Skip to content
Topic Contested in court

Encryption

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Encryption and cryptographic measures

169 linked items 8 Laws11 Case Law36 Guidance71 Enforcement32 News

Overview

19 sources · Jul 23, 2026

Legal Framework

Article 32 GDPR establishes the core obligation: controllers and processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing. Encryption is explicitly enumerated as an example of such a measure, alongside pseudonymisation. The provision requires a contextual assessment — state of the art, implementation costs, nature and scope of processing, and risk to data subjects all factor into determining what is "appropriate."

The AI Act reinforces this framework. Recital 69 makes clear that privacy and data protection must be guaranteed throughout the entire AI system lifecycle. Providers must apply data minimisation and data protection by design and by default. Encryption is expressly identified as a measure that can satisfy these principles, alongside anonymisation and technologies that permit algorithms to be brought to the data rather than transmitting personal data between parties.

The DSA touches encryption only obliquely, in the context of intermediary services and liability exemptions — but signals that deliberately facilitating illegal activity through encrypted communications can strip a provider of its neutral intermediary status.

Key Developments

Dutch courts have grappled extensively with encrypted communication platforms in criminal proceedings. The EncroChat and SkyECC cases established that evidence derived from encrypted PGP phones is admissible, but courts have demanded caution — the Rechtbank noted that many messages were only unilaterally decrypted and that an unknown number of chats are missing. The standard set is one of evidentiary restraint: encrypted data must be treated with care when its completeness cannot be verified.

The Amsterdam Court of Appeal's ruling on licence plate parking confirmed that data collection through technical systems is not inherently incompatible with the ECHR or data protection law, provided the processing meets proportionality requirements — a principle that extends to encrypted data collection and retention.

Enforcement actions confirm that the absence of encryption triggers liability. The Slovenian DPA fined a controller €1,300 after an employee stored personal data on a work laptop without security measures. The Spanish AEPD fined FREE TECHNOLOGIES EXCOM €10,000 following a password reset process that failed to safeguard personal data. Both decisions underscore that Article 32's encryption expectation is not aspirational — failure to encrypt personal data on portable devices or in transit constitutes a concrete violation.

Practical Guidance

  • Conduct a risk-based encryption assessment under Article 32 GDPR. Document the state of the art, implementation costs, and the specific risks to data subjects. This assessment must justify the chosen encryption standard or explain why encryption was deemed unnecessary for a particular processing context.

  • Encrypt personal data at rest on all portable devices and endpoints. The Slovenian enforcement action confirms that unencrypted personal data on work laptops is a direct Article 32 violation, regardless of whether a breach actually occurred.

  • Apply encryption as a data protection by design measure in AI systems. Recital 69 of the AI Act positions encryption as a core component of privacy-by-design compliance for AI providers, particularly where training data involves personal data.

  • Preserve evidentiary integrity when handling encrypted data. Following the EncroChat and SkyECC jurisprudence, organisations that decrypt or process encrypted communications must document the completeness and reliability of decrypted data, acknowledging gaps and limitations.

  • Secure password and key management processes. The Spanish AEPD decision demonstrates that encryption is undermined by weak credential handling — password resets and key management must themselves meet Article 32 security standards.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 8
Art. 6(4)(e) the existence of appropriate safeguards, which may include encryption or pseudonymisation. GDPR Art. 32(1)(a) the pseudonymisation and encryption of personal data; GDPR Art. 34(3)(a) the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affe… GDPR Art. 7(2)(b) on the inclusion and specification of cybersecurity-related requirements for ICT products and ICT services in public procurement, including in relatio… NIS2 rec 98 Recital 98 — Promoting encryption for electronic communications security NIS2 Dec 2022 rec 69 Recital 69 — privacy and data protection lifecycle AI Act Jun 2024 rec 104 Recital 104 — cybersecurity obligations for electronic communications providers NIS2 Dec 2022 rec 83 Recital 83 — data security risk assessment and mitigation GDPR Apr 2016 rec 121 Recital 121 — lawful personal data processing for cybersecurity NIS2 Dec 2022 rec 51 Recital 51 — Innovative technology for cybersecurity NIS2 Dec 2022 rec 125 Recital 125 — supervisory authority training and expertise NIS2 Dec 2022 rec 20 Recital 20 — collaboration in illegal activities exclusion DSA Oct 2022
Case Law 11
¶17 Article 113d of the TKG states: ‘A party that is subject to an obligation pursuant to Paragraph 113a(1) must ensure that the data retained pursuant to… Judgment of the Court (Grand Chamber) of 20 September 2022.#Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH.#Requests for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Directive 2002/58/EC – Article 15(1) – ¶24 Under Article 32 of the GDPR, entitled ‘Security of processing’: ‘1. Taking into account the state of the art, the costs of implementation and the nat… Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) – ¶12 Contained in Section 2 of that chapter, which is headed ‘Security of personal data’, Article 32 of that regulation, itself headed ‘Security of process… Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal ¶68 Lastly, it must be pointed out that, under Article 32(1)(a) and (b) of the GDPR, which gives specific expression to the principles of integrity and co… Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal 340/21 VB v Natsionalna agentsia za prihodite CJEU Dec 2023 446/21 Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos Court of Justice of the European Union Oct 2024 670/22 Judgment of the Court (Grand Chamber) of 30 April 2024.#Criminal proceedings against M.N.#Request for a preliminary ruling from the Landgericht Berlin.#Reference for a preliminary ruling – Judicial cooperation in criminal matters – Directive 2014/41/EU – European Investigation Order (EIO) in criminal matters – Obtaining of evidence already in the possession of the competent authorities of the executing State – Conditions for issuing an EIO – Encrypted telecommunications service – EncroChat – Nee Court of Justice of the European Union Apr 2024 169/23 Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t Court of Justice of the European Union Nov 2024 Administrative Court Düsseldorf VG Düsseldorf - 29 K 3490/24 Administrative Court Düsseldorf Jun 2026 District Court Rotterdam Rotterdam Court: DPA did not err in finding ING contactless chip payments GDPR-compliant District Court Rotterdam Jun 2026 GDPRhub CJEU - C‑755/21 P - Kočner v Europol GDPRhub Mar 2024 687/21 Judgment of the Court (Third Chamber) of 25 January 2024.#BL v MediaMarktSaturn Hagen-Iserlohn GmbH.#Request for a preliminary ruling from the Amtsgericht Hagen.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Interpretation of Articles 5, 24, 32 and 82 – Assessment of the validity of Article 82 – Inadmissibility of the request for an assessment of validity – Right to compensation for damage caused by Court of Justice of the European Union Jan 2024 77/21 Judgment of the Court (First Chamber) of 20 October 2022.#Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(b) and (e) – Principle of ‘purpose limitation’ – Principle of ‘storage limitation’ – Creation, from an existing database, of a datab Court of Justice of the European Union Oct 2022 175/20 Judgment of the Court (Fifth Chamber) of 24 February 2022.#SIA 'SS' v Valsts ieņēmumu dienests.#Request for a preliminary ruling from the Administratīvā apgabaltiesa.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 2 – Scope – Article 4 – Concept of ‘processing’ – Article 5 – Principles relating to processing – Purpose limitation – Data minimisation – Article 6 – Lawfulness of processing – Proc Court of Justice of the European Union Feb 2022 Social Court Nuremberg SG Nürnberg - S 5 SF 65/24 DS Social Court Nuremberg Jun 2026
Guidance 36
§0 14 December 2021 Version 2.0 ## Version history | Version 2.0 | 14 12 2021 | Adoption of the Guidelines after public consultation | |---------------|-… Guidelines 01/2021 §16 A frequent cause for a data breach notification is a ransomware attack suffered by the data controller. In these cases a malicious code encrypts the p… Guidelines 01/2021 §20 In this example, the attacker had access to personal data and the confidentiality of cipher text containing personal data in encrypted form was compro… Guidelines 01/2021 §25 In this case, following a detailed impact assessment and incident response process, the controller determined that the breach was unlikely to result i… Guidelines 01/2021 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 on processing of personal data through blockchain technologies Guidelines on processing of personal data through blockchain technologies EDPB Jul 2026 042020 on the use of location data and contact tracing tools in the Guidelines 04/2020 on the use of location data and contact tracing tools in the context of the COVID-19 outbreak EDPB Apr 2020 guidelines on processing of personal data through video devices Guidelines 3/2019 on processing of personal data through video devices EDPB Jan 2020 guidelines on processing personal data in the context of connected vehicles and mobility rel Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Jan 2020 guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 012020 on measures that supplement transfer tools to Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data EDPB Jun 2021 guidelines on the calculation of administrative fines under the gdpr Guidelines 04/2022 on the calculation of administrative fines under the GDPR EDPB May 2023 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 012020 on processing personal data in the context of connected Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Mar 2021 22020 on articles 46 2 a and 46 3 b of regulation 2016679 for Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies EDPB Dec 2020 032020 on the processing of data concerning health for the purpose Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak EDPB Apr 2020 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 guidelines on virtual voice assistants Guidelines 02/2021 on virtual voice assistants EDPB Jul 2021 of the work undertaken by the supervisory authorities within the Report of the work undertaken by the supervisory authorities within the 101 Taskforce EDPB Apr 2023 182024 on the draft decision of the austrian Opinion 18/2024 on the draft decision of the Austrian Supervisory Authority regarding DSGVO-zt GmbH certification criteria EDPB Jul 2024 72024 on the draft decision of the german north rhine Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria EDPB Apr 2024 edps joint opinion 042022 on the proposal for a regulation of EDPB-EDPS Joint Opinion 04/2022 on the Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse EDPB Jul 2022 Show 16 more →
Enforcement 71
AEPD (Spain) AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data AEPD (Spain) Jul 2026 UODO (Poland) UODO (Poland) - DKN.5131.5.2025 UODO (Poland) May 2026 VDAI (Lithuania) VDAI (Lithuania) - 3R-1143 VDAI (Lithuania) Jun 2026 Data Protection Authority of Ireland Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland May 2026 IP (Slovenia) Slovenian DPA fines processor €2,802 for failing to patch known vulnerability (Art. 32) IP (Slovenia) May 2026 Spanish Data Protection Authority (aepd) FREE TECHNOLOGIES EXCOM, S.L.: Insufficient technical and organisational measures to ensure information security Spanish Data Protection Authority (aepd) Feb 2026 AEPD (Spain) AEPD investigates University of Navarra over student COVID-19 vaccination status requests AEPD (Spain) Jul 2026 Slovenian Supervisory Authority (Informacijski pooblaščenec) Legal Entity: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) Dec 2025 Polish National Personal Data Protection Office (UODO) Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security Polish National Personal Data Protection Office (UODO) Nov 2025 HDPA (Greece) HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers HDPA (Greece) Jun 2026 Polish National Personal Data Protection Office (UODO) De districtsinspecteur voor volksgezondheid in Police: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Polish National Personal Data Protection Office (UODO) Nov 2025 NL Data Protection Authority of Ireland Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland Sep 2024 Polish National Personal Data Protection Office (UODO) POLAND DPA: Insufficient technical and organisational measures to ensure information security Polish National Personal Data Protection Office (UODO) Nov 2024 Spanish Data Protection Authority (aepd) Owner of a Pharmacy Office: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) May 2025 Spanish Data Protection Authority (aepd) Owner of a Pharmacy Office: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) May 2025 Polish National Personal Data Protection Office (UODO) POLAND DPA: Insufficient technical and organisational measures to ensure information security Polish National Personal Data Protection Office (UODO) Nov 2024 Spanish Data Protection Authority (aepd) Eigenaar van een apotheek: Niet-naleving van algemene principes voor gegevensverwerking. Spanish Data Protection Authority (aepd) May 2025 NL Spanish Data Protection Authority (aepd) Eigenaar van een apotheek: Overtreding van de algemene principes van gegevensverwerking. Spanish Data Protection Authority (aepd) May 2025 NL Danish Data Protection Authority (Datatilsynet) Municipality of Vejen: Insufficient technical and organisational measures to ensure information security Danish Data Protection Authority (Datatilsynet) Aug 2024 Polish National Personal Data Protection Office (UODO) Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security Polish National Personal Data Protection Office (UODO) Apr 2024 Show 51 more →
News 32
European Digital Rights The “Chat Control 1.0” saga: Big Tech can scan our private messages again – but Parliament sent a strong signal against mass surveillance European Digital Rights Aug 2026 Electronic Frontier Foundation Canada Is Forging Ahead with Its Dangerous Surveillance Bill Electronic Frontier Foundation Jun 2026 Electronic Frontier Foundation Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features Electronic Frontier Foundation Jul 2026 Access Now Access Now urges the Ninth Circuit to protect encryption from NSO’s spyware Access Now May 2026 Electronic Frontier Foundation Onward, Friends Electronic Frontier Foundation Jun 2026 Electronic Frontier Foundation Introducing Encrypt It Already Electronic Frontier Foundation Jan 2026 Electronic Frontier Foundation Surveillance and self-defense: A review of the year 2025. Electronic Frontier Foundation Jan 2026 Electronic Frontier Foundation Surveillance Self-Defense: 2025 Year in Review Electronic Frontier Foundation Jan 2026 Electronic Frontier Foundation Surveillance and Self-Defense: A Look Back at 2025. Electronic Frontier Foundation Jan 2026 Electronic Frontier Foundation 🗣 Homeland Security Wants Names | EFFector 38.3 Electronic Frontier Foundation Feb 2026 EDPB Support the work of the EDPB as an expert. EDPB Nov 2025 European Digital Rights Moving past ‘Chat Control’ to solutions that truly protect kids and privacy European Digital Rights Dec 2025 European Digital Rights From "chat monitoring" to solutions that truly protect children and their privacy. European Digital Rights Dec 2025 European Digital Rights From "Chat Control" to solutions that actually protect children and their privacy. European Digital Rights Dec 2025 noyb - European Center for Digital Rights Political Microtargeting by EU Commission illegal noyb - European Center for Digital Rights Dec 2024 noyb - European Center for Digital Rights Complaint: Amazon doesn’t allow baseline TLS security noyb - European Center for Digital Rights Mar 2020 Hogan Lovells UK data protection reform: How the UK's GDPR may change Hogan Lovells Sep 2022 Dutch Courts "Overijssel court rejects municipality's claim in cyber attack case" Dutch Courts May 2023 DataGuidance Hunton geeft een samenvatting van twee artikelen uit de nieuwe SCC-richtlijnen: het onderdeel over "lokale wetgeving en toegang tot overheidsinstanties". DataGuidance Oct 2022 NL News UN report details threats to global digital privacy, human rights News Sep 2022 Show 12 more →
Literature 11
Bankarstvo GDPR: A new challenge for personal data protection Bankarstvo Jan 2017 IJARCCE Challenges of Cloud Data Privacy in Surveillance: Legal, Technical, and Ethical Implications IJARCCE Jul 2026 International Journal of Social Sciences and Public Administration Regulatory Responses to Data Breaches: Evaluating the Effectiveness of GDPR and CCPA in Consumer Protection International Journal of Social Sciences and Public Administration Jan 2025 Journal of Information Technology Building data management capabilities to address data protection regulations: Learnings from EU-GDPR Journal of Information Technology Jan 2023 International Journal of Science and Research (IJSR) Tracing the Impact of GDPR on Global Data Privacy International Journal of Science and Research (IJSR) Sep 2024 Innovative STEM Education GDPR - General Data Protection Regulation on Sites Requiring Accessibility Innovative STEM Education Jun 2021 European Law Open The triple helix: markets, fundamental rights, and security in EU digital law European Law Open Jul 2026 Zenodo (CERN European Organization for Nuclear Research) Beyond GDPR: The Architectural Challenge of Data Sovereignty and Confidential Computing in the Post-2024 Era Zenodo (CERN European Organization for Nuclear Research) Dec 2026 International Journal of Law and Societal Studies Balancing Security and Privacy: Analyzing the Effectiveness of EU Digital Surveillance Laws in Criminal Proceedings International Journal of Law and Societal Studies Sep 2025 Electronics Comparative Analysis of Passkeys (FIDO2 Authentication) on Android and iOS for GDPR Compliance in Biometric Data Protection Electronics Oct 2025 European Economic Letters (EEL) "From Cookies to Context: Adapting Marketing Strategies in a Cookieless Digital Environment" European Economic Letters (EEL) Jun 2025