# Retention Period — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/bewaartermijn
> Sources are cited per item. Verify against the official texts before relying on them.

The duration for which personal data may be stored

## Overview

## Legal Framework

The primary governing provision for retention periods is [Article 5(1)(e) GDPR](/laws/gdpr/art-5#par-1-pnt-e), which establishes the storage limitation principle. Personal data must be kept in a form permitting identification of data subjects only for as long as necessary for the purposes of processing. This is complemented by [Article 5(1)(c)](/laws/gdpr/art-5#par-1-pnt-c) (data minimisation), which requires that data be "adequate, relevant and limited to what is necessary," and by [Article 25(2) GDPR](/laws/gdpr/art-25#par-1), which extends data-protection-by-default to "the period of their storage."

The core requirement is purpose-bound: the retention period must be calibrated to the specific purpose for which data are processed. Once that purpose is exhausted, erasure or anonymisation must follow.

> "kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed"
> — [GDPR Art. 5(1)(e)](/laws/gdpr/art-5#par-1-pnt-e)

Article 5(1)(e) also carves out a narrow exception: longer retention is permitted solely for archiving in the public interest, scientific or historical research, or statistical purposes, provided [Article 89(1)](/laws/gdpr/art-89#par-1) safeguards apply. [Article 47(2)(d) GDPR](/laws/gdpr/art-47#par-2-pnt-d) reinforces this by requiring that binding corporate rules specify "limited storage periods."

## Key Developments

The CJEU's ruling in *Digital Rights Ireland* established that blanket retention periods — undifferentiated across data categories or user types — fail to meet proportionality requirements. The Court criticised Directive 2006/24 for imposing a minimum six-month retention period without distinguishing between categories based on usefulness.

> "Article 6 of Directive 2006/24 requires that those data be retained for a period of at least six months, without any distinction being made between the categories of data"
> — [Digital Rights Ireland, ¶63](/posts/6161#seg-63)

The Court further found that the directive failed to "ensure the irreversible destruction of the data at the end of the data retention period," underscoring that retention limits are meaningless without enforceable erasure obligations.

The Dutch Council of State (*Raad van State*) addressed retention in the context of government email preservation, holding that a municipality could safeguard a mayor's deleted emails to prevent premature destruction under the Archiefwet — illustrating how sectoral archival legislation interacts with data-protection storage limits.

The EDPB's breach notification guidelines confirm that even documentation of personal data breaches has no fixed retention period under the GDPR; controllers must self-determine an appropriate period "in accordance with the principles in relation to the processing of personal data."

## Status of the Debate

Retention period is actively contested in litigation. Courts have diverged on how to calibrate storage limits across contexts — from telecommunications metadata to government emails to breach records. The fundamental principle (purpose-bound, minimised retention) is settled, but its application to specific sectors and data categories remains in flux. No uniform court-driven threshold exists for how long particular categories of data may be kept. What would resolve the open questions is further CJEU guidance on proportionality testing for sector-specific retention mandates, particularly where national archival laws intersect with GDPR storage limitation.

## Practical Guidance

- **Define purpose-specific retention schedules.** Map each processing purpose to a maximum retention period, grounded in [Article 5(1)(e)](/laws/gdpr/art-5#par-1-pnt-e). Avoid blanket periods that fail to distinguish between data categories or user types, as criticised in *Digital Rights Ireland*.
- **Implement automated erasure or anonymisation.** Configure technical measures under [Article 25(2)](/laws/gdpr/art-25#par-1) so that default storage periods are enforced systemically, not left to ad hoc human decision-making.
- **Document the rationale for each retention period.** Record why a specific duration is necessary for the stated purpose — this is essential for demonstrating compliance and defending against regulatory challenge.
- **Ensure irreversible destruction at end of period.** As the CJEU stressed, retention limits require enforceable erasure; partial or reversible deletion is insufficient.
- **Check sectoral archival laws.** Where national legislation (e.g., the Archiefwet) mandates longer retention, confirm that the [Article 89(1)](/laws/gdpr/art-89#par-1) safeguards — particularly pseudonymisation and data minimisation — are applied to the extended retention.

## Legislation (full text of key provisions)

### Recital 69 — privacy and data protection lifecycle

*Source: AI Act, aiact-rec-69-en, 2024-06-12 — https://overview.legal/posts/93820*

The right to privacy and to protection of personal data must be guaranteed throughout the entire lifecycle of the AI system. In this regard, the principles of data minimisation and data protection by design and by default, as set out in Union data protection law, are applicable when personal data are processed. Measures taken by providers to ensure compliance with those principles may include not only anonymisation and encryption, but also the use of technology that permits algorithms to be brought to the data and allows training of AI systems without the transmission between parties or copying of the raw or structured data themselves, without prejudice to the requirements on data governance provided for in this Regulation.

### Recital 156 — safeguards for archiving research processing

*Source: GDPR, gdpr-rec-156-en, 2016-04-27 — https://overview.legal/posts/91827*

The processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be subject to appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation. Those safeguards should ensure that technical and organisational measures are in place in order to ensure, in particular, the principle of data minimisation. The further processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is to be carried out when the controller has assessed the feasibility to fulfil those purposes by processing data which do not permit or no longer permit the identification of data subjects, provided that appropriate safeguards exist (such as, for instance, pseudonymisation of the data). Member States should provide for appropriate safeguards for the processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. Member States should be authorised to provide, under specific conditions and subject to appropriate safeguards for data subjects, specifications and derogations with regard to the information requirements and rights to rectification, to erasure, to be forgotten, to restriction of processing, to data portability, and to object when processing personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. The conditions and safeguards in question may entail specific procedures for data subjects to exercise those rights if this is appropriate in the light of the purposes sought by the specific processing along with technical and organisational measures aimed at minimising the processing of personal data in pursuance of the proportionality and necessity principles. The processing of personal data for scientific purposes should also comply with other relevant legislation such as on clinical trials.

### Recital 71 — protection of minors online

*Source: DSA, dsa-rec-71-en, 2022-10-19 — https://overview.legal/posts/95539*

The protection of minors is an important policy objective of the Union. An online platform can be considered to be accessible to minors when its terms and conditions permit minors to use the service, when its service is directed at or predominantly used by minors, or where the provider is otherwise aware that some of the recipients of its service are minors, for example because it already processes personal data of the recipients of its service revealing their age for other purposes. Providers of online platforms used by minors should take appropriate and proportionate measures to protect minors, for example by designing their online interfaces or parts thereof with the highest level of privacy, safety and security for minors by default where appropriate or adopting standards for protection of minors, or participating in codes of conduct for protecting minors. They should consider best practices and available guidance, such as that provided by the communication of the Commission on A Digital Decade for children and youth: the new European strategy for a better internet for kids (BIK+). Providers of online platforms should not present advertisements based on profiling using personal data of the recipient of the service when they are aware with reasonable certainty that the recipient of the service is a minor. In accordance with Regulation (EU) 2016/679, notably the principle of data minimisation as provided for in Article 5(1), point (c), thereof, this prohibition should not lead the provider of the online platform to maintain, acquire or process more personal data than it already has in order to assess if the recipient of the service is a minor. Thus, this obligation should not incentivize providers of online platforms to collect the age of the recipient of the service prior to their use. It should be without prejudice to Union law on protection of personal data.

### Recital 94 — law enforcement biometric data processing compliance

*Source: AI Act, aiact-rec-94-en, 2024-06-12 — https://overview.legal/posts/93870*

Any processing of biometric data involved in the use of AI systems for biometric identification for the purpose of law enforcement needs to comply with Article 10 of Directive (EU) 2016/680, that allows such processing only where strictly necessary, subject to appropriate safeguards for the rights and freedoms of the data subject, and where authorised by Union or Member State law. Such use, when authorised, also needs to respect the principles laid down in Article 4 (1) of Directive (EU) 2016/680 including lawfulness, fairness and transparency, purpose limitation, accuracy and storage limitation.

### Recital 51 — Innovative technology for cybersecurity

*Source: NIS2, nis2-rec-51-en, 2022-12-14 — https://overview.legal/posts/96630*

Member States should encourage the use of any innovative technology, including artificial intelligence, the use of which could improve the detection and prevention of cyberattacks, enabling resources to be diverted towards cyberattacks more effectively. Member States should therefore encourage in their national cybersecurity strategy activities in research and development to facilitate the use of such technologies, in particular those relating to automated or semi-automated tools in cybersecurity, and, where relevant, the sharing of data needed for training users of such technology and for improving it. The use of any innovative technology, including artificial intelligence, should comply with Union data protection law, including the data protection principles of data accuracy, data minimisation, fairness and transparency, and data security, such as state-of-the-art encryption. The requirements of data protection by design and by default laid down in Regulation (EU) 2016/679 should be fully exploited.

## Case law

### Judgment of the Court (First Chamber) of 20 October 2022.#Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(b) and (e) – Principle of ‘purpose limitation’ – Principle of ‘storage limitation’ – Creation, from an existing database, of a datab

*Source: Court of Justice of the European Union, C-77/21, 2022-10-20 — https://overview.legal/posts/132306 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0077*

In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) concerning a personal data breach. The Court held that creating a new database from an existing one for testing and error-correction purposes constitutes further processing requiring compatibility assessment under the purpose limitation principle, and that the storage limitation principle applies such that data must be deleted once the testing purpose is fulfilled. No fine was imposed at the EU level, as the matter was remitted to the referring Hungarian court.

### BVerwG - 6 C 13.18

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/158441 — original: https://gdprhub.eu/index.php?title=BVerwG_-_6_C_13.18*

Facts — Since 2016, SpaceNet AG, an ISP, has been challenging a German law which provides for an obligation to store traffic and location data of all users without any reason and across the board, arguing it is incompatible with the EU Charter of Fundamental Rights. Holding — Question referred "In the light of Articles 7, 8 and 11 and Article 52(1) of the Charter of Fundamental Rights of the European Union, on the one hand, and of Article 6 of the Charter of Fundamental Rights of the European Union and Article 4 of the Treaty on European Union, on the other hand, is Article 15 of Directive 2002/58/EC to be interpreted as precluding national legislation which obliges providers of publicly available electronic communications services to retain traffic and location data of end users of those services where that obligation does not require a specific reason in terms of location, time or region, the following data are the subject of the storage obligation in the provision of publicly available telephone services — including the transmission of short messages, multimedia messages or similar messages and unanswered or unsuccessful calls: the telephone number or other identifier of the calling and called parties as well as, in the case of call switching or forwarding, of every other line involved, the date and time of the start and end of the call or — in the case of the transmission of a short message, multimedia message or similar message — the times of dispatch and receipt of the message, and an indication of the relevant time zone, information regarding the service used, if different services can be used in the context of the telephone service, and also, in the case of mobile telephone services the International Mobile Subscriber Identity of the calling and called parties, the international identifier of the calling and called terminal equipment, in the case of pre-paid services, the date and time of the initial activation of the service, and an indication of the relevant time zone, the designations of the cells that were used by the calling and called parties at the beginning of the call, in the case of internet telephone services, the Internet Protocol addresses of the calling and the called parties and allocated user IDs, the following data are the subject of the storage obligation in the provision of publicly available internet access services: the Internet Protocol address allocated to the subscriber for internet use, a unique identifier of the connection via which the internet use takes place, as well as an allocated user ID, the date and time of the start and end of the internet use at the allocated Internet Protocol address, and an indication of the relevant time zone, in the case of mobile use, the designation of the cell used at the start of the internet connection, the following data must not be stored: the content of the communication, data regarding the internet pages accessed, data from electronic mail services, data underlying links to or from specific connections of persons, authorities and organisations in social or ecclesiastical spheres, the retention period is four weeks for location data, that is to say, the designation of the cell used, and ten weeks for the other data, effective protection of retained data against risks of misuse and against any unlawful access to that data is ensured, and the retained data may be used only to prosecute particularly serious criminal offences and to prevent a specific threat to life and limb or a person’s freedom or to the continued existence of the Federal Republic or of a Federal Land, with the exception of the Internet Protocol address allocated to a subscriber for internet use, the use of which data is permissible in the context of the provision of inventory data information for the prosecution of any criminal offence, maintaining public order and security and carrying out the tasks of the intelligence services?"

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos

*Source: Court of Justice of the European Union, C-446/21, 2024-10-04 — https://overview.legal/posts/132159 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0446*

In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR Articles 5(1)(b), 5(1)(c), 6(1), and 9 concerning the lawfulness of processing user personal data for personalised advertising on online social networks. The Court addressed whether such processing can be deemed compatible with the original purpose of data collection under a platform's terms of use, the applicability of the data minimisation principle, and the conditions under which special categories of personal data, including data concerning sexual orientation made public by the data subject, may be processed. No fine was imposed, as the ruling provides interpretative guidance to the Austrian Supreme Court for resolution of the underlying dispute.

### Judgment of the Court (Third Chamber) of 2 March 2023.#Norra Stockholm Bygg AB v Per Nycander AB.#Request for a preliminary ruling from the Högsta domstolen.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 6(3) and (4) – Lawfulness of processing – Production of a document containing personal data in civil court proceedings – Article 23(1)(f) and (j) – Protection of judicial independence and judicial proceedings – Enforcement of civil law clai

*Source: Court of Justice of the European Union, C-268/21, 2023-03-02 — https://overview.legal/posts/132293 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0268*

In Case C-268/21, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Swedish Supreme Court in proceedings between Norra Stockholm Bygg AB and Per Nycander AB concerning the disclosure of an electronic staff register in civil litigation. The Court held that the production of documents containing personal data in civil court proceedings may constitute lawful processing under GDPR Article 6(3) and (4) where Member State law provides a suitable legal basis, and that such processing must comply with the data minimisation principle under Article 5, requiring a proportionate balancing of the parties' interests in judicial protection against the data subjects' rights to privacy and data protection. No fine was imposed.

### Judgment of the Court (Fifth Chamber) of 24 February 2022.#SIA 'SS' v Valsts ieņēmumu dienests.#Request for a preliminary ruling from the Administratīvā apgabaltiesa.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 2 – Scope – Article 4 – Concept of ‘processing’ – Article 5 – Principles relating to processing – Purpose limitation – Data minimisation – Article 6 – Lawfulness of processing – Proc

*Source: Court of Justice of the European Union, C-175/20, 2022-02-24 — https://overview.legal/posts/132316 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0175*

In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a request by the Latvian State Tax Authority for SIA 'SS' to disclose personal data from online vehicle sale advertisements for tax enforcement purposes. The Court held that national law may require controllers to provide personal data to tax authorities under Article 6(1)(c) and (e), provided the request complies with data minimisation and purpose limitation principles, meaning authorities must limit requests to what is necessary and proportionate for the specific tax investigation. No fine was imposed as this was a preliminary ruling proceeding.

### CE - 439360

*Source: CE, 2021-04-13 — https://overview.legal/posts/125663 — original: https://gdprhub.eu/index.php?title=CE_-_439360*

Facts — In February 2020 the French minister of the interior enacted the Decree No. 2020-151 of 20 February 2020 authorising the automated processing of personal data known as "mobile note-taking application" (Décret n° 2020-151 du 20 février 2020 portant autorisation d'un traitement automatisé de données à caractère personnel dénommé «application mobile de prise de notes» (GendNotes)). The app should be used on the occasion of preventive actions, investigations or interventions necessary for the exercise of judicial or administrative police missions. Among the data that can be collected is information relating to alleged racial or ethnic origin, political, philosophical or religious opinions, trade union membership, health or sexual activities or orientation. A group of human rights organisations filed a complaint with the French Constitutional Court. Dispute — Is the "GendNotes" App of the French national police force (Gendarmerie nationale) unlawfully processing special category personal data? Holding — The French Highest Administrative Court held that the decree infringed Article 4 of the Law of 6 January 1978, implementing GDPR in France, the Council of Europe Convention No. 108 for the Protection of Individuals with regard to Automatic Processing of Personal Data and Article 8 CFR, as it excessively infringed upon the right to respect for private life and the correlative right to protection of personal data, without providing appropriate safeguards for their protection in terms of the purpose of the processing and the nature of the data collected, as well as excessive data retention period, data sharing and data security. The Court discussed whether the decree violated Article 4 (a) GDPR, Article 4 (b) GDPR, Article 4 (c) GDPR, and Article 4 (e) GDPR and Article 9 GDPR. According to the Court, the processing of data did not comply with the principle of purpose limitation, as data is collected for future investigations or proceedings. However, the Court did not find a violation on the collect of special category data, given the fact that the decree establishes that this data can only be processed in case of "absolute necessity". Additionally, the Court noted that, even if the decree provides a limitation for the storage of the data, in practice this can be ignored, as the data may be used in different or further investigations, that would impede its erasure. However, they found that the decree was lawful in this regard, given that it clearly stated a retention period of 3 months to 1 year. Taken the above-mentioned into account, the French Highest Administrative Court decided that the data processed by the French national police force can no longer be used "in other data processing, in particular by means of a pre-information system". Therefore, the Court held: In Article 1° of the decree, the words "in other data processing, in particular by means of a pre-information system," are cancelled out. The State will pay €3,000 to every claimant. The rest of the application is rejected. The allowance to collect special category data is not overruled, as the Court argues that the decree only allows it when it is "absolutely necessary". This decision will be notified to the claimants: the Ligue des droits de l'homme, the associations Homosexualités et socialismes and Internet Society France, the associations Mousse, Stop Homophobie, Adheos and Familles A, the association AIDES, the Syndicat de la magistrature, the Syndicat des avocats de France, the Conseil national des barreaux, the Quadrature du Net and the International League against Racism and Anti-Semitism, the Prime Minister and the Minister of the Interior.

### Hoge Raad - ECLI:NL:PHR:2023:935

*Source: Supreme Court of the Netherlands, ECLI:NL:PHR:2023:935, 2023-10-20 — https://overview.legal/posts/158435 — original: https://gdprhub.eu/index.php?title=Hoge_Raad_-_ECLI:NL:PHR:2023:935*

Facts — The data subject, an asset management professional, undertook an agreement with PME Investment Services. The agreement was that the data subject would take over a housing project mediated by PME, and in return PME would be awarded a fee and a minor percentage of the subsequent sale of the apartments. However, the data subject failed to uphold the agreement. As a result, on 9 May 2018, PME filed a suit against the data subject. After a first decision, on 27 January 2021, the case was brought to the attention of the Court of Appeal of Den Haag. In those proceedings, in an attempt to avoid liability, the data subject relied on the GDPR to anonymise and redact deeds which were key to the proceedings, on the basis of Article 5(1)(c) GDPR (data minimisation). In a judgment dated 4 October 2022, the Court of Appeal of Den Haag ignored the anonymised deeds and ruled in favour of PME and made a compensation order based on calculations which did not take into account the anonymised deeds. As a result, the compensation order was significantly higher than it would have been if the anonymised deeds were taken into account. On 3 January 2023, the data subject filed an appeal against the Court of Appeal's decision to the Supreme Court of the Netherlands. Holding — The Supreme Court of the Netherlands dismissed the appeal. In their ruling, the Supreme Court clarified the relationship between the GDPR and domestic evidentiary rules in civil proceedings. The Court held that it was possible to give evidence in a manner compliant with the GDPR and confirmed the CJEU case of Norra Stockholm Bygg AB (Case C‑268/21). In that case, the CJEU held that the GDPR does not contain an absolute ban on sharing personal data in civil proceedings as that would be in conflict with the right to a fair trial in Article 6 ECHR. However, in doing so, the national court must take into account the principle of proportionality and balance the right to a fair trial and Article 5(1)(c) GDPR (data minimisation). The CJEU concluded that it is for the national courts to determine whether the provision of personal data is sufficient and pertinent to achieve the objective pursued by the applicable provisions of national law and whether that objective could not be achieved by using less intrusive evidence in order to protect the personal data of data subjects. The Supreme Court relied on the CJEU's case to determine the issue at hand and found that the plaintiff's anonymisation of the deeds were not proportionate and veered on an abuse of rights. As a result, their purported reliance on the principle of data minimisation (Article 5(1)(c) GDPR) was unfounded. The plaintiff had the opportunity to provide the relevant evidence in a GDPR-compliant manner for the calculation of compensation, and chose not to. Furthermore, the Court of Appeal had a legal basis in Dutch Law to estimate the compensation without the relevant evidence that the plaintiff decided to not provide. Accordingly, the Supreme Court dismissed the appeal.

### Judgment of the Court (Fifth Chamber) of 26 January 2023.#Criminal proceedings against V.S.#Request for a preliminary ruling from the Spetsializiran nakazatelen sad.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Directive (EU) 2016/680 – Article 4(1)(a) to (c) – Principles relating to processing of personal data – Purpose limitation – Data minimisation – Article 6(a) – Clear distinction between personal data of different categ

*Source: Court of Justice of the European Union, C-205/21, 2023-01-26 — https://overview.legal/posts/132297 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0205*

In Case C-205/21, the Court of Justice of the European Union (Fifth Chamber) issued a preliminary ruling responding to a request from the Spetsializiran nakazatelen sad (Specialised Criminal Court, Bulgaria) in criminal proceedings against V.S., who refused to consent to the collection of her biometric and genetic data by police. The Court interpreted Directive (EU) 2016/680, addressing the principles of purpose limitation and data minimisation, the lawful processing of biometric and genetic data under Member State law, the concept of "strictly necessary," and the requirement to maintain a clear distinction between personal data of different categories of data subjects in light of Articles 7, 8, 47, 48, and 52 of the EU Charter of Fundamental Rights. No fine was imposed, as the ruling solely provides interpretive guidance on the compatibility of coercive data collection from accused persons with EU data protection law.

### CJEU - C‑371/24 - Comdribus

*Source: GDPRhub, 2026-03-19 — https://overview.legal/posts/125595 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑371/24_-_Comdribus*

Facts — In 2020, law enforcement officers arrested several people from a climate protest. One of the individuals detained (the data subject) provided their identity, but refused to be fingerprinted and photographed, as well as to provide the code to their phone (or unlock it themselves). The data subject was later accused before the Paris Criminal Court of unlawfully organising a protest, as well as refusing to provide their data for identification and investigation purposes in accordance with national law . The court found them guilty of not providing their biometric data and fined the data subject €300. Both the data subject and Public Prosecutor appealed the decision to the Paris Court of Appeal. The court requested a preliminary ruling from the CJEU, regarding the compatibility of national law with provisions of the Law Enforcement Directive (LED), taking into consideration previous case law . Specifically, the court had questions regarding the systematic processing of biometric data of a data subject reasonably suspected of having committed or attempted to commit an offense in the context of an investigation, when the data subject has not necessarily been accused of committing an offense. The court referred the following questions: 1. Does the Law Enforcement Directive 2016/680 preclude national legislation from systematically processing identification data from data subjects who are suspected of having committed or attempted to commit an offense? 2. Does the Law Enforcement Directive 2016/680 require national legislation to oblige a competent authority to sufficiently explain why it is strictly necessary to process this data on an individual basis? 3. Does the Law Enforcement Directive 2016/680 preclude national legislation from allowing data subjects to be prosecuted on the basis of refusing to provide identification data, even if they are not prosecuted for or convicted of the offense under which said data was processed? The French Government argued that the national law complies with the strict necessity requirements of the LED. For example, the wording of the law leaves the competent authority the discretion to process non-sensitive data for the purposes of the investigation. In addition, national law provisions strictly limit the processing of biometric data for investigation purposes. Finally, the government questioned the admissibility of the second and third questions, arguing that both concerned matters outside the scope of EU law. Holding — Question 1: systematic collection of biometric data under national law — The court first noted that Article 10 Law Enforcement Directive 2016/680 aims to ensure a higher level of protection for personal data that is considered sensitive by nature (e.g. biometric data), as its processing can create significant risks for data subjects’ fundamental rights. Under Article 10 Law Enforcement Directive 2016/680, processing activities allowed under national law must also be strictly necessary in relation to the purposes of processing this data. This also requires the purposes to be sufficiently precise, and the processing activities to be relevant and respects the principle of data minimisation (Article 4(1)(c) Law Enforcement Directive 2016/680). Therefore, Member States must either delegate the responsibility of complying with these requirements to a competent authority, or include assessment criteria in national law for authorities to follow. In this case, the court found that national law is not compatible with the LED in terms of collecting biometric data in an indiscriminate and generalised manner. This is because it provided for the systematic collection of biometric and genetic data of any person accused of an intentional offense with the purpose of entering them in a record, without also obliging competent authorities to demonstrate first that this data processing is strictly necessary. The court stated that the scope of processing biometric data was particularly broad, as it concerned all data subjects reasonably suspected of having committed or attempted to commit a criminal offense. The court took into consideration the possible interferences with data subjects’ fundamental rights . The court concluded that it was for the referring court to determine whether national law required the police authority to carry out a systematic collection of biometric data, and to verify the data subject’s claim of an automated database containing the fingerprints of 6.5 million data subjects. Question 2: obligation of a competent authority to explain the necessity of the data processing — The court first stated that this question was admissible, as it concerned the obligations of a national competent authority in relation to EU law (Article 10 of the LED). The court then noted that the obligation to implement appropriate safeguards when processing biometric data is connected to data subjects’ fundamental right to an effective judicial remedy (Article 47 CFR). Therefore, a competent authority must provide data subjects with information on why it is “strictly necessary” to process their biometric data to allow them to exercise this right. The court stated that this information could be succinct in order to not compromise the investigation. However, the information must also be sufficiently clear. Furthermore, this obligation was essential in ensuring that a competent authority carries a case by case assessment on whether it is “strictly necessary” to process a data subject’s biometric data, as well as allowing national courts to review the competent authority’s decision. This is especially relevant in relation to the competent authority’s obligation to demonstrate compliance with Articles 4(1)(a) to (c) Law Enforcement Directive 2016/680, as it acts as a controller in accordance with Article 3(8) Law Enforcement Directive 2016/680. In any event, this judicial review cannot compensate for cases where the competent authority is not obliged to state the reasons why the data processing is strictly necessary. Finally, the court noted that this obligation is not an excessive burden for the authority, since it was clear that it may not systematically process biometric data of data subjects reasonably suspected of having committed or attempted to commit an offense. Question 3: refusal to provide biometric data as an offense — The court first stated that this question was admissible, as it was not obvious that the facts in dispute bear no relation to EU law. The court clarified that the LED was also applicable to situations in which a competent authority attempts to process personal data. Therefore, if national law imposes a criminal penalty for refusing to provide this data, this penalty is lawful if it complies with the LED (in essence, the processing must meet the conditions of strict necessity in accordance with Article 10 Law Enforcement Directive 2016/680 and Articles 4(1)(a) to (c) Law Enforcement Directive 2016/680 and 8 Law Enforcement Directive 2016/680). The court stated that the LED does not preclude national law allowing data subjects to be prosecuted on the basis of refusing to provide identification data, even if they are not prosecuted for or convicted of the offense under which said data was processed. However, national law must meet the strict necessity requirement under Article 10 Law Enforcement Directive 2016/680, and the criminal penalty must be proportionate. The court noted that fact that a data subject is reasonably suspected of committing an offense or attempted to commit an offense is not in itself decisive to determine whether the data processing is strictly necessary. In addition, the criminal penalty must be proportionate to the offense, and take into account the individual circumstances of each case. The court concluded that it was for the referring court having jurisdiction to impose a criminal penalty to take into consideration the individual circumstances of the case.

### CJEU - Case C‑5/25 - Pilev

*Source: GDPRhub, 2026-03-05 — https://overview.legal/posts/125592 — original: https://gdprhub.eu/index.php?title=CJEU_-_Case_C‑5/25_-_Pilev*

Facts — In September 2023, the Bulgarian Public Prosecutor’s Office brought a criminal case against a data subject to the Sofia City Court. According to the Prosecutor’s Office, the data subject bribed police officers, and worked as a taxi driver without the necessary license. During the proceedings, the court requested personal data from the data subject in order to verify their identity. While a data subject can be identified with their identity card, national law requires national courts to ask further questions to further verify the data subject’s identity. The court had doubts on the compatibility of said national law provisions with the Bulgarian Constitution, and stayed proceedings. In addition, the court had doubts on whether requesting additional information (e.g. place of birth, ethnicity, or marital status) is necessary, and whether the national provisions are consistent with Article 10 Law Enforcement Directive 2016/680. The court referred the matter to the Constitutional Court. The Constitutional Court refused to give a substantive ruling, and the court therefore requested a preliminary ruling from the CJEU. Advocate General Opinion — The AG first stated that the data processing fell in the scope of the LED in accordance with Article 2(1) Law Enforcement Directive 2016/680. The LED is applicable if the data processing is carried out by a competent authority (Article 3(7) Law Enforcement Directive 2016/680) and for the purposes listed in Article 1(1) Law Enforcement Directive 2016/680. The LED is the lex specialis of the GDPR, which excludes from its scope processing of personal data that falls within the scope of the LED. In the AG’s view, the court falls within the definition of a competent authority; while it may not expressly follow the definition of competent authority, it can be inferred from the provisions’ context. The AG also considered that the definition of “prosecution of criminal offenses” can be interpreted broadly, and therefore the court’s processing activities fell under the scope of the LED. This does not contradict the principle that exceptions to the GDPR (as lex generalis) should be interpreted strictly, as criminal court proceedings would not be exempt from data protection regulations. The AG also highlighted that having two different data protection laws apply at different stages of the court proceedings and by different law enforcement actors would lead to a fragmented legal regime, in contradiction to the principle of legal certainty and consistent protection of personal data. Finally, the AG noted that the LED grants law enforcement authorities more flexibility in processing data, particularly in the case of processing sensitive personal data prohibited under Article 9(1) GDPR. In terms of national law provisions, the AG opined that national law requiring the systematic processing of data subjects’ personal data when verifying their identity was not compatible with the LED, when this data is not necessary for that purpose. The purpose of verifying that a data subject is the person being indicted is a legitimate purpose. However, the AG opined that requiring courts to systematically process data such as ethnicity, marital status or previous convictions were not compatible with the principle of data minimisation (Article 4(1)(c) Law Enforcement Directive 2016/680) or lawfulness (Article 8(1) Law Enforcement Directive 2016/680). This is because this information is not necessary at the stage of proceedings of verifying the data subject’s identity. Even in cases where this information was needed, the AG noted that the systematic nature of this data processing was disproportionate. Finally, the AG highlighted that the court would systematically process special categories of personal data, which Article 10 Law Enforcement Directive 2016/680 allows only where strictly necessary. Holding — TBD.

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

## Guidance

### Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications

*Source: EDPB, edpb-guidelines-on-processing-personal-data-in-the-context-of-connected-vehicles-and-mobility-rel, 2020-01-01 — https://overview.legal/posts/38135*

The EDPB adopted Guidelines 1/2020 to provide guidance on the application of the GDPR to the processing of personal data in connected vehicles and mobility-related applications. The guidelines address key issues including data minimisation, data protection by design and by default, transparency obligations, data subjects' rights, security, third-party data sharing, and international transfers, with practical case studies covering services provided by third parties, eCall, accidentology, anti-theft measures, and rental car information. The document does not impose fines but offers recommendations to help controllers and processors in the automotive ecosystem comply with their GDPR obligations.

### Statement 2/2025 on the implementation of the PNR Directive in light of CJEU Judgment C-817/19

*Source: CJEU, edpb-statement-20250313-implementation-of-the-pnr-directive-in-light-of-the-cjeu-judgment-en, 2025-03-14 — https://overview.legal/posts/50657 — original: https://www.edpb.europa.eu/documents/statement/statement-22025-on-the-implementation-of-the-pnr-directive-in-light-of-cjeu_en*

Adopted 1 Statement 2/2025 on the implementation of the PNR Directive in light of CJEU Judgment C - 817/19 Adopted on 13 March 2025 Adopted 2 3 Final remarks ................................ ................................ ................................ ................................ . 11 Adopted 3 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPOSE OF THIS STATEMENT 1. On 21 June 2022, the Court of Justice of the European Union (CJEU) rendered…

### Statement 1/2025 on Age Assurance

*Source: EDPB, statement-12025-on-age-assurance-en, 2025-02-12 — https://overview.legal/posts/125696 — original: https://www.edpb.europa.eu/documents/statement/statement-12025-on-age-assurance_en*

1 Statement 1/2025 on Age Assurance Adopted on 11 February 2025 1 The European Data Protection Board has adopted the following statement: 1. BACKGROUND AND PURPOSE OF THIS STATEMENT 1. The European regulatory framework calls for the increased protection of children in the digital environment. For example, the Audiovisual Media Services Directive 2 , which Member States have transposed into their national laws, highlights the possibility to implement age verification measures (Articles 6a and…

### EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)

*Source: EDPB, edpb-edps-joint-opinion-22022-on-the-proposal-of-the-european-en, 2022-05-04 — https://overview.legal/posts/125945 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-22022-on-the-proposal-of-the-european_en*

1 Adopted EDPB - EDP S Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act) Adopted on 4 May 2022 2 Adopted Executive s ummary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on Data Act and urge the co - legislature to take decisive action. The EDPB and EDPS note that the Proposal would apply to a broad range of products and…

### Guidelines 02/2021 on virtual voice assistants

*Source: EDPB, edpb-guidelines-on-virtual-voice-assistants, 2021-07-07 — https://overview.legal/posts/38077 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022021-on-virtual-voice-assistants_en*

A virtual voice assistant (VVA) is a service that understands voice commands and executes them or mediates with other IT systems if needed. VVAs are currently available on most smartphones and tablets, traditional computers, and, in the latest years, even standalone devices like smart speakers. VVAs act as interface between users and their computing devices and online services such as search engines  or  online  shops.  Due  to  their  role,  VVAs  have  access  to  a  huge  amount  of  personal...

### Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications

*Source: EDPB, guidelines-012020-on-processing-personal-data-in-the-context-of-connected-en, 2021-03-09 — https://overview.legal/posts/126056 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012020-on-processing-personal-data-in-the-context-of-connected_en*

Adopted 1 Guidelines 0 1 / 2020 on processing personal data in the context of connected vehicles and mobility related applications Version 2 .0 Adopted on 9 March 2021 Adopted 2 Version h istory Version 2.0 9 March 2021 Adoption of the Guidelines after public consultation Version 1.0 2 8 January 2020 Adoption of the Guidelines for public consultation Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1 ) ( e) of the Regulation 2016/679/EU of the European…

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### Statement on the processing of personal data in the context of reopening of borders following the COVID-19 outbreak

*Source: EDPB, statement-on-the-processing-of-personal-data-in-the-context-of-reopening-of-en, 2020-06-16 — https://overview.legal/posts/126144 — original: https://www.edpb.europa.eu/documents/statement/statement-on-the-processing-of-personal-data-in-the-context-of-reopening-of_en*

1 Statement on the processing of personal data in the context of reopening of borders following the COVID - 19 outbreak Adopted on 16 June 2020 The European Data Protection Board has adopted the following statement: 1. In the Communication from the Commission on the third assessment of the application of the temporary restriction on non - essential travel to the EU from 11 June 2020, the Schengen Member States and Schengen Associated State s are invited to lift internal border controls by 15…

## Enforcement decisions

### CZECH REPUBLIC DPA: Non-compliance with general data processing principles

*Source: Czech DPA (UOOU), 2019-03-21 — https://overview.legal/posts/46133 — original: https://www.enforcementtracker.com/ETid-18*

Data was not only processed if adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ('data minimisation') and not only kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed ('storage limitation').

### Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023

*Source: Tietosuojavaltuutetun toimisto (Finland), 2026-07-22 — https://overview.legal/posts/184713 — original: https://gdprhub.eu/index.php?title=Tietosuojavaltuutetun_toimisto_(Finland)_-_TSV/4630/2023*

Facts — A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022. The data subject made an access request in November 2022 – they suspected the misuse of their personal data as they had not submitted the loan application themselves. The data subject provided their name, phone number, and email address as identifying information in connection with the access request. The controller did not provide the requested information; instead, it asked the data subject to disclose their residential address and personal identification number as well as to sign the access request electronically using strong authentication in order to verify their identity. The data subject refused to comply with this request and filed a complaint with the DPA, stating that the controller’s procedure for verifying the identity of the data subject in connection with an access request violated Articles 5(1)(c), 12(2) and (6), and 25(2) GDPR. The controller considered the additional information necessary to identify the correct individual and avoid providing the data subject’s information to an unauthorised third party. Holding — The DPA found no GDPR violation and held that the controller was entitled to request the data subject to provide additional information necessary to verify their identity pursuant to Article 12(6) GDPR. The controller’s procedure was also in line with the principle of data minimisation laid down in Article 5(1)(c) GDPR. According to the DPA, the personal data originally provided by the data subject when making the access request could not be considered sufficient identifying information since several people might have the same name and the email address and the phone number of the data subject could also be known to third parties. The DPA considered that the controller had a legitimate reason to request that the data subject provide additional information to verify their identity, as the controller processes personal data concerning the financial status of its customers.

### AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage

*Source: AEPD (Spain), 2026-07-21 — https://overview.legal/posts/144029 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00159-2025*

Facts — On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The data subject’s vehicle had allegedly been damaged while parked in a facility operated by the controller. On 23 February 2024, the data subject’s legal representative requested access to the footage recorded between 12 and 19 February 2024. The request sought the images showing the collision or, alternatively, the licence plate of the vehicle responsible. The data subject also expressly requested that the controller preserve the relevant footage because it was required for the establishment, exercise or defence of legal claims. The controller acknowledged receipt of the request but did not provide a substantive response until 4 April 2024, after the one-month period under the GDPR had expired. It stated that the footage could only be disclosed to the police or a judge and instructed the data subject to file a police report. After the data subject challenged that requirement and reiterated both the access and preservation requests, the controller responded that it would not provide the recordings and that the footage had already been deleted. During the proceedings, the controller argued that the request was excessive because it covered footage from 16 cameras over several days, amounting to approximately 3,072 hours of recordings. It also maintained that the footage contained personal data relating to numerous third parties and that it was not established that the damage had occurred inside the car park. The controller acknowledged, however, that it had not explained these considerations to the data subject, asked the data subject to narrow the request or notified an extension of the response period. Holding — The DPA held that the controller infringed Articles 15 and 18 GDPR. Regarding Article 15 GDPR, the DPA found that the controller failed to respond to the access request within the one-month period required under Article 12(3) GDPR. Although the controller considered the request complex and excessive, it neither informed the data subject of an extension within the initial one-month period nor explained why it considered the request excessive. The DPA noted that the controller could have asked the data subject to provide additional information to narrow the search. It could also have reviewed the recordings and provided only the footage necessary for the specific incident, applying measures such as blurring or limiting the disclosed extract to protect third parties. The DPA rejected the controller’s position that the footage could only be provided following a request from the police or a court. The exercise of the right of access was not conditional on the prior filing of a police report. The controller was required to assess the request under the GDPR and provide a reasoned and timely response. The failure to respond in time resulted in the deletion of the requested footage. Consequently, the data subject was prevented from obtaining information that could have been relevant to identifying the person responsible for the damage and pursuing a legal claim. Regarding Article 18 GDPR, the DPA held that the data subject had expressly requested the preservation of the recordings for the establishment, exercise or defence of legal claims. Under Article 18(1)(c) GDPR, processing must be restricted where the controller no longer needs the data for its original purposes but the data subject requires it for legal claims. The controller did not address this request and deleted the footage under its ordinary retention schedule. The DPA considered that Article 22(3) Spanish Data Protection Act (LOPDGDD), which generally requires video surveillance images to be erased within one month, did not justify disregarding a valid restriction request. Once the data subject requested preservation for potential legal proceedings, the controller was required to retain the relevant images rather than erase them. The DPA also linked the preservation of the evidence to the data subject’s right to effective judicial protection under Article 24(1) of the Spanish Constitution. Deleting the footage made it more difficult for the data subject to identify the responsible party and exercise their rights before a court. The DPA initially imposed two fines of €75,000: one for the infringement of Article 15 GDPR and one for the infringement of Article 18 GDPR, amounting to €150,000 in total. The controller acknowledged liability and voluntarily paid the fine. Under Article 85 of Spanish Administrative (Law 39/2015), it received a 20% reduction for acknowledging liability and a further 20% reduction for voluntary payment. Consequently, the initial fine of €150,000 was reduced by 40% to a final amount of €90,000. The DPA also ordered the controller to adopt the compliance measures specified in the decision initiating the proceedings and to report their implementation to the DPA within three months after the decision became final and enforceable.

### Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-03 — https://overview.legal/posts/184565 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_484/2026*

Facts — EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller assessed the creditworthiness of potential customers through an internal and an external credit check. The internal assessment involved verifying whether potential customers had outstanding debts not only with the controller but also with Hera Comm S.p.A (hereinafter, the corporate group). The assessment was conducted on behalf of the controller by Hera S.p.A. (hereinafter, the processor), which returned an “OK” or “KO” result. Where the internal assessment returned an “OK”, the controller conducted an external assessment using credit information supplied by Experian Italia S.p.A. and commercial information provided by Cerved Group S.p.A. This information was combined using the “CGS-X” software provided by Major 1 S.r.l. (hereinafter, the software provider and processor). The software generated an integrated creditworthiness score and several underlying sub-scores. On the basis of the result, the controller could refuse to enter into an energy supply contract. The DPA received several complaints from data subjects whose requests for energy supply had been rejected on the basis of their risk profiles. However, when the data subjects contacted the credit and commercial information providers, they were informed that the relevant databases did not contain negative information or adverse events concerning them. The data subjects also submitted access requests under Article 15 GDPR. Although the controller responded within the applicable time limits, it did not provide the CGS-X score, the underlying sub-scores or meaningful information about the logic and criteria used to calculate the profiles. Instead, the controller referred the data subjects to the credit and commercial information providers. Following the complaints, the DPA consolidated the proceedings and initiated an ex officio investigation. It conducted inspections at the premises of the processor, the software provider and processor, and the credit and commercial information providers. The investigation also established that the controller retained the information obtained through the credit checks. Through the processor, the controller subsequently analysed this information to potentially refine the corporate group’s customer rating system. Between 2022 and March 2024, this processing concerned more than one million data subjects. Holding — The DPA held that the controller’s creditworthiness assessment infringed Articles 5(1)(a), (b), (d) and (e), 12, 13, 14, 15 and 28 GDPR. First, the controller failed to provide transparent information about the internal assessment of customers’ previous debts and the sharing of such information within the corporate group. The instructions given to the processor also did not adequately cover these processing operations. The DPA therefore found violations of Articles 5(1)(a), 13, 14 and 28 GDPR. Second, the controller provided incomplete responses to access requests. It did not disclose the CGS-X score, the underlying sub-scores or meaningful information on the logic and criteria used to generate the creditworthiness profile. Referring the data subjects to the credit and commercial information providers did not discharge the controller’s obligations under Articles 12 and 15 GDPR. Third, the controller had not established a justified retention period for the data collected during the external assessment. Applying a general ten-year retention period for accounting records was not shown to be necessary for the creditworthiness assessment, in violation of Article 5(1)(e) GDPR. The DPA also found that reusing credit and commercial information to refine the corporate group’s rating system was incompatible with the original purpose for which the data had been collected. Since the retained information could become outdated, this processing also violated the purpose limitation and accuracy principles under Articles 5(1)(b) and (d) GDPR. The DPA ordered the controller to adopt a compliant access-response template, provide the relevant information to the data subjects involved and establish procedures enabling rectification, human intervention and the possibility to challenge decisions. The controller had six months to demonstrate compliance. Finally, the DPA imposed a €1,400,000 fine, taking into account the seriousness and scale of the infringements, the impact on approximately one million data subjects and the risk of refusal of essential energy services. It also considered the controller’s cooperation, lack of previous relevant infringements and remedial measures as mitigating factors.

### Garante per la protezione dei dati personali (Italy) - 9794895

*Source: Garante per la protezione dei dati personali (Italy), 2022-06-09 — https://overview.legal/posts/6314 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9794895*

Facts — The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the Municipality had breached their data protection right of fair, transparent and lawful processing under art. 5(1)(a) as the sign signaling the CCTV monitoring referred to an outdated legislative decree. They also alleged a breach of art. 5(1)(e) and art. 13 GDPR, in so far the municipality never defined a data retention period for each processing purpose pursued. The last complaint moved forward by the data subject was that by being legally represented in Court by the same lawyer, who also acted as DPO of Policoro, the Municipality gave rise to a conflict of interest situation and breached art. 38(6) GDPR. The Municipality argued that the claim had been done in front of the Justice of Peace, who had no competency to decide on issues of privacy. It was also alleged the judgement only pertained an administrative matter, without rising any data protection concerns or a situation of conflict of interest with the Municipality's DPO. The last argument alleged the processing and retention of the CCTV footage was related to illegal dumps within the municipal territory, meaning the filming had been carried out in the course of judicial police investigations and the data retention periods of the GDPR did not apply in this case. Holding — The Italian DPA held that in this case the Municipality was carrying activities of data processing, by surveilling public entities by means of surveillance cameras. It also noted, that in par. 41 of the Guidelines 3/2019 on the Processing of Personal Data by Video Devices, waste management is "among the institutional activities entrusted to local authorities". This means the surveillance done by the Municipality of Policoro, a task carried out in the public interest in connection with the exercise of official authority as per art.6(1)(e) GDPR, was unrelated to public security and/or judicial police and obliging the controller to comply with data protection principles. The DPA found that the information provided in regards to the processing of personal data by means of surveillance cameras, did not meet the requirements of conciseness, transparency, intelligibility and easy readability contained in art. 5(1)(a) GDPR. The Municipality of Policoro had failed to provide suitable first-level information to the data subject, in so far the sign signaling the CCTV surveillance made reference to an outdated legislative decree (d.lgs 196/03) instead of the one currently in force (d.lgs 101/18). Furthermore, the data controller failed to provide the data subject with an adequate notice on second-level processing of their data. The signage did not include information on the most suitable impacts of the processing or an indication of a website, where to consult an extended version of the explanation. The DPA also found a violation of art. 13 GDPR as well as the principles of storage limitation and accountability in art. 5(1)(e) and art. 5(2). It stated that "the longer the intended storage period (especially if longer than 72 hours), the more reasoned the analysis referring to the legitimacy of the purpose and necessity of storage must be". In this case, the data controller not only failed to set a maximum retention period for the images taken for the purpose of combating illegal littering, but also established the administrative fines for the violation two months after the images were recorded. This did not allow for the data controller to respect the principle of accountability. Lastly, the DPA addressed the alleged conflict of interest raised by the involvement of the Policoro's DPO in the legal proceedings brought against the data subject. The DPA ruled DPOs "may perform other duties and functions," with the understanding that "the controller must ensure that such duties and functions do not give rise to a conflict of interest." The DPA also made reference to the Article 29 WP's Guidelines on Data Protection Officers, in which it is urged to not designate DPOs already acting as defense counsel for the same court. In the case at hand, it resulted that the DPO shared with the Municipality an interest in obtaining a rejection of the appeal. Consequently, the Italian Garante held this to be in violation of art. 38(6) GDPR, as well the fact that it undermined the DPO's independence. The Italian DPA held a cumulative breach of art. 5(1)(a) and (e) and (2) (in conjunction with article 24), 12, 13 and 38(6) GDPR. It balanced the fact that the personal data processing affected all other citizens, who passed through the areas under surveillance, against the lack of previous violations committed by the data controller. The DPA issued a fine of €26,000 EUR to the Municipality of Policoro.

### AEPD fines El Español for disclosing minor's identity in assault video

*Source: AEPD (Spain), 2026-07-27 — https://overview.legal/posts/184546 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00304-2024*

Facts — El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video showing both the victim and the assailant, who was a minor. Their image and voice were disclosed without applying techniques to prevent their direct or indirect identification. The controller also published the video through its accounts on two social media platforms. The DPA initiated preliminary investigations ex officio after becoming aware of the dissemination of the video. It ordered the controller, as a precautionary measure, to immediately remove the content from the relevant URLs. The controller subsequently informed the DPA that it had removed the article and prevented access through both external links and its internal search engine. The DPA verified that the video was no longer available through the identified web addresses. The DPA subsequently initiated disciplinary proceedings for a potential infringement of Article 5(1)(c) GDPR. The controller argued that the incident was newsworthy, the video had already gone viral and the publication was protected by freedom of information. It also claimed that the video was necessary to understand the news and that the assailant’s status as a minor should be assessed in light of his apparent maturity and awareness that he was being recorded. Holding — The DPA found that the controller violated the data minimisation principle under Article 5(1)(c) GDPR. The DPA clarified that the proceedings did not concern whether the incident was newsworthy or whether the controller could report on it. Instead, the relevant question was whether publishing the identifiable image and voice of the individuals was necessary and proportionate for that purpose. According to the DPA, freedom of information and the right to data protection are not absolute. Under Article 85 GDPR, they must be reconciled on a case-by-case basis. In this case, the controller could have informed the public about the incident while using technical measures, such as blurring the individuals’ faces or altering the audio, to prevent their identification. Showing the individuals in an identifiable manner was therefore not necessary to achieve the journalistic purpose. The DPA also rejected the argument that the previous virality of the video justified its republication. Each additional publication contributed to the further dissemination of the personal data and amplified the risks and adverse effects for the data subjects. Similarly, the fact that the affected individuals had not submitted a complaint did not prevent the DPA from exercising its supervisory powers ex officio. The DPA gave particular weight to the vulnerability of the victim and to the fact that the assailant was a minor. It held that the best interests and enhanced protection of minors had to be taken into account irrespective of the minor’s alleged maturity or awareness of being recorded. The age at which a minor may consent under Article 7 LOPDGDD did not reduce the controller’s obligation to assess whether the disclosure was necessary. The DPA further noted that, pursuant to Articles 5(2) and 25 GDPR, the controller was required to assess and document the risks of the processing and implement data protection by design and by default. As a professional media organisation regularly processing personal data, the controller was expected to apply a particularly high standard of diligence and to consider less intrusive methods of publication. When determining the sanction, the DPA considered the unrestricted online dissemination of the data, the potentially unlimited audience, the controller’s negligence, the sensitive circumstances surrounding the victim and the minor, and the impact of the infringement on the rights of a minor. It therefore imposed a €20,000 fine. Under Article 58(2)(d) GDPR, the DPA also ordered the controller to demonstrate, within three months after the decision became enforceable, that it had adopted measures to prevent the excessive publication or dissemination of personal data, particularly data concerning minors. It made the earlier precautionary measure definitive and required the permanent removal of the content, while allowing its restricted preservation where necessary as evidence for administrative, police or judicial proceedings.

### Italian Garante: OPI of Pisa must remove residential addresses from public register

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-16 — https://overview.legal/posts/122839 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10192784*

Facts — The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the residential address, information not necessary for the purposes of the Register [Note: the OPI is a governance body for registered nurses]. The OPI (the controller), when asked by the DPA to provide further clarification, initially stated that, in accordance with the applicable local regulation (DPR 221/1950), the public register included residential addresses to provide employers with accurate information and to avoid identity confusion in cases of identical names. During the investigation, the National Federation of Nursing Professional Orders (the “Federation”), the representative body entrusted with functions of guidance, coordination and administrative support to the territorial Orders, indicated that the residential address was not required for the functioning or the purpose of the register, expressly referring to Article 6(3) GDPR to confirm that no legal provision required the publication of such data. The controller subsequently revised its position, explaining that it routinely maintained two databases: a complete version and a reduced one containing only minimal information. The publication in which the residential address of a single data subject appeared resulted from an employee’s mistake during the update following a meeting of the Directive Council. Holding — The DPA upheld the complaint and found violations of Article 5(1)(a) GDPR, Article 6(1)(e) GDPR, Article 6(2) GDPR and Article 6(3) GDPR. The publication, through the internet, of personal data that exceeds the main purpose of the professional public registry, without a proper legal basis, breached the Article 6(1). The DPA rejected the controller’s argument that the disclosure resulted merely from an employee’s mistake, noting that the controller did not act promptly to prevent continued access through search engine caching and that such circumstances could not justify the unlawful disclosure. It also clarified that the version of the Register published online contained the residential addresses of all registered professionals, not only that of the complainant, as later confirmed by the DPA. It was mandatory for the the controller to comply with the principles governing data protection, including the principles of lawfulness, fairness and transparency, as well as data minimisation. In accordance with this principles, the data processing should had been processed lawfully, fairly and in a transparent manner in relation to the data subject, and adequate, relevant and limited to what was strictly necessary in relation to the purposes. Following this, the DPA imposed a €16,000 fine. In defining the amount, the DPA took into account that the violation was produced due to the negligence of the Controller (art. 83, par. 2, lett. b.) and its lack of cooperation.

### Italian DPA: Vasto municipality breached transparency duties over traffic cameras

*Source: Garante per la protezione dei dati personali (Italy), 2026-06-18 — https://overview.legal/posts/144036 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_457/2026*

Facts — The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A data subject filed a complaint against the controller after being fined for running a red light. The data subject argued that there were no signs or warnings near the cameras installed to detect violations, and that the controller did not obscure the windows to make data subjects unrecognisable. The controller argued that it provided warning signs of the presence of cameras. In addition, the cameras only capture data subjects’ license plates to comply with the principle of data minimisation (Article 5(1)(c) GDPR), and that the case of the data subject was a technical error. Holding — The DPA first noted that, in principle, a public entity can process this data if it is necessary to fulfil a legal obligation or for the public interest (Article 6(1)(c) and (e) GDPR). However, the controller still has the obligation to provide information to data subjects regarding the processing, in accordance with the principle of transparency (Article 5(1)(a) GDPR). The DPA found that, at the time of the complaint, the controller had not included any information near the cameras. In addition, the first level privacy policy did not comply with the requirements of Article 13 GDPR and were not provided in concise and transparent manner. Therefore, the DPA found a violation of Articles 5(1)(a), 12(1) and 13 GDPR. The DPA also found a violation of Article 5(1)(c) GDPR, as the controller failed to comply with the principle of data minimisation. The DPA stated that the controller had failed to ensure that the cameras only captured the vehicles’ license plates, and had therefore processed more data than necessary. Finally, the DPA found a violation of Article 35 GDPR, as the controller had prepared a data protection impact assessment (DPIA) only after the processing activities began. The DPA noted that the DPIA was also not specific enough. The DPA fined the controller €5,000. In addition, the DPA ordered the controller to adopt appropriate measures to provide data subjects with adequate information and update its DPIA.

## Recent developments

### Garante per la protezione dei dati personali (Italy) - 10273026

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291265 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10273026*

The DPA held that the dissemination of images of a body and the crime scene as part of the reporting on a murder case violated Article 5(1)(c) GDPR and the parents of the deceased were able to lodge a complaint on behalf of the deceased.The DPA held that the dissemination of images of a body and the crime scene as part of the reporting on a murder case violated the principle of data minimisation and the parents of the deceased, in accordance with national law, were able to lodge a complaint on b

### AG at CJEU: Facebook must "minimize" personal data for ads in EU

*Source: noyb - European Center for Digital Rights, 2024-04-25 — https://overview.legal/posts/53196 — original: https://noyb.eu/en/ag-cjeu-facebook-must-minimize-personal-data-ads-eu*

Online Advertising CJEU press releases (look for C-446/21 - Schrems)Full AG OpinionKatharina Raabe-Stuppnig, lawyer representing Mr Schrems: "We are very pleased by the opinion, even though this result was very much expected."Use of data for advertising must be limited by time, type and source. So far, Meta uses all the data it has ever collected for advertising. For example, Facebook user data can go back as far as 2004. To prevent such practices, the GDPR established the principle of "data min

### CJEU clarifies GDPR principles of purpose limitation and storage limitation

*Source: NL EU Court Expert, 2022-10-30 — https://overview.legal/posts/6247 — original: https://ecer.minbuza.nl/-/eu-hof-verduidelijkt-de-beginselen-van-doelbinding-en-opslagbeperking-uit-de-avg?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-1209*

The purpose limitation principle does not preclude a controller from capturing and storing in a test database established for testing and error correction purposes personal data previously collected and stored in another database. However, such "further processing" of personal data must be compatible with the specific purposes for which the personal data were originally collected. The principle of storage limitation precludes the retention of personal data in that test database for longer than n

### Collection and retention, by the French blood donation service (EFS), of personal data reflecting applicant’s presumed sexual orientation without proven factual basis: violation of Article 8 of the Convention

*Source: ECHR, 2022-09-08 — https://overview.legal/posts/6283 — original: https://hudoc.echr.coe.int/eng-press#entry-367*

In today’s Chamber judgment1 in the case of Drelon v. France (application no. 3153/16) the
European Court of Human Rights held, unanimously, that there had been:
a violation of Article 8 (right to respect for private and family life) of the European Convention on
Human Rights.

The applications concerned, first, the collection and retention, by the French blood donation service
(EFS) of personal data reflecting the applicant’s presumed sexual orientation – together with the
rejection of his criminal complaint for discrimination – and, second, the refusal of his offers to
donate blood, together with the dismissal by the Conseil d’État of his judicial review application
challenging an order of 5 April 2016 which amended the selection criteria for blood donors.
Addressing the first application, the Court found that the collection and retention of sensitive
personal data constituted an interference with the applicant’s right to respect for his private life.
That interference had a foreseeable legal basis as the authorities’ discretionary power to set up a
health database for such purpose was sufficiently regulated by the then applicable Law of 6 January
1978. Whilst the collection and

### CJEU: PNR Directive Valid if Limited to the “Strictly Necessary”

*Source: eucrim, 2022-08-04 — https://overview.legal/posts/6292 — original: https://eucrim.eu/news/cjeu-pnr-directive-valid-if-limited-to-the-strictly-necessary/#entry-388*

> In a landmark ruling of 21 June 2022, the CJEU (Grand Chamber), upheld the EU’s regime to collect and use records of travellers, provided that it is strictly interpreted in line with the EU’s fundamental rights. In addition, indiscriminate processing of the data in cases of flights carried out only within the EU is banned unless there is a threat of terrorism. In general, the passengers’ data must also be deleted after six months at the latest.

## Literature

### Automating the Design and Development of Usable, GDPR-Aware Web Forms

*Source: SN Computer Science, 2026-07-14 — https://overview.legal/posts/132119 — original: https://doi.org/10.1007/s42979-026-05219-7*

Abstract Personal data collection in web applications should follow mandated legislative frameworks such as the EU General Data Protection Regulation (GDPR) principles. Among others, web data collection forms should provide clear and transparent explanations regarding the purposes of the collection. At the same time, for users’ ease, such forms should follow standard usability principles. There have been works studying the merging of usability principles and privacy standards. Building on this l

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU

*Source: Unio - EU Law Journal, 2025-06-18 — https://overview.legal/posts/53865 — original: https://doi.org/10.21814/unio.11.1.6632*

The Mousse ruling represents a pivotal moment in EU data protection law, reinforcing strict limitations on personal data processing and clarifying the legal standards under the General Data Protection Regulation (GDPR). The Court of Justice of the European Union (CJEU) reaffirmed that data collection must be objectively indispensable for a specified legal basis, rejecting broad interpretations of contractual necessity and legitimate interest. Additionally, the ruling confirms that the right to o

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

### The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how

*Source: Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza, 2023-12-30 — https://overview.legal/posts/132546 — original: https://doi.org/10.14746/ppuam.2023.15.09*

The data subject’s right to access information on data processing has a very broad meaning. Considering the latest developments in this field (mainly the CJEU ruling on Austrian posts and EDPB guidelines) one can draw the conclusion that the controller’s right to protect its confidential in-formation is limited and less valuable than the data subject’s rights. However, this may lead to unfair and unequal treatment of companies and data subjects. When looking at this right in a more systematic pe

## Tools

### CNIL GDPR guide for developers

*Source: CNIL, 2026-07-04 — https://overview.legal/posts/53810 — original: https://github.com/LINCnil/GDPR-Developer-Guide*

Open-source best-practice guide by the French DPA translating GDPR obligations into concrete development practice: data minimisation in code, managing consent, securing data flows, retention, and preparing for data subject rights — organised in 16 practical sheets.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Storage Limitation** — https://overview.legal/topics/storage-limitation
  Principle that data should not be kept longer than necessary
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers

---
Generated by overview.legal · https://overview.legal/topics/bewaartermijn · 2026-08-22
