# Encryption — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/encryption
> Sources are cited per item. Verify against the official texts before relying on them.

Encryption and cryptographic measures

## Overview

## Legal Framework

Article 32 GDPR establishes the core obligation: controllers and processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing. Encryption is explicitly enumerated as an example of such a measure, alongside pseudonymisation. The provision requires a contextual assessment — state of the art, implementation costs, nature and scope of processing, and risk to data subjects all factor into determining what is "appropriate."

The AI Act reinforces this framework. Recital 69 makes clear that privacy and data protection must be guaranteed throughout the entire AI system lifecycle. Providers must apply data minimisation and data protection by design and by default. Encryption is expressly identified as a measure that can satisfy these principles, alongside anonymisation and technologies that permit algorithms to be brought to the data rather than transmitting personal data between parties.

The DSA touches encryption only obliquely, in the context of intermediary services and liability exemptions — but signals that deliberately facilitating illegal activity through encrypted communications can strip a provider of its neutral intermediary status.

## Key Developments

Dutch courts have grappled extensively with encrypted communication platforms in criminal proceedings. The EncroChat and SkyECC cases established that evidence derived from encrypted PGP phones is admissible, but courts have demanded caution — the Rechtbank noted that many messages were only unilaterally decrypted and that an unknown number of chats are missing. The standard set is one of evidentiary restraint: encrypted data must be treated with care when its completeness cannot be verified.

The Amsterdam Court of Appeal's ruling on licence plate parking confirmed that data collection through technical systems is not inherently incompatible with the ECHR or data protection law, provided the processing meets proportionality requirements — a principle that extends to encrypted data collection and retention.

Enforcement actions confirm that the absence of encryption triggers liability. The Slovenian DPA fined a controller €1,300 after an employee stored personal data on a work laptop without security measures. The Spanish AEPD fined FREE TECHNOLOGIES EXCOM €10,000 following a password reset process that failed to safeguard personal data. Both decisions underscore that Article 32's encryption expectation is not aspirational — failure to encrypt personal data on portable devices or in transit constitutes a concrete violation.

## Practical Guidance

- **Conduct a risk-based encryption assessment under Article 32 GDPR.** Document the state of the art, implementation costs, and the specific risks to data subjects. This assessment must justify the chosen encryption standard or explain why encryption was deemed unnecessary for a particular processing context.

- **Encrypt personal data at rest on all portable devices and endpoints.** The Slovenian enforcement action confirms that unencrypted personal data on work laptops is a direct Article 32 violation, regardless of whether a breach actually occurred.

- **Apply encryption as a data protection by design measure in AI systems.** Recital 69 of the AI Act positions encryption as a core component of privacy-by-design compliance for AI providers, particularly where training data involves personal data.

- **Preserve evidentiary integrity when handling encrypted data.** Following the EncroChat and SkyECC jurisprudence, organisations that decrypt or process encrypted communications must document the completeness and reliability of decrypted data, acknowledging gaps and limitations.

- **Secure password and key management processes.** The Spanish AEPD decision demonstrates that encryption is undermined by weak credential handling — password resets and key management must themselves meet Article 32 security standards.

## Legislation (full text of key provisions)

### Recital 98 — Promoting encryption for electronic communications security

*Source: NIS2, nis2-rec-98-en, 2022-12-14 — https://overview.legal/posts/96724*

In order to safeguard the security of public electronic communications networks and publicly available electronic communications services, the use of encryption technologies, in particular end-to-end encryption as well as data-centric security concepts, such as cartography, segmentation, tagging, access policy and access management, and automated access decisions, should be promoted. Where necessary, the use of encryption, in particular end-to-end encryption should be mandatory for providers of public electronic communications networks or of publicly available electronic communications services in accordance with the principles of security and privacy by default and by design for the purposes of this Directive. The use of end-to-end encryption should be reconciled with the Member States’ powers to ensure the protection of their essential security interests and public security, and to allow for the prevention, investigation, detection and prosecution of criminal offences in accordance with Union law. However, this should not weaken end-to-end encryption, which is a critical technology for the effective protection of data and privacy and the security of communications.

### Recital 69 — privacy and data protection lifecycle

*Source: AI Act, aiact-rec-69-en, 2024-06-12 — https://overview.legal/posts/93820*

The right to privacy and to protection of personal data must be guaranteed throughout the entire lifecycle of the AI system. In this regard, the principles of data minimisation and data protection by design and by default, as set out in Union data protection law, are applicable when personal data are processed. Measures taken by providers to ensure compliance with those principles may include not only anonymisation and encryption, but also the use of technology that permits algorithms to be brought to the data and allows training of AI systems without the transmission between parties or copying of the raw or structured data themselves, without prejudice to the requirements on data governance provided for in this Regulation.

### Recital 104 — cybersecurity obligations for electronic communications providers

*Source: NIS2, nis2-rec-104-en, 2022-12-14 — https://overview.legal/posts/96736*

Providers of public electronic communications networks or of publicly available electronic communications services should implement security by design and by default, and inform their service recipients of significant cyber threats and of measures they can take to protect the security of their devices and communications, for example by using specific types of software or encryption technologies.

### Recital 83 — data security risk assessment and mitigation

*Source: GDPR, gdpr-rec-83-en, 2016-04-27 — https://overview.legal/posts/91681*

In order to maintain security and to prevent processing in infringement of this Regulation, the controller or processor should evaluate the risks inherent in the processing and implement measures to mitigate those risks, such as encryption. Those measures should ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the costs of implementation in relation to the risks and the nature of the personal data to be protected. In assessing data security risk, consideration should be given to the risks that are presented by personal data processing, such as accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed which may in particular lead to physical, material or non-material damage.

### Recital 121 — lawful personal data processing for cybersecurity

*Source: NIS2, nis2-rec-121-en, 2022-12-14 — https://overview.legal/posts/96770*

The processing of personal data, to the extent necessary and proportionate for the purpose of ensuring security of network and information systems by essential and important entities, could be considered to be lawful on the basis that such processing complies with a legal obligation to which the controller is subject, in accordance with the requirements of Article 6(1), point (c), and Article 6(3) of Regulation (EU) 2016/679. Processing of personal data could also be necessary for legitimate interests pursued by essential and important entities, as well as providers of security technologies and services acting on behalf of those entities, pursuant to Article 6(1), point (f), of Regulation (EU) 2016/679, including where such processing is necessary for cybersecurity information-sharing arrangements or the voluntary notification of relevant information in accordance with this Directive. Measures related to the prevention, detection, identification, containment, analysis and response to incidents, measures to raise awareness in relation to specific cyber threats, exchange of information in the context of vulnerability remediation and coordinated vulnerability disclosure, the voluntary exchange of information about those incidents, and cyber threats and vulnerabilities, indicators of compromise, tactics, techniques and procedures, cybersecurity alerts and configuration tools could require the processing of certain categories of personal data, such as IP addresses, uniform resources locators (URLs), domain names, email addresses and, where they reveal personal data, time stamps. Processing of personal data by the competent authorities, the single points of contact and the CSIRTs, could constitute a legal obligation or be considered to be necessary for carrying out a task in the public interest or in the exercise of official authority vested in the controller pursuant to Article 6(1), point (c) or (e), and Article 6(3) of Regulation (EU) 2016/679, or for pursuing a legitimate interest of the essential and important entities, as referred to in Article 6(1), point (f), of that Regulation. Furthermore, national law could lay down rules allowing the competent authorities, the single points of contact and the CSIRTs, to the extent that is necessary and proportionate for the purpose of ensuring the security of network and information systems of essential and important entities, to process special categories of personal data in accordance with Article 9 of Regulation (EU) 2016/679, in particular by providing for suitable and specific measures to safeguard the fundamental rights and interests of natural persons, including technical limitations on the re-use of such data and the use of state-of-the-art security and privacy-preserving measures, such as pseudonymisation, or encryption where anonymisation may significantly affect the purpose pursued.

### Recital 51 — Innovative technology for cybersecurity

*Source: NIS2, nis2-rec-51-en, 2022-12-14 — https://overview.legal/posts/96630*

Member States should encourage the use of any innovative technology, including artificial intelligence, the use of which could improve the detection and prevention of cyberattacks, enabling resources to be diverted towards cyberattacks more effectively. Member States should therefore encourage in their national cybersecurity strategy activities in research and development to facilitate the use of such technologies, in particular those relating to automated or semi-automated tools in cybersecurity, and, where relevant, the sharing of data needed for training users of such technology and for improving it. The use of any innovative technology, including artificial intelligence, should comply with Union data protection law, including the data protection principles of data accuracy, data minimisation, fairness and transparency, and data security, such as state-of-the-art encryption. The requirements of data protection by design and by default laid down in Regulation (EU) 2016/679 should be fully exploited.

### Recital 125 — supervisory authority training and expertise

*Source: NIS2, nis2-rec-125-en, 2022-12-14 — https://overview.legal/posts/96778*

The competent authorities should ensure that their supervisory tasks in relation to essential and important entities are carried out by trained professionals, who should have the necessary skills to carry out those tasks, in particular with regard to conducting on-site inspections and off-site supervision, including the identification of weaknesses in databases, hardware, firewalls, encryption and networks. Those inspections and that supervision should be conducted in an objective manner.

### Recital 20 — collaboration in illegal activities exclusion

*Source: DSA, dsa-rec-20-en, 2022-10-19 — https://overview.legal/posts/95437*

Where a provider of intermediary services deliberately collaborates with a recipient of the services in order to undertake illegal activities, the services should not be deemed to have been provided neutrally and the provider should therefore not be able to benefit from the exemptions from liability provided for in this Regulation. This should be the case, for instance, where the provider offers its service with the main purpose of facilitating illegal activities, for example by making explicit that its purpose is to facilitate illegal activities or that its services are suited for that purpose. The fact alone that a service offers encrypted transmissions or any other system that makes the identification of the user impossible should not in itself qualify as facilitating illegal activities.

## Case law

### SG Nürnberg - S 5 SF 65/24 DS

*Source: Social Court Nuremberg, 2026-06-10 — https://overview.legal/posts/122874 — original: https://gdprhub.eu/index.php?title=SG_Nürnberg_-_S_5_SF_65/24_DS*

Facts — The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network. On 16 June 2023, the processor informed the controller about the incident. On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents. On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant. Holding — The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles: First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities. Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded. Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take. Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.

### CJEU - C‑755/21 P - Kočner v Europol

*Source: GDPRhub, 2024-03-05 — https://overview.legal/posts/122879 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑755/21_P_-_Kočner_v_Europol*

Facts — Following the murder of a Slovak journalist and his fiancée, Mr Ján Kuciak and Ms Martina Kušnírová, in Slovakia on 21 February 2018, the Slovak authorities (Národná kriminálna agentúra (National Crime Agency, Slovakia; ‘NAKA’)) conducted an extensive investigation. At the request of those authorities, the European Union Agency for Law Enforcement Cooperation (‘Europol’) extracted the data stored on two mobile telephones allegedly belonging to Mr Marian Kočner, the data subject, who was prosecuted as an accomplice to that murder for having ordered the killings, following the investigation. Europol sent its scientific reports to those authorities and delivered to them a hard disk containing the encrypted data it had extracted. In one of its reports, Europol stated that Mr Kočner had been detained on suspicion of a financial offence since 2018 and that his name was, inter alia, directly linked to the ‘so-called mafia lists’ and the ‘Panama Papers’. In May 2019, the Slovak press and international network of investigative journalists published a large amount of information relating to Mr Kočner from his mobile telephones, including transcripts of intimate communications exchanged between him and his girlfriend. The conversation was carried by means of encrypted messaging service. For the reasons stated above, Mr Kočner sent a complaint to Europol seeking compensation in the amount of €100,000 as a reparation for the non-material damage on the bases of Article 50(1) Regulation 2016/794. The sought compensation consisted of €50,000 for the unlawful disclosure of data subject's intimate conversation with his girlfriend and €50,000 for the inclusion of his name on the 'mafia list'. Europol and Slovak Republic contended that the arguments are unfounded as, firstly, Regulation 2016/794 (setting up the rules for the Europol) does not provide for such joint liability of Europol and the Member State. Secondly, Europol rejects any liability due to the absence of unlawful conduct on its part given that alleged harmful events occurred during storage of the national investigation file. As such, these circumstances do not constitute ‘unlawful data processing operations’ within the meaning of Article 50(1) Regulation 2016/794. Lastly, Europol stated that even if joint liability was applicable, the absence of any unlawful conduct on its part and of a causal link between such conduct and the damage suffered could not give rise to a liability. Holding — Firstly, the CJEU ruled that there is no need to establish additionally to which of these two entities - Europol or the Member State - that unlawful processing was attributable. In order for such joint and several liability to be incurred in the first stage, the individual concerned must show only that, in the course of cooperation between Europol and the Member State concerned, unlawful data processing that caused him or her to suffer damage has been carried out. Secondly, concerning specifically the leak of the 'so-called mafia list', the CJEU found that the data subject had failed to establish that the ‘mafia lists’ on which his name had allegedly been included had been drawn up and kept by Europol. The data subject's claim contradicted the evidence whereby it was apparent that the leaked Europol report containing Mr Kočner’s name on the ‘mafia list’ was subsequent to and, thus, unrelated to Slovak press publications where he was represented as ‘member of the mafia’. Thirdly, the CJEU rejected the Europol’s argument that it met its obligations and implemented appropriate technical and organizational measures to protect personal data against any form of unauthorized access. The Court observed that the data of such intimate nature bears out the need for its protection to be strictly ensured in cooperation with Member States under Regulation 2016/794. As an unauthorized access took place it constituted a sufficiently serious breach of a rule of EU law intended to confer rights on individuals. Fourthly, the Court held that European Union can incur non-contractual liability in the present case, as the result of publication of data subject’s intimate conversations. The leak of this information adversely affected his honour and professional reputation, and violated his rights to privacy, family life and respect for his communications guaranteed by Article 7 of the Charter of Fundamental Rights of the European Union. As a result, the CJEU held Europol and the Slovak Republic jointly and severally liable for the unlawful data processing which caused the data subject to suffer non-material damage. The Court stated that Europol has the possibility to refer the matter to its Management Board so that it can determine who has the ultimate responsibility for the compensation awarded to the data subject. However, this exclusively concerns the internal allocation of responsibilities between the two jointly liable controllers. The compensation attributed to the data subject for the inclusion of his name on the ‘mafia list’ by Europol was firstly set at €50,000. As this claim was dismissed, the Court only examined the damage regarding the compensation of €50,000 for disclosure of the data subject’s conversation with his girlfriend. The Court decided that the alleged damage resulted solely from the disclosure of transcripts of the conversation and no evidence established that any photographs have been disclosed. As a result, the CJEU granted Mr Kočner compensation in the amount of €2,000 as reparation for that damage.

### VB v Natsionalna agentsia za prihodite

*Source: CJEU, C-340/21, 2023-12-14 — https://overview.legal/posts/51485 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0340*

Data breach alone does not establish inadequate security measures. Burden on controller to prove adequacy.

### Judgment of the Court (Third Chamber) of 25 January 2024.#BL v MediaMarktSaturn Hagen-Iserlohn GmbH.#Request for a preliminary ruling from the Amtsgericht Hagen.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Interpretation of Articles 5, 24, 32 and 82 – Assessment of the validity of Article 82 – Inadmissibility of the request for an assessment of validity – Right to compensation for damage caused by

*Source: Court of Justice of the European Union, C-687/21, 2024-01-25 — https://overview.legal/posts/132272 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0687*

In Case C-687/21, the Court of Justice of the European Union interpreted Articles 5, 24, 32, and 82 of the GDPR in response to a preliminary ruling request from the Amtsgericht Hagen in proceedings between data subject BL and MediaMarktSaturn Hagen-Iserlohn GmbH concerning alleged non-material damage from personal data transmitted to an unauthorized third party due to employee error. The Court held that a controller's infringement of GDPR security obligations through employee error can give rise to a right to compensation under Article 82, that the severity of the infringement may be relevant to assessing both the appropriateness of protective measures and the existence of damage, and that the concept of non-material damage should be interpreted broadly without requiring a minimum threshold of severity. No fine was imposed, as the ruling addresses interpretation of GDPR provisions rather than administrative penalties.

### VG Düsseldorf - 29 K 3490/24

*Source: Administrative Court Düsseldorf, 2026-06-22 — https://overview.legal/posts/108992 — original: https://gdprhub.eu/index.php?title=VG_Düsseldorf_-_29_K_3490/24*

Facts — A district (the controller), acting as the lower water authority, initiated administrative proceedings after identifying unauthorised riverbank works and a private jetty on two riverside properties. One property belonged to a water utility company, while the other belonged to a municipality and was leased to the data subjects. During those proceedings, the controller shared the data subjects' personal data with various participants, including the owners of the affected properties, other public authorities and a lawyer who claimed to represent the data subjects. The data subjects lodged a complaint with the competent supervisory authority (LDI NRW), alleging that the controller had unlawfully processed and disclosed their personal data. They argued that their personal data had been shared with uninvolved third parties, that the controller had communicated with a lawyer whom they had not authorised, recorded a telephone conversation with an unknown person, and transmitted personal data by unencrypted email. The controller's data protection officer addressed each allegation and provided additional factual information concerning the disputed processing operations. The DPA initially informed the data subjects that no GDPR infringement was apparent, invited them to provide any additional factual information, and explained that it would obtain extracts from the controller's administrative file if there were concrete indications that it contained relevant facts not already available. The data subjects did not identify any additional facts and instead reiterated their legal position that the controller had breached its GDPR accountability obligations. The DPA rejected the complaint, concluding that no GDPR infringement could be established. The data subjects then brought an action before the Verwaltungsgericht Düsseldorf (Administrative Court Düsseldorf), seeking a fresh decision on their complaint on the basis that the DPA had failed to adequately investigate the complaint because it had not obtained the controller's administrative file before reaching its decision. Holding — The court held that Articles 57(1)(f) and 77(1) GDPR give rise to an enforceable right requiring a supervisory authority to investigate a complaint to the extent appropriate in the circumstances before determining whether a GDPR infringement has occurred. Recital 141 GDPR requires the investigation to extend as far as is appropriate in light of the circumstances of the individual case, including the significance of the complaint and the seriousness of the alleged infringement. Applying these principles, the court held that the DPA had adequately investigated the complaint. It had considered each allegation together with the detailed response provided by the controller's data protection officer, invited the data subjects to provide any additional factual information, and explained that it would obtain extracts from the administrative file if concrete indications emerged that further relevant facts required clarification. As the data subjects did not provide any additional facts and there were no objective indications that the information already available was inaccurate or incomplete, the court held that the DPA was not required to obtain the controller's administrative file or undertake further investigations in the absence of concrete indications that additional factual clarification was necessary. The court further held that the DPA had correctly concluded that no GDPR infringement had occurred. The court held that the disputed processing was lawful under Article 6(1)(e) GDPR, read together with Article 6(3) GDPR and § 88 of the German Water Resources Act (WHG), which provided the legal basis for the processing. The court also held that the transmission of personal data by email did not infringe Article 5(1)(f) GDPR because, in the circumstances of the case, transport encryption provided an appropriate level of security.

### Rotterdam Court: DPA did not err in finding ING contactless chip payments GDPR-compliant

*Source: District Court Rotterdam, 2026-06-24 — https://overview.legal/posts/96826 — original: https://gdprhub.eu/index.php?title=Rb._Rotterdam_-_ROT_25/7371*

Facts — ING Bank N.V. (the controller) is a bank. In 2022, several data subjects brought a complaint to the DPA regarding the controller’s contactless payments. The data subjects requested the controller to issue debit cards without a chip that would enable contactless payments. The controller stated that this was not possible, however, the contactless payment feature could be disabled on the data subjects’ cards. The data subjects later filed a complaint because the debit cards contained the chips even if the contactless feature was disabled. The DPA dismissed the complaint in 2024, on the grounds that further investigation would be needed to determine whether the controller violated the GDPR or not. The DPA stated that it had limited capacity and such an investigation would place a heavy burden on it. The data subjects appealed this decision to the court, who determined that the DPA had wrongfully failed to hear the data subjects during the objection phase. The DPA issued a new decision in 2025 and concluded that the controller had not violated the GDPR. The data subjects appealed this decision, arguing that the DPA had again not investigated the case sufficiently. In addition, the data subjects argued that the controller processed personal data through the debit card chip without a valid legal basis. This is because the chip allowed payments made with blocked or expired cards, meaning Article 6(1)(b) GDPR did not apply. The controller could also not rely on consent (Article 6(1)(a) GDPR) to process the data. The DPA argued that the GDPR does not require controllers to completely eliminate a risk. In addition, disabling contactless payments or blocking cards were related to the contract between the data subject and the controller; the DPA argued that this did not remove the basis to process personal data. Holding — The court found that the DPA investigated the complaint to an appropriate extent and was not required to conduct a further investigation. According to the court, the data subjects did not provide sufficient evidence that the controller’s statements were incorrect or that the DPA lacked the technical knowledge during its investigations. The court upheld the DPA’s reasoning that Article 32 GDPR does not require a security risk to be completely eliminated, and concluded that the DPA could reasonably decide that there was no violation of the GDPR. Similarly, the court upheld the DPA’s reasoning and concluded that the controller had a valid legal basis to process the data subjects’ personal data. The court saw no need to assess potential violations of other laws (e.g. fraud or forgery) or consumer law issues, on the grounds that the DPA’s investigation is limited to compliance with the GDPR. The DPA is also not required to coordinate or refer the case to other competent authorities. The court dismissed the appeal.

### Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t

*Source: Court of Justice of the European Union, C-169/23, 2024-11-28 — https://overview.legal/posts/132158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0169*

In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan Government Office, as controller issuing COVID-19 immunity certificates, was required to provide information to data subjects under Article 14 GDPR where the personal data was not collected directly from them. The Court held that data generated by the controller in the context of its own processes falls within the Article 14(5)(c) exemption from the obligation to provide information, provided that Member State law ensures appropriate measures to protect the data subject's legitimate interests, including data security measures under Article 32. The Court also confirmed that supervisory authorities retain competence to handle complaints under Article 77(1) even where the Article 14(5)(c) exemption applies.

### Judgment of the Court (First Chamber) of 20 October 2022.#Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(b) and (e) – Principle of ‘purpose limitation’ – Principle of ‘storage limitation’ – Creation, from an existing database, of a datab

*Source: Court of Justice of the European Union, C-77/21, 2022-10-20 — https://overview.legal/posts/132306 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0077*

In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) concerning a personal data breach. The Court held that creating a new database from an existing one for testing and error-correction purposes constitutes further processing requiring compatibility assessment under the purpose limitation principle, and that the storage limitation principle applies such that data must be deleted once the testing purpose is fulfilled. No fine was imposed at the EU level, as the matter was remitted to the referring Hungarian court.

### Judgment of the Court (Grand Chamber) of 30 April 2024.#Criminal proceedings against M.N.#Request for a preliminary ruling from the Landgericht Berlin.#Reference for a preliminary ruling – Judicial cooperation in criminal matters – Directive 2014/41/EU – European Investigation Order (EIO) in criminal matters – Obtaining of evidence already in the possession of the competent authorities of the executing State – Conditions for issuing an EIO – Encrypted telecommunications service – EncroChat – Nee

*Source: Court of Justice of the European Union, C-670/22, 2024-04-30 — https://overview.legal/posts/132261 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0670*

The Court of Justice of the European Union (Grand Chamber), in response to a preliminary ruling from the Landgericht Berlin, examined the interpretation of Directive 2014/41/EU (the European Investigation Order Directive) in the context of criminal proceedings against M.N. The case addressed the lawfulness of EIOs issued by German authorities to obtain evidence already in the possession of the executing State, specifically data derived from the EncroChat encrypted telecommunications service, and clarified the conditions for issuing an EIO and the impact of evidence obtained in potential breach of EU law on fundamental rights and data protection. The Court's ruling provides guidance on the principles of equivalence and effectiveness, the necessity of judicial authorization, and the admissibility of evidence gathered through cross-border investigative measures under the EIO framework.

### Judgment of the Court (Fifth Chamber) of 24 February 2022.#SIA 'SS' v Valsts ieņēmumu dienests.#Request for a preliminary ruling from the Administratīvā apgabaltiesa.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 2 – Scope – Article 4 – Concept of ‘processing’ – Article 5 – Principles relating to processing – Purpose limitation – Data minimisation – Article 6 – Lawfulness of processing – Proc

*Source: Court of Justice of the European Union, C-175/20, 2022-02-24 — https://overview.legal/posts/132316 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0175*

In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a request by the Latvian State Tax Authority for SIA 'SS' to disclose personal data from online vehicle sale advertisements for tax enforcement purposes. The Court held that national law may require controllers to provide personal data to tax authorities under Article 6(1)(c) and (e), provided the request complies with data minimisation and purpose limitation principles, meaning authorities must limit requests to what is necessary and proportionate for the specific tax investigation. No fine was imposed as this was a preliminary ruling proceeding.

### Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos

*Source: Court of Justice of the European Union, C-446/21, 2024-10-04 — https://overview.legal/posts/132159 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0446*

In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR Articles 5(1)(b), 5(1)(c), 6(1), and 9 concerning the lawfulness of processing user personal data for personalised advertising on online social networks. The Court addressed whether such processing can be deemed compatible with the original purpose of data collection under a platform's terms of use, the applicability of the data minimisation principle, and the conditions under which special categories of personal data, including data concerning sexual orientation made public by the data subject, may be processed. No fine was imposed, as the ruling provides interpretative guidance to the Austrian Supreme Court for resolution of the underlying dispute.

## Guidance

### Guidelines 9/2022 on personal data breach notification under GDPR

*Source: EDPB, edpb-guidelines-on-personal-data-breach-notification-under-gdpr, 2023-04-04 — https://overview.legal/posts/38058 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-92022-on-personal-data-breach-notification-under-gdpr_en*

The EDPB adopted Guidelines 9/2022 (Version 2.0, 28 March 2023) to update and replace the prior WP250 guidance on personal data breach notification under Articles 33 and 34 of the GDPR. The guidelines address the definition and types of personal data breaches, controller and processor notification obligations, the concept of a controller becoming "aware" of a breach, cross-border and non-EU establishment breach scenarios, and the conditions under which notification to supervisory authorities and data subjects is or is not required.

### Guidelines 01/2021

*Source: EDPB, edpb-guidelines-on-examples-regarding-personal-data-breach-notification, 2022-01-03 — https://overview.legal/posts/38047 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012021-on-examples-regarding-personal-data-breach-notification_en*

The European Data Protection Board (EDPB) adopted Guidelines 01/2021 on December 14, 2021, providing practical examples and analysis regarding personal data breach notification obligations under Articles 33 and 34 of the GDPR. The guidelines present hypothetical scenarios covering ransomware attacks and data exfiltration incidents, illustrating how controllers should assess risk to determine whether notification to supervisory authorities and communication to data subjects are required. The document serves as interpretive guidance for controllers evaluating breach severity, appropriate mitigation measures, and notification decisions, and does not impose any fines or sanctions.

### Report of the work undertaken by the supervisory authorities within the 101 Taskforce

*Source: EDPB, report-of-the-work-undertaken-by-the-supervisory-authorities-within-the-en, 2023-04-19 — https://overview.legal/posts/125859 — original: https://www.edpb.europa.eu/documents/task-force-report/report-of-the-work-undertaken-by-the-supervisory-authorities-within-the_en*

Final 1 Report of the work undertaken by the supervisory authorities within the 101 Task Force 28 March 2023 Final 2 Final 3 DISCLAIMER The EDPB created the 101 Task Force to promote cooperation and effective exchange of information between the Supervisory Authorities on this specific subject-matter, in accordance with Article 70(1)(u) GDPR. The positions presented in this document result from the coordination of the Supervisory Authorities taking part in the task force with a view to handling…

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### Guidelines on processing of personal data through blockchain technologies

*Source: EDPB, guidelines-on-processing-of-personal-data-through-blockchain-technologies-en, 2026-07-07 — https://overview.legal/posts/125668 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-on-processing-of-personal-data-through-blockchain-technologies_en*

Guidelines 02/2025 on processing of personal data through blockchain technologies Version 2.0 Adopted on 07 July 2026 1 | Adopted Version history Version Date Adoption information version 1.1 08 April 2025 adoption of the guidelines before public consultation version 2.0 07 July 2026 adoption of the guidelines after public consultation 3 | Adopted 4 | Adopted The European Data Protection Board Having regard to Article 70 (1)(e) of the Regulation 2016/679/EU of the European Parliament and of the…

### Statement 1/2024 on legislative developments regarding the Proposal for a Regulation laying down rules to prevent and combat child sexual abuse

*Source: EDPB, statement-12024-on-legislative-developments-regarding-the-en, 2024-02-14 — https://overview.legal/posts/125769 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-12024-on-legislative-developments-regarding-the_en*

1 Statement 1/2024 on legislative developments regarding the Proposal for a Regulation laying down rules to prevent and combat child sexual abuse Adopted on 13 February 2024 The European Data Protection Board has adopted the following statement: The European Data Protection Board (‘EDPB’) acknowledges the importance of the fight against child sexual abuse online 1 . While it welcomes the recent improvements proposed by the European Parliament 2 that remedy some of the main issues of the…

### Statement 03/2021 on the ePrivacy Regulation

*Source: EDPB, statement-032021-on-the-eprivacy-regulation-en, 2021-03-09 — https://overview.legal/posts/126052 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-032021-on-the-eprivacy-regulation_en*

1 Statement 03/2021 on the ePrivacy Regulation Adopted on 9 March 2021 The European Data Protection Board has adopted the following statement: The EDPB welcomes the agreed negotiati on mandate adopted by the Council on the protection of privacy and confidentiality in the use of electronic communication services ( ’ the Council ’s position ’ ) , as a positive step towards a new ePrivacy Regulation . It is of utmost importance that the EU gen eral data protection framework is rapidly complemented…

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

## Enforcement decisions

### AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data

*Source: AEPD (Spain), 2026-07-16 — https://overview.legal/posts/53655 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00020-2025*

Facts — Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first estimated that 25,000 persons were affected. It later stated that the incident had affected around 40,000 persons, including 75 minors. The incident affected confidentiality, availability and integrity. The attacker encrypted systems and exfiltrated between 3.5 and 4 TB of information from the document management server. The affected data included identification and contact data, ID numbers, dates of birth, financial and insurance data, bank account numbers, health data, employee data and access credentials. The controller also processed data relating to minors in accident claims. A data subject complained to the DPA after being informed that their personal data had been exposed. The data subject was concerned about identity theft and requested additional information from the controller. During the investigation, the DPA found that the controller had known that its IT systems faced an extreme cybercrime risk before the breach. The forensic report could not determine the initial entry point because the servers had been encrypted, but it showed that attackers could move laterally through the infrastructure, obtain privileged access, install tools, exfiltrate data and encrypt systems. The controller had carried out a risk analysis in 2019, but this document concluded that no DPIA was necessary. After the breach, a later analysis found that a DPIA was necessary for treatments involving health data and minors. The controller did not prove that it had carried out the required DPIA. Holding — The DPA held that the controller violated Article 5(1)(f) GDPR. It considered that the controller had failed to ensure the integrity and confidentiality of the personal data under its responsibility. The DPA emphasised that the principle in Article 5(1)(f) GDPR is not limited to the existence of isolated security measures. Rather, the controller must implement adequate technical and organisational measures capable of ensuring that personal data is protected against unauthorised or unlawful processing, loss, destruction or damage. The DPA rejected the controller’s argument that the attack was an external criminal act that could not be attributed to it. The DPA found that the controller was aware of an extreme cyber risk and that its internal vulnerabilities and security posture allowed the attackers to move through the systems, access personal data and encrypt files. The DPA therefore considered that the controller’s measures were clearly insufficient. The DPA also held that the controller violated Article 35 GDPR. The controller processed high-risk categories of data, including health data and data concerning minors. In these circumstances, it should have carried out a DPIA before the processing. The DPA found that the controller’s 2019 risk analysis wrongly concluded that no high risk existed, while its later documentation acknowledged that a DPIA was necessary. The DPA proposed a fine of €150,000 for the infringement of Article 5(1)(f) GDPR and €100,000 for the infringement of Article 35 GDPR, totalling €250,000. The controller paid voluntarily without acknowledging liability, obtaining a 20% reduction under Spanish Administrative Law (39/2015). The final payable amount was therefore €200,000. The DPA also ordered the controller, under Article 58(2)(d) GDPR, to prove within three months from the enforceability of the decision that it had carried out the mandatory DPIA required under Article 35 GDPR.

### UAB Prime Leasing: Insufficient technical and organisational measures to ensure information security

*Source: Lithuanian Data Protection Authority (VDAI), 2021-11-29 — https://overview.legal/posts/47042 — original: https://www.enforcementtracker.com/ETid-927*

The Lithuanian DPA has fined UAB Prime Leasing, the operator of the short-term car rental platform CityBee, EUR 110,000. The DPA conducted the investigation on its own initiative after information about a possible personal data breach (Art. 33 GDPR) of the company's customers became public in February 2021. According to the company, they learned about the security breach from another cybersecurity service provider who informed them that the customer data of 110,302 CityBee users had been publish

### UODO (Poland) - DKN.5131.5.2025

*Source: UODO (Poland), 2026-05-25 — https://overview.legal/posts/184680 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.5.2025*

Facts — A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’) personal data to a specialised entity established for this purpose (the processor). In January 2023, a work laptop belonging to an employee of the processor was stolen from the trunk of a car parked in a parking garage. This resulted in a breach of confidentiality of the data subjects’ personal data, including names, addresses, ID numbers, and land registry numbers. The controller notified this data breach to the DPA later in January 2023. The DPA conducted an investigation and initiated administrative proceedings regarding the GDPR compliance of the processing operations carried out by the controller and the processor in March 2025. Holding — The DPA issued the controller a fine of PLN 21,000 (€4,900) and the processor a fine of PLN 12,500 (€2,900). First, the DPA held that the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of personal data processing – the controller had failed to demonstrate that it had conducted a thorough risk assessment in a manner that would have allowed for the selection of adequate security measures. These infringements resulted in the violations of the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR. Second, the DPA found that the controller had also violated Article 28(1) GDPR: it had failed to verify the adequacy of the technical and organisational measures implemented by the processor. Finally, the DPA came to the conclusion that the processor had infringed Articles 32(1) and 32(2) GDPR in conjunction with Articles 28(3)(c) and 28(3)(f) GDPR. The DPA held that the processor had failed to assist the controller in fulfilling its obligations and contributed to the controller’s GDPR violations. Unlike the controller, the processor had conducted a risk assessment covering the processing operations at issue; however, the processor had not implemented security measures to protect data stored on laptops used outside of its office premises, such as encryption.

### FREE TECHNOLOGIES EXCOM, S.L.: Insufficient technical and organisational measures to ensure information security

*Source: Spanish Data Protection Authority (aepd), 2026-02-03 — https://overview.legal/posts/52409 — original: https://www.enforcementtracker.com/ETid-3055*

The Spanish DPA has imposed a fine of EUR 10,000 on FREE TECHNOLOGIES EXCOM, S.L. The controller had reset user passwords and communicated the new passwords to the clients via email. However, the email was not encrypted and did not implement any other appropriate security measures.

### Company: Insufficient technical and organisational measures to ensure information security

*Source: Polish National Personal Data Protection Office (UODO), 2023-07-18 — https://overview.legal/posts/48197 — original: https://www.enforcementtracker.com/ETid-2082*

The Polish DPA has imposed a fine of EUR 3,400 on a company. The controller had reported a data breach to the DPA. The company car of a senior employee had been broken into, resulting in the theft of a company laptop on which personal data of three persons were processed. During its investigation, the DPA determined that the controller had failed to implement appropriate technical and organizational measures to protect personal data. Among other things, the laptop had not been properly encrypted

### Partidul Uniunea Salvați România: Insufficient technical and organisational measures to ensure information security

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2023-03-15 — https://overview.legal/posts/47799 — original: https://www.enforcementtracker.com/ETid-1684*

The Romanian DPA has fined the Partidul Uniunea Salvați România party EUR 4,000. The controller had suffered a phishing attack in which the attackers gained unauthorized access to personal data such as first name, last name, email, phone number, as well as data on the political affiliation of the data subjects. The DPA found that the controller had failed to implement adequate technical and organizational measures such as data encryption to protect personal data, which facilitated such an attack

### Szczecin-Centrum District Court: Insufficient technical and organisational measures to ensure information security

*Source: Polish National Personal Data Protection Office (UODO), 2023-01-19 — https://overview.legal/posts/47803 — original: https://www.enforcementtracker.com/ETid-1688*

The Polish DPA has imposed a fine of EUR 6,400 on the Szczecin-Centrum District Court. The court had reported a data breach to the DPA involving the loss of three data carriers. One data carrier was an official and encrypted one, the other two were private and unencrypted data carriers containing drafts of court rulings and statements with personal data. In the course of its investigation, the DPA discovered that data carriers which had not been checked and secured by the court's IT department h

### Datatilsynet (Denmark) - 2022-63-0003

*Source: Datatilsynet (Denmark), 2022-10-28 — https://overview.legal/posts/6329 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2022-63-0003*

Facts — A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that the personal data was accessed by unauthorized persons, with a potential for harm to the data subjects. In March 2020, the law firm notified the Danish DPA of the data breach. Holding — The Danish DPA held that the law firm lacked basic security measures, especially considering the fact that its processing involved special categories of personal data. The DPA emphasized that in such cases a data breach would almost certainly entail a high risk to the data subjects' rights. Therefore, the controller must have especially strict security measures in place to avoid unauthorised accesses. Hence, when creating remote access to such IT systems, the controller could, for instance, implement multifactor authentication. Consequently, the DPA reported the firm to the police. The DPA assessed the appropriate sanctions in accordance with Article 83(2) GDPR and suggested a fine of approximately €67,000 (DKK 500,000).

## Recent developments

### Political Microtargeting by EU Commission illegal

*Source: noyb - European Center for Digital Rights, 2024-12-13 — https://overview.legal/posts/53170 — original: https://noyb.eu/en/political-microtargeting-eu-commission-illegal*

Political Microtargeting, Manipulation & Tracking noyb win against the European Commission: The EDPS (European Data Protection Supervisor) has issued a decision finding that the European Commission has illegally targeted advertising at citizens using "sensitive" personal data on their political views. Decision by the EDPSComplaint filed with the EDPS in 2023Related noyb complaints in Germany ("Target Leaks")EU Commission tried to influence political views in the Netherlands. In the contentious f

### Complaint: Amazon doesn’t allow baseline TLS security

*Source: noyb - European Center for Digital Rights, 2020-03-02 — https://overview.legal/posts/53371 — original: https://noyb.eu/en/complaint-amazon-doesnt-allow-baseline-tls-security*

Data Security Baseline email security missing. During their route to the recipient, emails are handled by different entities, nodes and service providers which may intercept, manipulate and unlawfully use the content. In order to reduce these risks, it is a baseline industry standard to use so-called TLS encryption. View complaint (PDF) “TLS is like an envelope around a letter. If not used, anyone can read the content of an email in transfer.” Stefano Rossetti, privacy lawyer at noyb Surprisingl

### Introducing Encrypt It Already

*Source: Electronic Frontier Foundation, 2026-01-29 — https://overview.legal/posts/52529 — original: https://www.eff.org/deeplinks/2026/01/introducing-encrypt-it-already*

Today, we’re launching Encrypt It Already, our push to get companies to offer stronger privacy protections to our data and communications by implementing end-to-end encryption. If that name sounds a little familiar, it’s because this is a spiritual successor to our 2019 campaign, Fix It Already, a campaign where we pushed companies to fix longstanding issues. End-to-end encryption is the best way we have to protect our conversations and data. It ensures the company that provides a service cannot

### UK data protection reform: How the UK's GDPR may change

*Source: Hogan Lovells, 2022-09-06 — https://overview.legal/posts/6285 — original: https://www.engage.hoganlovells.com/knowledgeservices/news/uk-data-protection-reform-how-the-uk-gdpr-may-change#entry-214*

> The current version of the Bill seeks to maintain the majority of key principles that underpin the UK data protection law framework, while at the same time modifying certain key provisions in relation to accountability, lawful grounds for processing, data subject access requests and cookies, amongst others.

A [consolidated redline version of the UK GDPR by Hogan Lovells](https://www.engage.hoganlovells.com/knowledgeservices/attachment_dw.action?attkey=FRbANEucS95NMLRN47z%2BeeOgEFCt8EGQJsWJiCH

### "Overijssel court rejects municipality's claim in cyber attack case"

*Source: Dutch Courts, 2023-05-12 — https://overview.legal/posts/6208 — original: https://deeplink.rechtspraak.nl/uitspraak?id=ECLI:NL:RBOVE:2023:1731&pk_campaign=rss&pk_medium=rss&pk_keyword=uitspraken#entry-4986*

> On December 1, 2020, a cyber attack took place at the municipality, encrypting and making inaccessible the municipality's network and backup systems and deleting many virtual servers. The municipality holds company responsible for this.

The court rejected the municipality's claim. There is no evidence that company failed to meet contractual obligations ni... (Machine translated)

## Literature

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

### Challenges of Cloud Data Privacy in Surveillance: Legal, Technical, and Ethical Implications

*Source: IJARCCE, 2026-07-07 — https://overview.legal/posts/83508 — original: https://doi.org/10.17148/ijarcce.2026.15701*

The migration of surveillance systems to cloud infrastructure has improved scalability and analytics capabilities but introduces distinct privacy challenges: jurisdictional conflicts between GDPR and the CLOUD Act, expanded attack surfaces from third-party integrations, mandatory retention that conflicts with data minimization, and function creep enabled by centralized data lakes.Using case law from Schrems II, breach reports from ENISA, and technical evaluations of federated learning and differ

### Regulatory Responses to Data Breaches: Evaluating the Effectiveness of GDPR and CCPA in Consumer Protection

*Source: International Journal of Social Sciences and Public Administration, 2025-01-23 — https://overview.legal/posts/132539 — original: https://doi.org/10.62051/ijsspa.v6n1.22*

In the digital age, data breaches have become a significant threat to consumer privacy, prompting the implementation of stringent data protection regulations worldwide. This paper evaluates the effectiveness of two prominent regulatory frameworks, the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States, in safeguarding consumer data and responding to data breaches. Through a comparative analysis of their key provisio

### Building data management capabilities to address data protection regulations: Learnings from EU-GDPR

*Source: Journal of Information Technology, 2023-01-19 — https://overview.legal/posts/132524 — original: https://doi.org/10.1177/02683962221141456*

The European Union’s General Data Protection Regulation (EU-GDPR) has initiated a paradigm shift in data protection toward greater choice and sovereignty for individuals and more accountability for organizations. Its strict rules have inspired data protection regulations in other parts of the world. However, many organizations are facing difficulty complying with the EU-GDPR: these new types of data protection regulations cannot be addressed by an adaptation of contractual frameworks, but requir

### Tracing the Impact of GDPR on Global Data Privacy

*Source: International Journal of Science and Research (IJSR), 2024-09-05 — https://overview.legal/posts/132625 — original: https://doi.org/10.21275/sr24906110537*

International Journal of Science and Research (IJSR) ISSN: 2319-7064 SJIF (2022): 7.942 Volume 13 Issue 9, September 2024 Fully Refereed | Open Access | Double Blind Peer Reviewed Journal www.ijsr.net Tracing the Impact of GDPR on Global Data Privacy Khushal Chauhan 1 , Mayur Ghawate 2 , Saachi Joshi 3 , Shrikant Kawade 4 1 Vishwakarma University, Department of Science and Technology, Kondhwa, Pune- 411048, India Email: khushal0519[at]gmail.com 2 Vishwakarma University, Department of Science and Technology, Kondhwa, Pune- 411048, India Corresponding Author Email: mayurghawate17[at]gmail.com 3 Vishwakarma University, Department of Science and Technology, Kondhwa, Pune- 411048, India Email: saachi.joshi26903[at]gmail.com 4 Vishwakarma University, Department of Science and Technology, Kondhwa, Pune- 411048, India Email: shrikantsk1224[at]gmail.com Abstract: The General Data Protection Regulation GDPR, enacted in May 2018, has reshaped data protection standards globally, enforcing strict requirements on organizations to protect personal data. This paper evaluates the impact of GDPR on modern cybersecurity practices, analyzing its influence on organizational policies, case studies of ma

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Security** — https://overview.legal/topics/beveiliging
  Technical and organizational measures to protect personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/encryption · 2026-08-22
