# Data Portability — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/dataportabiliteit
> Sources are cited per item. Verify against the official texts before relying on them.

Right to receive and transfer personal data in structured, machine-readable format

## Overview

## Legal Framework

Article 20 GDPR establishes the right to data portability, entitling data subjects to receive their personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller. This right applies cumulatively where two conditions are met: the processing must be based on consent under Article 6(1)(a) or Article 9(2)(a), or on a contract under Article 6(1)(b); and the processing must be carried out by automated means. The data subject may also request direct transmission of personal data from one controller to another where technically feasible.

The rationale is to strengthen user control over personal data and reduce lock-in effects, enabling individuals to switch service providers without losing their data history. The right covers only personal data provided by the data subject, including data generated by their activity (such as usage logs or sensor data), but not data derived through inference or profiling that goes beyond what the subject directly supplied.

Recital 73 confirms that Union or Member State law may impose restrictions on the portability right where necessary and proportionate in a democratic society to safeguard public security, prevention of crime, or other legitimate public interests. The Digital Services Act reinforces the broader machine-readable transparency ethos by requiring annual content moderation reports in machine-readable format from intermediary service providers, reflecting a regulatory trend toward standardized data exportability.

## Key Developments

The Court of Justice's reasoning in *Schrems* (C-362/14) and *Schecke* (C-92/09 and C-93/09, 9 November 2010) clarified the boundaries of consent-based processing, which is directly relevant because portability under Article 20 is contingent on consent or contractual necessity as the lawful basis. In *Schecke*, the Court distinguished mandatory statutory processing from genuine consent, establishing that merely informing data subjects does not equate to consent. Controllers relying on Article 6(1)(a) as the basis for portability must therefore ensure consent is freely given, specific, informed, and unambiguous.

Enforcement actions illustrate the financial exposure when portability obligations are violated alongside other GDPR requirements. The Croatian DPA (AZOP) imposed a €4.5 million fine on a telecommunications operator for multiple GDPR infringements, a sector where portability requests are frequent given the volume of user-generated data. The Italian Garante fined the Migliarino San Rossore Massaciuccoli Regional Park Authority €8,000, demonstrating that public-sector bodies are equally subject to data subject rights enforcement.

The EDPB's Guidelines 1/2020 on connected vehicles highlight that portability must be considered in IoT contexts, where vehicle-generated data constitutes personal data provided by the user through their driving behavior and vehicle interactions.

## Practical Guidance

- **Verify the lawful basis before responding.** Confirm that processing relies on Article 6(1)(a), 6(1)(b), or Article 9(2)(a). If processing is based on legitimate interests or legal obligation, portability does not apply.

- **Define the scope of "provided data" carefully.** Include data actively supplied by the user and data generated through observed activity, but exclude inferred or derived data such as risk scores or internal analytics that go beyond what the subject provided.

- **Implement automated export in standard formats.** Provide data in commonly used, structured, machine-readable formats such as JSON, CSV, or XML. Manual compilation on a case-by-case basis risks non-compliance and operational inefficiency.

- **Assess technical feasibility for direct transmission.** Where a data subject requests direct controller-to-controller transfer, document the technical assessment. If direct transmission is not feasible, provide the data to the subject and explain the limitation.

- **Establish a portability request workflow.** Integrate portability handling into existing subject rights processes, ensuring responses within one month under Article 12(3), with clear escalation procedures for complex or voluminous requests.

## Legislation (full text of key provisions)

### Right to data portability

*Source: GDPR, gdpr-art-20-en, 2016-04-27 — https://overview.legal/posts/90459*

### Recital 68 — data subject data portability right

*Source: GDPR, gdpr-rec-68-en, 2016-04-27 — https://overview.legal/posts/91651*

To further strengthen the control over his or her own data, where the processing of personal data is carried out by automated means, the data subject should also be allowed to receive personal data concerning him or her which he or she has provided to a controller in a structured, commonly used, machine-readable and interoperable format, and to transmit it to another controller. Data controllers should be encouraged to develop interoperable formats that enable data portability. That right should apply where the data subject provided the personal data on the basis of his or her consent or the processing is necessary for the performance of a contract. It should not apply where processing is based on a legal ground other than consent or contract. By its very nature, that right should not be exercised against controllers processing personal data in the exercise of their public duties. It should therefore not apply where the processing of the personal data is necessary for compliance with a legal obligation to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of an official authority vested in the controller. The data subject's right to transmit or receive personal data concerning him or her should not create an obligation for the controllers to adopt or maintain processing systems which are technically compatible. Where, in a certain set of personal data, more than one data subject is concerned, the right to receive the personal data should be without prejudice to the rights and freedoms of other data subjects in accordance with this Regulation. Furthermore, that right should not prejudice the right of the data subject to obtain the erasure of personal data and the limitations of that right as set out in this Regulation and should, in particular, not imply the erasure of personal data concerning the data subject which have been provided by him or her for the performance of a contract to the extent that and for as long as the personal data are necessary for the performance of that contract. Where technically feasible, the data subject should have the right to have the personal data transmitted directly from one controller to another.

### Recital 73 — lawful restrictions on data subject rights

*Source: GDPR, gdpr-rec-73-en, 2016-04-27 — https://overview.legal/posts/91661*

Restrictions concerning specific principles and the rights of information, access to and rectification or erasure of personal data, the right to data portability, the right to object, decisions based on profiling, as well as the communication of a personal data breach to a data subject and certain related obligations of the controllers may be imposed by Union or Member State law, as far as necessary and proportionate in a democratic society to safeguard public security, including the protection of human life especially in response to natural or manmade disasters, the prevention, investigation and prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, or of breaches of ethics for regulated professions, other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, the keeping of public registers kept for reasons of general public interest, further processing of archived personal data to provide specific information related to the political behaviour under former totalitarian state regimes or the protection of the data subject or the rights and freedoms of others, including social protection, public health and humanitarian purposes. Those restrictions should be in accordance with the requirements set out in the Charter and in the European Convention for the Protection of Human Rights and Fundamental Freedoms.

### Recital 156 — safeguards for archiving research processing

*Source: GDPR, gdpr-rec-156-en, 2016-04-27 — https://overview.legal/posts/91827*

The processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be subject to appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation. Those safeguards should ensure that technical and organisational measures are in place in order to ensure, in particular, the principle of data minimisation. The further processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is to be carried out when the controller has assessed the feasibility to fulfil those purposes by processing data which do not permit or no longer permit the identification of data subjects, provided that appropriate safeguards exist (such as, for instance, pseudonymisation of the data). Member States should provide for appropriate safeguards for the processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. Member States should be authorised to provide, under specific conditions and subject to appropriate safeguards for data subjects, specifications and derogations with regard to the information requirements and rights to rectification, to erasure, to be forgotten, to restriction of processing, to data portability, and to object when processing personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. The conditions and safeguards in question may entail specific procedures for data subjects to exercise those rights if this is appropriate in the light of the purposes sought by the specific processing along with technical and organisational measures aimed at minimising the processing of personal data in pursuance of the proportionality and necessity principles. The processing of personal data for scientific purposes should also comply with other relevant legislation such as on clinical trials.

### Recital 49 — intermediary services annual transparency reporting

*Source: DSA, dsa-rec-49-en, 2022-10-19 — https://overview.legal/posts/95495*

To ensure an adequate level of transparency and accountability, providers of intermediary services should make publicly available an annual report in a machine-readable format, in accordance with the harmonised requirements contained in this Regulation, on the content moderation in which they engage, including the measures taken as a result of the application and enforcement of their terms and conditions. However, in order to avoid disproportionate burdens, those transparency reporting obligations should not apply to providers that are micro or small enterprises as defined in Commission Recommendation 2003/361/EC (25) and which are not very large online platforms within the meaning of this Regulation.

### Recital 122 — Digital Services Coordinator activity reporting

*Source: DSA, dsa-rec-122-en, 2022-10-19 — https://overview.legal/posts/95641*

The Digital Services Coordinator should regularly publish, for example on its website, a report on the activities carried out under this Regulation. In particular, the report should be published in a machine-readable format and include an overview of complaints received and of their follow-up, such as the overall number of complaints received and the number of complaints that led to the opening of a formal investigation or to the transmission to other Digital Services Coordinators, without referring to any personal data. Given that the Digital Services Coordinator is also made aware of orders to take action against illegal content or to provide information regulated by this Regulation through the information sharing system, the Digital Services Coordinator should include in its annual report the number and categories of such orders addressed to providers of intermediary services issued by judicial and administrative authorities in its Member State.

## Case law

### Rb. Den Haag - C/09/689833

*Source: District Court Den Haag, 2026-05-27 — https://overview.legal/posts/53095 — original: https://gdprhub.eu/index.php?title=Rb._Den_Haag_-_C/09/689833*

Facts — Kindred Group PLC and Risepoint Limited (the controllers) are companies that provide online gambling products. Several companies within Kindred Group PLC (Risepoint was initially in this group) offered online gambling products before a national law requiring a license entered into force. In response, several lawsuits were filed before courts regarding the validity of the gambling agreements between players and unlicensed online gambling providers. Several data subjects later requested access (Article 15 GDPR, or in the alternative, the right to portability under Article 20 GDPR) to the controller to receive information on specific transaction data and the types of games they participated in. The data subjects did not receive access and brought a claim to the court. The data subjects requested the court to hold both companies liable (jointly or separately) The court initially dismissed the claim based on the code of civil procedure, but allowed the data subjects to amend their arguments regarding the GDPR. Both companies argued that they were not controllers, and that the requests made by the data subjects were abusive. According to the companies, the data subjects requested access for the sole purpose of bringing legal actions against them. Finally, the companies argued that they did not have the obligation to comply with the requests under Article 15(4) GDPR. Holding — The court first clarified that both Kindred Group PLC and Risepoint Limited were controllers. Kindred Group PLC argued that it did not exercise any decisive influence over the purpose and means of processing. The court took into consideration the functional definition of “controller” under Article 4(7) GDPR and CJEU case law, rather than a formal definition. The court found that Kindred Group PLC was a controller for access made between May and October 2024, but not for requests made after October 2024. This is because Kindred had a unified privacy policy for companies under its group, and answered the access request from an email address containing its name. However, after October 2024, Risepoint was no longer a part of the group, and the data from Kindred had been transferred to Risepoint. The court then dismissed the controllers’ arguments, and stated that the access requests were not abusive under Article 12(5) GDPR. Under Article 12(5) GDPR, a controller may refuse a request for access if it is manifestly unfounded or excessive. However, the CJEU has clarified that a data subject does not need to justify an access request, and a controller cannot refuse a request for access on the sole ground that it serves a purpose other than obtaining information about the processing of personal data and verifying its lawfulness. In any case, the court stated that the controller bears the burden in proving that a request is manifestly unfounded or excessive. Similarly, the controllers could not rely on Article 15(4) GDPR to refuse the data subjects’ requests. The court stated that the controllers’ interest in not granting information that data subjects could use against them in court is not recognised under EU law as a basis to refuse access. While the GDPR allows for national law to restrict specific rights under Article 23 GDPR, the court stated that the restriction must be necessary and proportionate. This, however, does not apply for hypothetical situations. The court upheld the data subjects’ claim, and ordered the controllers to provide them with a copy of their transaction data. The court specified that the controllers had the obligation to provide a complete copy, in accordance with CJEU case law.

### Judgment of the Court (First Chamber) of 4 September 2025.#European Data Protection Supervisor v Single Resolution Board.#Appeal – Protection of natural persons with regard to the processing of personal data – Procedure for granting compensation to shareholders and creditors of a banking institution following the resolution of that institution – Decision of the European Data Protection Supervisor finding that the Single Resolution Board failed to fulfil its obligations relating to the processing

*Source: Court of Justice of the European Union, C-413/23, 2025-09-04 — https://overview.legal/posts/132136 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0413*

The European Data Protection Supervisor (EDPS) appealed a General Court judgment that annulled its decision finding the Single Resolution Board (SRB) had failed to fulfil its obligations under Regulation (EU) 2018/1725 regarding the processing of personal data in a banking resolution compensation procedure. The core legal issues concerned whether pseudonymised data transmitted to a third party constitutes "personal data" under Article 3(1), the proper interpretation of "pseudonymisation" under Article 3(6), and the scope of the controller's obligation to inform data subjects under Article 15(1)(d). The Court of Justice (First Chamber) ruled on these interpretive questions in deciding whether to set aside the General Court's judgment.

### OVG Saarlouis - 2 A 165/24

*Source: Superior Administrative Court Saarlouis, 2025-05-13 — https://overview.legal/posts/125590 — original: https://gdprhub.eu/index.php?title=OVG_Saarlouis_-_2_A_165/24*

Facts — The data subject was an employee, the controller was the employer. On 14 January 2022, the data subject requested access to personal data from the controller under Article 15 GDPR. They did not respond. On 28 January 2022, the controller terminated the employment. On 17 February 2022, the data subject lodged a complaint with the Data Protection Authority (DPA) under Article 77 GDPR. The data subject alleged that the controller had failed to answer the access request, had taken unauthorised photographs, and had a copy of their vaccination certificate. On 24 February 2022, the employment relationship ended by a court settlement before the Labour Court. The settlement stated that all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, were settled, except for employment documents. By entering the settlement, the data subject agreed to not pursue further claims. After the settlement, the controller informed the DPA that it had not received an access request from the data subject, had not taken photographs, and had destroyed the vaccination certificate after the employee left. The data subject continued to raise issues with the DPA, including access to time-tracking data and alleged inaccuracies in the controller’s provided documents. The controller later provided partially redacted time-tracking data. On 26 July 2022, the DPA closed the administrative procedure, as it considered that the data subject no longer had a right of access under Article 15 GDPR because the settlement didn't allow for this claim. The data subject challenged the DPA’s decision before the Administrative Court. On 10 July 2024, the court dismissed the action. The data subject appealed. Holding — First, the court held that the right of access under Article 15 GDPR was, in principle, waivable. Although Article 8(2) CFR protects the right of access, the court noted that data protection law is based on self-determination, including the possibility to consent to processing under Article 7 GDPR. From this, the court inferred that a data subject could also waive the exercise of the right of access. Second, the court clarified that a waiver could not generally cover unknown future data processing. However, a waiver relating to past processing was permissible, especially after the end of an employment relationship, where the imbalance between employee and employer no longer existed. Third, the court held that the specific settlement covered the right of access under Article 15 GDPR. The clause settling all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, also included secondary claims linked to the employment relationship, such as access rights concerning employee data. The court considered the wording sufficiently clear and found no requirement to explicitly mention data protection rights. Fourth, the court noted that the data subject already knew about the access request and had raised it before concluding the settlement. Any internal intention not to waive data protection rights was legally irrelevant. Finally, the court upheld the DPA’s decision to close the procedure. Since the data subject had waived the right of access under Article 15 GDPR for past processing through the settlement, the DPA had no obligation to continue enforcement action against the employer.

### BVwG - W252 2247042-1

*Source: Federal Administrative Court, 2024-01-22 — https://overview.legal/posts/132104 — original: https://gdprhub.eu/index.php?title=BVwG_-_W252_2247042-1*

Facts — The controller, an Public Employment Service Austria, processed the personal data of the data subject in connection with his file. On 21 February 2019, 15 March 2019 and 25 November 2020, the data subject sent access requests to the controller by fax, each time explicitly insisting on delivery of the response by registered post, addressed personally and refusing delivery by email. With the November 2020 request, he also sent a blank DVD-R by post, asking the controller to copy the data onto it. The controller responded to each request with a printed access response sent by registered letter, the responses were substantially identical and the DVD-R was returned unused. The controller's usual practice is to provide access electronically through an online account. The access responses included the data subject's basic data, insurance and benefit periods and a chronological log of case notes "Informationen/Gesprächsnotizen/Vermerke", which listed attachments where relevant but did not include copies of entire documents. The data subject was aware of the content of the documents listed as attachments, since he himself had submitted them to the controller. None of the three responses referred to a specific case note dated 17 October 2018, recording a phone call between the controller and the data subject's family doctor about his health. The data subject repeatedly and specifically requested this note. The controller only produced it during the proceedings before the Federal Administrative Court, in a submission of 29 June 2023, which the Court forwarded to the data subject in July 2023. The data subject lodged a complaint with the Austrian DPA in February 2020, arguing that the access provided was deficient because copies of documents were missing, unexplained abbreviations were used, the response was not delivered in a common electronic format and it contained incorrect data. The DPA partially upheld the complaint (ordering the controller to explain certain abbreviations) but rejected the remainder, holding that the right of access does not include a right to copies of documents. The data subject appealed only the rejecting part of the DPA's decision to the Federal Administrative Court. Holding — First, the court held that the data subject was entitled, in the specific circumstances, to receive a copy of the case note of 17 October 2018. Citing CJEU case-law, the court noted that "personal data" must be interpreted broadly and that a "copy" means a faithful reproduction, not a mere general description or reference to categories of data. Because the data subject had specifically identified and requested this particular note as early as February 2019, the controller's asserted practice of a staged, multi-step access process could not be relied on to justify withholding it. However, the court held that this part of the complaint became moot once the controller supplied the missing note during the court proceedings, since the data subject's interest in access was thereby satisfied, even though the note reached him via the court rather than directly from the controller. Referring to national case-law, the court noted that there is no separate right to a formal declaration that a past infringement of the right of access occurred, once the substantive right has been satisfied. It also stated that any dispute about the accuracy of the date shown on the note was a matter for the right to rectification, not the right of access. Second, the court held that the right of access does not, in general, entitle a data subject to copies of entire documents or file attachments. Reproduction of extracts or whole documents is only necessary where needed to make the disclosed personal data intelligible. Since the data subject already knew the content of the referenced attachments (he had submitted them himself and had annotated copies of the responses identifying their content), the court held that further disclosure of the attachments was not necessary for comprehensibility and the access already given was complete. Third, the court rejected the data subject's argument that the access responses should have been delivered in a "common electronic format." While the GDPR provides that a request submitted electronically should, in principle, be answered electronically unless the data subject indicates otherwise, the court held that the data subject himself had explicitly and repeatedly requested delivery by registered post rather than email and this constituted "otherwise" within the meaning of that provision. The court also held that there is no obligation on a controller to use a physical data carrier (such as the data subject's own DVD-R) to provide access. It rejected the argument that paper delivery was designed to prevent the data being machine-searchable, noting that the right of access, unlike the right to data portability, does not guarantee a right to further processing of the data. The appeal was dismissed and the court declared that an appeal on points of law (Revision) was not admissible, since the relevant questions were already settled by existing CJEU and national supreme administrative court case-law.

### Österreichische Datenschutzbehörde v CRIF

*Source: CJEU, C-487/21, 2023-10-26 — https://overview.legal/posts/51486 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0487*

Right of access includes obtaining a copy in commonly used electronic form.

### LG Rostock - 3 O 762/19

*Source: LG Rostock, 2020-09-15 — https://overview.legal/posts/122848 — original: https://gdprhub.eu/index.php?title=LG_Rostock_-_3_O_762/19*

Facts — The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit against advocado GmbH (advocado, the defendant), a German-based company that runs an online platform where attorneys can offer their services. The defendant's website had used a cookie banner with pre-ticked boxes for the use of marketing and analytics cookies. This included the use of tools such as Google Analytics that entail a data transfer to third countries. The claimant argued that the data processing in connection with the placed cookies was unlawful under Article 6(1) GDPR: A user's consent under Article 6(1)(a) GDPR could not be considered valid under Articles 4(11) and 7 GDPR, especially since the boxes were pre-ticked. Moreover, the claimant claimed that the defendant had violated Articles 5(1)(a), 13/14, 26 and 44 et seqq. GDPR as it had failed to properly inform users of the scope of intended processing activities, joint controllers and international data transfers in connection with the use of cookies. The defendant stated that it had based the use of cookies on legitimate interests under Article 6(1)(f) GDPR until the CJEU issued its decision C-673/17 on 01.10.2019 ("Planet 49"). Afterwards, the defandent argued that they changed the legal basis for processing to consent under Article 6(1)(a) GDPR, which it considered valid under Articles 4(11) and 7 GDPR. The defendant also stated that it was the sole controller for the processing activities - there were no joint controllers involved, only processors. (Furthermore, the claimant had also argued that some provisions in the defendant's general terms and conditions were unlawful from a civil law / consumer protection law perspective. This will not be discussed further in this summary.) Dispute — Was it necessary to ask for the users' consent under Article 6(1)(a) GDPR or could the processing activities in connection with the use of marketing and analytics cookies be based on legitimate interest under Artilce 6(1)(f)? Was the consent given by users' when interacting with the defendant's cookie banner valid under Articles 6(1)(a), 4(11) and 7 GDPR? Did the defendant violate GDPR provisions on transparency? Was the defendant the sole controller regarding the processing activities in connection with the use of marketing and analytics cookies or were there any joint controllers? Holding — Legal basis and validity of consent — The court held that the marketing and analytics cookies used by the defendant c an only be placed with the users' consent under Article 6(1)(a) GDPR : § 15(3) Telemediengesetz that deals with such cookies must be interpreted in light of Article 5(3) e-Privacy Directive, which requires consent for cookies not strictly necessary for technical reasons. Taking into consideration the design of the cookie banner and the lack of information provided to a website user, the court held that consent given could not be considered valid under Articles 6(1)(a), 4(11) and 7 GDPR. The banner featured pre-ticked boxes and a big "OK" button. The option "use only necessary cookies" was designed to not look like an interactive button but rather a link. Consent could therefore not be considered "freely given" and was invalid. Transparency — The court further held that the defendant violated Article 13 GDPR by mentioning an incorrect transfer mechanism under Articles 44 et seqq. GDPR for data transfers in connection with the use of cookies. Sole or joint controllership when using Google Analytics? — Lastly, the court held that the use of Google Analytics results in joint controllership of the website provider using this tool and Google . Google does not qualify as the website provider's processor under Article 4(7). This is because Google does not process the data solely for the purpose of use by the website provider. Rather, Google, like other third-party providers, expressly reserves the right to process the data for its own purposes as well. The fact that the defendant and Google entered into a data processing agreement under Article 28 GDPR does not change this assessment. The court's legal view is in line with the official opinion of the "Datenschutzkonferenz", a gathering of all German DPAs.

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein

*Source: CJEU, C-210/16, 2018-06-05 — https://overview.legal/posts/51477 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0210&ref=51477*

Facebook fan page administrators are joint controllers with Facebook.

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

### VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”)

*Source: CJEU, 2010-11-09 — https://overview.legal/posts/6180 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6180*

Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their consent. (¶ 54)

### Meta Platforms and Others v Bundeskartellamt

*Source: CJEU, C-601/21, 2023-07-04 — https://overview.legal/posts/51482 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0601*

Competition authorities can assess GDPR compliance in context of competition law proceedings.

### Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t

*Source: Court of Justice of the European Union, C-169/23, 2024-11-28 — https://overview.legal/posts/132158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0169*

In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan Government Office, as controller issuing COVID-19 immunity certificates, was required to provide information to data subjects under Article 14 GDPR where the personal data was not collected directly from them. The Court held that data generated by the controller in the context of its own processes falls within the Article 14(5)(c) exemption from the obligation to provide information, provided that Member State law ensures appropriate measures to protect the data subject's legitimate interests, including data security measures under Article 32. The Court also confirmed that supervisory authorities retain competence to handle complaints under Article 77(1) even where the Article 14(5)(c) exemption applies.

## Guidance

### Right to data portability

*Source: EDPB, right-to-data-portability-en, 2018-05-25 — https://overview.legal/posts/126321 — original: https://www.edpb.europa.eu/documents/guideline/right-to-data-portability_en*

### Guidelines on the right to data portability under Regulation 2016/679, WP242 rev.01

*Source: EDPB, guidelines-on-the-right-to-data-portability-under-regulation-2016679-wp242-en, 2018-05-25 — https://overview.legal/posts/126336 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-on-the-right-to-data-portability-under-regulation-2016679-wp242_en*

J.No. 2022-7320-3298 Doc.no. 495942 Caseworker Ditte Hector Dalhoff The Danish Data Protection Agency Carl Jacobsens Vej 35 2500 Valby Denmark T 3319 3200 dt@datatilsynet.dk datatilsynet.dk VAT No. 11883729 [Name and address] Complaint about Organic Basics ApS 1. The Danish Data Protection Agency (hereinafter referred to as the ‘Danish DPA) returns to the case, where you on 20 October 2020 have complained to the Lander Commissioner for Data Protection and Freedom of Information — Free Hanseatic…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation

*Source: EDPB, joint-guidelines-interplay-between-digital-en, 2025-10-13 — https://overview.legal/posts/51268 — original: https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2025/joint-guidelines-interplay-between-digital_en*

Executive summary The Digital Markets Act (DMA) and the General Data Protection Regulation (GDPR) pursue different purposes and objectives and have different scopes. While the GDPR aims to protect natural persons with regard to the processing of personal data and ensure the free flow of personal data in the U nion covering all data controllers and processors, the DMA aims to tackle unfair prac tices, and their potential harmful effects for business users, by laying down harmonised rules…

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)

*Source: EDPB, edpb-edps-joint-opinion-22022-on-the-proposal-of-the-european-en, 2022-05-04 — https://overview.legal/posts/125945 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-22022-on-the-proposal-of-the-european_en*

1 Adopted EDPB - EDP S Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act) Adopted on 4 May 2022 2 Adopted Executive s ummary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on Data Act and urge the co - legislature to take decisive action. The EDPB and EDPS note that the Proposal would apply to a broad range of products and…

### Guidelines 10/2020 on restrictions under Article 23 GDPR

*Source: EDPB, edpb-guidelines-on-restrictions-under-article-23-gdpr, 2021-10-13 — https://overview.legal/posts/38062 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the scope and application of Article 23 of the GDPR, which allows Member States to restrict certain data subject rights and controller obligations. The guidelines outline the necessary conditions and safeguards, emphasizing that any restrictions must respect the essence of fundamental rights and be implemented via foreseeable, proportionate legislative measures. This document serves as authoritative guidance for interpreting the specific grounds and requirements under which Member States may legally impose such limitations.

### Guidelines 05/2020 on consent under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-consent, 2020-05-04 — https://overview.legal/posts/38053 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052020-on-consent-under-regulation-2016679_en*

The European Data Protection Board (EDPB) adopted Guidelines 05/2020 on consent under Regulation 2016/679 to provide detailed interpretive guidance on the requirements for valid consent under the GDPR, including the elements of freely given, specific, informed, and unambiguous consent, as well as the conditions for explicit consent and the obligation to demonstrate consent. The guidelines address practical issues such as power imbalances, conditionality, granularity, detriment, and the minimum content requirements for informing data subjects. No fines are imposed, as this is a guidance document rather than an enforcement decision.

## Enforcement decisions

### BfDI (Germany) - 24-191 II

*Source: BfDI (Germany), 2022-01-27 — https://overview.legal/posts/125601 — original: https://gdprhub.eu/index.php?title=BfDI_(Germany)_-_24-191_II*

Facts — The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject requested access from the controller to all of his data under Article 15 GDPR. He also requested to have his data transmitted in a portable format under Article 20 GDPR. The controller responded to both requests. The data subject, however, considered that both responses were not complete. He argued that information about his traffic data, his contracts with the controller and his requests to the controller's customer service were missing. Furthermore, the data subject criticised that the controller did not list all recipients in its answer, but only the "most important" ones, that the origin of the data was not specified and that the storage duration was not mentioned. He, therefore, lodged a complaint with the German Federal Data Protection Authority (Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit - BfDI). Holding — The BfDI partially upheld the complaint. It confirmed the data subject's view that the controller is obligated under Article 15 GDPR to name all recipients and not only the "most important" ones, to specify the origin of the data and to mention the deletion date. However, the DPA found it was not necessary to list each and every individual transfer to a recipient. With regard to the contract documents, the DPA found that it was sufficient that the controller referred the data subject to the online customer portal where the data subject could retrieve those documents. Regarding the data subject’s requests to the customer service of the controller, the DPA found that these requests are usually handled manually by phone or by paper and not automatically. Accordingly, the DPA concluded that Article 20(1)(b) GDPR was not met. Furthermore, the DPA held that the data collected in the course of service requests must be deleted immediately after the purpose has been achieved, that means after the request has been resolved, or, if the data is to be used for other purposes, it must be anonymised. Consequently, the DPA reasoned that the controller could not have provided this data in its answer to the request under Article 15 GDPR. Regarding the traffic data, the DPA reasoned that a data subject has no right to access traffic data under Article 15 GDPR because § 11 TTDSG (Telekommunikation-Telemedien-Datenschutz-Gesetz), which is an implementation of Article 7 ePrivacy Directive and lays down the right to receive itemized bills, takes precedence according to Article 95 GDPR. In the case at hand, the DPA concluded that the data subject did not invoke § 11 TTDSG since the data subject blackened this part of his submissions. Furthermore, the DPA held that by taking the principle of dataminimisation and Article 11 GDPR into account, the controller is only allowed to store IP addresses seven days. Since the IP addresses which were stored at the time of the request have already been deleted, the controller can no longer provide information about them. The DPA also determined that the controller was not obliged to give the data subject access to location data (Cell-ID) because the data subject did not sufficiently demonstrate that he was the sole user of the mobile phone in question. The DPA took the view that, since location data is very sensitive, the data subject must show that no one else was using the cellphone. Lastly, the DPA clarified that the controller is not allowed to record the content transmitted in an online session. Therefore, it found that it was impossible for the the controller to provide information on the visited websites under Articles 15 and 20 GDPR.

### AEPD (Spain) - EXP202203606

*Source: AEPD (Spain), 2022-04-22 — https://overview.legal/posts/125657 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202203606*

Facts — Resolution No. R/00665/2022 is highlighted by a case concerning a claimant (namely A.A.A) and a respondent party (namely Securitas Direct España, S.A). The claimant filed against the respondent party for not having been duly attended to his right of access and deletion enshrined in Articles 15 to 22 GDPR, Articles 13 to 18 LOPDGDD and Article 17 GDPR respectively. The conflict of law arose in this case when a sufficiently legally established response was not generated by the respondent to the claimants request. Furthermore, the claim was transferred to the respondent so that the entity could proceed with its analysis and provide a response to the claimant within a period of one month. The Director of the Spanish Data Protection Agency agreed to admit the claim for processing and the parties concerned were informed of the maximum term for resolution, that being six months. The competence of the Spanish Data Protection Agency is refined by Article 55 GDPR in the promotion of an obligation between controllers and processors to deal with complaints issued by data subjects. The result of the said transfer did not allow the claimants issues to be understood as satisfied. Consequently, due to the lack of attention delegated to the claimants rights further set forth in Article 15 GDPR, Article 16 GDPR, Article 17 GDPR, Article 18 GDPR, Article 19 GDPR, Article 20 GDPR, Article 21 GDPR and Article 22 GDPR, an agreement to admit for processing was initiated. Holding — The Director of the Spanish Data Protection Agency went on to note that considering the purpose of the outlined procedure was to ensure that the rights of affected parties were fully restored, the complaint that gave rise to this procedure should be upheld on formal grounds due to the fact that the right of access had been complied with and the right of erasure had been duly denied (on the applicable grounds of Article 17 GDPR).

### NAIH fines online store HUF 2M for unclear and incomplete privacy notice

*Source: NAIH (Hungary), 2026-07-22 — https://overview.legal/posts/156361 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-11443-3/2026*

Facts — The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The processing activities in question included, inter alia, cookies, registration, billing, shipping, consumer complaint, and processing of orders. The privacy notice of the company operating the online store had been in force unchanged from May 2018 to May 2025, and the period under investigation extended from 1 January 2020 to 27 June 2025. Holding — The DPA held that the controller had violated Articles 12(1), 13(1)(c), (d) and (f), and 13(2)(a) GDPR and issued the controller a fine of HUF 2,000,000 (€5,500). In addition, the DPA ordered the controller to bring its data processing operations into compliance with the GDPR and to amend the content of its privacy notice. First, the DPA found an infringement of Article 12(1) GDPR: the structure of the privacy notice was confusing and difficult to follow. The privacy notice also contained incomplete, incorrect, and unnecessary information as well as repetitive details. Based on this, the DPA concluded that the controller had failed to provide data subjects with information regarding the processing of personal data that was sufficiently concise, transparent, intelligible and easily accessible. Second, the DPA held that the controller had also violated Articles 13(1)(c), (d) and (f) GDPR by failing to specify a legal basis for certain processing operations such as the use of cookies, not specifying its legitimate interests when relying on Article 6(1)(f) GDPR as a legal basis, and not providing detailed information regarding the safeguards ensuring the lawfulness of data transfers to the United States. Finally, the DPA found a violation of Article 13(2)(a) GDPR as the controller had also failed to provide the data subjects information on the period for which the personal data processed would be stored.

### CNIL fines energy supplier for mishandling data subject access and objection requests

*Source: CNIL (France), 2026-07-17 — https://overview.legal/posts/125641 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2022-011*

Facts — The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French DPA (CNIL) that they had encountered difficulties in exercising their rights of access to personal information about them, and objection to receiving commercial prospecting telephone calls from the controller. The complaints concerned data subject requests for rectification of personal data, late, erroneous, or no response to access to personal data and access to the origin of personal data, failure to cease processing of personal data after objection to the processing of data for commercial prospecting (marketing) purposes, and request for personal data deletion. The DPA appointed a rapporteur that carried out an audit of the website of the controller and investigated the various complaints of the data subjects. The controller in its defence argued that 1) the data subjects' access requests were not sent by the data subjects to the controller’s dedicated unit and that the person who received the requests did not know how to identify their purpose; 2) the procedures it had put in place were not respected because of human error; 3) there were a large number of requests received in 2020 during the health crisis and this was impeded by the disruptions that followed; 4) there were difficulties in obtaining the necessary information from its business partners, thus unable to properly inform data subjects about the source of their data; 3) It had taken steps to modify its processing activities to comply with the relevant applicable laws; 4) The breach affected barely a fraction of its customers. Beyond the direct complaints made by the data subjects, the DPA in its investigation noted that when subscribing online on the controller's website, the subscription form had no option for users to object to the use of their personal data for marketing purposes. The subscription form informed users that their personal data may be used by the controller to present offers to them at a later date. On this point, the controller argued that 5) the CPCE did not apply to the online subscription form, since the collection of personal data through the form was not intended to promote the company's products or services, but to offer assistance to the user in order to help them finalize the current subscription. Holding — The DPA held that the lack of an option for a user to object to the processing of their personal data for marketing purposes, at the time of collection, constitutes a breach of the provisions of article L. 34-5 of the French Post and Electronic Telecommunications Code (CPCE). The DPA observed that, in certain cases, the data subjects contacted for marketing purposes were not provided with any information required in Article 14 GDPR, such as the purposes of the processing or the existence of the various rights. They were not informed that the call was being recorded, nor of their right to object to it. The DPA observed that the controller had failed to respond, supplied erroneous responses, or responded late to several data subject requests, beyond the deadlines set by Article 12 GDPR, often after several reminders from the data subject. The DPA observed that the controller failed to process the various data subject’s requests for access to personal data, their origin, as well as access to recordings of telephone conversations concerning the data subjects within the time limit set with the obligations of Article 15 GDPR. The DPA finally observed that the controller continued to process the personal data of data subjects after objections from the data subjects to the processing of their personal data in breach of Article 21 GDPR. The DPA held that the controller cannot rely on its difficulties in obtaining information from its commercial partners to justify its failure to provide a response to the applicants in accordance with the applicable provisions. It is the duty of the controller to organize itself in such a way as to be able to ensure that requests for access are processed in accordance with the applicable provisions and, in particular, to provide information on the origin of the data. The DPA further held that although data subjects did not send their access requests directly to the unit in charge of responding to them, it is up to the controller, as long as the requests, one of which was directly addressed to the data protection officer, were received in clear terms by the controller, to process them within the time limits provided for and to ensure that they were transmitted to the competent department responsible for handling such requests. For these violations, the DPA fined the controller €1,000,000. The controller argued against the publication of the penalty decision, on the ground that publication would be disproportionate in light of the limited nature of the alleged breaches and its compliance. It also claimed that publication of the penalty would have a significant impact on the controller’s image and that it would be favorable to its main competitors, in a very competitive market. The DPA also decided to make its decision public on the CNIL website and on the Légifrance website and held that the controller will no longer be identified by name after a period of two years from its publication. The DPA noted that the company has taken measures to bring its processing into compliance with the applicable laws, and the efforts made by the company to comply throughout the procedure. The DPA also noted that the controller’s agents have had to attend awareness training on the subjects of the complaints.

### NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations

*Source: NAIH (Hungary), 2026-05-12 — https://overview.legal/posts/184727 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-450-7-2026*

Facts — The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The period under review extended from January 2020 to November 2025. During this time, the company had multiple privacy notices in force, as well as other documents that contained relevant information on the processing of personal data. Holding — The DPA found the controller guilty of multiple GDPR violations and issued it a fine of HUF 15,000,000 (€41,500). In addition, it ordered the controller to bring its processing operations in compliance with the GDPR by amending the information system used on its website, in particular the data processing provisions of the general terms and conditions and the data processing notices related to prize contests. First, the DPA held that the controller had violated the principle of transparency laid down in Article 5(1)(a) GDPR: several separate documents contained partially conflicting, irrelevant, and incomplete information regarding the processing of personal data. The information was not organised within a uniform, transparent system. Second, the DPA determined that the controller had failed to provide concise, transparent, and intelligible information regarding the purposes and the legal basis for each processing activity and therefore infringed Article 12(1) GDPR. Finally, the DPA found infringements of Articles 13(1) and 13(2) GDPR – the controller had not provided the data subjects all information necessary when personal data is collected from data subjects. In particular, the controller had failed to adequately distinguish the purposes and the legal bases for each processing operation, recipients of personal data, and retention periods. The controller’s website also contained contradictory information on whether or not personal data was transferred to the United States.

### NAIH fines online store HUF 10M for missing and inadequate privacy notice

*Source: NAIH (Hungary), 2026-04-30 — https://overview.legal/posts/262255 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-4462-5-2026*

Facts — The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The controller’s main business activity was the wholesale distribution of beverages. The personal data of the data subjects was processed on the website of the online store for registration, placing orders, billing, communication, delivery, creation of user accounts, and newsletter subscription. During the period under review, i.e. between January 2020 and October 2025, no standalone privacy notice was available on the website. The previously archived privacy notice and the data processing section included in the general terms and conditions described the processing operations in a rather brief and general manner. The controller argued that the inaccessibility of the privacy notice followed from a technical error that was corrected upon discovery. Holding — The DPA found that the controller had violated Articles 5(1)(a), 5(2), 12(1), 13(1)(a), (c), and (e) as well as 13(2)(a)–(e) GDPR and issued it a fine of HUF 10,000,000 (€27,300). When issuing the fine, the DPA took into account that the identified infringements followed from systemic inadequacies of the privacy notice and were of continuous nature. In addition, the DPA ordered the controller to develop and publish a uniformly structured privacy notice that is aligned with its actual processing operations. First, the DPA identified a violation of the principle of transparency laid down in Article 5(1)(a) GDPR: the information provided to data subjects about the processing of their personal data was either incomplete or completely absent, and changes could not be tracked. Second, the DPA held that the controller had violated the principle of accountability set forth in Article 5(2) GDPR, as it had failed to submit appropriate documentation covering the period under review. In addition, the controller’s data processing practices could not be continuously monitored or subsequently verified based on the documentation it had provided. Finally, the DPA confirmed that the controller had not complied with the requirements laid down in Articles 12(1), 13(1)(a), (c) and (e), and 13(2)(a)–(e) GDPR. Due to the lack of a privacy notice, the controller could not demonstrate that it had provided data subjects with the information required under Article 13 GDPR apart from brief, general statements in the archived privacy notice and the general terms and conditions. The controller had thus failed to provide the data subjects clear and differentiated information regarding the purpose and legal basis for each processing operation. Furthermore, the controller had not adequately identified the recipients or the storage period of personal data or information on the data subjects' rights. Due to the form and scope of the information provided, the controller had also infringed Article 12(1) GDPR.

### CNPD (Portugal) - Deliberação 2019/494

*Source: CNPD (Portugal), 2019-09-03 — https://overview.legal/posts/122872 — original: https://gdprhub.eu/index.php?title=CNPD_(Portugal)_-_Deliberação_2019/494*

Facts — In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of the national legislator to a set of provisions that could potentially violate EU law, particularly the GDPR. The DPA emphasized the primacy of EU law as outlined in the EU treaties, particularly reflecting on Article 288 of the Treaty on the Functioning of the European Union (TFEU) and reinforced by the jurisprudence of the CJEU, which has consistently stated that national laws cannot obstruct the direct applicability of EU regulations and must comply with EU law to ensure uniform implementation across the Member States. However, Law 58/2019 came into force without incorporating all of the DPA's recommendations. The DPA explains that the decision to not apply some of its provisions aims to ensure legal certainty, reinforcing the importance of consistent GDPR application without being hindered by conflicting national rules. Holding — The DPA has decided to disapply the following provisions of Law 58/2019, in cases of personal data processing under its review due to their conflict with the GDPR: Article 2(1)(2): This article broadens the territorial scope of the GDPR to encompass all personal data processing within national territory and processing linked to national establishments outside the territory. The DPA believes this contradicts Article 3 and Article 56 of the GDPR, which outlines the applicable law in cross-border situations. Additionally, it undermines the one-stop-shop mechanism and fails to address instances where the GDPR applies, such as in Portuguese embassies, consulates, ships, and aircraft. Article 20(1): This article states that the right to be informed and the right of access cannot be exercised when a duty of secrecy is imposed on the data controller/processor. In the view of the DPA, this article lacks legal relevance in relation to the GDPR, as it merely repeats provisions already present in the GDPR, particularly concerning the possibility of restricting the data subject's right to information in cases where data collection is indirect and a legal duty of confidentiality exists. Regarding the possibility of restricting the right to information when collecting data directly from the data subject, this right can only be restricted under the provisions of Article 23 GDPR, and Law58/2019 does not meet the requirements therein, thus contradicting the norms of the GDPR and the Charter of Fundamental Rights. Article 23: This article allows public authorities to reuse personal data for any public interest without ensuring compliance with principles of purpose limitation and data minimization (Article 5 GDPR) and could lead to potential misuse of personal data and a violation of individuals’ rights, as it does not ensure that the reuse of data serves the original purpose for which it was collected nor respecting the requirements imposed in Article 23 GDPR. Article 28(3)(a): The employee's consent cannot be the legal basis if the processing results in a legal or economic advantage for the employee. The Portuguese DPA considers it to be a contraction of the doctrine established by European institutions, which accepts employee consent in situations where the act of giving or refusing consent does not, in itself, have negative consequences for the employee. The DPA therefore believes that this provision does not protect the dignity, fundamental rights, and legitimate interests of employees, and thus fails to meet the requirements set forth in Article 9 (2) (b) and Article 88 GDPR. Regime of Administrative Offenses – Articles 37, 38, and 39: The DPA notes that some of the violations outlined in the law contradict the exhaustive list provided in the GDPR (Article 83). The DPA also criticizes the distinction in sanctioning frameworks based on the size of companies and the collective or individual nature of the entities conducting data processing, as the impact on personal data does not depend on those characteristics but rather on the nature of the activity being carried out. Article 61(2) states that "if the expiration of consent is the reason for terminating a contract in which the data subject is a party, the processing of data is lawful until this occurs." The DPA notes that this provision is incongruent, conflating two types of legal basis: consent and contract execution. The contract in which the data subject is a party is sufficient to justify the processing of the data necessary for its execution. Regarding the reasons that led to publish this decision, the Portuguese DPA clarifies that it did so in order to ensure the transparency of its future decision-making processes and, in this regard, contribute to legal certainty and security. It also clarifies that the non-application, in future specific cases, of the legal provisions listed above results in the direct application of the GDPR provisions that were manifestly restricted, contradicted, or compromised in their useful effect.

### Italian DPA: Enna Health Authority violated GDPR by publishing judicial data

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-18 — https://overview.legal/posts/109000 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_471/2026*

Facts — The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial records). The data subject contacted the controller and requested the controller to remove or redact the data. The controller responded that it would remove it promptly, however, the data subjects’ data remained in a separate page of the controller’s website. The data subject later brought a complaint to the DPA. The controller stated that it completely removed the data subject’s personal data after the DPA requested it, including data that was accidentally included in its website. Holding — The DPA found a violation of Articles 5, 6 and 10 GDPR. The DPA first clarified that the controller processed data related to the commission of crimes or pending criminal proceedings involving the data subject. This data fell under the scope of Article 10 GDPR, meaning the controller had specific obligations for the processing activity to be lawful. The DPA considered that the controller had processed this data unlawfully by publishing it, and had failed to comply with the principle of lawfulness (Article 5(1)(a) GDPR) and data minimisation (Article 5(1)(c) GDPR). The DPA also found a violation of Article 17 GDPR. The DPA stated that the controller failed to adequately respond to the data subject’s request for erasure by not recognising that the data remained visible in a different section of its website. The DPA fined the controller €20,000.

## Recent developments

### HvJ: De PNR-richtlijn is geldig, mits deze beperkt blijft tot wat "strikt noodzakelijk" is.

*Source: eucrim, 2022-08-04 — https://overview.legal/posts/51841*

Op 21 juni 2022 heeft het Gerechtshof van de Europese Unie (Groot Beschouwingscollege) een baanbrekende uitspraak gedaan waarin het het EU-regime voor het verzamelen en gebruiken van gegevens van reizigers bevestigde, mits dit strikt wordt geïnterpreteerd in overeenstemming met de fundamentele rechten van de EU. Bovendien is het zonder onderscheid verwerken van deze gegevens bij vluchten die uitsluitend binnen de EU plaatsvinden verboden, tenzij er een dreiging van terrorisme bestaat. Over het algemeen moeten de gegevens van de passagiers ook binnen zes maanden worden verwijderd.

### Wat is er gebeurd met de risicogebaseerde aanpak voor de overdracht van gegevens?

*Source: Future of Privacy Forum, 2022-09-27 — https://overview.legal/posts/51813*

De AVG (Algemene Verordening Gegevensbescherming) omvat de verantwoordingsplicht (RBA) voor alle verplichtingen van de verantwoordelijke partij zoals die in de AVG zijn vastgelegd. Waar de overdrachtsregels worden beschreven als verplichtingen van de verantwoordelijke partij (in plaats van als absolute principes), is de verantwoordingsplicht van artikel 24 dus van toepassing. Volgens Lokke Moerel, professor in het internationaal ICT-recht aan de Universiteit van Tilburg en expert op het gebied van cyberbeveiliging, wordt dit niet tegengesproken door het vonnis van het Europees Hof van Justitie in de zaak Schrems II, noch door de aanbevelingen van het EDPB (European Data Protection Board) over aanvullende maatregelen na het vonnis Schrems II.

### Garante onderzoekt het gebruik van "cookie walls".

*Source: Garante Privacy, 2022-10-25 — https://overview.legal/posts/51828*

De Garante (de Italiaanse Autoriteit voor de bescherming van persoonsgegevens) merkt op dat de Europese wetgeving inzake de bescherming van persoonsgegevens in principe niet verhindert dat de eigenaar van een website de toegang tot content voor gebruikers afhankelijk maakt van hun toestemming voor het verzamelen van gegevens voor profilering (via cookies of andere trackingtools), of, als alternatief, van het betalen van een bedrag. Dit verwijst naar de initiatieven die de afgelopen dagen zijn genomen door verschillende online kranten, websites en bedrijven die actief zijn op internet.

### Het EU-VS-kader voor gegevensbescherming: Een nieuw tijdperk voor de overdracht van gegevens?

*Source: IAPP, 2022-10-07 — https://overview.legal/posts/51796*

Juridisch gezien moeten bedrijven, totdat een beoordeling van voldoende bescherming is verstrekt, de aanbevelingen van het Europees Comité voor gegevensbescherming (EDPB) blijven volgen met betrekking tot maatregelen die aanvullend zijn op de transferinstrumenten.
Echter, zodra de EU wordt aangewezen als een "erkende staat" (uitgaande van het feit dat dit zal gebeuren) en klachten kunnen worden ingediend, zou dit minder complex moeten worden. De aanbevelingen van het EDPB stellen dat bedrijven moeten "onderzoeken of er iets is in de wet- of praktijk van het derde land dat de effectiviteit van de goedkeuring kan beïnvloeden."

### Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures

*Source: Datatilsynet, 2022-09-21 — https://overview.legal/posts/6276 — original: https://www.datatilsynet.dk/english/google-analytics/use-of-google-analytics-for-web-analytics#entry-800*

The Danish Data Protection Agency has looked into the tool Google Analytics and its settings, and the terms under which the tool is provided. On the basis of this review, the Danish Data Protection Agency concludes that the tool cannot, without more, be used lawfully. Lawful use requires the implementation of supplementary measures in addition to the settings provided by Google.

## Literature

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how

*Source: Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza, 2023-12-30 — https://overview.legal/posts/132546 — original: https://doi.org/10.14746/ppuam.2023.15.09*

The data subject’s right to access information on data processing has a very broad meaning. Considering the latest developments in this field (mainly the CJEU ruling on Austrian posts and EDPB guidelines) one can draw the conclusion that the controller’s right to protect its confidential in-formation is limited and less valuable than the data subject’s rights. However, this may lead to unfair and unequal treatment of companies and data subjects. When looking at this right in a more systematic pe

### IMPACT OF GDPR ON UKRAINIAN PERSONAL DATA PROTECTION LEGISLATION

*Source: Pravo ta nauki, 2018-12-30 — https://overview.legal/posts/132472 — original: https://doi.org/10.66556/2522-4549.1519.koshovyi-b*

The article examines the impact of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation – GDPR), which entered into force on 25 May 2018, on Ukrainian personal data protection legislation. The main novelties of GDPR are analyzed, including the principle of accountability, the right to erasure (right to be

### PROTECTION OF DATA SUBJECT RIGHTS IN THE TRANSFER OF PERSONAL DATA BETWEEN DATA CONTROLLERS IN INDONESIA: A COMPARATIVE ANALYSIS OF THE PDP LAW AND THE EU GDPR

*Source: Awang Long Law Review, 2026-01-16 — https://overview.legal/posts/132506 — original: https://doi.org/10.56301/awl.v8i2.1827*

The rapid digital transformation and growth of e-commerce in Indonesia have triggered a high volume of personal data transfers between controllers. while Article 55 of the Personal Data Protection Law (UU PDP) provides only a general authorization without clear technical guidance, creating legal uncertainty and risks to data subject rights. This study analyzes the legal uncertainty of UU PDP’s regulation of controller-to-controller data transfers compared to the EU GDPR and proposes an accountab

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Profiling** — https://overview.legal/topics/profiling
  Automated processing to evaluate personal aspects

---
Generated by overview.legal · https://overview.legal/topics/dataportabiliteit · 2026-08-22
