the 25 May 2018. The BVwG held that the controller's conduct had proved negligent. The BVwG noted that the controller had made efforts to apply the GDPR correctly but criticized for example that the DPO had to monitor all processing activities which did not prove an effective monitoring and controlling system as it would require too much time for just one person. The BVwG held that it was clearly unacceptable that the DPO thought that the data processed did not constitute personal data, especially when it was explicitly connected to an individual person. Further, The BVwG found that the controller never conducted an assessment on whether certain affinities could constitute sensitive data under Article 9 GDPR. The BVwG classified this as grossly negligent behaviour on the part of the controller. The BVwG concluded that the controller should have consulted an external expert around the uncertainties it had concerning the correct application of the GDPR. Affinity towards receiving packages In relation to the data processed to assess their affinity for receiving packages, the controller was in a privileged position to have access to the relevant data. However, it then further processed this data contrary to their legal mandate for creating projection models for marketing purposes in violation of Article 6(4) GDPR. The court also held that this violated the principles of fairness and transparency under Article 5(1)(a) GDPR. The BVwG highlighted that the controller knew that its positions as postal service provider and data broker is likely to cause issues, therefore its behaviour was classified as negligent. Affinity towards moving house Assessing whether data subjects were likely to move house differed to the assessment of an affinity towards receiving packages as there was a contractual relationship between the data subject and the controller due to contractual redirection orders. The BVwG assessed that the minimal information provided to data subjects on the processing for marketing purposes, proved to be just about enough as the personal data was made up of a calculation of averages which was then anonymized. The court found that this could be classified as processing which, based on the controllers description, could be expected from the notice included in the contract. In addition, data subjects could easily refuse the data processing. Data Protection Impact Assessment The controller had processed an extensive amount of sensitive data which requires a data protection impact assessment. The controller’s assessment that this data processing was of low risk was therefore faulty. The controller had therefore violated Article 35(3)(b) GDPR and Article 35(7) GDPR. The BVwG held that as the controller had negligently categorized its processing as not concerning any sensitive data, it consequently also proves to have acted negligently in assessing the risks under Article 35 GDPR. The BVwG rejected the controller’s argument that penalization under Article 35 GDPR would result in a double punishment for the same offence. It explained that the general obligations under the GDPR pursue a different aim to the provisions governing lawfulness of the processing. Further, the DPIA is to be conducted prior to processing. Records of processing The faulty and therefore inadequate DPIA resulted in a violation of Article 30(1)(c) GDPR, which requires the records of data processing to include the categories of data processed. The BVwG again assessed that the controller had acted negligently in relation to this aftereffect of its faulty categorization of the processed data. The controller had merely stated that the data would be processed for marketing purposes and this was held to have been inadequate as the controller processed data such as the political affinities. The BVwG held that the controller had failed to provide a full description of all the processed categories. Fine The BVwG reduced the fine to €16 million mainly based on the controller's low annual turnover. Further, the BVwG noted that the political data had only been sold to two political parties which resulted in a limited amount of data subjects being affected.

### Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t

*Source: Court of Justice of the European Union, C-169/23, 2024-11-28 — https://overview.legal/posts/132158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0169*

In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan Government Office, as controller issuing COVID-19 immunity certificates, was required to provide information to data subjects under Article 14 GDPR where the personal data was not collected directly from them. The Court held that data generated by the controller in the context of its own processes falls within the Article 14(5)(c) exemption from the obligation to provide information, provided that Member State law ensures appropriate measures to protect the data subject's legitimate interests, including data security measures under Article 32. The Court also confirmed that supervisory authorities retain competence to handle complaints under Article 77(1) even where the Article 14(5)(c) exemption applies.

### Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos

*Source: Court of Justice of the European Union, C-446/21, 2024-10-04 — https://overview.legal/posts/132159 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0446*

In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR Articles 5(1)(b), 5(1)(c), 6(1), and 9 concerning the lawfulness of processing user personal data for personalised advertising on online social networks. The Court addressed whether such processing can be deemed compatible with the original purpose of data collection under a platform's terms of use, the applicability of the data minimisation principle, and the conditions under which special categories of personal data, including data concerning sexual orientation made public by the data subject, may be processed. No fine was imposed, as the ruling provides interpretative guidance to the Austrian Supreme Court for resolution of the underlying dispute.

### Judgment of the Court (Sixth Chamber) of 7 March 2024.#Endemol Shine Finland Oy.#Request for a preliminary ruling from the Itä-Suomen hovioikeus.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Articles 2, 4, 6, 10 and 86 – Data held by a court relating to the criminal convictions of a natural person – Oral disclosure of such data to a commercial company on account of a competition organised by that company – Concept of ‘processing of personal data’

*Source: Court of Justice of the European Union, C-740/22, 2024-03-07 — https://overview.legal/posts/132269 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0740*

In Case C-740/22, the Court of Justice of the European Union (Sixth Chamber) ruled on a preliminary reference from the Itä-Suomen hovioikeus (Court of Appeal, Eastern Finland) concerning whether the oral disclosure by a court of data relating to a natural person's criminal convictions to Endemol Shine Finland Oy, a commercial company organizing a competition, constitutes "processing of personal data" under the GDPR. The Court held that such oral disclosure falls within the scope of GDPR Article 2(1), as the concept of processing is not limited by the means or format of transmission, and that national legislation governing public access to official documents must reconcile the right of access with the GDPR's data protection requirements, particularly given the sensitive nature of criminal conviction data under Article 10. No fine was imposed, as the ruling solely addressed the interpretation of EU law.

### BVwG - W256 2227693-1

*Source: Federal Administrative Court, 2023-09-28 — https://overview.legal/posts/125664 — original: https://gdprhub.eu/index.php?title=BVwG_-_W256_2227693-1*

Facts — On 05.09.2019, the Austrian DPA (DSB) notified the controller of a customer loyalty program that they were initiating an ex officio investigation. The controller responded by answering the provided questionnaire and submitting further documents. On 23.10.2019, the DPA ruled that the investigation was justified and that the declaration of consent for profiling using certain registration methods (website, app, partner company store, flyer) did not comply with the requirements of Article 4(11) GDPR and Article 7 GDPR, nor were they provided in an intelligible way. If a contract covers several aspects, the declaration of consent must be clearly distinguishable. Regarding the website and flyer, the following was found: The website says 'Enjoy your personal benefits' without providing clear information that 'personal benefits' involves profiling. In an embedded box, the relevant points were merely referred to. Information regarding profiling was only accessible by scrolling down further. Concerning the flyer, the following information was provided under the signature field: 'This signature only applies to the declaration of consent and is voluntary. Your registration [...] is also valid without a signature.' Thus, it conveyed the impression that a signature was required to confirm the registration. Consequently, the controller was required to amend the declaration and to cease using any obtained consents for the purpose of profiling prior to 01.05.2020. The controller lodged a complaint. In addition to other information, the controller stated that the data processing was in accordance with Article 6(1)(a) GDPR, and that they had a legitimate interest under Article 6(1)(f) GDPR. The DPA ruled a preliminary decision on the complaint, thereby changing the ruling that the website and flyer did not meet the requirements under Article 6(1)(a) GDPR, and thus, the processing of personal data, collected in that cases, was forbidden. The other methods ensured that the consent was clearly separated from the rest of the registration process. The controller then filed a request for referral to the court, arguing that the DPA had exceeded their corrective powers by prohibiting the processing of the data. Furthermore, the data processing for profiling would be used to manage customer memberships under Article 6(1)(b) GDPR. Following their view, processing under Article 6(4) GDPR was applicable. Additionally, the controller denied the DPA's view that a violation of the principle of good faith would foreclose a weighing of interests under Article 6(1)(f) GDPR. The court quashed the preliminary decision as the DPA had not examined the other grounds of justification for data processing under Article 6(1) GDPR in their initial decision. The DPA then lodged an appeal to the Austrian Supreme Administrative Court (Verwaltungsgerichtshof), which overturned the court's ruling (VwGH 08.02.2022, Ro 2021/04/0033). It was the court's responsibility to examine the potential legal bases, rather than overturning the DPA's decision. Therefore, the case was returned to the court. In the meantime, the controller complied with the preliminary decision by deleting the affected personal data in 2021 and changing their registration process in 2020. Holding — First, the court found that they had to formally rule on whether the DPA's decision was lawful at the time it was ruled. It is not to be considered that the controller complied with the administrative decision and fulfilled the required steps (VwGH 28.04.2022, Ra 2022/06/0056). Second, the court held that the controller did not comply with the transparency requirements regarding the layout of their declaration of consent under Article 7(2) GDPR in both cases (website, flyer). Third, the court ruled that they could not agree with DPA's view, that an invalid declaration of consent always constitutes unlawful data processing and that a review of other grounds of justification would not be necessary (CLEU in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537). Further on, the Supreme Administrative Court ruled that both, the DPA and the court are required to examine the presence of other grounds (VwGH 08.02.2022, Ro 2021/04/0033). Fourth, the court held that the controller could not base their appeal on Article 6(4) GDPR as the data processing did not satisfy the grounds of justification, nor were other grounds apparent. Inter alia, following the CLEU's preliminary ruling in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537, three cumulative requirements must be met for data processing under Article 6(1)(f) GDPR: (1) The controller or a third party must have a legitimate interest, (2) which requires the processing of that personal data, (3) and 'the fundamental rights and freedoms of the data subject' must not outweigh those interests. There were no doubts about the controller's legitimate interest in processing the personal data in question for targeted marketing purposes, as this was both necessary and reasonable. However, the data subject should have been notified about profiling. The wording 'only if the member consents' did not constitute such a notification, and therefore the data subjects were not to be expected that their personal data was used for profiling purposes. Furthermore, the controller explicitly excluded it in their general terms and conditions. Hence, the data subject's right to secrecy overrode the controller's legitimate interest. In summary, the court dismissed the controller's complaint. Last, the court held that an appeal to the Supreme Administrative Court was admissible under Article 133(4) B-VG, as no prevailing case law concerning the implementation of a declaration of consent existed. Hence, the decision relied on a legal question of fundamental importance.

### Judgment of the Court (Fifth Chamber) of 4 May 2023.#UZ v Bundesrepublik Deutschland.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to processing – Controllership – Article 6 – Lawfulness of processing – Electronic file compiled by an administrative authority relating to an asylum application – Tra

*Source: Court of Justice of the European Union, C-60/22, 2023-05-04 — https://overview.legal/posts/132289 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0060*

In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik Deutschland regarding the processing of personal data in an asylum application file. The Court held that an administrative authority transmitting an electronic asylum file to a competent national court via an electronic mailbox constitutes processing under the GDPR, and that where both the authority and the court determine the purposes and means of processing, they are joint controllers under Article 26, requiring an arrangement allocating responsibility and maintaining records of processing activities under Article 30. The Court further clarified that transmission of personal data without the data subject's consent constitutes unlawful processing, triggering the right to erasure under Article 17(1)(d) and the right to restriction under Article 18(1)(b), and that national courts must disregard such unlawfully processed data. No fine was imposed.

### Judgment of the Court (First Chamber) of 20 October 2022.#Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(b) and (e) – Principle of ‘purpose limitation’ – Principle of ‘storage limitation’ – Creation, from an existing database, of a datab

*Source: Court of Justice of the European Union, C-77/21, 2022-10-20 — https://overview.legal/posts/132306 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0077*

In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) concerning a personal data breach. The Court held that creating a new database from an existing one for testing and error-correction purposes constitutes further processing requiring compatibility assessment under the purpose limitation principle, and that the storage limitation principle applies such that data must be deleted once the testing purpose is fulfilled. No fine was imposed at the EU level, as the matter was remitted to the referring Hungarian court.

### Judgment of the Court (Grand Chamber) of 21 June 2022.#Ligue des droits humains ASBL v Conseil des ministres.#Request for a preliminary ruling from the Cour constitutionnelle.#Reference for a preliminary ruling – Processing of personal data – Passenger Name Record (PNR) data – Regulation (EU) 2016/679 – Article 2(2)(d) – Scope – Directive (EU) 2016/681 – Use of PNR data of air passengers of flights operated between the European Union and third countries – Power to include data of air passengers

*Source: Court of Justice of the European Union, C-817/19, 2022-06-21 — https://overview.legal/posts/132311 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62019CJ0817*

In a preliminary ruling referred by the Belgian Constitutional Court in Ligue des droits humains v. Conseil des ministres (Case C-817/19), the CJEU Grand Chamber assessed the validity of the PNR Directive (EU) 2016/681 and its interplay with the GDPR and the API Directive in light of Articles 7, 8, and 52(1) of the EU Charter of Fundamental Rights. The Court upheld the PNR Directive's validity, finding that the collection, retention, and automated processing of passenger name record data for combating terrorist offences and serious crime constitutes a justified and proportionate limitation on fundamental rights to privacy and data protection, provided the directive's safeguards are strictly observed. No fine was imposed, as the ruling solely provides interpretive guidance on EU law validity and scope for the referring national court.

### Judgment of the Court (Fifth Chamber) of 24 February 2022.#SIA 'SS' v Valsts ieņēmumu dienests.#Request for a preliminary ruling from the Administratīvā apgabaltiesa.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 2 – Scope – Article 4 – Concept of ‘processing’ – Article 5 – Principles relating to processing – Purpose limitation – Data minimisation – Article 6 – Lawfulness of processing – Proc

*Source: Court of Justice of the European Union, C-175/20, 2022-02-24 — https://overview.legal/posts/132316 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0175*

In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a request by the Latvian State Tax Authority for SIA 'SS' to disclose personal data from online vehicle sale advertisements for tax enforcement purposes. The Court held that national law may require controllers to provide personal data to tax authorities under Article 6(1)(c) and (e), provided the request complies with data minimisation and purpose limitation principles, meaning authorities must limit requests to what is necessary and proportionate for the specific tax investigation. No fine was imposed as this was a preliminary ruling proceeding.

## Guidance

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### Guidelines 01/2021

*Source: EDPB, edpb-guidelines-on-examples-regarding-personal-data-breach-notification, 2022-01-03 — https://overview.legal/posts/38047 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012021-on-examples-regarding-personal-data-breach-notification_en*

The European Data Protection Board (EDPB) adopted Guidelines 01/2021 on December 14, 2021, providing practical examples and analysis regarding personal data breach notification obligations under Articles 33 and 34 of the GDPR. The guidelines present hypothetical scenarios covering ransomware attacks and data exfiltration incidents, illustrating how controllers should assess risk to determine whether notification to supervisory authorities and communication to data subjects are required. The document serves as interpretive guidance for controllers evaluating breach severity, appropriate mitigation measures, and notification decisions, and does not impose any fines or sanctions.

### Recommendation 01/2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 39.4 of Regulation (EU) 2018/1725)

*Source: EDPB, recommendation-012019-on-the-draft-list-of-the-european-data-protection-en, 2019-07-12 — https://overview.legal/posts/126224 — original: https://www.edpb.europa.eu/documents/recommendation/recommendation-012019-on-the-draft-list-of-the-european-data-protection_en*

Adopted 1 Recommendation 01/ 2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 3 9 .4 of Regulation (EU) 2018/1725) Adopted on 10 July 2019 Adopted 2 3 CONCLUSION ................................ ................................ ................................ ................................ ... 7 Adopted 3 The European Data Protection Board Having regard to Article…

### Opinion 6/2024 on the draft list of the Latvian SA on pro-cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR)

*Source: EDPB, opinion-62024-on-the-draft-list-of-the-latvian-sa-on-pro-en, 2024-04-18 — https://overview.legal/posts/125762 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-62024-on-the-draft-list-of-the-latvian-sa-on-pro_en*

Adopted 1 Opinion 6/2024 on the draft list of the Latvian SA on pro- cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR) Adopted on 16 April 2024 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64 (2) and Article 35 (1), (5) and (6) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data…

### Report of the work undertaken by the supervisory authorities within the 101 Taskforce

*Source: EDPB, report-of-the-work-undertaken-by-the-supervisory-authorities-within-the-en, 2023-04-19 — https://overview.legal/posts/125859 — original: https://www.edpb.europa.eu/documents/task-force-report/report-of-the-work-undertaken-by-the-supervisory-authorities-within-the_en*

Final 1 Report of the work undertaken by the supervisory authorities within the 101 Task Force 28 March 2023 Final 2 Final 3 DISCLAIMER The EDPB created the 101 Task Force to promote cooperation and effective exchange of information between the Supervisory Authorities on this specific subject-matter, in accordance with Article 70(1)(u) GDPR. The positions presented in this document result from the coordination of the Supervisory Authorities taking part in the task force with a view to handling…

### Guidelines 9/2022 on personal data breach notification under GDPR

*Source: EDPB, edpb-guidelines-on-personal-data-breach-notification-under-gdpr, 2023-04-04 — https://overview.legal/posts/38058 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-92022-on-personal-data-breach-notification-under-gdpr_en*

The EDPB adopted Guidelines 9/2022 (Version 2.0, 28 March 2023) to update and replace the prior WP250 guidance on personal data breach notification under Articles 33 and 34 of the GDPR. The guidelines address the definition and types of personal data breaches, controller and processor notification obligations, the concept of a controller becoming "aware" of a breach, cross-border and non-EU establishment breach scenarios, and the conditions under which notification to supervisory authorities and data subjects is or is not required.

### Statement 03/2021 on the ePrivacy Regulation

*Source: EDPB, statement-032021-on-the-eprivacy-regulation-en, 2021-03-09 — https://overview.legal/posts/126052 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-032021-on-the-eprivacy-regulation_en*

1 Statement 03/2021 on the ePrivacy Regulation Adopted on 9 March 2021 The European Data Protection Board has adopted the following statement: The EDPB welcomes the agreed negotiati on mandate adopted by the Council on the protection of privacy and confidentiality in the use of electronic communication services ( ’ the Council ’s position ’ ) , as a positive step towards a new ePrivacy Regulation . It is of utmost importance that the EU gen eral data protection framework is rapidly complemented…

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

## Enforcement decisions

### VDAI (Lithuania) - 3R-1143

*Source: VDAI (Lithuania), 2026-06-19 — https://overview.legal/posts/53896 — original: https://gdprhub.eu/index.php?title=VDAI_(Lithuania)_-_3R-1143*

Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other personal data of patients (the data subjects). The first breach potentially concerned 63 data subjects, whereas the latter breach affected approximately 10,000 employees and 383,000 data subjects. The DPA initiated two separate investigations against the controllers in September 2024 and November 2025 respectively and later combined the cases. Holding — The DPA imposed a fine of €450,000 on the first controller it investigated as this company was also the legal successor of the other controller. It held that the controllers had failed to implement appropriate technical and organisational measures to ensure the security of processing and compliance with the principles of integrity and confidentiality. The controller had violated Articles 5(1)(f), 24(1), and 32(1)(b) GDPR. When assessing the GDPR infringements, the DPA took into account that the controllers processed sensitive categories of personal data. The DPA held the controllers lacked adequate security measures for protecting against unauthorised access to an IT system, such as access control and authentication. For instance, passwords used by employees did not reach a certain level of complexity, and multi-factor authentication was not used.

### UODO (Poland) - DKN.5131.5.2025

*Source: UODO (Poland), 2026-05-25 — https://overview.legal/posts/184680 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.5.2025*

Facts — A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’) personal data to a specialised entity established for this purpose (the processor). In January 2023, a work laptop belonging to an employee of the processor was stolen from the trunk of a car parked in a parking garage. This resulted in a breach of confidentiality of the data subjects’ personal data, including names, addresses, ID numbers, and land registry numbers. The controller notified this data breach to the DPA later in January 2023. The DPA conducted an investigation and initiated administrative proceedings regarding the GDPR compliance of the processing operations carried out by the controller and the processor in March 2025. Holding — The DPA issued the controller a fine of PLN 21,000 (€4,900) and the processor a fine of PLN 12,500 (€2,900). First, the DPA held that the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of personal data processing – the controller had failed to demonstrate that it had conducted a thorough risk assessment in a manner that would have allowed for the selection of adequate security measures. These infringements resulted in the violations of the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR. Second, the DPA found that the controller had also violated Article 28(1) GDPR: it had failed to verify the adequacy of the technical and organisational measures implemented by the processor. Finally, the DPA came to the conclusion that the processor had infringed Articles 32(1) and 32(2) GDPR in conjunction with Articles 28(3)(c) and 28(3)(f) GDPR. The DPA held that the processor had failed to assist the controller in fulfilling its obligations and contributed to the controller’s GDPR violations. Unlike the controller, the processor had conducted a risk assessment covering the processing operations at issue; however, the processor had not implemented security measures to protect data stored on laptops used outside of its office premises, such as encryption.

### ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026

*Source: ANSPDCP (Romania), 2026-07-29 — https://overview.legal/posts/144034 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_Orange_Romania_SA_of_July_17,_2026*

Facts — The investigation was initiated after Orange Romania SA (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR, related to its mobile application. A customer (the data subject) of the controller was able to access and download invoices belonging to other customers. As a result, personal data such as names, addresses, delivery addresses, ID document details, and invoice information were disclosed. The incident was caused by a mismatch between two interconnected applications, which incorrectly linked the data subject's account to an employee account. During the investigation, another vulnerability was identified in the controller's ticketing application. The platform was publicly accessible and lacked adequate security measures, such as VPN protection, multi-factor authentication, and IP-based access restrictions. This vulnerability enabled a cyberattack that resulted in the theft of a large volume of personal data, including names, contact details, national identification numbers, copies of identity documents, banking-related information, login credentials, customer codes, and IBAN numbers. Holding — First, the DPA found that the controller infringed Article 25 GDPR by failing to implement appropriate technical and organisational measures when designing and operating its digital platforms. The DPA considered that these shortcomings enabled unauthorised access to personal data and failed to adequately protect data subjects' rights. For this infringement, the DPA imposed a fine of RON 104,780 (€20,000). Second, the DPA found that the controller infringed Article 32 GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The DPA noted that the controller had not adequately secured its platforms and had failed to regularly test and assess the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 419,120 (€80,000). In addition, as a corrective measure, the DPA ordered the controller to implement a monitoring and testing process for all IT applications used in its activities. The process must include controls over software changes and vulnerability testing.

### AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data

*Source: AEPD (Spain), 2026-07-16 — https://overview.legal/posts/53655 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00020-2025*

Facts — Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first estimated that 25,000 persons were affected. It later stated that the incident had affected around 40,000 persons, including 75 minors. The incident affected confidentiality, availability and integrity. The attacker encrypted systems and exfiltrated between 3.5 and 4 TB of information from the document management server. The affected data included identification and contact data, ID numbers, dates of birth, financial and insurance data, bank account numbers, health data, employee data and access credentials. The controller also processed data relating to minors in accident claims. A data subject complained to the DPA after being informed that their personal data had been exposed. The data subject was concerned about identity theft and requested additional information from the controller. During the investigation, the DPA found that the controller had known that its IT systems faced an extreme cybercrime risk before the breach. The forensic report could not determine the initial entry point because the servers had been encrypted, but it showed that attackers could move laterally through the infrastructure, obtain privileged access, install tools, exfiltrate data and encrypt systems. The controller had carried out a risk analysis in 2019, but this document concluded that no DPIA was necessary. After the breach, a later analysis found that a DPIA was necessary for treatments involving health data and minors. The controller did not prove that it had carried out the required DPIA. Holding — The DPA held that the controller violated Article 5(1)(f) GDPR. It considered that the controller had failed to ensure the integrity and confidentiality of the personal data under its responsibility. The DPA emphasised that the principle in Article 5(1)(f) GDPR is not limited to the existence of isolated security measures. Rather, the controller must implement adequate technical and organisational measures capable of ensuring that personal data is protected against unauthorised or unlawful processing, loss, destruction or damage. The DPA rejected the controller’s argument that the attack was an external criminal act that could not be attributed to it. The DPA found that the controller was aware of an extreme cyber risk and that its internal vulnerabilities and security posture allowed the attackers to move through the systems, access personal data and encrypt files. The DPA therefore considered that the controller’s measures were clearly insufficient. The DPA also held that the controller violated Article 35 GDPR. The controller processed high-risk categories of data, including health data and data concerning minors. In these circumstances, it should have carried out a DPIA before the processing. The DPA found that the controller’s 2019 risk analysis wrongly concluded that no high risk existed, while its later documentation acknowledged that a DPIA was necessary. The DPA proposed a fine of €150,000 for the infringement of Article 5(1)(f) GDPR and €100,000 for the infringement of Article 35 GDPR, totalling €250,000. The controller paid voluntarily without acknowledging liability, obtaining a 20% reduction under Spanish Administrative Law (39/2015). The final payable amount was therefore €200,000. The DPA also ordered the controller, under Article 58(2)(d) GDPR, to prove within three months from the enforceability of the decision that it had carried out the mandatory DPIA required under Article 35 GDPR.

### UODO (Poland) - DKN.5131.12.2022

*Source: UODO (Poland), 2026-06-11 — https://overview.legal/posts/144031 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.12.2022*

Facts — The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor). The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022. Holding — The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated Article 28(1) GDPR: while the controller had concluded a data processing agreement with the processor, it had failed to verify whether the processor provided sufficient guarantees to implement appropriate technical and organisational measures. Second, the DPA found that the controller had infringed Articles 24(1), 25(1), and 32(1) and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of processing via the email system. The DPA took into account that the controller had not taken any measures to minimise the risks identified. In addition, the DPA pointed out that the breach involved sensitive health data, and the passwords used by the controller did not meet the usual security requirements. As a consequence of the previous violations, the controller had infringed the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR as well. Finally, the DPA found a violation of Article 35(1) GDPR in conjunction with Article 35(3) GDPR due to the controller’s failure to conduct a data protection impact assessment. The DPA also reprimanded the processor for the failure to implement appropriate technical and organisational measures to ensure the security of processing – the processor had failed to conduct a risk analysis and to implement adequate security measures, such as blocking a user’s account after a certain amount of login attempts. The DPA held that the processor had violated Articles 32(1) and 32(2) GDPR in conjunction with Article 28(3)(c) GDPR.

### UODO (Poland) - DKN.5131.7.2022

*Source: UODO (Poland), 2026-04-13 — https://overview.legal/posts/53109 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.7.2022*

Facts — An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone application between July 2020 and March 2021 to send pictures of customer contracts containing the personal data of individuals residing at addresses visited during door-to-door sales (the data subjects). The controller had not authorised this practice, and former employees of the sub-processor could still access the personal data through the app. The controller identified the use of the app as a data breach and notified the supervisory authority about it in April 2021. The DPA initiated administrative proceedings in March 2022. Holding — First, the DPA held that the controller had violated the principles of integrity and confidentiality enshrined in Article 5(1)(f) and the principle of accountability laid down in Article 5(2) GDPR. It had also violated Articles 24(1), 25(1), 28(1), 32(1) and 32(2) GDPR, which specify these principles. The DPA issued the controller a reprimand. The DPA found the controller had failed to implement appropriate technical and organisational measures itself and also failed to properly verify whether the (sub-)processors had provided sufficient guarantees that they had implemented such measures. The data protection agreements required in Article 28(1) GDPR were very general in nature, and none of the parties in the chain of contracts had conducted a risk analysis to select appropriate security measures. In addition, the controller had not continuously monitored the processing activities. Second, the DPA held that the two processor and the sub-processor had violated Articles 32(1) and 32(2) GDPR read in conjunction with Article 28(4) GDPR. They had all failed to implement appropriate technical and organisational measures to ensure the security of personal data processing. The sub-processor was largely held responsible for the data breach – it had started using the app to process customers’ personal data without authorisation from the controller or the processors. Furthermore, the DPA pointed out the sub-processor should have verified whether the application would allow access to the personal data through it even after the termination of the employment relationship. The DPA reprimanded the processors and fined the sub-processor €2,415.

### Datatilsynet (Denmark) - 2022-63-0003

*Source: Datatilsynet (Denmark), 2022-10-28 — https://overview.legal/posts/6329 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2022-63-0003*

Facts — A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that the personal data was accessed by unauthorized persons, with a potential for harm to the data subjects. In March 2020, the law firm notified the Danish DPA of the data breach. Holding — The Danish DPA held that the law firm lacked basic security measures, especially considering the fact that its processing involved special categories of personal data. The DPA emphasized that in such cases a data breach would almost certainly entail a high risk to the data subjects' rights. Therefore, the controller must have especially strict security measures in place to avoid unauthorised accesses. Hence, when creating remote access to such IT systems, the controller could, for instance, implement multifactor authentication. Consequently, the DPA reported the firm to the police. The DPA assessed the appropriate sanctions in accordance with Article 83(2) GDPR and suggested a fine of approximately €67,000 (DKK 500,000).

### ANSPDCP (Romania) - Fine against Homelux SRL

*Source: ANSPDCP (Romania), 2026-08-11 — https://overview.legal/posts/187378 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_Homelux_SRL*

Facts — HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform that had not been updated to the latest version released by the software provider. The website subsequently suffered a cyberattack affecting the security of the personal data processed through it. This incident was further facilitated by weak password requirements for user accounts, a deficiency that remained unremedied after the breach. As a result, the security of personal data processed by the controller, including names, surnames, addresses, email addresses and passwords, was compromised. During the investigation, the DPA also found that the controller stored non-essential cookies on users' devices and accessed this information without obtaining the users' prior consent. Holding — First, the DPA found that the controller infringed Article 32(1)(d) and 32(2) GDPR by failing to implement adequate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing. The DPA considered these shortcomings insufficient to ensure a level of security appropriate to the risk. It also found that the controller had failed to establish a process for regularly testing, assessing, and evaluating the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 78,570 (€15,000). Second, the DPA found that the controller infringed Article 4(5) of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector by placing non-essential cookies on users' devices without obtaining prior consent. The DPA noted that these cookies were not technically necessary for the operation of the website and therefore could not be deployed without user consent. For this infringement, the DPA imposed a fine of RON 30,000 (€5,715). In addition, as corrective measures, the DPA ordered the controller to implement a procedural plan for the regular testing, evaluation and assessment of its IT systems and subsequent modifications. The DPA also required the controller to strengthen access controls by introducing stronger password requirements, multi-factor authentication, the deactivation of inactive accounts and limiting each user to only the access rights necessary for their role according to the principle of least privilege. Furthermore, the DPA required the controller to implement measures aimed at reducing vulnerabilities, including mechanisms to detect and block cyberattacks and restrictions on access to administrative interfaces. Finally, the DPA ordered the controller to ensure compliance with Article 4(5) of Law No. 506/2004 on its website.

## Recent developments

### ICO (UK) - ACRO Criminal Records Office

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291401 — original: https://gdprhub.eu/index.php?title=ICO_(UK)_-_ACRO_Criminal_Records_Office*

The ICO reprimanded ACRO for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. English Summary. Facts. ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes per

### ANSPDCP (Romania) - ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291402 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_ANSPDCP_(Romania)_-_Fine_against_Poliserv_JG_(PJG)_SRL*

The Romanian DPA imposed a fine of RON 15,728 (€ 3,000) on a car dealer for failing to implement appropriate technical and organisational measures in order to guarantee the security of its processing, in breach of Article 32 GDPR. English Summary. Facts. A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges. Thus, the personal data of individual customers (at least their fi

### DPC (Ireland) - IN-19-9-4

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291263 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_IN-19-9-4*

The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR.The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR. English Summary. English Summary On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the

### ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291260 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_AMATO_BESTSELLER_S.R.L.*

The DPA imposed a 54,300 fine to a controller for violations of Article 32(4), Article 14 and Article 5(1)(c) in conjunction with Article 9 GDPR and ePrivacy Directive.The DPA imposed a RON 285,395 (€54,300) fine on a wholesale company for, amongst others, failing to implement appropriate security measures, allowing former employees to access personal data as well as for unlawfully using automated dialing and communication systems to call a significant number of data subjects. English Summary. E

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

## Literature

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### Trends in Interpretation of EU Data Protection Authorities of Cybersecurity Requirements Under the GDPR

*Source: International Journal of Information Security and Cybercrime, 2022-06-28 — https://overview.legal/posts/132502 — original: https://doi.org/10.19107/ijisc.2022.01.01*

One of the main legal requirements for the adopting the GDPR was the technical and organizational security requirements, alongside the transparency and purpose limitation principles. The wide wording mentioned by the GDPR in terms of state-of-the-art security measures has given rise to a series of interpretations both in literature and by the data controllers and data processors. The manner in which national data protection authorities interpret this wording on a case-by-case basis is a good ind

### Council of Europe ∙ Convention 108+, the GDPR, and Data Processing in the National Security Domain

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132483 — original: https://doi.org/10.21552/edpl/2022/3/14*

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

## Tools

### CNIL record of processing activities template

*Source: CNIL, 2026-07-17 — https://overview.legal/posts/125621 — original: https://www.cnil.fr/en/record-processing-activities*

The French DPA's explanation of the Article 30 record-keeping obligation with a simplified downloadable register template aimed at SMEs: one sheet per processing activity covering purposes, data categories, recipients, transfers, retention and security measures.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Processing Agreement** — https://overview.legal/topics/verwerkersovereenkomst
  Contract between controller and processor defining processing terms
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data

---
Generated by overview.legal · https://overview.legal/topics/beveiliging · 2026-08-22
