# Codes of Conduct — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/codes-of-conduct
> Sources are cited per item. Verify against the official texts before relying on them.

Industry codes of conduct for data protection

## Overview

## Legal Framework

Codes of conduct under the GDPR are governed primarily by Article 40, which enables representative associations to draft codes contributing to proper application of the Regulation. While Article 40's operative text is not reproduced here, its practical force is felt through cross-references in key compliance provisions.

[Article 32(3)](/laws/gdpr/art-32#par-3) explicitly recognizes adherence to an approved code of conduct as a compliance demonstration tool:

> "Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate compliance"
> — [GDPR Art. 32(3)](/laws/gdpr/art-32#par-3)

Similarly, [Article 25(3)](/laws/gdpr/art-25#par-3) provides that an approved certification mechanism under Article 42 may demonstrate compliance with data protection by design and by default obligations. [Article 28](/laws/gdpr/art-28) requires controllers to select processors providing sufficient guarantees — a standard that industry codes can help operationalize. Article 47 governs binding corporate rules, a distinct but related instrument for international transfers.

## Key Developments

The CJEU's Schrems II judgment invalidated the EU-US Privacy Shield, reinforcing the need for robust transfer safeguards including BCRs under Article 47. The Court situated this within the broader context of escalating data collection:

> "De mate waarin persoonsgegevens worden verzameld en gedeeld, is significant gestegen."
> — [HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) ¶8](/posts/1#seg-8)

At the national level, Dutch courts have examined the binding force of industry codes. In the EVR registration case, the court analyzed the Gedragscode Behandeling Letselschadedossiers (GBL):

> "De Medische paragraaf van de gedragscode Behandeling Letselschadedossiers (GBL), waar verzekeraars aan gebonden zijn, bepaalt welke informatie aan verzekeraars moet worden verstrekt."
> — [Handhaving EVR registratie ¶3.3](/posts/50396#seg-3.3)

In a separate whistleblowing dispute, the court found that reliance on a code of conduct does not automatically create enforceable disclosure rights:

> "Daarvoor is geen grondslag te vinden in Regeling A van de Gedragscode en de Wbk"
> — [Afwijzing vorderingen ¶4.7](/posts/50482#seg-4.7)

## Status of the Debate

This topic is actively contested. Courts diverge on the legal weight of codes of conduct — whether adherence creates enforceable rights for data subjects or merely serves as a compliance indicator. The Schrems II line applies rigorous scrutiny to transfer-related safeguards under Article 47, while national courts take varying approaches to industry-specific codes under Article 40. The Dutch cases illustrate that codes may bind industry participants contractually but do not necessarily generate standalone claims for third parties. No definitive CJEU ruling on Article 40 codes specifically has yet resolved this boundary. Clarification would likely require a preliminary reference on whether code adherence creates direct enforceable rights for data subjects, or remains a compliance-demonstration tool limited to accountability under [Article 32](/laws/gdpr/art-32) and [Article 25](/laws/gdpr/art-25).

## Practical Guidance

- **Leverage codes for compliance demonstration**: Adherence to an approved code under Article 40 can evidence compliance with [Article 32](/laws/gdpr/art-32) security requirements and, through Article 42 certification, with [Article 25](/laws/gdpr/art-25) data protection by design obligations.
- **Select processors with code adherence in mind**: [Article 28](/laws/gdpr/art-28) requires processors providing sufficient guarantees — participation in a relevant industry code can serve as supporting evidence.
- **Do not treat codes as substitutes for legal obligations**: Dutch case law confirms that codes define industry practice but do not override GDPR requirements or create independent enforcement rights for third parties.
- **Document code adherence systematically**: Maintain records of which approved codes your organization follows and map specific provisions to corresponding GDPR articles to demonstrate accountability.
- **Monitor transfer-safeguard distinctions**: Given Schrems II, ensure that any code-based transfer mechanisms comply with Article 46 safeguards — codes of conduct under Article 40 alone do not constitute an adequate transfer basis.

## Legislation (full text of key provisions)

### Binding corporate rules

*Source: GDPR, gdpr-art-47-en, 2016-04-27 — https://overview.legal/posts/90900*

### Recital 104 — code of conduct consideration areas

*Source: DSA, dsa-rec-104-en, 2022-10-19 — https://overview.legal/posts/95605*

It is appropriate that this Regulation identify certain areas of consideration for such codes of conduct. In particular, risk mitigation measures concerning specific types of illegal content should be explored via self- and co-regulatory agreements. Another area for consideration is the possible negative impacts of systemic risks on society and democracy, such as disinformation or manipulative and abusive activities or any adverse effects on minors. This includes coordinated operations aimed at amplifying information, including disinformation, such as the use of bots or fake accounts for the creation of intentionally inaccurate or misleading information, sometimes with a purpose of obtaining economic gain, which are particularly harmful for vulnerable recipients of the service, such as minors. In relation to such areas, adherence to and compliance with a given code of conduct by a very large online platform or a very large online search engine may be considered as an appropriate risk mitigating measure. The refusal without proper explanations by a provider of an online platform or of an online search engine of the Commission’s invitation to participate in the application of such a code of conduct could be taken into account, where relevant, when determining whether the online platform or the online search engine has infringed the obligations laid down by this Regulation. The mere fact of participating in and implementing a given code of conduct should not in itself presume compliance with this Regulation.

### Recital 110 — binding corporate rules for group transfers

*Source: GDPR, gdpr-rec-110-en, 2016-04-27 — https://overview.legal/posts/91735*

A group of undertakings, or a group of enterprises engaged in a joint economic activity, should be able to make use of approved binding corporate rules for its international transfers from the Union to organisations within the same group of undertakings, or group of enterprises engaged in a joint economic activity, provided that such corporate rules include all essential principles and enforceable rights to ensure appropriate safeguards for transfers or categories of transfers of personal data.

### Recital 81 — processor guarantees and contract requirements

*Source: GDPR, gdpr-rec-81-en, 2016-04-27 — https://overview.legal/posts/91677*

To ensure compliance with the requirements of this Regulation in respect of the processing to be carried out by the processor on behalf of the controller, when entrusting a processor with processing activities, the controller should use only processors providing sufficient guarantees, in particular in terms of expert knowledge, reliability and resources, to implement technical and organisational measures which will meet the requirements of this Regulation, including for the security of processing. The adherence of the processor to an approved code of conduct or an approved certification mechanism may be used as an element to demonstrate compliance with the obligations of the controller. The carrying-out of processing by a processor should be governed by a contract or other legal act under Union or Member State law, binding the processor to the controller, setting out the subject-matter and duration of the processing, the nature and purposes of the processing, the type of personal data and categories of data subjects, taking into account the specific tasks and responsibilities of the processor in the context of the processing to be carried out and the risk to the rights and freedoms of the data subject. The controller and processor may choose to use an individual contract or standard contractual clauses which are adopted either directly by the Commission or by a supervisory authority in accordance with the consistency mechanism and then adopted by the Commission. After the completion of the processing on behalf of the controller, the processor should, at the choice of the controller, return or delete the personal data, unless there is a requirement to store the personal data under Union or Member State law to which the processor is subject.

### Recital 106 — codes of conduct for self-regulation

*Source: DSA, dsa-rec-106-en, 2022-10-19 — https://overview.legal/posts/95609*

The rules on codes of conduct under this Regulation could serve as a basis for already established self-regulatory efforts at Union level, including the Product Safety Pledge, the Memorandum of understanding on the sale of counterfeit goods on the internet, the Code of conduct on countering illegal hate speech online, as well as the Code of Practice on Disinformation. In particular for the latter, following the Commission’s guidance, the Code of Practice on Disinformation has been strengthened as announced in the European Democracy Action Plan.

### Recital 117 — general-purpose AI model compliance codes

*Source: AI Act, aiact-rec-117-en, 2024-06-12 — https://overview.legal/posts/93916*

The codes of practice should represent a central tool for the proper compliance with the obligations provided for under this Regulation for providers of general-purpose AI models. Providers should be able to rely on codes of practice to demonstrate compliance with the obligations. By means of implementing acts, the Commission may decide to approve a code of practice and give it a general validity within the Union, or, alternatively, to provide common rules for the implementation of the relevant obligations, if, by the time this Regulation becomes applicable, a code of practice cannot be finalised or is not deemed adequate by the AI Office. Once a harmonised standard is published and assessed as suitable to cover the relevant obligations by the AI Office, compliance with a European harmonised standard should grant providers the presumption of conformity. Providers of general-purpose AI models should furthermore be able to demonstrate compliance using alternative adequate means, if codes of practice or harmonised standards are not available, or they choose not to rely on those.

### Recital 145 — enhanced supervision of very large platforms

*Source: DSA, dsa-rec-145-en, 2022-10-19 — https://overview.legal/posts/95687*

Given the potential significant societal effects of an infringement of the additional obligations to manage systemic risks that solely apply to very large online platforms and very large online search engines and in order to address those public policy concerns, it is necessary to provide for a system of enhanced supervision of any action undertaken to effectively terminate and remedy infringements of this Regulation. Therefore, once an infringement of one of the provisions of this Regulation that solely apply to very large online platforms or very large online search engines has been ascertained and, where necessary, sanctioned, the Commission should request the provider of such platform or of such search engine to draw a detailed action plan to remedy any effect of the infringement for the future and communicate such action plan within a timeline set by the Commission, to the Digital Services Coordinators, the Commission and the Board. The Commission, taking into account the opinion of the Board, should establish whether the measures included in the action plan are sufficient to address the infringement, taking also into account whether adherence to relevant code of conduct is included among the measures proposed. The Commission should also monitor any subsequent measure taken by the provider of a very large online platform or of a very large online search engine concerned as set out in its action plan, taking into account also an independent audit of the provider. If following the implementation of the action plan the Commission still considers that the infringement has not been fully remedied, or if the action plan has not been provided or is not considered suitable, it should be able to use any investigative or enforcement powers pursuant to this Regulation, including the power to impose periodic penalty payments and initiating the procedure to disable access to the infringing service.

### Recital 87 — VLOPs VLOSEs mitigating measures for illegal content

*Source: DSA, dsa-rec-87-en, 2022-10-19 — https://overview.legal/posts/95571*

Providers of very large online platforms and of very large online search engines should consider under such mitigating measures, for example, adapting any necessary design, feature or functioning of their service, such as the online interface design. They should adapt and apply their terms and conditions, as necessary, and in accordance with the rules of this Regulation on terms and conditions. Other appropriate measures could include adapting their content moderation systems and internal processes or adapting their decision-making processes and resources, including the content moderation personnel, their training and local expertise. This concerns in particular the speed and quality of processing of notices. In this regard, for example, the Code of conduct on countering illegal hate speech online of 2016 sets a benchmark to process valid notifications for removal of illegal hate speech in less than 24 hours. Providers of very large online platforms, in particular those primarily used for the dissemination to the public of pornographic content, should diligently meet all their obligations under this Regulation in respect of illegal content constituting cyber violence, including illegal pornographic content, especially with regard to ensuring that victims can effectively exercise their rights in relation to content representing non-consensual sharing of intimate or manipulated material through the rapid processing of notices and removal of such content without undue delay. Other types of illegal content may require longer or shorter timelines for processing of notices, which will depend on the facts, circumstances and types of illegal content at hand. Those providers may also initiate or increase cooperation with trusted flaggers and organise training sessions and exchanges with trusted flagger organisations.

### Recital 93 — audit report content and transmission

*Source: DSA, dsa-rec-93-en, 2022-10-19 — https://overview.legal/posts/95583*

The audit report should be substantiated, in order to give a meaningful account of the activities undertaken and the conclusions reached. It should help inform, and where appropriate suggest improvements to the measures taken by the providers of the very large online platform and of the very large online search engine to comply with their obligations under this Regulation. The audit report should be transmitted to the Digital Services Coordinator of establishment, the Commission and the Board following the receipt of the audit report. Providers should also transmit upon completion without undue delay each of the reports on the risk assessment and the mitigation measures, as well as the audit implementation report of the provider of the very large online platform or of the very large online search engine showing how they have addressed the audit’s recommendations. The audit report should include an audit opinion based on the conclusions drawn from the audit evidence obtained. A ‘positive opinion’ should be given where all evidence shows that the provider of the very large online platform or of the very large online search engine complies with the obligations laid down by this Regulation or, where applicable, any commitments it has undertaken pursuant to a code of conduct or crisis protocol, in particular by identifying, evaluating and mitigating the systemic risks posed by its system and services. A ‘positive opinion’ should be accompanied by comments where the auditor wishes to include remarks that do not have a substantial effect on the outcome of the audit. A ‘negative opinion’ should be given where the auditor considers that the provider of the very large online platform or of the very large online search engine does not comply with this Regulation or the commitments undertaken. Where the audit opinion could not reach a conclusion for specific elements that fall within the scope of the audit, an explanation of reasons for the failure to reach such a conclusion should be included in the audit opinion. Where applicable, the report should include a description of specific elements that could not be audited, and an explanation of why these could not be audited.

### Recital 107 — online advertising codes of conduct

*Source: DSA, dsa-rec-107-en, 2022-10-19 — https://overview.legal/posts/95611*

The provision of online advertising generally involves several actors, including intermediary services that connect publishers of advertisements with advertisers. Codes of conduct should support and complement the transparency obligations relating to advertising for providers of online platforms, of very large online platforms and of very large online search engines set out in this Regulation in order to provide for flexible and effective mechanisms to facilitate and enhance the compliance with those obligations, notably as concerns the modalities of the transmission of the relevant information. This should include facilitating the transmission of the information on the advertiser who pays for the advertisement when they differ from the natural or legal person on whose behalf the advertisement is presented on the online interface of an online platform. The codes of conduct should also include measures to ensure that meaningful information about the monetisation of data is appropriately shared throughout the value chain. The involvement of a wide range of stakeholders should ensure that those codes of conduct are widely supported, technically sound, effective and offer the highest levels of user-friendliness to ensure that the transparency obligations achieve their objectives. In order to ensure the effectiveness of codes of conduct, the Commission should include evaluation mechanisms in drawing up the codes of conduct. Where appropriate, the Commission may invite the Fundamental Rights Agency or the European Data Protection Supervisor to express their opinions on the respective code of conduct.

## Case law

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)

*Source: Hof van Justitie EU, 2020-07-16 — https://overview.legal/posts/1 — original: https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62018CJ0311*

Het Hof van Justitie verklaart het Privacy Shield-akkoord ongeldig wegens onvoldoende waarborgen voor Europese burgers tegen toegang door Amerikaanse inlichtingendiensten.

### X - BA-6S/221/2019

*Source: Regional Administrative Court Bratislava, 2025-06-25 — https://overview.legal/posts/132105 — original: https://gdprhub.eu/index.php?title=X_-_BA-6S/221/2019*

Facts — Sociálna poisťovňa, the social insurance agency (the controller), processes applications for foreign invalidity pensions and forwards related documents to the social insurance institutions of other EU Member States. A data subject applied for a Danish invalidity pension. On 22 October 2018, the controller sent the data subject's sensitive personal data (including health data, personal identification number and a Danish personal identifier) to the Danish social insurance institution by ordinary (uninsured, untracked) second-class mail rather than by registered mail. The data subject could not confirm delivery and, in November 2018, filed a request with the Slovak DPA alleging that sending sensitive data by ordinary mail, without any proof of dispatch or protection against loss, violated their data protection rights. The controller resent the documents by the same method in December 2018. The DPA's first-instance decision (13 June 2019) found that the controller had violated Article 24(1) in conjunction with Article 32(1) and (2) GDPR, because sending sensitive personal data by ordinary rather than registered mail did not ensure a level of security appropriate to the risk. The DPA ordered the controller to use registered mail for such dispatches going forward and imposed a fine of €50,000. The controller's appeal was rejected, and the Slovak DPA president upheld the first-instance decision. The controller then brought an action before the Regional Administrative Court Bratislava, arguing among other things that: the parcel had in fact been delivered (as confirmed by the Danish institution by email), registered mail offers no greater protection against loss of confidentiality than ordinary mail, only one data subject was concerned and no damage had occurred and the decision's operative part improperly referred to the data of pension applicants generally, not just the individual data subject who had filed the complaint. Holding — The court did not rule on the substance of the security measures dispute, since it found the DPA's decision unreviewable on procedural grounds. First, the court held that the operative part of the DPA's decision was contradictory and imprecise. The administrative proceedings had been triggered by, and the evidence had concerned, an alleged violation of rights of one specific data subject (loss of their parcel). However, the decision extended the finding of violation to the controller's general practice of sending all pension applicants' data by ordinary mail. The court noted that a systemic pattern affecting other data subjects could, at most, be taken into account as an aggravating circumstance when setting the fine, but it could not itself form part of the sanctioned conduct in a proceeding limited to one individual's complaint. Second, the court found that the DPA had failed to properly assess evidence submitted by the controller showing that the parcel had actually been delivered to the Danish institution. The DPA only addressed this evidence for the first time in its written observations in the court proceedings, not in the administrative decision itself, even though the decision's entire reasoning rested on the (contested) premise that the parcel had been lost. Third, the court observed that the fine had been imposed under a provision of the national Data Protection Act that only permits fines for breaches of Articles 25 to 32 GDPR, whereas the DPA's decision had also relied on Article 24(1) GDPR, which is not covered by that provision. Because of these defects, the court annulled the DPA's decision and remanded the case for further proceedings, without addressing the parties' remaining arguments on the merits . The court instructed the DPA to first clearly establish the specific conduct underlying the alleged offence and then decide the case again, addressing all evidence submitted by the controller. The court awarded the controller full reimbursement of costs.

### Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t

*Source: Court of Justice of the European Union, C-169/23, 2024-11-28 — https://overview.legal/posts/132158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0169*

In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan Government Office, as controller issuing COVID-19 immunity certificates, was required to provide information to data subjects under Article 14 GDPR where the personal data was not collected directly from them. The Court held that data generated by the controller in the context of its own processes falls within the Article 14(5)(c) exemption from the obligation to provide information, provided that Member State law ensures appropriate measures to protect the data subject's legitimate interests, including data security measures under Article 32. The Court also confirmed that supervisory authorities retain competence to handle complaints under Article 77(1) even where the Article 14(5)(c) exemption applies.

### Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) –

*Source: Court of Justice of the European Union, C-492/23, 2025-12-02 — https://overview.legal/posts/132130 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0492*

In Case C-492/23, the Court of Justice of the European Union (Grand Chamber) addressed a preliminary reference from the Curtea de Apel Cluj concerning whether an online marketplace operator (Russmedia Digital SRL and Inform Media Press SRL) qualifies as a data "controller" under Article 4(7) GDPR for personal data contained in advertisements published by user advertisers. The Court examined the allocation of controller responsibility, including potential joint control with user advertisers, and analyzed whether the operator's obligations under Articles 5(2), 9, 24, 25, and 32 GDPR—including prior identification of sensitive data and advertisers, refusal of unlawful advertisements, and implementation of security measures—preclude reliance on the intermediary liability exemptions under Articles 12 to 15 of Directive 2000/31/EC (E-Commerce Directive). No fine was imposed, as the ruling is an interpretive preliminary reference rather than an enforcement action.

### Judgment of the Court (First Chamber) of 26 September 2024.#TR v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(a) and (f) – Tasks of the supervisory authority – Article 58(2) – Corrective powers – Administrative fine – Discretion of the supervisory authority – Limits.#Case C-768/21.

*Source: Court of Justice of the European Union, C-768/21, 2024-09-26 — https://overview.legal/posts/132245 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0768*

In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of the Hessischer Beauftragte für Datenschutz und Informationsfreiheit (HBDI) for declining to exercise corrective powers against Sparkasse X following a personal data breach complaint. The Court clarified the limits of supervisory authorities' discretion under GDPR Articles 57(1) and 58(2), holding that while authorities retain discretion in selecting corrective measures, they are legally obliged to exercise those powers when an infringement is established, and complainants have a right to an effective remedy under Article 77 even where no enforcement action was taken. No fine was imposed in this proceeding, as the ruling addressed the supervisory authority's enforcement obligations rather than penalizing a controller.

### VB v Natsionalna agentsia za prihodite

*Source: CJEU, C-340/21, 2023-12-14 — https://overview.legal/posts/51485 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0340*

Data breach alone does not establish inadequate security measures. Burden on controller to prove adequacy.

### Meta Platforms and Others v Bundeskartellamt

*Source: CJEU, C-601/21, 2023-07-04 — https://overview.legal/posts/51482 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0601*

Competition authorities can assess GDPR compliance in context of competition law proceedings.

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### Judgment of the Court (Third Chamber) of 11 April 2024.#GP v juris GmbH.#Request for a preliminary ruling from the Landgericht Saarbrücken.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 82 – Right to compensation for damage caused by data processing that infringes that regulation – Concept of ‘non-material damage’ – Impact of the seriousness of the damage suffered – Liability of the controlle

*Source: Court of Justice of the European Union, C-741/21, 2024-04-11 — https://overview.legal/posts/132262 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0741*

In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject GP and juris GmbH concerning GP's claim for compensation under Article 82 GDPR after the company processed his personal data for marketing purposes despite his objections. The Court held that "non-material damage" under Article 82(1) GDPR must be interpreted broadly and is not subject to a seriousness threshold, that a controller may be exempt from liability under Article 82(3) if it proves it was not in any way responsible for the infringement (including where a person acting under its authority under Article 29 was at fault), and that the criteria for administrative fines under Article 83 GDPR do not apply to the assessment of compensation amounts.

### Deutsche Wohnen SE v Staatsanwaltschaft Berlin

*Source: CJEU, C-807/21, 2023-12-05 — https://overview.legal/posts/51487 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0807*

Fines can be imposed directly on legal persons without identifying responsible natural person.

### CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is

*Source: CJEU, 2010-06-29 — https://overview.legal/posts/6182 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62008CJ0028&ref=6182*

Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69)

## Guidance

### Opinion 18/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Rubrik Group

*Source: EDPB, opinion-182026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-06-08 — https://overview.legal/posts/125673 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-182026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 18/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Rubrik Group Adopted on 08 June 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group

*Source: EDPB, opinion-192026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-06-08 — https://overview.legal/posts/125672 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-192026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group Adopted on 08 June 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 17/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Infor Group

*Source: EDPB, opinion-172026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-05-11 — https://overview.legal/posts/125676 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-172026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 17 / 2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Infor Group Adopted on 11 May 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 5/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Arcadis Group

*Source: EDPB, opinion-52026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-02-10 — https://overview.legal/posts/125691 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-52026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 5 / 2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Arcadis Group Adopted on 10 February 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of…

### Opinion 30/2025 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Illumina Group

*Source: EDPB, edpb-opinion302025-bcr-p-illumina-en, 2025-12-02 — https://overview.legal/posts/51412 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-302025-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 30 / 2025 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Illumina Group Adopted on 02 December 2025 1 | 2 | The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Opinion 25/2025 on the decision of the Polish Supervisory Authority regarding the Processor Binding Corporate Rules of the BOX Group

*Source: EDPB, opinion-252025-on-the-decision-of-the-polish-supervisory-en, 2025-10-07 — https://overview.legal/posts/125693 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-252025-on-the-decision-of-the-polish-supervisory_en*

Opinion 25/2025 on the decision of the Polish Supervisory Authority regarding the Processor Binding Corporate Rules of the BOX Group Adopted on 07 October 2025 1 | 2 | The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing…

### Opinion 24/2025 on the decision of the Polish Supervisory Authority regarding the Controller Binding Corporate Rules of the BOX Group

*Source: EDPB, opinion-242025-on-the-decision-of-the-polish-supervisory-en, 2025-10-07 — https://overview.legal/posts/125694 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-242025-on-the-decision-of-the-polish-supervisory_en*

Opinion 24/2025 on the decision of the Polish Supervisory Authority regarding the Controller Binding Corporate Rules of the BOX Group Adopted on 07 October 2025 1 | 2 | The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing…

### Opinion 12/2025 on the Proposal for a Regulation amending Regulation (EU) 2021/2115 and Regulation (EU) 2021/2116, in particular as regards data and interoperability governance

*Source: EDPS, 2025-07-09-opinion-122025-regulation-amending-regulation-eu-20212115-and-regulation-eu-20212116-part, 2025-06-06 — https://overview.legal/posts/50984 — original: https://www.edps.europa.eu/data-protection/our-work/publications/opinions/2025-07-09-opinion-122025-regulation-amending-regulation-eu-20212115-and-regulation-eu-20212116-particular-regards-data-and-interoperability-governance_en*

Adopted Opinion 12 /2025 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the ASML Group Adopted on 4 June 2025 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64(1) (f) and Article 47 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

## Enforcement decisions

### NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations

*Source: NAIH (Hungary), 2026-05-12 — https://overview.legal/posts/184727 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-450-7-2026*

Facts — The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The period under review extended from January 2020 to November 2025. During this time, the company had multiple privacy notices in force, as well as other documents that contained relevant information on the processing of personal data. Holding — The DPA found the controller guilty of multiple GDPR violations and issued it a fine of HUF 15,000,000 (€41,500). In addition, it ordered the controller to bring its processing operations in compliance with the GDPR by amending the information system used on its website, in particular the data processing provisions of the general terms and conditions and the data processing notices related to prize contests. First, the DPA held that the controller had violated the principle of transparency laid down in Article 5(1)(a) GDPR: several separate documents contained partially conflicting, irrelevant, and incomplete information regarding the processing of personal data. The information was not organised within a uniform, transparent system. Second, the DPA determined that the controller had failed to provide concise, transparent, and intelligible information regarding the purposes and the legal basis for each processing activity and therefore infringed Article 12(1) GDPR. Finally, the DPA found infringements of Articles 13(1) and 13(2) GDPR – the controller had not provided the data subjects all information necessary when personal data is collected from data subjects. In particular, the controller had failed to adequately distinguish the purposes and the legal bases for each processing operation, recipients of personal data, and retention periods. The controller’s website also contained contradictory information on whether or not personal data was transferred to the United States.

### VDAI (Lithuania) - 3R-1143

*Source: VDAI (Lithuania), 2026-06-19 — https://overview.legal/posts/53896 — original: https://gdprhub.eu/index.php?title=VDAI_(Lithuania)_-_3R-1143*

Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other personal data of patients (the data subjects). The first breach potentially concerned 63 data subjects, whereas the latter breach affected approximately 10,000 employees and 383,000 data subjects. The DPA initiated two separate investigations against the controllers in September 2024 and November 2025 respectively and later combined the cases. Holding — The DPA imposed a fine of €450,000 on the first controller it investigated as this company was also the legal successor of the other controller. It held that the controllers had failed to implement appropriate technical and organisational measures to ensure the security of processing and compliance with the principles of integrity and confidentiality. The controller had violated Articles 5(1)(f), 24(1), and 32(1)(b) GDPR. When assessing the GDPR infringements, the DPA took into account that the controllers processed sensitive categories of personal data. The DPA held the controllers lacked adequate security measures for protecting against unauthorised access to an IT system, such as access control and authentication. For instance, passwords used by employees did not reach a certain level of complexity, and multi-factor authentication was not used.

### UODO (Poland) - DKE.561.4.2026

*Source: UODO (Poland), 2026-05-22 — https://overview.legal/posts/108997 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKE.561.4.2026*

Facts — The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending beyond the boundary of their property to include public roads and the data subjects’ properties. The DPA decided that the controller had unlawfully processed data subjects’ data. The DPA held that the controller had the obligation to erase the data, and prohibited the controller from future monitoring. The DPA later requested the controller to provide evidence of compliance with the decision, but did not receive a response from the controller. The DPA received a complaint from one of the data subjects, stating that the controller continued to violate the GDPR despite the DPA’s decision. The DPA found that the controller had reinstalled the cameras and continued to cover areas outside their property, even after the cameras were removed by police officers. Holding — The DPA found a violation of Article 5(2) GDPR, as the controller had failed to demonstrate compliance with the DPA’s decision. The DPA stated that the obligation to demonstrate compliance with the principle of lawfulness (Article 5(1)(a) GDPR) extended to complying with decisions from the DPA. The DPA reiterated that the controller processed data subjects’ personal data unlawfully through their surveillance camera. The DPA took into account the small size of the local community and the number of data subjects affected, and concluded that the controller’s continuous monitoring disrupted the community’s functioning by deeply interfering with data subjects’ lives. In addition, the DPA stated that the manner in which the controller used the surveillance footage suggested that the processing purpose was to harass data subjects. The DPA fined the controller PLN 26,711 (approximately €6,174).

### AEPD (Spain) - PS/00421/2020

*Source: AEPD (Spain), 2026-07-24 — https://overview.legal/posts/158454 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00421/2020*

Facts — The client of a financial institution lodged a complaint before the Spanish DPA (AEPD) due to the delivery of a mail for commercial purposes, even though he had expressly rejected the delivery of commercial communications and promotional offers. Dispute — Are the electronic communication sent by a financial entity to its clients to be considered as necessary for contract fulfilment or do they have commercial purposes (and thus would breach the principle of Article 21(1) of the Spanish Information Society Services Act (LSSI) regarding the delivery of electronic commercial communications to data subjects without prior authorization)? Holding — The DPA rejected the argument of transaction-based customer communication and held that the mail had marketing purposes because the Controller publicizes its services, although the data subject had expressly indicated his refusal to receive advertising content. As a result, the DPA considered that the financial entity violated Article 21(1) LSSI. Furthermore, the commercial communication did not inform the recipient about his right to object to the processing of its data for marketing purposes. As a consequence, the Spanish DPA imposed a fine of €5,000.

### HDPA (Greece) 33/2020 — Employee's access and erasure claims against the American College

*Source: HDPA (Greece), 2026-07-24 — https://overview.legal/posts/158444 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_33/2020*

Facts — The data subject was under the employment of the College for a certain period of time, during which two female students of the College filed a complaint against the complainant regarding the latter's posts on social media that violated the College's Code of Conduct due to their homophobic and racist content. After this event, the College decided to move the complainant to a different position, while reacting to this situation the complainant argued that he had suffered a defamation by the College and requested the altering of the situation. The College asked the complainant to appear to the new position, something the complainant never did, but, nevertheless, the College continued paying the complainant's salary up to the ending point of their contract. Then, the data subject/complainant filed a request to the American College of Greece, asking for access to and copies of their personal data the latter is keeping in its records given the employment relationship between the two, while they specifically requested access to the two complaints made by the two students. With the same request, the data subject asked for the erasure of their personal data from the College's records, since the reason for which the data had been collected and were being kept was no longer valid, since the employment relationship between the complainant and the College had expired. In addition, with the same request, the complainant revoked their - possibly given silently - consent for the keeping and processing of their personal data by the College. The complainant claimed that there was no response from the College to their request. The HDPA requested the College's response to the situation. The latter claimed that the request under question only came into its attention via the HDPA's request for response to the claims. It justified this situation by mentioning that the employee who received the request was not in a good state of health, while the period when the request was filed was a period of heavy workload at the College. The College further underlined that, as soon as the request came to its attention, it contacted the complainant and: i) fulfilled their right to access their data by informing them for all data currently kept by the College and for providing information on how to get copies of all personal data, but not for the data referring to the personal information of one female student of the College who had filed a complaint against the data subject/complainant regarding the latter's behaviour, since the student expressed her not willingness for her name and complained to be known. The College also sent a question to the HDPA regarding the existence or not of their legal responsibility to provide access to the details of the complaint made by the student who expressed her not willingness to be known, as well as regarding the conditions under which such an access should be provided. This question, as the HDPA found, was never answered. ii) informed the complainant that the right to erasure could only be partly fulfilled, since some of the personal data being kept by the College must continue being kept due to the existence of the legal necessity for their existence, in order for the College to be able to fulfil some of its legal responsibilities, according to the provisions of Article 17(3)f GDPR, 250-253 Civil Law Code, and 95 Law 4387/2016. Moreover, the College claimed that it had the right to deny the fulfilment of the complainant's right to access and erasure, according to article 12(5)b GDPR, since the respective request has been made in a manifestly unfounded or excessive and repetitive manner. Answering to the College's claims, the complainant argued that the College is not fulfilling their rights to access and erasure, as well as that the College is not properly justifying the excessive or unfounded manner of the complainant's requests based on the said GDPR article. Additionally, the complainant argued that their right to access had never been fulfilled as their relevant request to the College was only answered by the latter with the explanation that the College had sent a question to the HDPA regarding the legality of fulfilling such a request, but with no information being provided later on by the College. Thus, the complainant underlined that, under Article 55 of Law 4629/2019, the College had the legal responsibility, as a data processor, to inform the data subject for all the data being kept and processed and to fulfil the data subject's right to access before fulfilling their right to erasure. Dispute — Whether the American College of Greece violated the complainant's right to access and erasure of their personal data? Holding — The HDPA confirmed its jurisdiction to rule on the complaint regarding a possible violation of the rights to access to and erasure of personal data, according to Articles 51,55,57,58 GDPR and Articles 9,13,15 of Law 4624/2019. On the contrary, it underlined its lack of jurisdiction to rule on the dispute of the complainant and the American College of Greece as regards the conditions of the employment relationship between them. The HDPA, after presenting the principles of data processing of Article 5(1) GDPR, underlined that, based on Article 5(2) GDPR, it is the data processor's responsibility to conform and to be able to prove their conformity with these principles at all times and by themselves (principle of accountability). Additionally, the HDPA stated that, in accordance with Article 8(1) of the Charter of Fundamental Rights of the EU, Article 9A of the Greek Constitution, and the Recital 4 of GDPR, the right to protection of personal data is not an absolute right, but a right that should be perceived always in connection to its function within society and a right that should be weighted in connection to other fundamental rights, always according to the principle of proportionality. Furthermore, the HDPA referred to Articles 12 and 15 GDPR regarding the right to access personal data, while it also underlined the restrictions to this right that Articles 23 GDPR and 33 Law 4624/2019 provide. More specifically, Article 33 mentions that the right to access cannot be fulfilled when: "1) [...] b) the data i) were recorded just because they could not have been erased due to legal provisions for the necessity of their keeping or ii) exclusively serve purposes of protection or control of data, and the provision of information would require a disproportional effort and the necessary technical and organisational measures render the processing of the data impossible for other purposes. 2) The reasons for the denial of provision of information to the data subject should be justified. The denial must be justified to the data subject, unless the provision of the real and legal reasons on which the denial is based would put the purpose of the denial into danger. [...] 4) The right to information on their data according to Article 15 GDPR does not apply, to the degree that through the provision of information other information, that according to a legal provision or to their nature, especially due to a third party's interest, must remain confidential, would be revealed. " Adding to this, the HDPA noted its past Decision 73/2010, where it judged that "the information of who is complaining against the accused constitutes an information that refers to the latter and is included in the right to access [...] . More specifically, the right to know the source of the data means that the data processor must inform the data subject of the source of the data (HDPA Decisions 4/2005, 39/2005). The HDPA has ruled that the "source" can also be a third party (natural person) (HDPA Decisions 4/2003 & 43/2003, where it is underlined that the accused has the right to access the text of the complaint and to know - when the complaint is eponymous - the name of the complainant, without the matter of whether the complainant is a third party or not being examined). After all, the knowledge of the source of the data is necessary for the data subject to be able to exercise their further rights [...]. Therefore, the HDPA underlined that the name of the female student in included in the content of the term personal data for which the data subject has the right to access, according to Article 15(1)g GDPR. Thus, the HDPA held that the College as a data controller, according to Article 4(7) GDPR, fulfilled the right to access of the complainant via the provision of copies of the data being kept. But, as concerns the non provision of the information for the complaint made by the second female student, the College violated Article 15 GDPR regarding the right to access, since it connected the provision of access to those with the consent of the female student, without examining Article 15 GDPR or Article 33 Law 2462/2019. In addition, from the merits of the case, there is no evidence for the existence of any danger faced by the female student nor is there any claim by the College or the female student for such a danger, given as well that the College did not pursue a disciplinary process against the complainant, while it also continued their salary payments even though the complainant denied to work in the new position where they were transferred. {Here there was a separate opinion of one member of the HDPA, highlighting that the text of the female student's complaint should have been provided to the complainant but with the covering of all relevant data pointing to the female student's identity.}. Additionally, the College's claim for the sickness of their employee and the work overload have no effect over the responsibility of the College to respond to the complainant's request, while there is also no effect on this responsibility from the fact that the HDPA did not answer to the College's request for its Opinion, since the HDPA did not have jurisdiction to impose to the data processor the provision to a third person of data nor had a complained been filed to the HDPA by th data subject (the female student) so as to open up the HDPA's jurisdiction (Article 5 Law 2472/1997, HDPA Opinions 4/2009, 6/2013, HDPA Decision 8/2019). Furthermore, the HDPA held that the complainant's claim that the College did not prove the unfounded or excessive character of their request is of no meaning, since the College responded to their request, even though with delay. The HDPA also held that the complainant's claim for the implementation of Article 55(5) Law 4624/2019 is unfounded, as its provisions cannot be implemented in this case. Lastly, the HDPA referred to Article 17 GDPR on the right to erasure and the restrictions of this non-absolute right provided in par.3 of the said Article and in Article 34 Law 4624/2019. Thus, the HDPA underlined that in the case under question the College as a data processor fulfilled the complainant's right to erasure. The HDPA held that there is, in this case, a legal case of exception from the right to erasure concerning the data referring to the complainant's employment relationship with the College that the latter is required to be keeping based on Article 17(3)b & e GDPR. Additionally, the HDPA held that the College has the legal right to keep the data referring to the two complaints made by the students according to Articles 17(3)e GDPR and 34(1) Law 4624/2019. Therefore, the HDPA held that the College partly fulfilled the data subject's right to access, since it did not provide information on the second female student's complaint, including her name, in violation of Articles 5,15 GDPR, 33 Law 4624/2019. Thus, the HDPA, making use of its corrective powers of Article 58(2)c GDPR, ordered the College to provide the complainant with the relevant information. Additionally, the HDPA held that the College fulfilled the right to access but in violation of the deadlines for such a fulfilment provided by Article 12(3) & (4) GDPR. For this reason, an administrative fine of 1000 EUR was imposed (83(5)b GDPR). Lastly, the HDPA held that the College fulfilled the complainant's right to erasure but in violation of the deadlines provided for such a fulfilment by Article 12(3) & (4) GDPR. For this reason, an administrative fine of 1000 EUR was imposed (Article 83(5)b GDPR).

### Italian Garante: Employer's recording of locker opening and destruction of contents

*Source: Garante per la protezione dei dati personali (Italy), 2026-06-18 — https://overview.legal/posts/184562 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_462/2026*

Facts — The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data subject learned that its working relationship with the controller would soon end. The data subject called in sick and did not show up to work again. When his contract ran out, some of his belongings were still in a locker in its workplace. Over the month of January, the data subject booked and annulled several appointments with the controller to empty his locker. In this phase, communications between the controller and the data subject were mediated by the staffing agency. Eventually, the controller opened and emptied the locker. The opening took place the day before the last planned appointment and roughly one month since the data subject had last worked for the controller. A collaborator of the controller (specifically, a member of the external security staff) recorded the opening of the locker with her personal smartphone, in order to defend the controller from possible claims over missing items. Inside the locker, the controller found some of its own products which could no longer be sold, along with personal items of intimate use which could not be preserved due to hygiene concerns. All the contents were destroyed. The data subject later learned that the controller had opened his locked and filed a complaint. He claimed that the opening of its locker constituted an unlawful processing of his personal data. In its defense, the controller protested that the content of the data subject’s locker, did not constitute personal data as defined under Article 4(1) GDPR. The controller also put forward the alternative argument that the emptying of the locker, did not fall under Article 2(1) GDPR (i.e.: it was neither an automated processing of personal data, nor a non-automated processing of personal data “which form part of a filing system or are intended to form part of a filing system”). Finally, the controller claimed that in any case, the processing would have been justified under its legitimate interest to free up the data subject’s locker and make it available to other employees. Holding — On the position of the former employer — The DPA issued a €6,600 fine over the violation of Articles 5, 6, and 13 GDPR. On the material scope of the GDPR — First, the DPA found that the personal items in the locker constituted personal data under Article 4(1) GDPR because they provided information about an identified natural person (i.e.: the data subject). Second, the DPA held that the opening of the locker, the filming of the operation, and the subsequent destruction of the employee's belongings, constituted data processing operations for the purpose of Article 4(2) GDPR. In this regard, the DPA clarified that the notion of “data processing” is to be understood broadly and that the data processing operations, listed in the Article, are mere examples. Finally, the DPA held that the notion of a “filing system” under Article 2(1) GDPR, must also be construed broadly. On these grounds, the DPA held that the case fell within the material scope of the GDPR. On lawfulness — The DPA held that legitimate interest was not a viable legal basis in the case at hand. Furthermore, the DPA held that the controller did not balance its legitimate interest correctly anyway. In this regard, the DPA observed that the reasonable expectation of data subjects are relevant to the balancing of legitimate interests. In the case at hand, the data subject had agreed to an appointment in order to empty his locker and, therefore, could not reasonably expect that the locker would be opened beforehand. On these grounds, the DPA held that the processing of personal data was unlawful. On transparency and fairness — The DPA held that the controller failed to provide workers with written information on its locker room policy. Furthermore, the DPA found that the controller failed to inform the worker about the urgency of clearing out his locker. In the DPA’s view, the controller should have communicated this urgency more clearly and should have given the data subject an ultimatum to clear his locker within a specific deadline. The DPA also found that the controller failed to inform the data subject about the opening of his locker, even after it had taken place. On these grounds, the DPA found a violation of Article 13 GDPR. The DPA also clarified that within the employment relationship the obligation to provide information to data subjects is a consequence of the general principle of fairness. On these grounds, the DPA found a violation of Article 5(1)(a) GDPR. Other findings — The DPA held that the controller processed personal data very invasively by viewing items of personal and intimate nature. On these grounds, the DPA found a violation of the principle of data minimization. On the position of the staffing agency — As explained above, the staffing agency was not directly involved in the opening of the locker but served as a messenger between the data subject and the controller, in order to help solve the locker issue. During the procedure, the staffing agency claimed that it had no role in the processing of personal data at hand, as it was not part of the employment relationship between the data subject and the controller. In this regard, the agency pointed out to a professional code of conduct for the sector. The DPA did not counter the argument and did not issue any findings with regards to the position and responsibilities of the staffing agency.

## Recent developments

### Article 40 of the GDPR (General Data Protection Regulation).

*Source: GDPRhub, 2026-01-05 — https://overview.legal/posts/51997*

Commentary: Codes of Conduct (CoCs) are voluntary instruments that establish specific data protection rules for certain categories of controllers and processors. In other words, a CoC can serve as a guide for a group of controllers and processors, outlining how a processing activity that complies with the GDPR looks in a specific processing situation. <ref>EDPB, 'Guidelines 1/2019 on Codes of Conduct and Supervisory Authorities under Regulation 2016/679', June 4, 2019 (version 2.0), footnote 7 (available at [https://www.

### Artikel 40 van de AVG (Algemene Verordening Gegevensbescherming).

*Source: GDPRhub, 2026-01-05 — https://overview.legal/posts/51680*

Commentaar: Codes van Gedrag (CoC) zijn vrijwillige instrumenten die specifieke regels voor gegevensbescherming vaststellen voor bepaalde categorieën van verantwoordelijken en verwerkers. Met andere woorden, een CoC kan een handleiding vormen voor een groep verantwoordelijken en verwerkers, waarin beschreven staat hoe een verwerking die voldoet aan de AVG er in een specifieke verwerkingssituatie uitziet. <ref>EDPB, ‘Richtlijnen 1/2019 over Codes van Gedrag en Toezichthoudende Instanties onder Verordening 2016/679’, 4 juni 2019 (versie 2.0), voetnoot 7 (beschikbaar op [https://ww

### Article 40 of the General Data Protection Regulation (GDPR).

*Source: GDPRhub, 2026-01-05 — https://overview.legal/posts/52006*

(1) Promotion of codes of conduct and supervisory authorities: * EDPB, 'Guidelines 1/2019 on codes of conduct and supervisory authorities pursuant to Regulation 2016/679', June 4, 2019 (version 2.0) (available here), and * EDPB, 'Guidelines 1/2019 on codes of conduct and supervisory authorities pursuant to Regulation 2016/679', June 4, 2019 (version 2.0) (available at [https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_201901_v2.0_codesofconduct_en.pdf here]), and * E

### Artikel 40 van de Algemene Verordening Gegevensbescherming (AVG).

*Source: GDPRhub, 2026-01-05 — https://overview.legal/posts/51687*

(1) Stimulering van gedragscodes en toezichthoudende instanties: * EDPB, 'Richtlijnen 1/2019 over gedragscodes en toezichthoudende instanties in overeenstemming met Verordening 2016/679', 4 juni 2019 (versie 2.0) (beschikbaar hier), en * EDPB, 'Richtlijnen 1/2019 over gedragscodes en toezichthoudende instanties in overeenstemming met Verordening 2016/679', 4 juni 2019 (versie 2.0) (beschikbaar [https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_201901_v2.0_codesofconduct_en.pdf hier]), en * E

### Artikel 41 van de AVG (Algemene Verordening Gegevensbescherming).

*Source: GDPRhub, 2026-01-05 — https://overview.legal/posts/51684*

(a) Aantoonbare onafhankelijkheid en expertise (a) Aantoonbare onafhankelijkheid en expertise. (a) Aantoonbare onafhankelijkheid en expertise . Het is duidelijk uit artikel 41(1) van de AVG dat de instantie een "passend niveau van expertise" moet bezitten op het gebied waar de gedragscode betrekking op heeft, met als doel een effectieve naleving te waarborgen. Dit is ook een vereiste van het proces dat is beschreven in artikel 41(2)(a) van de AVG, volgens welke de toezichthoudende instantie "kan zijn..."

## Literature

### European Union ∙ First of Many? First GDPR Transnational Code of Conduct Officially Approved After EDPB Opinions 16/2021 and 17/2021

*Source: European Data Protection Law Review, 2021-01-01 — https://overview.legal/posts/132561 — original: https://doi.org/10.21552/edpl/2021/2/12*

### GDPR codes of conduct and their (extra)territorial features: a tale of two systems

*Source: International Data Privacy Law, 2022-11-01 — https://overview.legal/posts/132559 — original: https://doi.org/10.1093/idpl/ipac018*

### Codes of (Mis)conduct? An Appraisal of Articles 40-41 GDPR in View of the 1995 Data Protection Directive and Its Shortcomings

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132558 — original: https://doi.org/10.21552/edpl/2020/2/9*

### GDPR Codes of Conduct and the Impact on Global Business: A Case Study of Amazon Web Services

*Source: SSRN Electronic Journal, 2023-01-01 — https://overview.legal/posts/132562 — original: https://doi.org/10.2139/ssrn.4505297*

### Adhering to GDPR codes of conduct: A possible option for SMEs to GDPR certification

*Source: Journal of Data Protection Privacy, 2019-07-01 — https://overview.legal/posts/132551 — original: https://doi.org/10.69554/sjri4947*

The paper shows that adherence to a code of conduct (CoC) offers small and medium enterprises (SMEs) an interesting option to a certification obtained under Article 42 of the General Data Protection Regulation (GDPR). Adhering controllers or processors benefit from similar rights to the one attached to certification without having to demonstrate conformity with the content of the CoC. Moreover, CoCs offer a set of customised guidelines, approved by a data protection authority (DPA(s)) that are a

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals

---
Generated by overview.legal · https://overview.legal/topics/codes-of-conduct · 2026-08-22
