# Direct Marketing — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/direct-marketing
> Sources are cited per item. Verify against the official texts before relying on them.

Processing for marketing and advertising purposes

## Overview

## Legal Framework

Direct marketing processing sits at the intersection of two legal regimes. Under the GDPR, [Article 21(2)](/laws/gdpr/art-21#par-2) grants data subjects an unqualified right to object to direct marketing processing, while [Article 21(3)](/laws/gdpr/art-21#par-3) makes that right absolute — no balancing test applies. The ePrivacy Directive's [Article 13](/laws/eprivacy/art-13) imposes a consent requirement that is stricter and more specific, governing the channel through which marketing reaches the data subject.

The ePrivacy regime operates as *lex specialis* for electronic communications. Article 13(1) requires prior consent for marketing via automated calling systems, fax, or electronic mail. The soft-opt-in exception in [Article 13(2)](/laws/eprivacy/art-13#par-2) permits a controller to market its own similar products to existing customers using contact details obtained during a sale, provided an opt-out is offered at collection and in each subsequent message.

> "for the purposes of direct marketing may be allowed only in respect of subscribers or users who have given their prior consent."
> — [ePrivacy Art. 13(1)](/laws/eprivacy/art-13#par-1)

Under the GDPR, the controller must inform the data subject of the right to object at the latest at the time of the first communication, clearly and separately from other information.

## Key Developments

The CJEU's January 2025 ruling in *Mousse* (C‑394/23) confirmed that direct marketing can constitute a legitimate interest under Article 6(1)(f), but this does not displace the absolute objection right in Article 21(2)–(3):

> "the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest"
> — [CJEU, Mousse, C‑394/23, ¶54](/posts/50377#seg-54)

Dutch courts have reinforced that once a data subject objects, the controller cannot override that objection by invoking promotional interests. In a 2024 enforcement case, the court accepted that promotional and advertising interests are equivalent to "direct marketing," triggering the absolute objection right:

> "Derde-partijen wijzen erop dat zij, als betrokkenen, een absoluut recht van bezwaar hebben ten aanzien van de verwerking ten behoeve van direct marketing."
> — [Rechtbank, AVG-handhaving, ¶8.2](/posts/50406#seg-8.2)

The EDPB's consent guidelines further clarify that consent bundled with service delivery — such as a bank conditioning account access on marketing consent from third parties — is invalid, because refusal must not trigger denial of service or fee increases.

## Status of the Debate

This topic is actively contested in court. The core framework — consent under ePrivacy, legitimate interest under GDPR, and the absolute objection right — is well established. What remains disputed is the boundary between lawful interest-based marketing and unlawful processing, particularly where controllers attempt to reclassify marketing as service-related communication to avoid the consent requirement. The *Mousse* ruling narrows but does not fully resolve this question. A future CJEU reference directly addressing whether relationship management communications fall outside "direct marketing" would clarify the perimeter. Meanwhile, DPAs are enforcing aggressively, with fines issued for both consent failures and inadequate opt-out mechanisms.

## Practical Guidance

- **Map your channels to the correct legal basis**: Electronic mail and automated calls require prior consent under [Article 13(1) ePrivacy](/laws/eprivacy/art-13#par-1); the soft-opt-in under Article 13(2) applies only to your own similar products sold to existing customers.
- **Implement absolute opt-out**: Under [Article 21(3) GDPR](/laws/gdpr/art-21#par-3), an objection to direct marketing must halt all processing for that purpose immediately — no balancing test, no exceptions.
- **Disclose the objection right at first contact**: Article 21(4) requires explicit, clearly separated notice of the right to object no later than the first communication with the data subject.
- **Do not bundle marketing consent with service delivery**: If refusal to consent to marketing results in denied service or higher fees, the consent is not freely given and is invalid.
- **Never swap lawful bases mid-stream**: If consent obtained under prior legislation does not meet GDPR standards, refresh it compliantly or cease processing — switching to legitimate interest is not permitted.

## Legislation (full text of key provisions)

### EPRIVACY-ART-13

*Source: ePrivacy Directive, eprivacy-art-13, 2025-10-08 — https://overview.legal/posts/3181*

### Unsolicited communications

*Source: ePrivacy, eprivacy-art-13-en, 2002-07-12 — https://overview.legal/posts/132209*

### Review

*Source: ePrivacy, eprivacy-art-18-en, 2002-07-12 — https://overview.legal/posts/132239*

ReviewThe Commission shall submit to the European Parliament and the Council, not later than three years after the date referred to in Article 17(1), a report on the application of this Directive and its impact on economic operators and consumers, in particular as regards the provisions on unsolicited communications, taking into account the international environment. For this purpose, the Commission may request information from the Member States, which shall be supplied without undue delay. Where appropriate, the Commission shall submit proposals to amend this Directive, taking account of the results of that report, any changes in the sector and any other proposal it may deem necessary in order to improve the effectiveness of this Directive.

### Recital 70 — right to object to direct marketing

*Source: GDPR, gdpr-rec-70-en, 2016-04-27 — https://overview.legal/posts/91655*

Where personal data are processed for the purposes of direct marketing, the data subject should have the right to object to such processing, including profiling to the extent that it is related to such direct marketing, whether with regard to initial or further processing, at any time and free of charge. That right should be explicitly brought to the attention of the data subject and presented clearly and separately from any other information.

### Recital 173 — Relationship with ePrivacy Directive

*Source: GDPR, gdpr-rec-173-en, 2016-04-27 — https://overview.legal/posts/91861*

This Regulation should apply to all matters concerning the protection of fundamental rights and freedoms vis-à-vis the processing of personal data which are not subject to specific obligations with the same objective set out in Directive 2002/58/EC of the European Parliament and of the Council (18), including the obligations on the controller and the rights of natural persons. In order to clarify the relationship between this Regulation and Directive 2002/58/EC, that Directive should be amended accordingly. Once this Regulation is adopted, Directive 2002/58/EC should be reviewed in particular in order to ensure consistency with this Regulation,

### Recital 47 — legitimate interests as processing legal basis

*Source: GDPR, gdpr-rec-47-en, 2016-04-27 — https://overview.legal/posts/91609*

The legitimate interests of a controller, including those of a controller to which the personal data may be disclosed, or of a third party, may provide a legal basis for processing, provided that the interests or the fundamental rights and freedoms of the data subject are not overriding, taking into consideration the reasonable expectations of data subjects based on their relationship with the controller. Such legitimate interest could exist for example where there is a relevant and appropriate relationship between the data subject and the controller in situations such as where the data subject is a client or in the service of the controller. At any rate the existence of a legitimate interest would need careful assessment including whether a data subject can reasonably expect at the time and in the context of the collection of the personal data that processing for that purpose may take place. The interests and fundamental rights of the data subject could in particular override the interest of the data controller where personal data are processed in circumstances where data subjects do not reasonably expect further processing. Given that it is for the legislator to provide by law for the legal basis for public authorities to process personal data, that legal basis should not apply to the processing by public authorities in the performance of their tasks. The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned. The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.

## Case law

### Judgment of the Court (First Chamber) of 13 November 2025.#Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).#Request for a preliminary ruling from the Curtea de Apel Bucureşti.#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Article 13(1) and (2) – Unsolicited communications – Concept of communication ‘for the purposes of di

*Source: Court of Justice of the European Union, C-654/23, 2025-11-13 — https://overview.legal/posts/132132 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0654*

The Court of Justice of the European Union ruled on a preliminary reference from the Romanian Curtea de Apel Bucureşti in proceedings between Inteligo Media SA and the Romanian DPA (ANSPDCP) concerning the scope of "direct marketing" and the customer-relationship exception under Article 13 of the ePrivacy Directive (Directive 2002/58/EC) in relation to GDPR Article 6. The case addressed whether a daily newsletter sent to users who registered on an online platform to access additional content qualifies as a communication "for the purposes of direct marketing" and whether the platform registration constitutes obtaining contact details "in the context of the sale of a product or a service" under Article 13(2). The Court's ruling clarifies the interplay between the ePrivacy Directive's specific consent regime for unsolicited communications and the GDPR's general lawfulness requirements, with the underlying national proceedings involving an administrative penalty imposed by ANSPDCP for processing customers' personal data without consent.

### Judgment of the Court (Third Chamber) of 25 November 2021.#StWL Städtische Werke Lauf a.d. Pegnitz GmbH v eprimo GmbH.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Directive 2002/58/EC – Processing of personal data and the protection of privacy in the electronic communications sector – Article 2(h) – Concept of ‘electronic mail’ – Article 13(1) – Concept of ‘use of … electronic mail for the purposes of direct marketing’ – Directive 2005/29/EC

*Source: Court of Justice of the European Union, C-102/20, 2021-11-25 — https://overview.legal/posts/132319 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0102*

In Case C-102/20, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Bundesgerichtshof (Germany) in proceedings between StWL Städtische Werke Lauf a.d. Pegnitz GmbH and eprimo GmbH concerning whether "inbox advertising" (advertising messages posted directly into users' email inboxes by the email service provider, rather than sent over a public communications network) constitutes "electronic mail" under Article 2(h) and unsolicited direct marketing under Article 13(1) of Directive 2002/58/EC. The Court held that the concept of "electronic mail" under the ePrivacy Directive covers only messages sent over a public communications network, and that inbox advertising placed by an email service provider into its own users' inboxes without using such a network does not fall within that definition or the prior-consent requirement of Article 13(1). No fine was imposed, as the ruling was solely interpretative.

### Spanish court reviews DPA decision on KFC Spain website privacy information and DPO

*Source: National Court, 2026-07-16 — https://overview.legal/posts/184690 — original: https://gdprhub.eu/index.php?title=AN_-_SAN_3154/2026*

Facts — In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website. The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer. The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented corrective measures. Holding — The Court dismissed the appeal and upheld the total fine of €25,000. Regarding Article 13 GDPR, the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding Article 37(1)(b) GDPR, the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.

### CJEU - C-673/17 - Planet49

*Source: GDPRhub, 2026-07-16 — https://overview.legal/posts/122861 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-673/17_-_Planet49*

Facts — A German company called Planet49 organized an online lottery hosted on their webpage. In order to participate in the lottery the participant had to enter a name and an address. Underneath the input field there were two checkboxes. The first checkbox required the user to accept being contacted by firms for promotional offers. The second checkbox required the user to consent to cookies being installed on the participants computer. The first checkbox was not pre-ticked, while the second checkbox was. To participate in the lottery the user had to tick, at least, the first checkbox. The Federation of German Consumer Organisations (the “Bundesverband”) initated court proceedings against Planet49, claiming that the declaration of consent did not meet the requirements for a freely given and informed consent. The case reached the Federal Court of Justice (“Bundesgerichtshof”), which referred questions regarding the scope of consent under provisions of the Data Protection Directive 95/46/EC, the ePrivacy Directive 2002/58/EC, and the GDPR to the CJEU. The case was referred to the Court of Justice on 5 October 2017 - before the GDPR became applicable on 25 May 2018. As the Bundesverband sought an injunction to prevent Planet49 from continuing its practices in the future, the Court’s decision takes into account the requirements for consent on the basis of both the Directive 95/46/EC and the GDPR. The decision of the Court — The Court assessed the requirements for a valid consent under both Directive 95/46/EC and the GDPR and found that there were no substantial differences between them, noting however that the GDPR explicitly states requirements that need to be inferred under Directive 95/46/EC. As the Court notes, the notion of consent under the ePrivacy directive should have the same meaning as consent under Directive 95/46/EC and the GDPR. Consent — A key question posed by the referring court in relation to the consent requirement was whether consent could be “passive” or if it had to be “active”. The Court concluded that a key component of a valid consent is that the consent is given by a clear affirmative act. Requiring the user to untick a box to “opt-out” is not sufficient. The Court emphasized that inaction is insufficient to establish whether the consent is a “freely given and informed decision”. The Court concludes on this basis that Planet 49’s consent model was inadequate with regards to securing a compliant consent to place cookies on the user’s device. The Court’s conclusion follows from reading Article 5(3) of the ePrivacy directive in conjunction with Article 2(h) of Directive 95/46/EC, and noting that active consent is now regulated under GDPR. For the consent to be valid, it must be “given” on the basis of “clear and comprehensive information” communicated to the user. The requirement for the information to be “clear and comprehensive” implies that in cases where the cookie aim to collect information for advertising purposes, there should be information about “the duration of the operation of cookies and whether or not third parties may have access to those cookies”. Worth noting here is that the Court explicitly referred to Article 13 GDPR and Article 10 Directive 95/46/EC as the relevant framework for determining which information should be provided to the user. The ePrivacy directive and GDPR — The German law transposing the ePrivacy directive establishes a difference between the collection of “personal data” and other data. The Court referenced the earlier opinion of the AG, noting that the AG correctly interpreted the provision to protect the user from any privacy interference, irrespective of whether that interference concerns personal data or other data. The obligation to secure a valid consent for the placement of cookies is therefore applicable regardless of the legal status of that information. A consequence of this view is that the German incorporation of directive 2002/58 is not fully in line with the directive. It is worth highlighting that Article 5(3) of the ePrivacy directive carves out an exception for the consent requirement for cookies that are “strictly necessary” to provide the service as requested by the user. In broad strokes, this means that so-called “functional cookies” that are essential for browsing and using the website, typically for holding items in the cart while browsing a web shop, are exempt for the consent requirement (most often first-party session cookies).

### French Supreme Court upholds €8M CNIL fine against Apple for App Store ad tracking

*Source: Supreme Administrative Court, 2025-10-10 — https://overview.legal/posts/122852 — original: https://gdprhub.eu/index.php?title=CE_-_473833*

Facts — The DPA imposed an €8 million administrative fine on Apple (the controller) in 2022 (CNIL - SAN-2022-025). The DPA found that Apple used identifiers stored on users’ devices to enable personalized advertising in the App Store without first obtaining valid user consent, as required by Article 82 of the French Data Protection Act, which implements Article 5(3) of the ePrivacy Directive. Apple challenged the sanction before the Supreme Administrative Court (Conseil d’État), arguing that the DPA lacked jurisdiction, that the investigation violated Apple’s procedural rights, that the advertising-related processing did not fall within the scope of Article 82, and that the case should be referred to the Court of Justice of the EU. Apple also claimed that the fine was disproportionate. Holding — The court held that reading identifiers stored on user devices for the purpose of delivering personalised advertising constitutes access to information under Article 5(3) of the ePrivacy Directive, requiring the controller to obtain the user’s prior consent. It reasoned that since this operation was to implement personalized advertising it could not fall within the exemptions to the consent requirement. The court found that the national authority was competent because the controller’s establishment within the country contributed to the advertising operations in question. It did so by marketing devices pre-equipped with the App Store where personalized advertising appears and by providing Search Ads Specialists who helped monetize and optimize that advertising space. It also rejected the controller’s claim that the authority had violated its procedural rights, finding that the right to remain silent did not apply during CNIL investigations and that the authority had lawfully carried out the investigation providing sufficient opportunity for the controller to respond. Additionally, the court rejected Apple's request to reference the case to the Court of Justice of the EU stating that there wasn't any reasonable doubt Finally, it held that the €8 million fine was proportionate, noting the scale of the processing, the number of affected users, and the economic significance of the advertising activity.

### BVwG - W258 2227269-1/39E

*Source: Federal Administrative Court, 2024-12-27 — https://overview.legal/posts/184564 — original: https://gdprhub.eu/index.php?title=BVwG_-_W258_2227269-1/39E*

Facts — On the 8 January 2019, the Austrian DPA (Datenschutzbehörde – DSB) launched an investigation into the actions of the Austrian postal service as it also had a business license for address publishing and direct marketing. Media reports had claimed that the postal service (the controller) sold data concerning the political affinities of data subjects to third parties. The controller ran a platform entitled “Adress Shop” on which it sold personal data to legal entities. The datasets included names and addresses but more importantly it included data subjects’ affinities to certain things such as an affinity to moving house, an affinity to organic products or how frequently a data subject receives packages. The purpose of the data processing was to sell this data to third parties who would use it for marketing purposes and therefore could avoid scattering losses. In order to create this database, the controller abused its position as postal service provider. In the postal service contract provided to data subjects the controller had included a notice stating that data subject are agreeing to their personal data being processed for marketing purposes. The contract however also included a box which could be ticked in order to refuse the data processing for marketing purposes. One of these affinities was concluded through an affinity score concerning the main political parties in Austria. For example, data subjects would be assessed with either a “very low”, “low”, “high” or “very high” affinity towards the SPÖ (the Socialist Party of Austria), the ÖVP (the Conservative Party of Austria) or any other major political party. The controller calculated this score through combing anonymous survey results, socio-demographic data (e.g., age or level of income and education) and voting results of particular region. On the 20 Febuary 2019, the DSB alleged that the controller had unlawfully processed sensitive data under Article 9 GDPR. The DSB found that the controller could not rely on a legal basis for the processing of this data and that the controller had sold the data to third parties. The DSB issued a fine of fine of €18,000,000 for the processing of sensitive data and other violations. The full details can be found here. On the 25 November 2019, the controller appealed the decision of the DSB to the Austrian Federal Administrative Court (Bundesverwaltungsgericht – BVwG) and alleged that the DSB had inadequately assessed the situation. On the 26 November, the BVwG annulled the decision of the DSB stating that the DSB had failed to name a natural person to whom the actions of the controller could be attributed to. Based on an Austrian provision, namely paragraph 45(1)(3) of the Administrative Penal Code (Verwaltungsstrafgesetz - VStG), in order to fine a legal person for a violation of the GDPR all necessary requirements for the penalization of a natural person must be fulfilled. This finding was however annulled by the Supreme Administrative Court (Verwaltungsgerichtshof – VwGH) on the 1 February 2024. The VwGH explained that although the BVwG correctly applied the national provision, the CJEU case C-807/21 Deutsche Wohnen showed that Article 58(2)(i) GDPR and Article 83 GDPR are excluded from national derogations. Therefore, the BVwG should not have applied the national provision. The case was therefore reverted back to the BVwG. Holding — The BVwG reassessed the case and partly upheld the DSB decision but made the following alterations. Article 9 GDPR data related to political affinities The BVwG confirmed that the controller had at no point in time obtained the consent of the data subject and therefore was processing data in violation of Article 9(1) GDPR since the 25 May 2018. The BVwG held that the controller's conduct had proved negligent. The BVwG noted that the controller had made efforts to apply the GDPR correctly but criticized for example that the DPO had to monitor all processing activities which did not prove an effective monitoring and controlling system as it would require too much time for just one person. The BVwG held that it was clearly unacceptable that the DPO thought that the data processed did not constitute personal data, especially when it was explicitly connected to an individual person. Further, The BVwG found that the controller never conducted an assessment on whether certain affinities could constitute sensitive data under Article 9 GDPR. The BVwG classified this as grossly negligent behaviour on the part of the controller. The BVwG concluded that the controller should have consulted an external expert around the uncertainties it had concerning the correct application of the GDPR. Affinity towards receiving packages In relation to the data processed to assess their affinity for receiving packages, the controller was in a privileged position to have access to the relevant data. However, it then further processed this data contrary to their legal mandate for creating projection models for marketing purposes in violation of Article 6(4) GDPR. The court also held that this violated the principles of fairness and transparency under Article 5(1)(a) GDPR. The BVwG highlighted that the controller knew that its positions as postal service provider and data broker is likely to cause issues, therefore its behaviour was classified as negligent. Affinity towards moving house Assessing whether data subjects were likely to move house differed to the assessment of an affinity towards receiving packages as there was a contractual relationship between the data subject and the controller due to contractual redirection orders. The BVwG assessed that the minimal information provided to data subjects on the processing for marketing purposes, proved to be just about enough as the personal data was made up of a calculation of averages which was then anonymized. The court found that this could be classified as processing which, based on the controllers description, could be expected from the notice included in the contract. In addition, data subjects could easily refuse the data processing. Data Protection Impact Assessment The controller had processed an extensive amount of sensitive data which requires a data protection impact assessment. The controller’s assessment that this data processing was of low risk was therefore faulty. The controller had therefore violated Article 35(3)(b) GDPR and Article 35(7) GDPR. The BVwG held that as the controller had negligently categorized its processing as not concerning any sensitive data, it consequently also proves to have acted negligently in assessing the risks under Article 35 GDPR. The BVwG rejected the controller’s argument that penalization under Article 35 GDPR would result in a double punishment for the same offence. It explained that the general obligations under the GDPR pursue a different aim to the provisions governing lawfulness of the processing. Further, the DPIA is to be conducted prior to processing. Records of processing The faulty and therefore inadequate DPIA resulted in a violation of Article 30(1)(c) GDPR, which requires the records of data processing to include the categories of data processed. The BVwG again assessed that the controller had acted negligently in relation to this aftereffect of its faulty categorization of the processed data. The controller had merely stated that the data would be processed for marketing purposes and this was held to have been inadequate as the controller processed data such as the political affinities. The BVwG held that the controller had failed to provide a full description of all the processed categories. Fine The BVwG reduced the fine to €16 million mainly based on the controller's low annual turnover. Further, the BVwG noted that the political data had only been sold to two political parties which resulted in a limited amount of data subjects being affected.

### BVwG - W 108 2284491-1

*Source: Federal Administrative Court, 2024-07-31 — https://overview.legal/posts/122850 — original: https://gdprhub.eu/index.php?title=BVwG_-_W_108_2284491-1*

Facts — The data subject visited a website operated by a media company (the controller). Upon opening the website a cookie banner showed up. This cookie banner was designed in such a way that a reject button was “hidden” in a second layer. The cookie banner’s first layer presented only an option to accept the cookies or to manage the options. The cookie manage option was presented as a link. When the data subject clicked on the accept button, they also agreed to pre-ticked options, visible only within the cookie management link. The reject button was a part of the second layer of the cookie banner (within the cookie management link). The data subject lodged a complaint with the Austrian DPA (DSB), claiming the controller violated, inter alia, Article 5(1)(a) GDPR and Article 6(1)(a) GDPR. The data subject was represented by noyb. The controller argued to the DPA that the website provided access to online newspaper articles. Because of that, the processing activities were carried for journalistic purposes and the DPA was not competent to hear the case. In the meantime the controller updated the settings of the cookie banner and introduced a reject button on its first layer, next to the accept button. Also, the link to manage the cookie settings was redesigned as a button. Moreover, the controller added a floating icon, allowing the website users to withdraw the consent given at any time. If a website user rejected the cookies or withdrew the consent via the floating icon, the controller would interpret such a conduct to be an objection under Article 21 GDPR. Additionally, the controller informed they deleted the data concerning the data subject. In response, the data subject emphasized that due to new settings of the website, the controller wrongly qualified certain cookies to be strictly necessary. In consequence, the controller installed the cookies before the website’s user interacted with the cookie banner, violating Article 5(3) ePrivacy Directive. Although the controller announced that it would implement a completely new cookie banner, they later retracted from that plan. The controller changed the cookie banner and – after improving it initially – removed the reject button again. Eventually, updated cookie banner didn’t include a reject button on the first layer any longer. The DPA issued a decision, ordering the controller to modify the cookie banner so that its first layer offered an option to close the cookie banner without giving consent. This option had to be visually equivalent to the accept button. The DPA rejected the applications of the data subject regarding the deletion of its data, an order to stop unlawful processing and establishing the violation of data confidentiality (“Recht auf Geheimhaltung”). The controller appealed the DPA’s order to introduce an equivalent reject option in the first layer of its cookie banner to the Federal Administrative Court (Bundesverwaltungsgericht – BVwG). After hearing the parties and visiting the website itself the court issued its decision. Holding — The court dismissed the appeal of the controller as unfounded. No exemption from the GDPR through media privilege (“Medienprivileg”) — The controller’s processing activities didn’t fall within the scope of journalistic purposes. The court emphasised that the controller placed the cookies and processed the collected data for analytical and advertising purposes. Need for an equivalent reject option in cookie banners — The court also upheld the interpretation of the DPA that the first layer of the cookie banner needs to contain a visually equivalent option to reject cookies. According to the court Article 7(3) GDPR implies that refusing consent shall be as easy as giving consent. In particular, refusing consent shall not require more interactions than giving consent. In the case at hand consenting required only one click, whereas rejecting consent required two clicks. Therefore no equivalence between the options was given. Furthermore, the different design of the options in the first layer – a button for consent on one hand and a link to access the second layer on the other – equally lead to the conclusion that the options cannot be considered equivalent. A mere explanation in the first layer of the cookie banner on how to reject cookies does not change this assessment. Additionally, the cookie manage link at the bottom of the website is not an equivalent option either, since it is only available after an interaction with the cookie banner. Hence, the DPA order was found to be correct. The court did not find that the controller had complied with this order in the meantime.

### Judgment of the Court (Tenth Chamber) of 13 June 2024.#Criminal proceedings against HYA and Others.#Request for a preliminary ruling from the Sofiyski gradski sad.#Reference for a preliminary ruling – Telecommunications sector – Processing of personal data and the protection of privacy – Directive 2002/58/EC – Article 15(1) – Restriction of the confidentiality of electronic communications – Judicial decision authorising listening, tapping and storage in respect of telephone conversations of pers

*Source: Court of Justice of the European Union, C-229/23, 2024-06-13 — https://overview.legal/posts/132256 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0229*

In a preliminary ruling brought by the Sofia City Court in criminal proceedings against HYA and others, the Court of Justice of the European Union interpreted Article 15(1) of Directive 2002/58/EC (the ePrivacy Directive) in conjunction with Article 47 of the Charter of Fundamental Rights. The core issue was whether national legislation requiring judicial authorization for the interception of electronic communications to contain an express written statement of reasons—even where the criminal authorities had already submitted a reasoned application—complies with EU law. The Court ruled that the second paragraph of Article 47 of the Charter imposes an obligation on national courts to provide an express statement of reasons in their own decisions authorizing such interception measures, independent of any reasoned application by prosecuting authorities, to ensure adequate judicial safeguards for the fundamental right to privacy.

### CJEU - C‑178/22 - Procura della Repubblica presso il Tribunale di Bolzano

*Source: GDPRhub, 2024-04-30 — https://overview.legal/posts/158447 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑178/22_-_Procura_della_Repubblica_presso_il_Tribunale_di_Bolzano*

Facts — Two complaints were lodged with the Italian Public Prosecutor's office concerning acts of mobile theft. In order to identify the perpetrators, the Public Prosecutor's office requested an authorisation to obtain the telephone records of the stolen telephones from all the telephone companies. These requests concerned all the data in the possession of the telephone companies, with tracking and localisation methods, in particular the users and International Mobile Equipment Identity (IMEI) codes of the devices called or making the calls, the sites visited and reached, the times and durations of the calls and connections, the details of the cells and/or towers concerned, and the users and IMEI code of senders and receivers of SMS and MMS. These requests were made to the judge responsible for preliminary investigations at the District Court, Bolzano (‘Giudice delle indagini preliminari presso il Tribunale di Bolzano’) on the basis of an Italian National law, Article 132(3) of Legislative Decree n°196/2003. The referring court was uncertain whether Article 132(3) of Legislative Decree n°196/2003 is compatible with Article 15(1) of Directive 2002/58 (‘ePrivacy Directive’) as interpreted by CJEU, 2 March 2021, Prokuratuur, C-746/18. First, according to paragraph 45 of that judgement, national provisions that allow public authorities to access telephone records containing a set of traffic or location data are justifiable if those provisions are intended for the prosecution of serious offences such as threats to public security and other serious crimes. Second, Article 132(3) of Legislative Decree n°196/2003 establishes that if there is sufficient evidence of the commission of an offence for which the penalty is a maximum term of imprisonment of at least three years, the Public Prosecutor may acquire data relevant to the facts, with the prior authorization of the court. According to the referring court, the Italian courts have a very limited margin of discretion to refuse authorisation to obtain telephone records as the authorization must be granted when there is ‘sufficient evidence of the commission of an offence’ and the data requested are ‘relevant to establishing the facts’. The Giudice delle indagini preliminari presso il Tribunale di Bolzano decided to stay the proceedings and referred the following question to the CJEU: Does Article 15(1) of the ePrivacy Directive preclude a national provision which requires a national court to authorise access to a set of traffic or location data for the purposes of investigating a criminal offence with a penalty of a maximum term of imprisonment of at least 3 years, provided that there is sufficient evidence and that those data are relevant to establishing the facts? Holding — Firstly, the CJEU indicated that access to traffic and location data retained by providers of electronic communications services may be granted to public authorities for the purposes of the prevention, investigation, detection and prosecution of criminal offences pursuant to a national law adopted under Article 15(1) ePrivacy Directive. However, a legislative measure cannot allow the general and indiscriminate retention of traffic and location data as a preventative measure (§35 of the Judgement). The CJEU also held that only the objectives of combating serious crime or preventing serious threats to public security are capable of justifying a serious interference with the fundamental rights of Articles 7 and 8 of the Charter (§36 of the Judgement). Secondly, the CJEU assessed the question of whether access to the traffic and location data in the present case may be classified as a serious interference with the fundamental rights guaranteed by Articles 7 and 8 of the Charter. Access to the set of traffic or location data requested in the present case may allow precise conclusions to be drawn concerning the private lives of the persons whose data have been retained, for example the habits of their everyday life, their permanent or temporary places of residence, their daily movements, the activities they carried out, their social relationships and social environments frequented by them. The CJEU found that in such a case, the interference with the fundamental rights guaranteed in Articles 7 and 8 of the Charter would likely to be classified as serious (§39 of the Judgement). The Court considered that for the purposes of assessing the existence of a serious interference with the fundamental rights, it was irrelevant that the access may not concern the data of the owners of the phones, but the data of the persons who communicated with each other after the theft. Indeed, Article 5(1) ePrivacy Directive establishes that the obligation to ensure confidentiality of the traffic data covers communications made by the ‘users’ of that network. The ‘users’ are defined as any natural person using a publicly available electronic communications service, without necessarily having subscribed to that service (§41 of the Judgement). Thirdly, the CJEU added that national law determines the conditions under which providers of electronic communications services grant access to the data in the provider's possession. However, the legislation must lay down clear and precise rules governing the scope and conditions for the application of such access. As a general rule, the CJEU noted that access can be granted in relation to the objective of fighting crime, only for the data of individuals suspected of being implicated in a serious crime. The Court also pointed out that in order to ensure that the interference is limited to what is strictly necessary, the access must be subject to a prior review carried out by a court or an independent administrative body. This does not apply in cases of duly justified emergency (§43 of the Judgement). Regarding the definition of the concept of 'serious offence', the EU has not legislated in that field. This concept reflects social realities and legal traditions, which vary between the Member States and over time. Therefore, it is up to the Member States to define 'serious offences’ for the purposes of applying Article 15(1) ePrivacy Directive (§46 of the Judgement). The CJEU recalled that Article 15(1) ePrivacy Directive is an exception to the obligation to ensure the confidentiality of electronic communications and data and must not become the rule (§48 of the Judgement). Furthermore, the national measures taken by Member States under this provision must comply with the general principles of EU law, in particular the principle of proportionality and ensuring respect for the fundamental rights enshrined in Articles 7, 8 and 11 of the Charter (§49 of the Judgement). Therefore, the Court considered that Member States must not distort the concept of ‘serious offence’ and ‘serious crime’ by including within it, offences which are manifestly not serious offences. In the present case, the CJEU pointed out that Article 132(3) Legislative Decree n°196/2003 defines the offences for which access to data retained by providers of electronic communications services may be granted, by reference to a maximum term of imprisonment of at least three years. Additionally, there must be sufficient evidence to the commission of an offence and the data must be relevant to establishing the facts (§52 of the Judgement). The CJEU held that the definition of ‘serious offence’ cannot cover the vast majority of criminal offences, which would be the case if the maximum term of imprisonment was sent at an excessively low level. The Court considered that a maximum term of imprisonment of three years does not appear excessively low (CJEU, 21 June 2022, Ligue des droits humains, C-817/19, §150). Lastly, the CJEU found that setting a maximum term of imprisonment may create a situation in which the access would be requested for the purposes of prosecuting offences which do not constitute a serious crime. However, the Court held that setting a minimum period above which the maximum term of imprisonment for an offence justifies the classification of that offence as a serious offence is not necessarily contrary to the principle of proportionality (§58 of the Judgement). Thus, the CJEU concluded that Article 15(1) ePrivacy Directive does not preclude a national provision which requires a national court, acting in the context of a prior review, to authorise access to traffic or location data for the purposes of investigating criminal offences punishable under national law by minimum 3 years imprisonment. However, the court must be entitled to refuse such access in the context of investigating an offence which is manifestly not a serious offence in the light of the societal conditions prevailing in the Member State concerned.

### Judgment of the Court (Full Court) of 30 April 2024.#La Quadrature du Net and Others v Premier ministre and Ministère de la Culture.#Request for a preliminary ruling from the Conseil d'État (France).#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Confidentiality of electronic communications – Protection – Article 5 and Article 15(1) – Charter of Fundamental Rights of the European Unio

*Source: Court of Justice of the European Union, C-470/21, 2024-04-30 — https://overview.legal/posts/132259 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0470*

In Case C-470/21, the CJEU addressed a preliminary reference from the French Conseil d'État concerning La Quadrature du Net and others v. Premier ministre and Ministre de la Culture, which challenged France's "graduated response" system allowing public authorities to access civil identity data associated with IP addresses retained by ISPs for the purpose of combating online copyright infringement. The Court ruled that while such access may be justified under Article 15(1) of Directive 2002/58/EC (the ePrivacy Directive) for intellectual property protection, it requires strict safeguards including prior review by a court or independent administrative body, and must be limited to what is strictly necessary, proportional, and subject to substantive and procedural protections against abuse. No fine was imposed as this was a preliminary ruling.

### Judgment of the Court (First Chamber) of 7 September 2023.#A. G. v Lietuvos Respublikos generalinė prokuratūra.#Request for a preliminary ruling from the Lietuvos vyriausiasis administracinis teismas.#Reference for a preliminary ruling – Telecommunications – Processing of personal data in the electronic communications sector – Directive 2002/58/EC – Scope – Article 15(1) – Data retained by providers of electronic communications services and made available to authorities in charge of criminal pro

*Source: Court of Justice of the European Union, C-162/22, 2023-09-07 — https://overview.legal/posts/132283 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0162*

In Case C-162/22, the Court of Justice of the European Union interpreted Article 15(1) of Directive 2002/58/EC (the ePrivacy Directive) in response to a preliminary reference from the Lithuanian Supreme Administrative Court concerning A.G.'s challenge to his dismissal as a prosecutor by the Lithuanian Prosecutor General's Office. The core issue was whether telecommunications data retained by providers and initially accessed for criminal proceedings could subsequently be used by authorities in an investigation into misconduct in office. The Court held that such data, retained and accessed under Article 15(1) for the purpose of criminal proceedings, may be reused for investigating misconduct in office provided that the subsequent use is subject to strict safeguards ensuring necessity and proportionality, and is surrounded by robust substantive and procedural protections.

### CJEU - C-162/22 - Lietuvos Respublikos generalinė prokuratūra

*Source: GDPRhub, 2023-09-07 — https://overview.legal/posts/125587 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-162/22_-_Lietuvos_Respublikos_generalinė_prokuratūra*

Facts — The Lithuanian Prosecutor General´s Office investigated one of its public prosecutors, who was found responsible of misconduct in its office. The research into the public prosecutor´s misconduct was authorised by a court order, allowing for the interception and recording of data transmitted over electronic communication. Following these findings, the Prosecutor General´s Office dismissed the public prosecutor from office. The public prosecutor contested the decision before the Regional Administrative Court (Vilniaus apygardos administracinis teisma), which dismissed the claim due to the lawfulness of the criminal intelligence operations and process behind the data gathered. The controller then appealed the case to the Supreme Administrative Court (Lietuvos vyriausiasis administracinis teisma), as he alleged that the access by intelligence bodies to traffic data and actual content of electronic communications was such a serious interference with fundamental rights that access could only be granted to combat serious crime. The Supreme Administrative Court considered it apparent that Article 15(1) ePrivacy Directive 2002/58/EC, together with Article 3ePrivacy Directive 2002/58/EC thereof, extends the scope of that directive only to legislative measures requiring providers of electronic communications services to grant the competent national authorities access to data (as found in C-623/17 Privacy International). Moreover, it follows from C-746/18 Prokuratuur, that only actions to combat serious crime and measures to prevent serious threats to public security are capable of justifying serious interference with Article 7 CFR and Article 8 CFR (hereinafter: the Charter). However, the CJEU did not yet rule on the impact of the subsequent use of the data concerned on the interference with fundamental rights. The Supreme Administrative Court doubted whether such subsequent use constituted a serious interference with Article 7 CFR and Article 8 CFR, and whether such use is justifiable only for the purposes of combating serious crime and preventing serious threats to public security. Thus, the Supreme Administrative Court of Lithuania referred to the CJEU the following preliminary question: - Whether Article 15(1) ePrivacy Directive 2002/58/EC precludes the use, in connection with investigations into corruption-related misconduct in office, of personal data relating to electronic communications retained, pursuant to an authorised order, by providers of electronic communications services and subsequently made available to the competent authorities to combat serious crime? Holding — The CJEU pointed out that the referring court only questions the subsequent use of personal data retained by electronic communication providers on the basis of Article 15(1) Directive 2002/58. Thus, the data to be considered in this preliminary ruling decision is the data retained on the basis of Article 65(2) of Lithuanian Law on Electronic Communications, which, together with Annex I, requires electronic service providers to retain, generally and indiscriminately, traffic and location data relating to such communications for the purpose of combating serious crime. The CJEU considered that the subsequent use of traffic and location data relating to electronic communications, to combat serious crime, is only possible on two conditions: - retention of those data by providers of electronic communications services must be consistent with Article 15(1) ePrivacy Directive 2002/58/EC; and - access to those data granted to the competent authorities must be itself consistent with that provision. In C-793/19 SpaceNet and Telekom Deutschland, legislation allowing the pre-emptive retention of traffic and location data was considered not in line with EU law. However, legislation allowing for data retention under strict requirements to combat serous crime and prevent serious threats to public security was allowed under ePrivacy Directive 2002/58/EC. In light of these preliminary remarks, the CJEU started its analysis by stating that Article 15 ePrivacy Directive 2002/58/EC allows Member States to introduce exceptions to the obligations laid out in Article 5(1) ePrivacy Directive 2002/58/EC for the safeguard of national security, defence and public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system. However, the CJEU considered that Article 15 ePrivacy Directive 2002/58/EC cannot expand excessively the exception to the principle of confidentiality and data storage present in Article 5 Directive 2002/58. Thus, the CJEU reiterated that the objectives listed in Article 15(1) ePrivacy Directive 2002/58/EC is exhaustive. Once having established that no other objectives can be added to the ones laid out in Article 15 ePrivacy Directive 2002/58/EC, the CJEU considered that there is a hierarchy behind the objectives according to their importance, which in turn needs to be balanced against the seriousness of the interference to an individual´s life it entails (C-140/20 Commissioner of An Garda Síochána and Others). The objective of safeguarding national security exceeds in importance the other objectives of Article 15 Directive 2002/58 and, thus, can justify more serious interference with Article 7 CFR and 8 CFR. Differently, with regards to the objective of preventing, investigating, detecting and prosecuting criminal offenses, only actions to combat serious crime and serious threats to public security can justify a serious interference with Article 7 CFR and Article 8 CFR. Thus, deciding whether there is a justification to the limitations to Article 5 ePrivacy Directive 2002/58/EC, Article 6 ePrivacy Directive 2002/58/EC and Article 9 ePrivacy Directive 2002/58/EC depends on the seriousness of the interference stemming from this limitation and on the importance of public interest objective pursued by that limitation in relation to its seriousness (C-511/18 La Quadrature du Net and Others). This reasoning applies mutatis mutandis to the subsequent use of traffic of location data retained by providers of electronic communications services ex Article 15(1) ePrivacy Directive 2002/58/EC. In the case at hand, for the CJEU, the fact that the referring Supreme Administrative Court did not indicate any threat to public security in its documents, and that investigating a misconduct in office does not correspond to the objective of prosecuting and punishing criminal offenses, ex Article 15(1) ePrivacy Directive 2002/58/EC, proves that investigations of misconduct in office does not fall within the category of combating serious crime. Therefore, the CJEU found that Article 15(1) ePrivacy Directive 2002/58/EC, read in the light of Article 7 CFR, Article 8 CFR, Article 11 CFR and Article 52(1) CFR, does not allow the use, in connection with investigations into corruption-related misconduct in office, of personal data relating to electronic communications which have been retained by providers of electronic communications services and which have subsequently been made available to the competent authorities for the purpose of combating serious crime.

## Guidance

### Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive

*Source: EDPB, edpb-guidelines-on-technical-scope-of-art-53-of-eprivacy-directive, 2024-10-16 — https://overview.legal/posts/38063 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22023-on-technical-scope-of-art-53-of-eprivacy-directive_en*

The European Data Protection Board (EDPB) issued Guidelines 2/2023 to clarify the technical scope of Article 5(3) of the ePrivacy Directive, focusing on its application to emerging tracking technologies that operate as alternatives to cookies. The guidelines establish three key elements—information, terminal equipment, and gaining access/storage—to determine whether specific technical operations require user consent. The document applies this framework to common use cases such as URL and pixel tracking, local processing, IP-based tracking, intermittent IoT reporting, and the use of unique identifiers.

### Report of the work undertaken by the Cookie Banner Taskforce

*Source: EDPB, report-of-the-work-undertaken-by-the-cookie-banner-taskforce-en, 2023-01-18 — https://overview.legal/posts/125875 — original: https://www.edpb.europa.eu/documents/task-force-report/report-of-the-work-undertaken-by-the-cookie-banner-taskforce_en*

Adopted 1 Report of the work undertaken by the Cookie Banner Taskforce Adopted on 17 January 2023 Adopted 2 Adopted 3 DISCLAIMER The positions presented in this document result from the coordination of the members of the TF with a view to handling the “cookies banner” complaints received from NOYB. They reflect the common denominator agreed by the SAs in their interpretation of the applicable provisions of the ePrivacy Directive, and of the applicable provisions of the GDPR, for the analysis to…

### Statement 03/2021 on the ePrivacy Regulation

*Source: EDPB, statement-032021-on-the-eprivacy-regulation-en, 2021-03-09 — https://overview.legal/posts/126052 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-032021-on-the-eprivacy-regulation_en*

1 Statement 03/2021 on the ePrivacy Regulation Adopted on 9 March 2021 The European Data Protection Board has adopted the following statement: The EDPB welcomes the agreed negotiati on mandate adopted by the Council on the protection of privacy and confidentiality in the use of electronic communication services ( ’ the Council ’s position ’ ) , as a positive step towards a new ePrivacy Regulation . It is of utmost importance that the EU gen eral data protection framework is rapidly complemented…

### Statement on the ePrivacy Regulation and the future role of Supervisory Authorities and the EDPB

*Source: EDPB, statement-on-the-eprivacy-regulation-and-the-future-role-en, 2020-11-19 — https://overview.legal/posts/126113 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-the-eprivacy-regulation-and-the-future-role_en*

1 Statement on the ePrivacy Regulation and the future role of Supervisory Authorities and the EDPB Adopted on 19 November 2020 The European Data Protection Board has adopted the following statement: Firstly, the EDPB wants to stress that this statement is without prejudice to its previous positions , including s tatement 3/2019 1 and its statement of 25 May 2018 2 . The ePrivacy Regulation must under no circumstances lower the level of protection offered by the curren t ePrivacy Directive…

### EDPB Annual Report 2019

*Source: EDPB, edpb-annual-report-2019-en, 2020-05-18 — https://overview.legal/posts/126163 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2019_en*

EDPB Annual Report 2019 1 EDPB Annual Report 2019 1 European Data Protection Board 2019 Annual Report WORKING TOGETHER FOR STRONGER RIGHTS An Executive Summary of this report, which provides an overview of key EDPB activities in 2019, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. EDPB Annual Report 2019 EDPB Annual Report 2019 2 3 FOREWORD 1 4 MISSION STATEMENT, TASKS AND PRINCIPLES 2 5 Tasks and duties Guiding principles 5 6 2.1. 2.2 . ABOUT…

### Statement 3/2019 on an ePrivacy regulation

*Source: EDPB, statement-32019-on-an-eprivacy-regulation-en, 2019-03-13 — https://overview.legal/posts/126229 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32019-on-an-eprivacy-regulation_en*

1 Statement 3 / 2019 on an ePrivacy r egulation Adopted on 13 March 2019 The European Data Protection Board has adopted the following statement: The EDPB calls on the EU legislators to intensify efforts towards the adoption of a n ePrivacy Regulation , which is necessary to complete the EU’s framework for data protection and confidentiality of communications. The EDPB wishes to reiterate the positions previously adopted by data protection authorities in the EU, including the Opinion 1/2017 of…

### Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities

*Source: EDPB, opinion-52019-on-the-interplay-between-the-eprivacy-directive-en, 2019-03-12 — https://overview.legal/posts/126232 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-52019-on-the-interplay-between-the-eprivacy-directive_en*

adopted 1 Opinion 5 / 2019 on the i nterplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities Adopted on 12 March 2019 adopted 2 adopted 3 The European Data Protection Board Having regard to article 63 and article 64 (2) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free…

### Statement of the EDPB on the revision of the ePrivacy Regulation and its impact on the protection of individuals with regard to the privacy and confidentiality of their communications

*Source: EDPB, statement-of-the-edpb-on-the-revision-of-the-eprivacy-en, 2018-05-25 — https://overview.legal/posts/126329 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-of-the-edpb-on-the-revision-of-the-eprivacy_en*

Statement of the EDPB on the revision of the ePrivacy Regulation and its impact on the protection of individuals with regard to the privacy and confidentiality of their communications The Data Protection Authorities of the European Union, united in the European Data Protection Board, consider that the revision of the current ePrivacy Directive (2002/58/EC, amended by 2009/136/EC) is an important and necessary step that has to be concluded rapidly. The use of IP based communication services has…

## Enforcement decisions

### ICO (UK) - Allay Claims Ltd

*Source: ICO (UK), 2026-01-15 — https://overview.legal/posts/52735 — original: https://gdprhub.eu/index.php?title=ICO_(UK)_-_Allay_Claims_Ltd*

Facts — Allay Claims Ltd (the controller) sent over 4 million direct marketing text messages to individuals promoting a different entity’s services. The DPA received over 48,000 complaints regarding the direct marketing messages sent by the controller over the course of one year. The controller claimed it relied on the soft opt-in in Regulation 22(3) of the Privacy and Electronic Communications Regulations 2003 (PECR), where an organisation may send direct marketing communications to its customers even if they did not specifically consent to electronic mail. However, only the organisation that collected the contact details can rely on the soft opt-in rule. The controller therefore argued that it did not require the consent of the individuals for such direct marketing messages. It further argued that the recipients of the messages were previous customers. Holding — The DPA noted that the controller did not obtain valid consent from the data subjects for electronic direct marketing messages. Subsequently, the DPA analysed if the controller could have relied on the soft opt-in exception. However, the DPA found that data subjects did not have the opportunity to refuse direct marketing communications at the moment of collection of customer details. Thus, the DPA found that the controller breached Regulation 22(3)(c) PECR, ordered the cessation of unlawful direct marketing communications and fined the controller GBP 120,000 (approximately €138,000).

### Belgian DPA: Political campaign email without consent violates GDPR and ePrivacy

*Source: APD/GBA (Belgium), 2024-05-16 — https://overview.legal/posts/158448 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_74/2024*

Facts — On 30 January 2024, the data subject received an email from a candidate in the June 2024 regional elections (‘controller’), promoting their programme. On 3 January 2024, the data subject responded to the email indicating that Belgian law prohibits political spamming practices. He also indicated that he no longer wished for the controller to use his data, and made an access request, in particular to understand where the controller collected his personal data. On 5 February 2024, the controller responded to the access request by explaining that the data subject’s personal data was probably already in his address book, although it was possible that friends had given it to him. On 5 April 2024, the data subject lodged a complaint with the Belgian DPA (‘APD’). Holding — First, regarding the use of the data subject’s email address for electoral propaganda purposes, Article 6(1)(a) GDPR establishes that the processing of personal data is lawful if the data subject has consented to the processing. Article 13(1) ePrivacy directive states that the use of an email for the purposes of direct marketing may be authorised only if the targeted subscribers have given consent. Furthermore, the APD published a note on the processing of personal data in the context of elections in which it established that the targeting people with political propaganda on the basis of voters’ personal data must be considered direct marketing within the meaning of the GDPR and ePrivacy Directive. In the present case, the APD noted that the data subject did not give consent to the processing of his email address for direct marketing purposes. Therefore, the DPA held that the controller may have breached Article 6(1)(a) GDPR as well as Article 13(1) ePrivacy directive. The DPA examined the possibility of invoking legitimate interest under Article 6(1)(f) GDPR as a legal basis. This article establishes that the processing of personal data is lawful if it is necessary for the purposes of the legitimate interests pursued by the controller, unless the interests or fundamental rights and freedoms of the data subject prevail. Recital 47 GDPR states that the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest. In CJEU, 4 May 2017, Rigas, C-13/16, the Court of Justice held that Article 6(1)(f) GDPR lays down three cumulative conditions. (i) the pursuit of a legitimate interest by the controller, (ii) the necessity of the processing in order to achieve the legitimate interest pursued and (iii) the fundamental rights and freedoms of the data subject must not prevail. Regarding the pursuit of a legitimate interest, Belgian law provides that candidates in elections may promote their programme through communications. Moreover, the APD described the controller’s interest as ‘sending direct marketing communications to promote the electoral programme for the regional elections in June 2024’. Thus, the controller’s interest is sufficiently specific that it represents a real and present interest. The APD considered that the controller is pursuing a legitimate interest. Regarding the necessity of the processing in order to achieve the legitimate interest, the APD took into account the existence of less intrusive means to attain the objective. The DPA considered that an election programme can be promoted by means of flyers placed in people’s mailboxes for example, which is far less intrusive, even if It may require some extra effort. Therefore, the APD held that the direct marketing was not strictly necessary to the legitimate interest pursued, namely the promotion of its electoral programme. Thus, the APD concluded that the controller may have committed a potential breach of Article 6 GDPR. Second, regarding the access request in order to discover the source of the data used, the APD considered that the controller sent vague and imprecise information about the source of the data subject’s personal data. Therefore, the APD concluded that there may have been a breach of Articles 5(1)(a) and 12(1) GDPR. Hence, the APD issued a prima facie warning to the controller.

### IP - 07121-1/2020/1570

*Source: IP (Slovenia), 2020-09-11 — https://overview.legal/posts/158458 — original: https://gdprhub.eu/index.php?title=IP_-_07121-1/2020/1570*

Facts — The IP received a request for an opinion concerning sending of an SMS message to users about the new #StayHealthy app created by the National Institute of Public Health (NIJZ). The SMS message was to be carried out on a voluntary basis by operators at the initiative of NIJZ. The opinion relates to the legal basis for this SMS message. Dispute — Is there a legal basis under Slovenian national law for sending an SMS message to all users about a new application launched by the Slovenian National Institute of Public Health? Holding — The IP held that Article 6(3) GDPR applies in this context. As such the legal basis for processing is laid down by the Slovenian Electronic Communications Act (ZEKom-1). To come to this conclusion, the IP referred to the EDPB Opinion 5/2019 on the relationship between the ePrivacy Directive 2002/58/EC (transposed into Slovenian law by ZEKom-1) and the GDPR to establish that ZEKom-1 applies. The IP found that there are restrictions imposed by ZEKom-1 on electronic communications operators regarding lawful data processing. Article 148 ZEKom-1 provides a legal basis for processing subscribers' data, but limits the purposes for which such data is processed with the consent of the data subject. IP added that Article 158 ZEKom-1 restricts sending of unsolicited communications for the purpose of direct marketing through SMS messages. Such communications are only permitted on the basis of consent or certain exceptions. According to IP, the restriction in Article 158 applies to commercial and non-commercial communications, including for the promotion of ideas, political promotions and promotions by NGOs. Therefore, it is unlikely that unsolicited communications on ground relating to emergencies are exempt. Therefore, there was no legal basis for the SMS.

### ICO (UK) - KRA Consultancy Ltd

*Source: ICO (UK), 2026-05-20 — https://overview.legal/posts/53105 — original: https://gdprhub.eu/index.php?title=ICO_(UK)_-_KRA_Consultancy_Ltd*

Facts — The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services. The case was initially connected to investigations into other companies and individuals involved in mass SMS marketing. During these investigations, the DPA identified links between the controller, debt advice websites, bulk SMS platforms, short URLs and complaints submitted by subscribers to the 7726 spam reporting service. The controller was found to have used different trading names, websites and bulk messaging services to send large volumes of SMS messages to subscribers. These messages promoted debt write-off or debt solution services and invited recipients to click links leading to websites operated by, or connected to, the controller. The DPA also found evidence that the controller used personal data obtained from loan decline datasets and other third-party sources. The controller did not demonstrate that the subscribers had provided valid consent to receive marketing SMS messages about debt solutions. The DPA further found that the controller used so-called “fake bailiff messages” to pressure individuals into responding. These messages suggested that enforcement agents or bailiffs would attend the recipient’s address. The DPA considered that these messages targeted financially vulnerable individuals and were likely to cause distress. During the investigation, the DPA executed search warrants and seized electronic devices. The evidence included WhatsApp messages, SMS messages, access to bulk SMS platforms, customer communications, call recordings and internal group chats. These showed that the controller was involved in the transmission or instigation of the SMS messages and had sought to make the messages difficult to trace. Holding — The DPA held that the controller infringed Regulation 22 PECR by transmitting or instigating the transmission of unsolicited direct marketing SMS messages without valid consent. The DPA found that, between 24 April 2022 and 29 May 2025, 5,575,715 direct marketing SMS messages were delivered by, or at the instigation of, the controller. These messages generated over 60,000 complaints to the 7726 spam reporting service. The DPA considered that the controller could not rely on valid consent. Consent under PECR must meet the UK GDPR standard, meaning that it must be freely given, specific, informed and unambiguous. The DPA found no evidence that the subscribers had specifically consented to receive marketing from the controller. The use of old or purchased datasets, and the absence of adequate due diligence, did not meet the required standard. The DPA also held that the controller infringed Regulation 23 PECR. The controller had concealed its identity by using generic trading names, anonymous websites and messaging services designed to make the SMS activity untraceable. The DPA considered this conduct especially serious because recipients were not properly informed of who was behind the marketing communications. The DPA found that the infringement was serious due to the very high volume of messages, the number of complaints and the nature of the marketing. It also found that the infringement was deliberate. The controller had obtained loan decline data, failed to verify consent, used fake bailiff messages and sought repeated assurances that the messages could not be traced. In the alternative, the DPA found that the controller was at least negligent. The controller knew or ought to have known about the risk of non-compliance, given the DPA’s public guidance on direct marketing and consent. The controller nevertheless failed to take reasonable steps to prevent the contraventions. As aggravating factors, the DPA considered that the controller concealed its identity, targeted financially vulnerable individuals, sent distressing fake bailiff messages, provided debt-related advice despite not being FCA-authorised, misled the DPA during the search warrant, obstructed the investigation and continued unlawful marketing activity after the warrant. The DPA found no mitigating factors. The DPA therefore issued a monetary penalty of £300,000. The penalty could be reduced to £240,000 if paid early and if no appeal was lodged.

### AEPD (Spain) - PS/00249/2025

*Source: AEPD (Spain), 2026-08-12 — https://overview.legal/posts/187487 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00249/2025*

Facts — MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November 2024, the data subject received a marketing call from an agent acting on behalf of the controller. The agent addressed the data subject by name and asked questions about the type of residence in which he lived. When the data subject asked whether the controller had checked the Robinson List, the agent stated that this was unnecessary because the call was based on a “database”. When the data subject subsequently asked about the source of his personal data, the call ended. The data subject later contacted the controller’s customer service to enquire about the source of his data and was told that the data had been obtained by its sales department and might originate from his acceptance of cookies. The data subject disputed this, stating that he had never visited the controller’s website. At the time of the call, his telephone number had been registered with the Robinson List since March 2024. The controller explained that it obtained databases from external marketing providers which guaranteed that the personal data had been lawfully collected. It claimed that the data subject had consented in June 2020 through an online form to the processing of his data, the receipt of marketing communications and the disclosure of his data to third parties. As evidence, the controller provided a record containing the data subject’s details, an IP address, a timestamp and consent indicators, as well as a generic version of the relevant online form. However, the form was blank and did not contain any information specifically identifying the data subject. The controller also acknowledged that it did not independently verify the validity of the consent provided by its external supplier. Holding — The DPA held that the controller violated Article 66(1)(b) LGTel and Article 14 GDPR. First, regarding the commercial call, the DPA considered that the controller had not demonstrated that the data subject had given valid consent within the meaning of Article 4(11) GDPR. The documentation provided did not establish that the data subject personally completed the registration, entered the telephone number or could be linked to the IP address contained in the record. Moreover, the controller did not provide the privacy policy applicable when the alleged consent was obtained, meaning that it could not establish the purposes or third parties covered by that consent. The DPA recalled that, pursuant to Articles 5(2) and 7 GDPR, it is for the controller to demonstrate that valid consent was obtained. This responsibility could not be transferred to the external data provider through contractual guarantees. The controller remained responsible for establishing a valid legal basis for using the purchased data for its own marketing campaign. This was particularly relevant because the data subject's telephone number was registered with the Robinson List. Although the registration, and as specific consent was not sufficiently demonstrated, the controller could not rely on the exception under Article 23(4) LOPDGDD. Consequently, the DPA found that the unsolicited call lacked a valid legal basis and violated Article 66(1)(b) LGTel. Second, the DPA found a violation of Article 14 GDPR. Since the controller had obtained the personal data from a third party, it was required to provide the information listed in Article 14 GDPR. During the call, the agent merely referred to an unspecified “database” and did not adequately inform the data subject about the source of the data, the controller's identity, the legal basis for the processing or his data protection rights. The duration or termination of the call did not relieve the controller of this obligation, and the controller had not demonstrated that the required information was provided through another channel. The DPA imposed a fine of €5,000 for the violation of Article 66(1)(b) LGTel and a further €5,000 for the violation of Article 14 GDPR, resulting in a total fine of €10,000.

### ANSPDCP (Romania) - Fine against There's an AI for that S.R.L

*Source: ANSPDCP (Romania), 2026-07-24 — https://overview.legal/posts/158433 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_There's_an_AI_for_that_S.R.L*

Facts — In October 2025, the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal – ANSPDCP) concluded an investigation into THERE’S AN AI FOR THAT S.R.L., a company operating a website that used cookies. The investigation began after a data subject submitted a complaint alleging a possible breach of data protection rules. Holding — The ANSPDCP found that the controller’s website stored cookies that were not technically necessary on users’ devices. The authority also found that users were not provided with clear and complete information about these cookies and that their explicit consent had not been obtained before such cookies were placed. The ANSPDCP held that the controller violated Article 4(5)(a) and Article 4(5)(b) of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector (implementing ePrivacy Directive). As a result, the authority imposed an administrative fine of RON 30,000 (€6,000) on the controller for processing data through non-essential cookies without proper information or consent.

### EDPB - Binding Decision 1/2026

*Source: EDPB, 2026-05-28 — https://overview.legal/posts/144037 — original: https://gdprhub.eu/index.php?title=EDPB_-_Binding_Decision_1/2026*

Facts — On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The complaint concerned the controller’s cookie banner and alleged infringements of Articles 5(1)(a), 6(1)(a), 12(1), 12(2) and 13(1)(c) GDPR, as well as Article 5(3) ePrivacy Directive. It formed part of a wider project involving similar cookie banner complaints submitted by noyb across the EEA. The Austrian DPA transferred the complaint to the Belgian DPA, which acted as the lead supervisory authority. In its draft decision, the DPA proposed dismissing the complaint without examining its merits. It considered that the data subject and noyb had abused the rights provided under Articles 77 and 80(1) GDPR. The DPA relied on factors including the standardised and partly automated preparation of the complaints, noyb’s role in selecting the targeted controllers, the relationship between the data subject and noyb, and the broader strategic objectives pursued by the organisation. It considered that both the objective and subjective elements required to establish an abuse of rights were present. The Austrian DPA raised a relevant and reasoned objection under Article 60(4) GDPR. It argued that the circumstances did not demonstrate an abuse of rights and requested that the complaint be examined on its merits in accordance with Article 57(1)(f) GDPR. As the DPA did not follow the objection, it referred the dispute to the EDPB under Article 65(1)(a) GDPR. Holding — The EDPB first held that it was competent to decide the dispute. Its powers under Article 65(1)(a) GDPR are not limited to determining whether a controller infringed the GDPR. They also cover disputes concerning whether an action envisaged by a supervisory authority, including the dismissal of a complaint, complies with the GDPR. The EDPB found that the Austrian DPA’s objection met the requirements of Article 4(24) GDPR. The objection was directly connected to the draft decision, proposed a different outcome and sufficiently demonstrated the risks that the dismissal would create for data subjects’ rights and the consistent application of the GDPR. On the merits, the EDPB recalled that the prohibition of abuse of rights must be interpreted strictly, particularly where its application may restrict the fundamental right to data protection and the rights provided by Articles 77 and 80(1) GDPR. The supervisory authority alleging abuse bears the burden of establishing both its objective and subjective elements on the basis of sufficient evidence. Regarding the objective element, the EDPB acknowledged that noyb had organised a project involving predefined selection criteria, standardised complaints and automated tools. However, the data subject had validly mandated noyb under Article 80(1) GDPR and had lodged a complaint concerning an alleged infringement of their own data protection rights. Consequently, the objectives of Articles 77 and 80(1) GDPR had been fulfilled rather than circumvented. Regarding the subjective element, the EDPB found no evidence that the complaint had been submitted to obtain an undue advantage unrelated to the purposes of the GDPR. The objectives pursued by noyb could not be separated from those of the data subject merely because the organisation had played a leading role in preparing the complaint. Nor was there evidence that the data subject or noyb had sought compensation or another financial benefit. The EDPB therefore concluded that the data subject had not abused the right to lodge a complaint under Article 77 GDPR or the right to be represented under Article 80(1) GDPR. It instructed the DPA not to dismiss the complaint on that basis, to assess it on its merits and to submit a new draft decision to the supervisory authorities concerned under Article 60(3) GDPR.

### AEPD sanctions Tiger Media Inc. for installing advertising cookies without user consent

*Source: AEPD (Spain), 2025-11-14 — https://overview.legal/posts/158452 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00480-2025*

Facts — Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting publishers offering advertising space with advertisers seeking to display ads on those websites. Through this platform, the controller processed personal data of users visiting publishers’ websites where its ads were displayed. This included IP addresses, device and browser information, website URLs, referral URLs, clicks, impressions and cookie identifiers. According to the controller, the data were processed for ad delivery, fraud prevention, frequency capping, performance measurement and service improvement. The controller argued that it did not carry out behavioural advertising or profiling. It claimed that any targeting was limited to contextual factors, such as country and language. The controller relied mainly on legitimate interest as a legal basis and argued that publishers, as independent controllers of their own websites, were responsible for obtaining any consent required for cookies. The DPA investigated the controller’s platform and several Spanish websites using it. It found that cookies linked to the controller’s platform were installed on users’ devices without prior consent. These cookies were used for advertising-related purposes, including measuring ad performance, improving ad relevance, limiting frequency and detecting fraud. The AEPD also noted that the controller was not established in the EU. Although the controller stated that it had appointed a representative in Northern Ireland and was in the process of changing representative, the DPA considered that it did not have a valid representative established in the Union. Holding — The AEPD held that the controller violated Article 6 GDPR by processing personal data without a valid legal basis. The DPA emphasised that the LSSI, the Spanish law implementing the ePrivacy Directive require prior consent for storing or accessing information on a user’s device through cookies, unless an exemption applies. The DPA distinguished between the placement or reading of cookies, which is governed by the cookie rules, and the subsequent processing of personal data obtained through those cookies, which must comply with the GDPR. Since the cookies were installed without consent, the subsequent processing of the data collected through them could not be considered lawful. The AEPD rejected the controller’s reliance on legitimate interest under Article 6(1)(f) GDPR. It found that users had not received clear information and had not consented to the use of cookies. Moreover, users of the affected websites did not have a reasonable expectation that their browsing-related data would be processed by a third-party advertising network for advertising purposes. Therefore, the processing did not pass the balancing test required under Article 6(1)(f) GDPR. The DPA also held that the controller violated Article 27 GDPR. Since the controller was not established in the EU but processed personal data of users in Spain in connection with its advertising services, it was required to appoint a representative established in an EU Member State. A representative in Northern Ireland did not meet this requirement. The AEPD fined the controller €120,000 in total: €70,000 for the violation of Article 6 GDPR and €50,000 for the violation of Article 27 GDPR. Pursuant to Article 85 of the Spanish administrative Law 39/2015, the notice of initiation informed the controller of the possibility of acknowledging liability and making a voluntary payment of the proposed penalty, which would entail two cumulative reductions of 20% each. With the application of these two reductions, the final penalty was set at €72,000, and its payment resulted in the termination of the proceedings. The AEPD also ordered the controller to adopt corrective measures within three months. In particular, the controller had to ensure compliance with Article 6 GDPR, ensure compliance with the Spanish cookie rules by the service providers using its cookies, appoint an EU representative and notify the AEPD of the measures adopted.

## Recent developments

### ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291260 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_AMATO_BESTSELLER_S.R.L.*

The DPA imposed a 54,300 fine to a controller for violations of Article 32(4), Article 14 and Article 5(1)(c) in conjunction with Article 9 GDPR and ePrivacy Directive.The DPA imposed a RON 285,395 (€54,300) fine on a wholesale company for, amongst others, failing to implement appropriate security measures, allowing former employees to access personal data as well as for unlawfully using automated dialing and communication systems to call a significant number of data subjects. English Summary. E

### Digital Omnibus Report V3: Analysis of Select GDPR and ePrivacy Proposals by the Commission

*Source: noyb - European Center for Digital Rights, 2026-02-24 — https://overview.legal/posts/53132 — original: https://noyb.eu/en/digital-omnibus-report-v3-analysis-select-gdpr-and-eprivacy-proposals-commission*

GDPR Policy On 19 November 2025, the European Commission published its proposal for the "Digital Omnibus", subsequently sparking significant criticism and opposition. noyb conducted a thorough analysis of all the changes relevant to the GDPR and the ePrivacy Directive, which we firstly published a few days after the proposal was issued by the European Commission. The comprehensive report provides a comparison of the existing law with the Commission's proposal and compiles all our insights. The r

### Digital Omnibus: EU DPAs reject many proposed changes to the GDPR

*Source: noyb - European Center for Digital Rights, 2026-02-11 — https://overview.legal/posts/52485 — original: https://noyb.eu/en/digital-omnibus-eu-dpas-reject-many-proposed-changes-gdpr*

GDPR Policy The EDPB (combining all independent data protection authorities) and the European Data Protection Supervisor (EDPS) published a joint opinion expressing serious concerns about key elements of the proposed GDPR and ePrivacy changes in the so-called “Digital Omnibus” proposed by the European Commission. Specifically, the authorities strongly oppose the proposed narrowing of the definition of personal data. The opinion also question the need for various key proposals, such as the legal

### noyb WIN: French DPA fines Google €325 million for “Spam Emails” in Gmail

*Source: noyb - European Center for Digital Rights, 2025-09-04 — https://overview.legal/posts/53140 — original: https://noyb.eu/en/noyb-win-french-dpa-fines-google-eu325-million-spam-emails-gmail*

Forced Consent & Consent Bypass More than three years ago, noyb had filed a complaint against Google for sending unsolicited advertising emails directly to the inboxes of Gmail users. Contrary to EU law, the company never asked the people concerned for their consent. That's how the competent data protection authority sees it, too: Today, the CNIL has issued a decision siding with noyb – and fined Google €325 million. Press release by the CNILOriginal complaints from 2022Ads disguised as emails.

### Gmail creates “Spam Emails”, despite CJEU judgment

*Source: noyb - European Center for Digital Rights, 2022-08-24 — https://overview.legal/posts/53267 — original: https://noyb.eu/en/gmail-creates-spam-emails-despite-cjeu-judgment*

Today, noyb.eu filed a complaint against Google with the French Data Protection Authority (CNIL). The tech giant has repeatedly ignored the European Court of Justice (CJEU) ruling on direct marketing emails and used its email platform Gmail to send unsolicited advertising emails without valid consent of the users. Complaint filed with French Data Protection Authority CNIL (EN) Complaint filed with French Data Protection Authority CNIL (FR) Ads disguised as emails. Google sends Gmail users unsoli

## Literature

### Can the GPC standard eliminate consent banners in the EU?

*Source: Computer law & security review, 2025-12-10 — https://overview.legal/posts/53850 — original: https://doi.org/10.1016/j.clsr.2026.106332*

In the EU, the General Data Protection Regulation and the ePrivacy Directive mandate informed consent for behavioural advertising and use of tracking technologies. However, the ubiquity of consent banners and popups has led to widespread consent fatigue and questions regarding the effectiveness of these mechanisms in protecting users' data. In contrast, users in California and other US jurisdictions can utilize Global Privacy Control (GPC), a browser-based privacy signal that automatically broad

### La Quadrature du Net II and Data Retention under Article 15(1) ePrivacy Directive: CJEU Walks a Tightrope on IP Addresses Retention and Access for Public Authorities in Non-Serious Crime

*Source: European Data Protection Law Review, 2025-01-01 — https://overview.legal/posts/132457 — original: https://doi.org/10.21552/edpl/2025/2/17*

La Quadrature du Net II and Data Retention under Article 15(1) ePrivacy Directive Citation for published version (APA): Elisabeth Dekhuijzen, A. (2025). La Quadrature du Net II and Data Retention under Article 15(1) ePrivacy Directive: CJEU Walks a Tightrope on IP Addresses Retention and Access for Public Authorities in Non- Serious Crime. European Data Protection Law Review , 11 (2), 253-258. https://doi.org/10.21552/edpl/2025/2/17 Document status and date: Published: 01/01/2025 DOI: 10.21552/edpl/2025/2/17 Document Version: Publisher's PDF, also known as Version of record Document license: Taverne Please check the document version of this publication: • A submitted manuscript is the version of the article upon submission and before peer-review. There can be important differences between the submitted version and the official published version of record. People interested in the research are advised to contact the author for the final version of the publication, or visit the DOI to the publisher's website. • The final author version and the galley proof are versions of the publication after peer review. • The final published version features the final layout of the paper including

### European Union ∙ New EDPB Guidance Expands the Technical Scope of Article 5(3) ePrivacy Directive to Many Standard Tracking Technologies

*Source: European Data Protection Law Review, 2025-01-01 — https://overview.legal/posts/132452 — original: https://doi.org/10.21552/edpl/2024/4/8*

### Germany ∙ Data Protection Authorities Give Guidance on Direct Marketing under GDPR

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132491 — original: https://doi.org/10.21552/edpl/2019/1/14*

### European Union ∙ EDPB on the Interplay between the ePrivacy Directive and the GDPR

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132451 — original: https://doi.org/10.21552/edpl/2019/2/12*

## Tools

### ICO data protection self-assessment checklists

*Source: ICO, 2026-07-17 — https://overview.legal/posts/125624 — original: https://ico.org.uk/for-organisations/advice-for-small-organisations/checklists/*

Self-assessment checklists by the UK regulator for small organisations: controllers, processors, information security, direct marketing, records management and CCTV — each producing a rating with suggested actions.

## Related topics

- **Marketing** — https://overview.legal/topics/marketing
  Use of personal data for marketing and advertising purposes
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes

---
Generated by overview.legal · https://overview.legal/topics/direct-marketing · 2026-08-22
