# DPIA — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/dpia
> Sources are cited per item. Verify against the official texts before relying on them.

Data Protection Impact Assessment - systematic evaluation of processing risks

## Overview

## Legal Framework

The DPIA obligation is anchored in [Article 35 GDPR](/laws/gdpr/art-35), which requires controllers to assess processing risks before they begin, and flows into [Article 36 GDPR](/laws/gdpr/art-36) when residual risk remains high. The core trigger is risk-based: a DPIA is mandatory where processing is "likely to result in a high risk to the rights and freedoms of natural persons." Three specific situations in [Article 35(3)](/laws/gdpr/art-35#par-3) always require one: automated decision-making with legal or similarly significant effects, large-scale processing of special categories under Article 9 or Article 10, and large-scale systematic monitoring of publicly accessible areas.

> "the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data"
> — GDPR Art. 35(1)

The DPO plays a central role: under [Article 35(2)](/laws/gdpr/art-35#par-2), the controller must seek the DPO's advice, and under [Article 39(1)(c)](/laws/gdpr/art-39#par-1-pnt-c), the DPO must both advise on and monitor the DPIA's execution. Supervisory authorities are required under [Article 35(4)](/laws/gdpr/art-35#par-4) to publish lists of processing operations subject to mandatory DPIA, giving controllers a concrete reference point. Where the completed DPIA shows unmitigated high risk, [Article 36(1)](/laws/gdpr/art-36#par-1) requires prior consultation with the supervisory authority before processing can proceed.

## Key Developments

Courts are actively testing the thresholds of "large scale" and "systematic monitoring." The Raad van State addressed both concepts in a parking-enforcement case, finding that license-plate-based parking data collection did not trigger a DPIA:

> "Ook gaat het hier niet om grootschalige verwerking die een DPIA zou 'triggeren'."
> — [Raad van State, r.o. 5.5](/posts/53671#seg-5.5)

The court compared the processing to ANPR-equipped scan vehicles and found the scale insufficient, illustrating that not all public-space data collection meets the Article 35(3)(c) threshold. Meanwhile, the Rechtbank Gelderland's e-screener ruling exposed a structural problem: where multiple parties dispute controller status, the DPIA obligation can fall through the cracks entirely, as neither the minister nor the korpschef accepted responsibility for the processing at issue.

On the enforcement side, the EDPB's breach-notification guidelines confirm that a well-conducted DPIA serves as a foundational risk assessment that can accelerate breach response, though it may not capture the specificity of an actual incident.

## Status of the Debate

This topic is **contested in court**. The core obligation under Article 35 is settled, but its boundaries — particularly what constitutes "large scale" and "systematic monitoring" — are actively litigated. The Regulation does not define "large scale," leaving courts and supervisory authorities to develop criteria incrementally. The Raad van State's approach of comparing processing against known DPIA-list examples (like scan vehicles) offers one methodology, but no uniform judicial standard has emerged. The publication of national DPIA lists under Article 35(4) provides partial clarity, yet divergence across Member States persists. A CJEU ruling on the scope of "large scale" or "systematic monitoring" would resolve the open question definitively.

## Practical Guidance

- **Screen against all three Article 35(3) triggers first**: automated decision-making, special-category data at scale, and systematic public-area monitoring. If any applies, a DPIA is mandatory — do not rely solely on the risk-based threshold.
- **Consult your DPO early**: Article 35(2) requires seeking DPO advice during the DPIA, not after. The DPO's role under [Article 39(1)(c)](/laws/gdpr/art-39#par-1-pnt-c) extends to monitoring implementation, so involve them from scoping onward.
- **Check the relevant supervisory authority's published list**: Article 35(4) lists provide a concrete compliance benchmark. If your processing appears on the list, a DPIA is required regardless of your own risk assessment.
- **Plan for prior consultation as a contingency**: If the DPIA identifies high residual risk after mitigation, Article 36 requires consultation with the supervisory authority — build the potential eight-week timeline (extendable by six) into your project schedule.
- **Establish clear controller attribution**: The e-screener case demonstrates that disputed controller status can undermine DPIA compliance. Document data-responsibility allocations in processing agreements before processing begins.

## Legislation (full text of key provisions)

### Data protection impact assessment

*Source: GDPR, gdpr-art-35-en, 2016-04-27 — https://overview.legal/posts/90662*

### Prior consultation

*Source: GDPR, gdpr-art-36-en, 2016-04-27 — https://overview.legal/posts/90693*

### Recital 95 — processor assistance with DPIA and prior consultation

*Source: GDPR, gdpr-rec-95-en, 2016-04-27 — https://overview.legal/posts/91705*

The processor should assist the controller, where necessary and upon request, in ensuring compliance with the obligations deriving from the carrying out of data protection impact assessments and from prior consultation of the supervisory authority.

### Recital 94 — prior consultation high risk processing

*Source: GDPR, gdpr-rec-94-en, 2016-04-27 — https://overview.legal/posts/91703*

Where a data protection impact assessment indicates that the processing would, in the absence of safeguards, security measures and mechanisms to mitigate the risk, result in a high risk to the rights and freedoms of natural persons and the controller is of the opinion that the risk cannot be mitigated by reasonable means in terms of available technologies and costs of implementation, the supervisory authority should be consulted prior to the start of processing activities. Such high risk is likely to result from certain types of processing and the extent and frequency of processing, which may result also in a realisation of damage or interference with the rights and freedoms of the natural person. The supervisory authority should respond to the request for consultation within a specified period. However, the absence of a reaction of the supervisory authority within that period should be without prejudice to any intervention of the supervisory authority in accordance with its tasks and powers laid down in this Regulation, including the power to prohibit processing operations. As part of that consultation process, the outcome of a data protection impact assessment carried out with regard to the processing at issue may be submitted to the supervisory authority, in particular the measures envisaged to mitigate the risk to the rights and freedoms of natural persons.

### Recital 90 — data protection impact assessment requirements

*Source: GDPR, gdpr-rec-90-en, 2016-04-27 — https://overview.legal/posts/91695*

In such cases, a data protection impact assessment should be carried out by the controller prior to the processing in order to assess the particular likelihood and severity of the high risk, taking into account the nature, scope, context and purposes of the processing and the sources of the risk. That impact assessment should include, in particular, the measures, safeguards and mechanisms envisaged for mitigating that risk, ensuring the protection of personal data and demonstrating compliance with this Regulation.

### Recital 93 — member state data protection impact assessment

*Source: GDPR, gdpr-rec-93-en, 2016-04-27 — https://overview.legal/posts/91701*

In the context of the adoption of the Member State law on which the performance of the tasks of the public authority or public body is based and which regulates the specific processing operation or set of operations in question, Member States may deem it necessary to carry out such assessment prior to the processing activities.

### Recital 84 — high risk data protection impact assessment

*Source: GDPR, gdpr-rec-84-en, 2016-04-27 — https://overview.legal/posts/91683*

In order to enhance compliance with this Regulation where processing operations are likely to result in a high risk to the rights and freedoms of natural persons, the controller should be responsible for the carrying-out of a data protection impact assessment to evaluate, in particular, the origin, nature, particularity and severity of that risk. The outcome of the assessment should be taken into account when determining the appropriate measures to be taken in order to demonstrate that the processing of personal data complies with this Regulation. Where a data-protection impact assessment indicates that processing operations involve a high risk which the controller cannot mitigate by appropriate measures in terms of available technology and costs of implementation, a consultation of the supervisory authority should take place prior to the processing.

### Recital 92 — broader scope data protection impact assessment

*Source: GDPR, gdpr-rec-92-en, 2016-04-27 — https://overview.legal/posts/91699*

There are circumstances under which it may be reasonable and economical for the subject of a data protection impact assessment to be broader than a single project, for example where public authorities or bodies intend to establish a common application or processing platform or where several controllers plan to introduce a common application or processing environment across an industry sector or segment or for a widely used horizontal activity.

### Recital 89 — abolition of general notification obligation

*Source: GDPR, gdpr-rec-89-en, 2016-04-27 — https://overview.legal/posts/91693*

Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. While that obligation produces administrative and financial burdens, it did not in all cases contribute to improving the protection of personal data. Such indiscriminate general notification obligations should therefore be abolished, and replaced by effective procedures and mechanisms which focus instead on those types of processing operations which are likely to result in a high risk to the rights and freedoms of natural persons by virtue of their nature, scope, context and purposes. Such types of processing operations may be those which in, particular, involve using new technologies, or are of a new kind and where no data protection impact assessment has been carried out before by the controller, or where they become necessary in the light of the time that has elapsed since the initial processing.

### Recital 91 — high risk processing requiring impact assessment

*Source: GDPR, gdpr-rec-91-en, 2016-04-27 — https://overview.legal/posts/91697*

This should in particular apply to large-scale processing operations which aim to process a considerable amount of personal data at regional, national or supranational level and which could affect a large number of data subjects and which are likely to result in a high risk, for example, on account of their sensitivity, where in accordance with the achieved state of technological knowledge a new technology is used on a large scale as well as to other processing operations which result in a high risk to the rights and freedoms of data subjects, in particular where those operations render it more difficult for data subjects to exercise their rights. A data protection impact assessment should also be made where personal data are processed for taking decisions regarding specific natural persons following any systematic and extensive evaluation of personal aspects relating to natural persons based on profiling those data or following the processing of special categories of personal data, biometric data, or data on criminal convictions and offences or related security measures. A data protection impact assessment is equally required for monitoring publicly accessible areas on a large scale, especially when using optic-electronic devices or for any other operations where the competent supervisory authority considers that the processing is likely to result in a high risk to the rights and freedoms of data subjects, in particular because they prevent data subjects from exercising a right or using a service or a contract, or because they are carried out systematically on a large scale. The processing of personal data should not be considered to be on a large scale if the processing concerns personal data from patients or clients by an individual physician, other health care professional or lawyer. In such cases, a data protection impact assessment should not be mandatory.

## Case law

### VwGH - VwGH Ro 2025/04/0007-7

*Source: Austrian Administrative Supreme Court, 2026-06-24 — https://overview.legal/posts/184547 — original: https://gdprhub.eu/index.php?title=VwGH_-_VwGH_Ro_2025/04/0007-7*

Facts — The controller was an address publisher and direct advertising company that operated a data application to provide advertisers with personal data for targeted marketing measures. In 2019, following media reports concerning the alleged sale of personal data, particularly information about natural persons’ political party affinity, the Austrian DPA (DSB) initiated an ex officio investigation against the controller. Based on its investigation, the DPA found that the controller had unlawfully processed political party affinity data and unlawfully further processed parcel-frequency data, and had infringed its obligations concerning the DPIA and record of processing activities. It consequently imposed a fine of €18,000,000. The controller appealed to the Federal Administrative Court (BVwG), arguing that the commission of an infringement by a legal person was not, in itself, sufficient for a fine to be imposed under the GDPR. It claimed that since a legal person could not act on its own, the culpable conduct of a natural person had to be identified and attributed to it. The controller argued that the DPA had failed to establish such attribution. The court agreed and, on 26 November 2020, annulled the fine. It found that the DPA had failed to establish that natural persons acting on behalf of the controller had engaged in culpable conduct. The DPA filed an extraordinary official appeal against this judgment with the Austrian Supreme Administrative Court (VwGH). The court stayed the proceedings pending the CJEU’s preliminary ruling in Case C-807/21 (Deutsche Wohnen SE), as the questions referred in that case were also relevant to the appeal proceedings. The CJEU published its judgement on this matter on 5 December 2023. The CJEU held that a fine under Article 83(4) GDPR, Article 83(5) GDPR and Article 83(6) GDPR may be imposed on anyone who qualifies as a controller where it is established that the controller committed the relevant infringement intentionally or negligently. A controller may be sanctioned where it could not have been unaware of the infringing nature of its conduct, regardless of whether it knew that its conduct infringed the GDPR. The CJEU further clarified that, where the controller is a legal person, the application of Article 83 GDPR does not require any action or knowledge on the part of its governing body. Member States may not impose additional substantive requirements for the imposition of fines beyond those laid down in Article 83 GDPR. For the determination of the fine, the controller may also constitute an undertaking within the meaning of EU competition law, with the turnover of the relevant economic unit being taken into account. Following the CJEU judgment, the Supreme Administrative Court annulled the Federal Administrative Court’s judgment on 1 February 2024. The Federal Administrative Court issued a new judgment on 27 December 2024, largely upholding the infringements but reducing the fine to €16,000,000. The controller appealed this decision before the Supreme Administrative Court. Holding — The court found that the controller gathered information concerning the political party affinity of the Austrian population based on anonymous surveys conducted by commissioned polling institutes. These surveys included specific questions concerning interest in election advertising, together with sociodemographic information such as age, level of education and income, place of residence and interest in advertising from political parties. Marketing groups were subsequently formed based on the sociodemographic data and place of residence. For each group, calculations were made to determine the likelihood that an individual with particular sociodemographic characteristics and religious affiliation would be interested in advertising from the political parties concerned. By assigning an identifiable individual to a particular marketing group, the controller linked that person to the probability values calculated for the group and the resulting political party affinity. The court held that the controller did not obtain consent from the data subjects to whom these probability scores were assigned. In total, political party affinity was attributed to approximately 2,200,000 individuals. The court reiterated that political party affinity scores attributed to identifiable individuals constituted personal data revealing political opinions within the meaning of Article 9(1) GDPR. It therefore upheld the finding that the controller had infringed Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. In assessing the controller’s culpability, the court relied heavily on the CJEU’s judgment in Deutsche Wohnen SE. It held that the fact that the controller believed it had complied with the GDPR because it had established a quality-assured organisation was not decisive. It pointed out that under GDPR, a legal person’s fault does not require knowledge or awareness on the part of the management body. The establishment of a data protection compliance system, like the obtaining of legal advice, did not in itself exculpate the controller. It stated that the decisive question was whether the controller could have been aware of the unlawfulness of the processing of political party affinity data during the relevant period. The court ruled that the controller had incorrectly assessed that political party affinity scores did not constitute personal data and that it had consequently failed to examine whether they constituted special categories of personal data under Article 9 GDPR. The court rejected the controller’s argument that political party affinity was processed only in relation to groups rather than in relation to specific identifiable individuals. It also rejected the argument that marketing classifications used for political advertising posed no risk to data subjects. The court concluded that given the controller’s resources and its ability to examine the applicable legal position, that legal assessment amounted to gross negligence concerning the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. Furthermore, the court ruled that the controller’s incorrect assessment that political party affinity scores did not constitute personal data or special categories of personal data also led it to conclude in its Data Protection Impact Assessment (DPIA) that the processing did not pose a high risk and that the scope of Article 35(3)(a) GDPR was therefore not applicable. The court held that the DPIA-related infringement was therefore absorbed from the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. It found no separate element of wrongdoing. The court additionally ruled that the same incorrect legal assessment resulted in the controller’s failure to include political party affinity as a separate category of personal data in its record of processing activities under Article 30(1)(c) GDPR. The court similarly found that these documentation failures did not contain a separate element of wrongdoing beyond that already covered by the infringement of Article 5(1)(a) GDPR and Article 9(1) GDPR. The court therefore discontinued the proceedings concerning the separate DPIA and record-of-processing infringements. It further held that, where a controller commits multiple GDPR infringements, a single aggregate fine must be imposed under Article 83(3) GDPR, the total amount of which may not exceed the amount applicable to the most serious infringement. The court reassessed the penalty and reduced it to €13,000,000, because the DPIA and record of processing infringements were no longer to be taken into account in determining the fine.

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### BVwG - W258 2227269-1/39E

*Source: Federal Administrative Court, 2024-12-27 — https://overview.legal/posts/184564 — original: https://gdprhub.eu/index.php?title=BVwG_-_W258_2227269-1/39E*

Facts — On the 8 January 2019, the Austrian DPA (Datenschutzbehörde – DSB) launched an investigation into the actions of the Austrian postal service as it also had a business license for address publishing and direct marketing. Media reports had claimed that the postal service (the controller) sold data concerning the political affinities of data subjects to third parties. The controller ran a platform entitled “Adress Shop” on which it sold personal data to legal entities. The datasets included names and addresses but more importantly it included data subjects’ affinities to certain things such as an affinity to moving house, an affinity to organic products or how frequently a data subject receives packages. The purpose of the data processing was to sell this data to third parties who would use it for marketing purposes and therefore could avoid scattering losses. In order to create this database, the controller abused its position as postal service provider. In the postal service contract provided to data subjects the controller had included a notice stating that data subject are agreeing to their personal data being processed for marketing purposes. The contract however also included a box which could be ticked in order to refuse the data processing for marketing purposes. One of these affinities was concluded through an affinity score concerning the main political parties in Austria. For example, data subjects would be assessed with either a “very low”, “low”, “high” or “very high” affinity towards the SPÖ (the Socialist Party of Austria), the ÖVP (the Conservative Party of Austria) or any other major political party. The controller calculated this score through combing anonymous survey results, socio-demographic data (e.g., age or level of income and education) and voting results of particular region. On the 20 Febuary 2019, the DSB alleged that the controller had unlawfully processed sensitive data under Article 9 GDPR. The DSB found that the controller could not rely on a legal basis for the processing of this data and that the controller had sold the data to third parties. The DSB issued a fine of fine of €18,000,000 for the processing of sensitive data and other violations. The full details can be found here. On the 25 November 2019, the controller appealed the decision of the DSB to the Austrian Federal Administrative Court (Bundesverwaltungsgericht – BVwG) and alleged that the DSB had inadequately assessed the situation. On the 26 November, the BVwG annulled the decision of the DSB stating that the DSB had failed to name a natural person to whom the actions of the controller could be attributed to. Based on an Austrian provision, namely paragraph 45(1)(3) of the Administrative Penal Code (Verwaltungsstrafgesetz - VStG), in order to fine a legal person for a violation of the GDPR all necessary requirements for the penalization of a natural person must be fulfilled. This finding was however annulled by the Supreme Administrative Court (Verwaltungsgerichtshof – VwGH) on the 1 February 2024. The VwGH explained that although the BVwG correctly applied the national provision, the CJEU case C-807/21 Deutsche Wohnen showed that Article 58(2)(i) GDPR and Article 83 GDPR are excluded from national derogations. Therefore, the BVwG should not have applied the national provision. The case was therefore reverted back to the BVwG. Holding — The BVwG reassessed the case and partly upheld the DSB decision but made the following alterations. Article 9 GDPR data related to political affinities The BVwG confirmed that the controller had at no point in time obtained the consent of the data subject and therefore was processing data in violation of Article 9(1) GDPR since the 25 May 2018. The BVwG held that the controller's conduct had proved negligent. The BVwG noted that the controller had made efforts to apply the GDPR correctly but criticized for example that the DPO had to monitor all processing activities which did not prove an effective monitoring and controlling system as it would require too much time for just one person. The BVwG held that it was clearly unacceptable that the DPO thought that the data processed did not constitute personal data, especially when it was explicitly connected to an individual person. Further, The BVwG found that the controller never conducted an assessment on whether certain affinities could constitute sensitive data under Article 9 GDPR. The BVwG classified this as grossly negligent behaviour on the part of the controller. The BVwG concluded that the controller should have consulted an external expert around the uncertainties it had concerning the correct application of the GDPR. Affinity towards receiving packages In relation to the data processed to assess their affinity for receiving packages, the controller was in a privileged position to have access to the relevant data. However, it then further processed this data contrary to their legal mandate for creating projection models for marketing purposes in violation of Article 6(4) GDPR. The court also held that this violated the principles of fairness and transparency under Article 5(1)(a) GDPR. The BVwG highlighted that the controller knew that its positions as postal service provider and data broker is likely to cause issues, therefore its behaviour was classified as negligent. Affinity towards moving house Assessing whether data subjects were likely to move house differed to the assessment of an affinity towards receiving packages as there was a contractual relationship between the data subject and the controller due to contractual redirection orders. The BVwG assessed that the minimal information provided to data subjects on the processing for marketing purposes, proved to be just about enough as the personal data was made up of a calculation of averages which was then anonymized. The court found that this could be classified as processing which, based on the controllers description, could be expected from the notice included in the contract. In addition, data subjects could easily refuse the data processing. Data Protection Impact Assessment The controller had processed an extensive amount of sensitive data which requires a data protection impact assessment. The controller’s assessment that this data processing was of low risk was therefore faulty. The controller had therefore violated Article 35(3)(b) GDPR and Article 35(7) GDPR. The BVwG held that as the controller had negligently categorized its processing as not concerning any sensitive data, it consequently also proves to have acted negligently in assessing the risks under Article 35 GDPR. The BVwG rejected the controller’s argument that penalization under Article 35 GDPR would result in a double punishment for the same offence. It explained that the general obligations under the GDPR pursue a different aim to the provisions governing lawfulness of the processing. Further, the DPIA is to be conducted prior to processing. Records of processing The faulty and therefore inadequate DPIA resulted in a violation of Article 30(1)(c) GDPR, which requires the records of data processing to include the categories of data processed. The BVwG again assessed that the controller had acted negligently in relation to this aftereffect of its faulty categorization of the processed data. The controller had merely stated that the data would be processed for marketing purposes and this was held to have been inadequate as the controller processed data such as the political affinities. The BVwG held that the controller had failed to provide a full description of all the processed categories. Fine The BVwG reduced the fine to €16 million mainly based on the controller's low annual turnover. Further, the BVwG noted that the political data had only been sold to two political parties which resulted in a limited amount of data subjects being affected.

### Judgment of the Court (Grand Chamber) of 21 March 2024.#RL v Landeshauptstadt Wiesbaden.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Regulation (EU) 2019/1157 – Strengthening the security of identity cards of EU citizens – Validity – Legal basis – Article 21(2) TFEU – Article 77(3) TFEU – Regulation (EU) 2019/1157 – Article 3(5) – Obligation for Member States to include two fingerprints in interoperable digital formats in the stora

*Source: Court of Justice of the European Union, C-61/22, 2024-03-21 — https://overview.legal/posts/132266 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0061*

The Court of Justice of the European Union (Grand Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden in proceedings between RL and the Landeshauptstadt Wiesbaden concerning RL's request for an identity card without fingerprints, which the city rejected. The core issue was the validity of Regulation (EU) 2019/1157, particularly Article 3(5), which obliges Member States to include two fingerprints in the storage medium of EU citizens' identity cards, and whether the regulation was validly adopted under Articles 21(2) and 77(3) TFEU and complies with Articles 7 and 8 of the Charter of Fundamental Rights. The Court upheld the regulation's validity, finding the legal basis appropriate and the fingerprint storage requirement a proportionate interference with fundamental rights that is justified by the objective of strengthening identity document security and preventing fraud, while also clarifying Member States' obligation to conduct data protection impact assessments under Article 35 of GDPR for the national implementing measures.

### Judgment of the Court (Sixth Chamber) of 9 February 2023.#X-FAB Dresden GmbH & Co. KG v FC.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 38(3) – Data protection officer – Prohibition on dismissing data protection officer for performing his or her tasks – Requirement for functional independence – National legislation prohibiting

*Source: Court of Justice of the European Union, C-453/21, 2023-02-09 — https://overview.legal/posts/132296 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0453*

In Case C-453/21, the CJEU addressed a preliminary reference from the Bundesarbeitsgericht concerning X-FAB Dresden GmbH & Co. KG's dismissal of its employee FC from the position of data protection officer. The Court interpreted Article 38(3) and (6) GDPR, ruling that the second sentence of Article 38(3) is valid and that the prohibition on dismissing a DPO for performing their tasks implies DPOs must enjoy enhanced protection against dismissal beyond the general protections afforded to ordinary employees, while also clarifying that conflicts of interest under Article 38(6) must be assessed based on whether a DPO's additional duties could lead them to determine the purposes and means of processing personal data. No fine was imposed as the proceedings involved interpretation of EU law rather than an enforcement action.

### Amsterdam Court of Appeal: Controller may reject watermarked ID copy for verification

*Source: Court of Appeal Amsterdam, 2024-04-30 — https://overview.legal/posts/125642 — original: https://gdprhub.eu/index.php?title=GHAMS_-_200.324.736/01*

Facts — The data subject had a business credit card issued by the controller. In 2021, the controller asked the data subject to identify themselves online by taking a picture of the ID and then taking a selfie of themselves. The data subject wanted to upload a copy of the ID with a watermark on it for fraud prevention purposes (saying, for example: “copy for [the controller]”). The controller, on the other hand, rejected this copy, arguing that the data subject should upload a copy without any writing on it. Therefore, the data subject brought legal proceedings before the District Court of Amsterdam (Rechtbank Amsterdam - Rb. Amsterdam), seeking the court to declare that the controller cannot request an ID copy without the watermark and that the controller should not block the credit card. On 20 April 2022, the District Court of Amsterdam dismissed the data subject’s request. The data subject appealed the decision before the Court of Appeal of Amsterdam (Gerechtshof Amsterdam - GHAMS). They argued that the provisions of the Money Laundering and Terrorist Financing Prevention Act (Wet ter voorkoming van witwassen en financieren van terrorisme – Wwft) do not require that the identification process is performed in the way envisaged by the controller. Therefore, the legal basis provided for by Article 6(1)(c) GDPR cannot be used, since there is no legal obligation to require this kind of identification. Moreover, they argued that the controller should not store the copy of the ID. The controller pointed out that the electronic technique used in the scanning of the ID has currently the highest reliability in the field of authentication and that the use of this technique enables it to recognize high value forgeries of IDs better than with the use of persons trained and educated for this purpose. Holding — First of all, the court noted that the Wwft does not prescribe a way in which the identification should be conducted. Moreover, it pointed out that neither the GDPR nor the Wwft confer the data subject a right to a non-online identification. Secondly, the court noted that Article 13(1)(a) Directive 2015/849 allows the controller to perform the identification through electronic means. Thirdly, the court agreed with the controller’s argument. It held that, since there is an added value in using this ID scanning tool, this use may be considered necessary within the meaning of Article 6(1)(c) GDPR in order to comply with its obligation to conduct a customer due diligence under the Wwft. The court pointed out that, due to the large amount of customers, the controller has a legitimate interest in organizing the identification and verification procedure as uniformly as possible. Fourthly, as for the retention issue, the court noted that the controller is obliged to keep a copy of the proof of identity whose authenticity it has verified by means of the scan pursuant to Article 33(1) Wwft. However, the court highlighted that the controller is obliged to store this data securely. Therefore, the court dismissed the appeal and upheld the judgement of the District Court of Amsterdam.

### Spanish court reviews DPA decision on KFC Spain website privacy information and DPO

*Source: National Court, 2026-07-16 — https://overview.legal/posts/184690 — original: https://gdprhub.eu/index.php?title=AN_-_SAN_3154/2026*

Facts — In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website. The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer. The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented corrective measures. Holding — The Court dismissed the appeal and upheld the total fine of €25,000. Regarding Article 13 GDPR, the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding Article 37(1)(b) GDPR, the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.

### Digital Rights Ireland Ltd v Minister for Communications

*Source: CJEU, C-293/12, 2014-04-08 — https://overview.legal/posts/51474 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0293&ref=51474*

Invalidated Data Retention Directive as incompatible with fundamental rights.

### Judgment of the General Court (First Chamber, Extended Composition) of 10 September 2025.#Meta Platforms Ireland Ltd v European Commission.#Digital services – Regulation (EU) 2022/2065 – Commission decision determining the amount of the supervisory fee for 2023 – Article 43(3) to (5) of Regulation 2022/2065 – Article 4(2) of Delegated Regulation (EU) 2023/1127 – Method for calculating the number of average monthly active recipients – Temporal adjustment of the effects of an annulment.#Case T-55/

*Source: General Court, T-55/24, 2025-09-10 — https://overview.legal/posts/132133 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62024TJ0055*

Meta Platforms Ireland Ltd challenged a European Commission decision setting the 2023 DSA supervisory fee for Facebook and Instagram, arguing the Commission unlawfully established a methodology for calculating average monthly active recipients (AMAR) through individual implementing decisions rather than through a delegated act as required by the DSA. The General Court examined whether the Commission exceeded its implementing authority by supplementing the DSA's framework via annexes to the fee decision rather than adopting the methodology through the proper delegated regulation procedure under Article 33(3) of the DSA.

## Guidance

### Opinion 6/2024 on the draft list of the Latvian SA on pro-cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR)

*Source: EDPB, opinion-62024-on-the-draft-list-of-the-latvian-sa-on-pro-en, 2024-04-18 — https://overview.legal/posts/125762 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-62024-on-the-draft-list-of-the-latvian-sa-on-pro_en*

Adopted 1 Opinion 6/2024 on the draft list of the Latvian SA on pro- cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR) Adopted on 16 April 2024 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64 (2) and Article 35 (1), (5) and (6) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data…

### Opinion 7/2020 on the draft list of the competent supervisory authority of France regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR)

*Source: EDPB, opinion-72020-on-the-draft-list-of-the-competent-supervisory-en, 2020-04-22 — https://overview.legal/posts/126167 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-72020-on-the-draft-list-of-the-competent-supervisory_en*

Adopted 1 Opinion 7 / 2020 on the draft list of the com petent supervisory authority of France regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35( 5 ) GDPR) Adopted on 22 April 2020 Adopted 2 Adopted 3 The European Data Protection Board Having r egard to Article 63, Article 64 (2) , Article 64(3) and Article 35( 1), (5), (6) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the…

### Opinion 10/2019 on the draft list of the competent supervisory authority of Cyprus regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35(4) GDPR)

*Source: EDPB, opinion-102019-on-the-draft-list-of-the-competent-supervisory-en, 2019-07-12 — https://overview.legal/posts/126214 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-102019-on-the-draft-list-of-the-competent-supervisory_en*

A dopted 1 Opinion 10/2019 on the draft list of the competent supervisory authorit y of Cyprus regarding the processing operation s subject to the requirement of a data protection impact assessment (Article 35(4) GDPR) Adopted on 9 July 2019 A dopted 2 A dopted 3 The European Data Protection Board Having r egard to Article 63, Article 64 (1 )(a), (3) - (8) and Article 35 (1), (3), (4), (6) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the…

### Opinion 11/2019 on the draft list of the competent supervisory authority of the Czech Republic regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR)

*Source: EDPB, opinion-112019-on-the-draft-list-of-the-competent-supervisory-en, 2019-07-12 — https://overview.legal/posts/126216 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-112019-on-the-draft-list-of-the-competent-supervisory_en*

Adopted 1 Opinion 11 /2019 on the draft list of the com petent supervisory authority of the Czech Republic regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR) Adopted on 10 July 2019 Adopted 2 Adopted 3 The European Data Protection Board Having regar d to Article 63, Article 64(2) and Article 35 (1) , (5), (6) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 12/2019 on the draft list of the competent supervisory authority of Spain regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR)

*Source: EDPB, opinion-122019-on-the-draft-list-of-the-competent-supervisory-en, 2019-07-12 — https://overview.legal/posts/126210 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-122019-on-the-draft-list-of-the-competent-supervisory_en*

Adopted 1 Opinion 12 /2019 on the draft list of the com petent supervisory authority of Spain regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35 ( 5 ) GDPR) Adopted on 10 July 2019 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 6 3, Article 64(2)and Article 35 (1), (5), (6) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural…

### Opinion 13/2019 on the draft list of the competent supervisory authority of France regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR)

*Source: EDPB, opinion-132019-on-the-draft-list-of-the-competent-supervisory-en, 2019-07-12 — https://overview.legal/posts/126218 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-132019-on-the-draft-list-of-the-competent-supervisory_en*

Adopted 1 Opinion 13 /2019 on the draft list of the com petent supervisory authority of France regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35( 5 ) GDPR) Adopted on 10 July 2019 Adopted 2 Adopted 3 The European Data Protection Board Having r egard to Article 63, Article 64 (2)and Article 35( 1), (5), (6) of the Regulation 2016/679/E U of the European Parliament and of the Council of 27 April 2016 on the protection of natural…

### Recommendation 01/2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 39.4 of Regulation (EU) 2018/1725)

*Source: EDPB, recommendation-012019-on-the-draft-list-of-the-european-data-protection-en, 2019-07-12 — https://overview.legal/posts/126224 — original: https://www.edpb.europa.eu/documents/recommendation/recommendation-012019-on-the-draft-list-of-the-european-data-protection_en*

Adopted 1 Recommendation 01/ 2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 3 9 .4 of Regulation (EU) 2018/1725) Adopted on 10 July 2019 Adopted 2 3 CONCLUSION ................................ ................................ ................................ ................................ ... 7 Adopted 3 The European Data Protection Board Having regard to Article…

### Opinion 7/2019 on the draft list of the competent supervisory authority of Iceland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-72019-on-the-draft-list-of-the-competent-supervisory-en, 2019-03-12 — https://overview.legal/posts/126234 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-72019-on-the-draft-list-of-the-competent-supervisory_en*

Adopted 1 EDPB Plenary m eeting, 12 - 13 March 2019 - Item 2.3.1 Opinion 7 /201 9 on the draft list of the competent supervisory authority of Iceland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 12 March 201 9 Adopted 2 Contents 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2 Assessment…

## Enforcement decisions

### Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4)

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6313 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-431-0061_(Helsingor_decision_no._4)*

Facts — This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor municipality, the controller, has been using Google Chromebooks and Workspace for Education in violation of several GDPR requirements, as detailed in the first decision of September 2021, the second decision of 14 July 2022 and the third decision of 18 August 2022. Following the third decision, the municipality submitted more documentation and also requested a consultation with the DPA as per Article 36 GDPR. Holding — The DPA temporarily suspended its processing ban against Helsingor municipality until 5 November 2022, and also ordered the municipality to: Change the data processing agreement with Google so that the DPA's remarks in their 14 July and 18 August decisions, are implemented. This includes, at a minimum, a clarification of where and if Google acts as a sole controller and any uncertainties that may entail that Google acts beyond their role as a processor, see Article 28(3)(a) GDPR. Document that all transfers of personal data to insecure third countries, are in line with the GDPR. Describe all data flows and identify the personal data that are shared with the vendor, and clarify when the vendor acts as a sole or joint controller. This documentation must include the whole technology stack used by the municipality (for this processing activity). Update their data protection impact assessment based on all identified risks. Consult the DPA if the DPIA shows any high risks the municipality is not able to mitigate. If any processing activities are still not in line with the GDPR before the DPA's deadline 3 November 2022, present a final plan for bringing them in line with the GDPR.

### Italian DPA: Vasto municipality breached transparency duties over traffic cameras

*Source: Garante per la protezione dei dati personali (Italy), 2026-06-18 — https://overview.legal/posts/144036 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_457/2026*

Facts — The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A data subject filed a complaint against the controller after being fined for running a red light. The data subject argued that there were no signs or warnings near the cameras installed to detect violations, and that the controller did not obscure the windows to make data subjects unrecognisable. The controller argued that it provided warning signs of the presence of cameras. In addition, the cameras only capture data subjects’ license plates to comply with the principle of data minimisation (Article 5(1)(c) GDPR), and that the case of the data subject was a technical error. Holding — The DPA first noted that, in principle, a public entity can process this data if it is necessary to fulfil a legal obligation or for the public interest (Article 6(1)(c) and (e) GDPR). However, the controller still has the obligation to provide information to data subjects regarding the processing, in accordance with the principle of transparency (Article 5(1)(a) GDPR). The DPA found that, at the time of the complaint, the controller had not included any information near the cameras. In addition, the first level privacy policy did not comply with the requirements of Article 13 GDPR and were not provided in concise and transparent manner. Therefore, the DPA found a violation of Articles 5(1)(a), 12(1) and 13 GDPR. The DPA also found a violation of Article 5(1)(c) GDPR, as the controller failed to comply with the principle of data minimisation. The DPA stated that the controller had failed to ensure that the cameras only captured the vehicles’ license plates, and had therefore processed more data than necessary. Finally, the DPA found a violation of Article 35 GDPR, as the controller had prepared a data protection impact assessment (DPIA) only after the processing activities began. The DPA noted that the DPIA was also not specific enough. The DPA fined the controller €5,000. In addition, the DPA ordered the controller to adopt appropriate measures to provide data subjects with adequate information and update its DPIA.

### Kymen Vesi Oy: Non-compliance with general data processing principles

*Source: Deputy Data Protection Ombudsman, 2020-05-22 — https://overview.legal/posts/46395 — original: https://www.enforcementtracker.com/ETid-280*

Fine for failure to carry out a data protection impact assessment ('DPIA') for the processing of location data of employees with a vehicle information system

### Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security

*Source: Norwegian Supervisory Authority (Datatilsynet), 2020-07-10 — https://overview.legal/posts/46448 — original: https://www.enforcementtracker.com/ETid-333*

Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data Protection Impact Assessment ('DPIA') in accordance with Article 35 of the General Data Protection Regulation (Regulation (EU) 2016/679) ('GDPR') prior to the start of the processing and had not taken adequate technical and organisational measures in accordance with Article 32 of the GDPR, resulting in an increased risk o

### AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data

*Source: AEPD (Spain), 2026-07-16 — https://overview.legal/posts/53655 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00020-2025*

Facts — Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first estimated that 25,000 persons were affected. It later stated that the incident had affected around 40,000 persons, including 75 minors. The incident affected confidentiality, availability and integrity. The attacker encrypted systems and exfiltrated between 3.5 and 4 TB of information from the document management server. The affected data included identification and contact data, ID numbers, dates of birth, financial and insurance data, bank account numbers, health data, employee data and access credentials. The controller also processed data relating to minors in accident claims. A data subject complained to the DPA after being informed that their personal data had been exposed. The data subject was concerned about identity theft and requested additional information from the controller. During the investigation, the DPA found that the controller had known that its IT systems faced an extreme cybercrime risk before the breach. The forensic report could not determine the initial entry point because the servers had been encrypted, but it showed that attackers could move laterally through the infrastructure, obtain privileged access, install tools, exfiltrate data and encrypt systems. The controller had carried out a risk analysis in 2019, but this document concluded that no DPIA was necessary. After the breach, a later analysis found that a DPIA was necessary for treatments involving health data and minors. The controller did not prove that it had carried out the required DPIA. Holding — The DPA held that the controller violated Article 5(1)(f) GDPR. It considered that the controller had failed to ensure the integrity and confidentiality of the personal data under its responsibility. The DPA emphasised that the principle in Article 5(1)(f) GDPR is not limited to the existence of isolated security measures. Rather, the controller must implement adequate technical and organisational measures capable of ensuring that personal data is protected against unauthorised or unlawful processing, loss, destruction or damage. The DPA rejected the controller’s argument that the attack was an external criminal act that could not be attributed to it. The DPA found that the controller was aware of an extreme cyber risk and that its internal vulnerabilities and security posture allowed the attackers to move through the systems, access personal data and encrypt files. The DPA therefore considered that the controller’s measures were clearly insufficient. The DPA also held that the controller violated Article 35 GDPR. The controller processed high-risk categories of data, including health data and data concerning minors. In these circumstances, it should have carried out a DPIA before the processing. The DPA found that the controller’s 2019 risk analysis wrongly concluded that no high risk existed, while its later documentation acknowledged that a DPIA was necessary. The DPA proposed a fine of €150,000 for the infringement of Article 5(1)(f) GDPR and €100,000 for the infringement of Article 35 GDPR, totalling €250,000. The controller paid voluntarily without acknowledging liability, obtaining a 20% reduction under Spanish Administrative Law (39/2015). The final payable amount was therefore €200,000. The DPA also ordered the controller, under Article 58(2)(d) GDPR, to prove within three months from the enforceability of the decision that it had carried out the mandatory DPIA required under Article 35 GDPR.

### UODO (Poland) - DKN.5131.12.2022

*Source: UODO (Poland), 2026-06-11 — https://overview.legal/posts/144031 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.12.2022*

Facts — The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor). The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022. Holding — The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated Article 28(1) GDPR: while the controller had concluded a data processing agreement with the processor, it had failed to verify whether the processor provided sufficient guarantees to implement appropriate technical and organisational measures. Second, the DPA found that the controller had infringed Articles 24(1), 25(1), and 32(1) and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of processing via the email system. The DPA took into account that the controller had not taken any measures to minimise the risks identified. In addition, the DPA pointed out that the breach involved sensitive health data, and the passwords used by the controller did not meet the usual security requirements. As a consequence of the previous violations, the controller had infringed the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR as well. Finally, the DPA found a violation of Article 35(1) GDPR in conjunction with Article 35(3) GDPR due to the controller’s failure to conduct a data protection impact assessment. The DPA also reprimanded the processor for the failure to implement appropriate technical and organisational measures to ensure the security of processing – the processor had failed to conduct a risk analysis and to implement adequate security measures, such as blocking a user’s account after a certain amount of login attempts. The DPA held that the processor had violated Articles 32(1) and 32(2) GDPR in conjunction with Article 28(3)(c) GDPR.

### Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met

*Source: Garante per la protezione dei dati personali (Italy), 2026-05-28 — https://overview.legal/posts/53883 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_382/2026*

Facts — A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and Health Care Agency, however, the organisation was later merged with the controller. According to the data subject, the controller initiated discliplinary proceedings and suspended them based on data collected unlawfully through a tracking system in the company vehicle. The data subject also argued that the controller did not sufficiently inform employees that their location was being tracked through the company vehicles. The DPA received several complaints from other data subjects, and joined the complaints. The controller argued that the geolocation system was a measure to protect its assets, to optimise the management of its vehicles, and to ensure worker safety (e.g. to ensure that an employee followed the route while carrying hazardous materials). The controller argued that it did not process employees’ personal data, as it tracked the vehicles themselves and did not link the vehicle with the employee. Finally, the controller argued that the tracking was in compliance with its workers’ statutes. Holding — The DPA first stated that the controller had complied with its information obligations. Following the collective bargaining agreement, the controller informed data subjects of how their data was going to be processed. In addition, the controller had included a notice on how their location data was processed. Therefore, the DPA did not find a violation of Article 13 GDPR. The DPA found a violation of Article 5(1)(c) GDPR. The DPA found that the controller systematically and continuously monitored employees assigned company vehicles, as they were tracked at very frequent intervals without allowing them to deactivate the tracking. The DPA found this frequent tracking particularly detrimental to data subjects’ rights and freedoms, because the controller was able to access real-time information on vehicle movements. The DPA considered that the controller processed more data than necessary for its purposes, and that it risked processing data related to data subjects’ personal lives. The controller’s need to ensure that hazardous materials are transported safely did not justify continuously monitoring employees, especially because the controller later increased the interval of monitoring to every 15 minutes. Finally, the DPA dismissed the argument that the controller only tracked vehicles and not data subjects. This is because the controller could identify the data subject at any time by checking the logbook inside the vehicles. The DPA also found a violation of Articles 5(1)(a), (b), 6 and 88 GDPR. The DPA stated that a collective bargaining agreement was a necessary but not always sufficient condition for the data processing activities to be lawful. This means that the controller must comply with both labour and data protection legislation. Given the excessive amount of data processed, the DPA found that the controller did not have a legal basis to process this data. The DPA found that the controller also unlawfully further processed the location data of data subjects for disciplinary proceedings, in violation of the principle of purpose limitation. This is because the disciplinary proceedings did not specifically concern the data subject’s movements detected by the tracking system, but rather the data subject’s failure to notify potentially dangerous situations that occurred during the performance of their duties. Finally, the DPA found a violation of Articles 25 and 35 GDPR. The DPA found that the controller failed to choose a less invasive solution during the design phase. Therefore, its processing activities did not meet the requirements of privacy by design and default (Article 25 GDPR). The controller violated Article 35 GDPR by not conducting a data protection impact assessment (DPIA) before processing data subjects’ location data. The controller’s awareness of data protection issues and evidence of introducing measures to protect data subjects was not sufficient to meet this requirement. The DPA fined the controller €6,000. The DPA took into consideration the changes the controller had made during its investigations, including adjusting the interval of tracking vehicles from every 60 seconds to every 15 minutes

### Greek Ministry of Immigration and Asylum: Insufficient technical and organisational measures to ensure information security

*Source: Hellenic Data Protection Authority (HDPA), 2024-04-02 — https://overview.legal/posts/48381 — original: https://www.enforcementtracker.com/ETid-2266*

The Hellenic DPA has imposed a fine of EUR 175,000 on the Greek Ministry of Immigration and Asylum. The DPA found that the controller had failed to properly carry out a required data protection impact assessment and had not cooperated properly with the DPA.

## Recent developments

### AP vraagt reacties op lijst DPIA-uitzonderingen

*Source: Autoriteit Persoonsgegevens, 2026-06-24 — https://overview.legal/posts/53065 — original: https://autoriteitpersoonsgegevens.nl/actueel/ap-vraagt-reacties-op-lijst-dpia-uitzonderingen*

De Autoriteit Persoonsgegevens (AP) heeft een lijst opgesteld van soorten verwerkingen waarvoor geen ‘data protection impact assessment' (DPIA) vereist is. Om deze lijst goed aan te laten sluiten bij de praktijk, vraagt de AP via een consultatie reacties aan het mkb, zelfstandige ondernemers, experts en (andere) belanghebbenden.

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

### ICO: How can Privacy Enhancing Technologies help with data protection compliance?

*Source: ICO, 2025-11-07 — https://overview.legal/posts/6334 — original: https://ico.org.uk/media/about-the-ico/consultations/4021464/chapter-5-anonymisation-pets.pdf#entry-362*

> How can PETs help with data protection compliance?
At a glance
• PETs can help you demonstrate a ‘data protection by design and by
default’ approach to your processing.
• PETs can help you to comply with the data minimisation principle by
ensuring you only process the data you need for your purposes, and
provide an appropriate level of security for your processing.
• You can use PETs to give access to datasets which would otherwise be
too sensitive to share, while ensuring individuals’ data is

### ICO: How can privacy-enhancing technologies contribute to compliance with data protection legislation?

*Source: ICO, 2025-11-07 — https://overview.legal/posts/52104*

How can Privacy-Enhancing Technologies (PETs) contribute to compliance with privacy regulations?
In short:
• PETs can help you demonstrate an approach where privacy protection is "naturally" and "by default" integrated into your processes.
• PETs can help you comply with the principle of data minimization by ensuring that you only process the data you need for your purposes, and that you provide an appropriate level of security for your processing.
• You can use PETs to provide access to datasets that would otherwise be too sensitive to share, while simultaneously ensuring that the personal data of individuals remains protected.

### The competitive compass.

*Source: EU News, 2025-04-09 — https://overview.legal/posts/52186*

As previously announced in the "Competitive Compass" (page 12), it appears that, similar to another section of Omnibus III, the rules of the GDPR (General Data Protection Regulation) for SMEs (small and medium-sized enterprises) may be simplified. There seems to be a focus on Article 30 of the GDPR (the registration requirement), and according to reports in Politico, there may also be changes to...

## Literature

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### IMPACT OF GDPR ON UKRAINIAN PERSONAL DATA PROTECTION LEGISLATION

*Source: Pravo ta nauki, 2018-12-30 — https://overview.legal/posts/132472 — original: https://doi.org/10.66556/2522-4549.1519.koshovyi-b*

The article examines the impact of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation – GDPR), which entered into force on 25 May 2018, on Ukrainian personal data protection legislation. The main novelties of GDPR are analyzed, including the principle of accountability, the right to erasure (right to be

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132480 — original: https://doi.org/10.21552/edpl/2020/4/15*

### GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132426 — original: https://doi.org/10.21552/edpl/2019/4/11*

## Tools

### CNIL PIA software (privacy impact assessment tool)

*Source: CNIL, 2026-07-04 — https://overview.legal/posts/53803 — original: https://www.cnil.fr/en/privacy-impact-assessment-pia*

Free, open-source software by the French DPA that guides controllers through a data protection impact assessment (DPIA) as required by Article 35 GDPR: contextualise the processing, assess necessity/proportionality, evaluate risks and document measures. Available as desktop app and self-hostable web version, in many languages.

### ICO Data Protection Impact Assessment (DPIA) guidance and template

*Source: ICO, 2026-07-04 — https://overview.legal/posts/53806 — original: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/*

The UK regulator's step-by-step DPIA guidance with a downloadable template: screening questions to decide whether a DPIA is required, how to describe processing, consultation, risk assessment and sign-off. Widely used as a model beyond the UK.

## Related topics

- **Privacy Impact Assessment** — https://overview.legal/topics/privacy-impact-assessment
  Data protection impact assessments (DPIA)
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/dpia · 2026-08-22
