# Fairness & Transparency — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/fairness-transparency-principle
> Sources are cited per item. Verify against the official texts before relying on them.

Fairness and transparency are co-principles with lawfulness in Article 5(1)(a) GDPR and are inseparable from the concept of lawful processing, deserving dedicated coverage.

## Overview

## Legal Framework

Fairness and transparency are co-principles with lawfulness in [Article 5(1)(a)](/laws/gdpr/art-6) GDPR, but they operate through specific operational provisions — chiefly [Articles 13 and 14]((/laws/gdpr/art-13) GDPR, which mandate information duties when data is collected from or obtained about the data subject. These articles do not merely require disclosure; they frame transparency as the mechanism through which fairness is delivered.

Article 13 requires that, at the time personal data are obtained from the data subject, the controller provide identity and contact details, purposes and legal basis, recipients, retention periods, and information on data subject rights. Article 14 imposes parallel obligations where data has not been obtained directly from the subject. Both articles explicitly tie these requirements to fairness:

> "the controller shall, at the time when personal data are obtained, provide the data subject with the following further information necessary to ensure fair and transparent processing"
> — [GDPR Art. 13(2)](/laws/gdpr/art-13#par-2)

Article 15 reinforces this architecture by granting the data subject an access right that mirrors the transparency obligations — purposes, categories of data, recipients, retention, source, and automated decision-making information must all be provided on request.

The interplay between [Article 6](/laws/gdpr/art-6) (lawful basis) and the transparency articles is structural: a controller cannot claim a lawful basis without disclosing it, and fairness demands that the disclosed basis correspond to the actual processing.

## Key Developments

The CJEU's ruling in *Bara* (2015) established that the fairness requirement obliges public bodies to inform data subjects even when data is transferred between administrative bodies — a scenario where controllers might assume no transparency duty arises:

> "the requirement of fair processing of personal data laid down in Article 6 of Directive 95/46 requires a public administrative body to inform the data subjects of the transfer of those data to another public administrative body"
> — [Bara ¶34](/posts/5957#seg-34)

The *Rynes* decision (2014) further clarified that where data is not obtained from the subject, the controller must provide at least identity, purposes, and any further information necessary to guarantee fair processing, including categories of data and the existence of access and rectification rights.

Dutch enforcement illustrates the practical burden. In a livestream case, the court held that the controller bore the burden of proving that processing was lawful, fair, and transparent — and that a bare assertion of necessity was insufficient:

> "het op de weg van eiseres ligt om te bewijzen dat zij persoonsgegevens verzamelt op een ten aanzien van betrokkenen rechtmatige, behoorlijke en transparante wijze"
> — [Rechtbank ¶10.9.1](/posts/50406#seg-10.9.1)

The EDPB has reinforced that fairness constrains even the transition between lawful bases — controllers cannot freely swap bases without ensuring continued fair processing.

## Status of the Debate

This topic is actively contested in court. While the core obligation — that controllers must inform data subjects to ensure fair and transparent processing — is well established, the boundaries of what constitutes sufficient transparency in novel processing contexts (live streaming, inferred data, secondary use of publicly available data) remain in flux. Courts diverge on how far the fairness principle extends when data subjects are in public spaces or when processing serves a public-interest function. No definitive CJEU ruling under the GDPR itself has yet resolved these tensions. A future CJEU reference clarifying the proportionality analysis between controller interests and transparency burdens in public-space processing would settle the open questions.

## Practical Guidance

- **Map every processing activity to a specific transparency article**: If data is collected directly, comply with [Article 13](/laws/gdpr/art-13); if obtained indirectly, comply with [Article 14](/laws/gdpr/art-14). Do not assume public-space or public-source data exempts you.

- **Document the nexus between lawful basis and disclosure**: The legal basis disclosed to the data subject must match the basis actually relied upon under [Article 6](/laws/gdpr/art-6). Mismatch is a fairness violation independent of the lawfulness analysis.

- **Prepare to prove necessity with concrete evidence**: As the Dutch livestream case demonstrates, courts require controllers to substantiate necessity with specific data, not conclusory assertions. Build a proportionality file for each processing activity.

- **Treat inter-organisational transfers as triggering transparency duties**: *Bara* establishes that transfers between public bodies require informing data subjects. Apply this to private-sector data sharing arrangements as well.

- **Do not swap lawful bases without a fairness assessment**: The EDPB's consent guidance confirms that transitioning between bases requires ensuring continued fair processing. If a compliant transition is impossible, processing must stop.

## Legislation (full text of key provisions)

### Recital 60 — fair transparent processing information to data subjects

*Source: GDPR, gdpr-rec-60-en, 2016-04-27 — https://overview.legal/posts/91635*

The principles of fair and transparent processing require that the data subject be informed of the existence of the processing operation and its purposes. The controller should provide the data subject with any further information necessary to ensure fair and transparent processing taking into account the specific circumstances and context in which the personal data are processed. Furthermore, the data subject should be informed of the existence of profiling and the consequences of such profiling. Where the personal data are collected from the data subject, the data subject should also be informed whether he or she is obliged to provide the personal data and of the consequences, where he or she does not provide such data. That information may be provided in combination with standardised icons in order to give in an easily visible, intelligible and clearly legible manner, a meaningful overview of the intended processing. Where the icons are presented electronically, they should be machine-readable.

### Recital 39 — lawful fair transparent personal data processing

*Source: GDPR, gdpr-rec-39-en, 2016-04-27 — https://overview.legal/posts/91593*

Any processing of personal data should be lawful and fair. It should be transparent to natural persons that personal data concerning them are collected, used, consulted or otherwise processed and to what extent the personal data are or will be processed. The principle of transparency requires that any information and communication relating to the processing of those personal data be easily accessible and easy to understand, and that clear and plain language be used. That principle concerns, in particular, information to the data subjects on the identity of the controller and the purposes of the processing and further information to ensure fair and transparent processing in respect of the natural persons concerned and their right to obtain confirmation and communication of personal data concerning them which are being processed. Natural persons should be made aware of risks, rules, safeguards and rights in relation to the processing of personal data and how to exercise their rights in relation to such processing. In particular, the specific purposes for which personal data are processed should be explicit and legitimate and determined at the time of the collection of the personal data. The personal data should be adequate, relevant and limited to what is necessary for the purposes for which they are processed. This requires, in particular, ensuring that the period for which the personal data are stored is limited to a strict minimum. Personal data should be processed only if the purpose of the processing could not reasonably be fulfilled by other means. In order to ensure that the personal data are not kept longer than necessary, time limits should be established by the controller for erasure or for a periodic review. Every reasonable step should be taken to ensure that personal data which are inaccurate are rectified or deleted. Personal data should be processed in a manner that ensures appropriate security and confidentiality of the personal data, including for preventing unauthorised access to or use of personal data and the equipment used for the processing.

### Recital 45 — legal basis for public interest processing

*Source: GDPR, gdpr-rec-45-en, 2016-04-27 — https://overview.legal/posts/91605*

Where processing is carried out in accordance with a legal obligation to which the controller is subject or where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, the processing should have a basis in Union or Member State law. This Regulation does not require a specific law for each individual processing. A law as a basis for several processing operations based on a legal obligation to which the controller is subject or where processing is necessary for the performance of a task carried out in the public interest or in the exercise of an official authority may be sufficient. It should also be for Union or Member State law to determine the purpose of processing. Furthermore, that law could specify the general conditions of this Regulation governing the lawfulness of personal data processing, establish specifications for determining the controller, the type of personal data which are subject to the processing, the data subjects concerned, the entities to which the personal data may be disclosed, the purpose limitations, the storage period and other measures to ensure lawful and fair processing. It should also be for Union or Member State law to determine whether the controller performing a task carried out in the public interest or in the exercise of official authority should be a public authority or another natural or legal person governed by public law, or, where it is in the public interest to do so, including for health purposes such as public health and social protection and the management of health care services, by private law, such as a professional association.

### Recital 71 — automated decision making and profiling rights

*Source: GDPR, gdpr-rec-71-en, 2016-04-27 — https://overview.legal/posts/91657*

The data subject should have the right not to be subject to a decision, which may include a measure, evaluating personal aspects relating to him or her which is based solely on automated processing and which produces legal effects concerning him or her or similarly significantly affects him or her, such as automatic refusal of an online credit application or e-recruiting practices without any human intervention. Such processing includes ‘profiling’ that consists of any form of automated processing of personal data evaluating the personal aspects relating to a natural person, in particular to analyse or predict aspects concerning the data subject's performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, where it produces legal effects concerning him or her or similarly significantly affects him or her. However, decision-making based on such processing, including profiling, should be allowed where expressly authorised by Union or Member State law to which the controller is subject, including for fraud and tax-evasion monitoring and prevention purposes conducted in accordance with the regulations, standards and recommendations of Union institutions or national oversight bodies and to ensure the security and reliability of a service provided by the controller, or necessary for the entering or performance of a contract between the data subject and a controller, or when the data subject has given his or her explicit consent. In any case, such processing should be subject to suitable safeguards, which should include specific information to the data subject and the right to obtain human intervention, to express his or her point of view, to obtain an explanation of the decision reached after such assessment and to challenge the decision. Such measure should not concern a child. In order to ensure fair and transparent processing in respect of the data subject, taking into account the specific circumstances and context in which the personal data are processed, the controller should use appropriate mathematical or statistical procedures for the profiling, implement technical and organisational measures appropriate to ensure, in particular, that factors which result in inaccuracies in personal data are corrected and the risk of errors is minimised, secure personal data in a manner that takes account of the potential risks involved for the interests and rights of the data subject and that prevents, inter alia, discriminatory effects on natural persons on the basis of racial or ethnic origin, political opinion, religion or beliefs, trade union membership, genetic or health status or sexual orientation, or that result in measures having such an effect. Automated decision-making and profiling based on special categories of personal data should be allowed only under specific conditions.

## Case law

### SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”)

*Source: CJEU, 2015-10-01 — https://overview.legal/posts/5957 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0201*

Right to be informed: National law that does not require the specific transfer involved in the case cannot constitute “prior information” under Article 10 of Directive 95/46 (information requirement where data is collected from the data subject), enabling the controller to dispense with his obligation to inform the data subject of the recipients of the data. (¶¶ 34–38). Article 11 (information requirement where data is not collected from data subject) requires that specified information be provi

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### BVwG - W 108 2284491-1

*Source: Federal Administrative Court, 2024-07-31 — https://overview.legal/posts/122850 — original: https://gdprhub.eu/index.php?title=BVwG_-_W_108_2284491-1*

Facts — The data subject visited a website operated by a media company (the controller). Upon opening the website a cookie banner showed up. This cookie banner was designed in such a way that a reject button was “hidden” in a second layer. The cookie banner’s first layer presented only an option to accept the cookies or to manage the options. The cookie manage option was presented as a link. When the data subject clicked on the accept button, they also agreed to pre-ticked options, visible only within the cookie management link. The reject button was a part of the second layer of the cookie banner (within the cookie management link). The data subject lodged a complaint with the Austrian DPA (DSB), claiming the controller violated, inter alia, Article 5(1)(a) GDPR and Article 6(1)(a) GDPR. The data subject was represented by noyb. The controller argued to the DPA that the website provided access to online newspaper articles. Because of that, the processing activities were carried for journalistic purposes and the DPA was not competent to hear the case. In the meantime the controller updated the settings of the cookie banner and introduced a reject button on its first layer, next to the accept button. Also, the link to manage the cookie settings was redesigned as a button. Moreover, the controller added a floating icon, allowing the website users to withdraw the consent given at any time. If a website user rejected the cookies or withdrew the consent via the floating icon, the controller would interpret such a conduct to be an objection under Article 21 GDPR. Additionally, the controller informed they deleted the data concerning the data subject. In response, the data subject emphasized that due to new settings of the website, the controller wrongly qualified certain cookies to be strictly necessary. In consequence, the controller installed the cookies before the website’s user interacted with the cookie banner, violating Article 5(3) ePrivacy Directive. Although the controller announced that it would implement a completely new cookie banner, they later retracted from that plan. The controller changed the cookie banner and – after improving it initially – removed the reject button again. Eventually, updated cookie banner didn’t include a reject button on the first layer any longer. The DPA issued a decision, ordering the controller to modify the cookie banner so that its first layer offered an option to close the cookie banner without giving consent. This option had to be visually equivalent to the accept button. The DPA rejected the applications of the data subject regarding the deletion of its data, an order to stop unlawful processing and establishing the violation of data confidentiality (“Recht auf Geheimhaltung”). The controller appealed the DPA’s order to introduce an equivalent reject option in the first layer of its cookie banner to the Federal Administrative Court (Bundesverwaltungsgericht – BVwG). After hearing the parties and visiting the website itself the court issued its decision. Holding — The court dismissed the appeal of the controller as unfounded. No exemption from the GDPR through media privilege (“Medienprivileg”) — The controller’s processing activities didn’t fall within the scope of journalistic purposes. The court emphasised that the controller placed the cookies and processed the collected data for analytical and advertising purposes. Need for an equivalent reject option in cookie banners — The court also upheld the interpretation of the DPA that the first layer of the cookie banner needs to contain a visually equivalent option to reject cookies. According to the court Article 7(3) GDPR implies that refusing consent shall be as easy as giving consent. In particular, refusing consent shall not require more interactions than giving consent. In the case at hand consenting required only one click, whereas rejecting consent required two clicks. Therefore no equivalence between the options was given. Furthermore, the different design of the options in the first layer – a button for consent on one hand and a link to access the second layer on the other – equally lead to the conclusion that the options cannot be considered equivalent. A mere explanation in the first layer of the cookie banner on how to reject cookies does not change this assessment. Additionally, the cookie manage link at the bottom of the website is not an equivalent option either, since it is only available after an interaction with the cookie banner. Hence, the DPA order was found to be correct. The court did not find that the controller had complied with this order in the meantime.

### SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”)

*Source: CJEU, 2015-10-01 — https://overview.legal/posts/6149 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0201&ref=6149*

Principle of fairness and lawfulness: The requirement of fair processing laid down in Article 6 of Directive 95/46 requires a public administrative body to inform the data subjects of the transfer of their data to another public administrative body for the purpose of their processing by the latter in its capacity as recipient of those data. (¶¶ 34–38)

### VwGH - VwGH Ro 2025/04/0007-7

*Source: Austrian Administrative Supreme Court, 2026-06-24 — https://overview.legal/posts/184547 — original: https://gdprhub.eu/index.php?title=VwGH_-_VwGH_Ro_2025/04/0007-7*

Facts — The controller was an address publisher and direct advertising company that operated a data application to provide advertisers with personal data for targeted marketing measures. In 2019, following media reports concerning the alleged sale of personal data, particularly information about natural persons’ political party affinity, the Austrian DPA (DSB) initiated an ex officio investigation against the controller. Based on its investigation, the DPA found that the controller had unlawfully processed political party affinity data and unlawfully further processed parcel-frequency data, and had infringed its obligations concerning the DPIA and record of processing activities. It consequently imposed a fine of €18,000,000. The controller appealed to the Federal Administrative Court (BVwG), arguing that the commission of an infringement by a legal person was not, in itself, sufficient for a fine to be imposed under the GDPR. It claimed that since a legal person could not act on its own, the culpable conduct of a natural person had to be identified and attributed to it. The controller argued that the DPA had failed to establish such attribution. The court agreed and, on 26 November 2020, annulled the fine. It found that the DPA had failed to establish that natural persons acting on behalf of the controller had engaged in culpable conduct. The DPA filed an extraordinary official appeal against this judgment with the Austrian Supreme Administrative Court (VwGH). The court stayed the proceedings pending the CJEU’s preliminary ruling in Case C-807/21 (Deutsche Wohnen SE), as the questions referred in that case were also relevant to the appeal proceedings. The CJEU published its judgement on this matter on 5 December 2023. The CJEU held that a fine under Article 83(4) GDPR, Article 83(5) GDPR and Article 83(6) GDPR may be imposed on anyone who qualifies as a controller where it is established that the controller committed the relevant infringement intentionally or negligently. A controller may be sanctioned where it could not have been unaware of the infringing nature of its conduct, regardless of whether it knew that its conduct infringed the GDPR. The CJEU further clarified that, where the controller is a legal person, the application of Article 83 GDPR does not require any action or knowledge on the part of its governing body. Member States may not impose additional substantive requirements for the imposition of fines beyond those laid down in Article 83 GDPR. For the determination of the fine, the controller may also constitute an undertaking within the meaning of EU competition law, with the turnover of the relevant economic unit being taken into account. Following the CJEU judgment, the Supreme Administrative Court annulled the Federal Administrative Court’s judgment on 1 February 2024. The Federal Administrative Court issued a new judgment on 27 December 2024, largely upholding the infringements but reducing the fine to €16,000,000. The controller appealed this decision before the Supreme Administrative Court. Holding — The court found that the controller gathered information concerning the political party affinity of the Austrian population based on anonymous surveys conducted by commissioned polling institutes. These surveys included specific questions concerning interest in election advertising, together with sociodemographic information such as age, level of education and income, place of residence and interest in advertising from political parties. Marketing groups were subsequently formed based on the sociodemographic data and place of residence. For each group, calculations were made to determine the likelihood that an individual with particular sociodemographic characteristics and religious affiliation would be interested in advertising from the political parties concerned. By assigning an identifiable individual to a particular marketing group, the controller linked that person to the probability values calculated for the group and the resulting political party affinity. The court held that the controller did not obtain consent from the data subjects to whom these probability scores were assigned. In total, political party affinity was attributed to approximately 2,200,000 individuals. The court reiterated that political party affinity scores attributed to identifiable individuals constituted personal data revealing political opinions within the meaning of Article 9(1) GDPR. It therefore upheld the finding that the controller had infringed Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. In assessing the controller’s culpability, the court relied heavily on the CJEU’s judgment in Deutsche Wohnen SE. It held that the fact that the controller believed it had complied with the GDPR because it had established a quality-assured organisation was not decisive. It pointed out that under GDPR, a legal person’s fault does not require knowledge or awareness on the part of the management body. The establishment of a data protection compliance system, like the obtaining of legal advice, did not in itself exculpate the controller. It stated that the decisive question was whether the controller could have been aware of the unlawfulness of the processing of political party affinity data during the relevant period. The court ruled that the controller had incorrectly assessed that political party affinity scores did not constitute personal data and that it had consequently failed to examine whether they constituted special categories of personal data under Article 9 GDPR. The court rejected the controller’s argument that political party affinity was processed only in relation to groups rather than in relation to specific identifiable individuals. It also rejected the argument that marketing classifications used for political advertising posed no risk to data subjects. The court concluded that given the controller’s resources and its ability to examine the applicable legal position, that legal assessment amounted to gross negligence concerning the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. Furthermore, the court ruled that the controller’s incorrect assessment that political party affinity scores did not constitute personal data or special categories of personal data also led it to conclude in its Data Protection Impact Assessment (DPIA) that the processing did not pose a high risk and that the scope of Article 35(3)(a) GDPR was therefore not applicable. The court held that the DPIA-related infringement was therefore absorbed from the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. It found no separate element of wrongdoing. The court additionally ruled that the same incorrect legal assessment resulted in the controller’s failure to include political party affinity as a separate category of personal data in its record of processing activities under Article 30(1)(c) GDPR. The court similarly found that these documentation failures did not contain a separate element of wrongdoing beyond that already covered by the infringement of Article 5(1)(a) GDPR and Article 9(1) GDPR. The court therefore discontinued the proceedings concerning the separate DPIA and record-of-processing infringements. It further held that, where a controller commits multiple GDPR infringements, a single aggregate fine must be imposed under Article 83(3) GDPR, the total amount of which may not exceed the amount applicable to the most serious infringement. The court reassessed the penalty and reduced it to €13,000,000, because the DPIA and record of processing infringements were no longer to be taken into account in determining the fine.

### VG München - M 26a K 25.5210

*Source: Administrative Court Munich, 2026-05-18 — https://overview.legal/posts/108991 — original: https://gdprhub.eu/index.php?title=VG_München_-_M_26a_K_25.5210*

Facts — The data subject had been liable to pay broadcasting contributions to the Controller, a German regional public broadcasting authority, since 2007. Following objections to several contribution assessment notices, the data subject submitted a request under Article 15 GDPR seeking a copy of all personal data processed about him by the Controller. The Controller responded by providing the categories of personal data and related information specified under § 11(8) of the German Broadcasting Contribution Treaty (RBStV), which governs data subject access requests relating to broadcasting contribution records, together with general privacy information. The data subject argued that the response was incomplete because it did not include copies of all documents containing his personal data, including correspondence with him and third parties. The Controller maintained that it had fully complied with its obligations under the RBStV. After the Controller declined to provide additional information, the data subject brought proceedings seeking disclosure of all personal data concerning him processed by the Controller. Holding — The Court held that § 11(8) of the German Broadcasting Contribution Treaty (RBStV) constituted a lawful restriction of the broader right of access under Article 15 GDPR pursuant to Article 23(1)(e) GDPR. It found that the national provision was a valid legislative measure, respected the essence of the fundamental right to data protection, and pursued an important public interest by ensuring the effective financing and administration of the public broadcasting system. The Court further held that the restriction was necessary and proportionate, noting that requiring the Controller to comply with the full scope of Article 15 GDPR across more than 44 million broadcasting contribution accounts would impose a disproportionate administrative and financial burden capable of undermining that public interest. The Court also held that § 11(8) RBStV satisfied the safeguards required under Article 23(2) GDPR by specifying the purposes of processing, categories of personal data, scope of the restriction, safeguards against misuse and unlawful access, the identity of the Controller, applicable storage periods and other statutory protections. Accordingly, while the Controller was required to disclose the categories of information specified under § 11(8) RBStV, it was not required to provide a copy of all personal data processed under Article 15(3) GDPR. As the Controller had already provided all information required under the national provision, the court dismissed the action.

### SO Warszawa - III C 904/23

*Source: Regional Court in Warsaw, 2026-02-16 — https://overview.legal/posts/53100 — original: https://gdprhub.eu/index.php?title=SO_Warszawa_-_III_C_904/23*

Facts — The Financial Ombudsman’s office (the controller) sent a letter containing the name, the address, and the case reference number of a customer (the data subject) to 28,366 public institutions and entities registered on an official government platform in February 2021. The data subject demanded compensation for the unauthorised disclosure of his personal data from the controller in November 2021. The controller refused to accept liability for the incident. The supervisory authority issued the controller a reprimand in September 2022 for disclosure of personal data in violation of Article 6(1) GDPR. The data subject brought a lawsuit for damages under Article 82 GDPR before the Regional Court in Warsaw in August 2023. The data subject stated that they had experienced severe stress and lost the sense of security and control over their data as a result of the unauthorised disclosure of the letter. The controller argued it was not at fault for the incident as it was caused by a temporary IT system failure that the controller could not have foreseen. Holding — The Regional Court in Warsaw held that the controller was undoubtedly liable for the unauthorised disclosure of the data subject’s personal data pursuant to Article 82 GDPR: the controller was an administrator for the government platform and had not taken adequate measures to secure the data. Second, the court held that the data subject had suffered non-material damage in connection with the aforementioned incident. It took into account that the data had been disclosed to numerous entities. In addition, the deterioration of the data subject’s mental state was confirmed by a witness. The court awarded the data subject PLN 40,000 in damages. It considered the data subject’s claim of PLN 50,000 to be excessive in light of established case law.

### Judgment of the Court (First Chamber) of 3 April 2025.#L. H. v Ministerstvo zdravotnictví.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 4 – Definitions – Article 6 – Lawfulness of processing – Article 86 – Public access to official documents – Data concerning the representative of a legal person – Case-law of a national court imposing an obligation to inform and consult the data subject prio

*Source: Court of Justice of the European Union, C-710/23, 2025-04-03 — https://overview.legal/posts/132145 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0710*

In Case C-710/23, the Court of Justice of the European Union (First Chamber) addressed a preliminary reference from the Czech Supreme Administrative Court concerning whether personal data of individuals acting as representatives of legal persons, contained in official documents related to COVID-19 screening test contracts, may be disclosed under GDPR Article 86 and the lawfulness of processing under Article 6. The case arose from a dispute between L.H. and the Czech Minister of Health, who had refused to disclose certain information about representatives of legal persons named in those contracts and related certificates. The Court held that data concerning a representative of a legal person constitutes personal data within the meaning of the GDPR when it allows the natural person to be identified, and that Member States may provide for public access to official documents containing such personal data, provided that the disclosure is reconciled with the right to data protection; however, a national court cannot impose a general obligation to inform and consult the data subject prior to every disclosure of official documents, as this would undermine the public's right of access to official documents.

### Judgment of the Court (Eighth Chamber) of 27 February 2025.#Amt der Tiroler Landesregierung v Datenschutzbehörde.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Direct designation of the controller by national law – Auxiliary administrative entity in the service of a regional government – Lack of

*Source: Court of Justice of the European Union, C-638/23, 2025-02-27 — https://overview.legal/posts/132147 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0638*

In Case C-638/23, the Court of Justice interpreted Article 4(7) GDPR in response to a preliminary reference from the Austrian Verwaltungsgerichtshof in proceedings between the Amt der Tiroler Landesregierung (Office of the Provincial Government of Tyrol) and the Datenschutzbehörde (Austrian Data Protection Authority). The core issue was whether an auxiliary administrative entity lacking legal personality and legal capacity, operating in the service of a regional government, qualifies as a "controller" under the GDPR when national law directly designates it to determine the purposes and means of personal data processing. The Court held that such an entity may be designated as a controller by Member State law provided it in fact determines the purposes and means of the processing, with the concept of "other body" in Article 4(7) not requiring the entity to possess legal personality or its own legal capacity.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

### BVwG - W258 2227269-1/39E

*Source: Federal Administrative Court, 2024-12-27 — https://overview.legal/posts/184564 — original: https://gdprhub.eu/index.php?title=BVwG_-_W258_2227269-1/39E*

Facts — On the 8 January 2019, the Austrian DPA (Datenschutzbehörde – DSB) launched an investigation into the actions of the Austrian postal service as it also had a business license for address publishing and direct marketing. Media reports had claimed that the postal service (the controller) sold data concerning the political affinities of data subjects to third parties. The controller ran a platform entitled “Adress Shop” on which it sold personal data to legal entities. The datasets included names and addresses but more importantly it included data subjects’ affinities to certain things such as an affinity to moving house, an affinity to organic products or how frequently a data subject receives packages. The purpose of the data processing was to sell this data to third parties who would use it for marketing purposes and therefore could avoid scattering losses. In order to create this database, the controller abused its position as postal service provider. In the postal service contract provided to data subjects the controller had included a notice stating that data subject are agreeing to their personal data being processed for marketing purposes. The contract however also included a box which could be ticked in order to refuse the data processing for marketing purposes. One of these affinities was concluded through an affinity score concerning the main political parties in Austria. For example, data subjects would be assessed with either a “very low”, “low”, “high” or “very high” affinity towards the SPÖ (the Socialist Party of Austria), the ÖVP (the Conservative Party of Austria) or any other major political party. The controller calculated this score through combing anonymous survey results, socio-demographic data (e.g., age or level of income and education) and voting results of particular region. On the 20 Febuary 2019, the DSB alleged that the controller had unlawfully processed sensitive data under Article 9 GDPR. The DSB found that the controller could not rely on a legal basis for the processing of this data and that the controller had sold the data to third parties. The DSB issued a fine of fine of €18,000,000 for the processing of sensitive data and other violations. The full details can be found here. On the 25 November 2019, the controller appealed the decision of the DSB to the Austrian Federal Administrative Court (Bundesverwaltungsgericht – BVwG) and alleged that the DSB had inadequately assessed the situation. On the 26 November, the BVwG annulled the decision of the DSB stating that the DSB had failed to name a natural person to whom the actions of the controller could be attributed to. Based on an Austrian provision, namely paragraph 45(1)(3) of the Administrative Penal Code (Verwaltungsstrafgesetz - VStG), in order to fine a legal person for a violation of the GDPR all necessary requirements for the penalization of a natural person must be fulfilled. This finding was however annulled by the Supreme Administrative Court (Verwaltungsgerichtshof – VwGH) on the 1 February 2024. The VwGH explained that although the BVwG correctly applied the national provision, the CJEU case C-807/21 Deutsche Wohnen showed that Article 58(2)(i) GDPR and Article 83 GDPR are excluded from national derogations. Therefore, the BVwG should not have applied the national provision. The case was therefore reverted back to the BVwG. Holding — The BVwG reassessed the case and partly upheld the DSB decision but made the following alterations. Article 9 GDPR data related to political affinities The BVwG confirmed that the controller had at no point in time obtained the consent of the data subject and therefore was processing data in violation of Article 9(1) GDPR since the 25 May 2018. The BVwG held that the controller's conduct had proved negligent. The BVwG noted that the controller had made efforts to apply the GDPR correctly but criticized for example that the DPO had to monitor all processing activities which did not prove an effective monitoring and controlling system as it would require too much time for just one person. The BVwG held that it was clearly unacceptable that the DPO thought that the data processed did not constitute personal data, especially when it was explicitly connected to an individual person. Further, The BVwG found that the controller never conducted an assessment on whether certain affinities could constitute sensitive data under Article 9 GDPR. The BVwG classified this as grossly negligent behaviour on the part of the controller. The BVwG concluded that the controller should have consulted an external expert around the uncertainties it had concerning the correct application of the GDPR. Affinity towards receiving packages In relation to the data processed to assess their affinity for receiving packages, the controller was in a privileged position to have access to the relevant data. However, it then further processed this data contrary to their legal mandate for creating projection models for marketing purposes in violation of Article 6(4) GDPR. The court also held that this violated the principles of fairness and transparency under Article 5(1)(a) GDPR. The BVwG highlighted that the controller knew that its positions as postal service provider and data broker is likely to cause issues, therefore its behaviour was classified as negligent. Affinity towards moving house Assessing whether data subjects were likely to move house differed to the assessment of an affinity towards receiving packages as there was a contractual relationship between the data subject and the controller due to contractual redirection orders. The BVwG assessed that the minimal information provided to data subjects on the processing for marketing purposes, proved to be just about enough as the personal data was made up of a calculation of averages which was then anonymized. The court found that this could be classified as processing which, based on the controllers description, could be expected from the notice included in the contract. In addition, data subjects could easily refuse the data processing. Data Protection Impact Assessment The controller had processed an extensive amount of sensitive data which requires a data protection impact assessment. The controller’s assessment that this data processing was of low risk was therefore faulty. The controller had therefore violated Article 35(3)(b) GDPR and Article 35(7) GDPR. The BVwG held that as the controller had negligently categorized its processing as not concerning any sensitive data, it consequently also proves to have acted negligently in assessing the risks under Article 35 GDPR. The BVwG rejected the controller’s argument that penalization under Article 35 GDPR would result in a double punishment for the same offence. It explained that the general obligations under the GDPR pursue a different aim to the provisions governing lawfulness of the processing. Further, the DPIA is to be conducted prior to processing. Records of processing The faulty and therefore inadequate DPIA resulted in a violation of Article 30(1)(c) GDPR, which requires the records of data processing to include the categories of data processed. The BVwG again assessed that the controller had acted negligently in relation to this aftereffect of its faulty categorization of the processed data. The controller had merely stated that the data would be processed for marketing purposes and this was held to have been inadequate as the controller processed data such as the political affinities. The BVwG held that the controller had failed to provide a full description of all the processed categories. Fine The BVwG reduced the fine to €16 million mainly based on the controller's low annual turnover. Further, the BVwG noted that the political data had only been sold to two political parties which resulted in a limited amount of data subjects being affected.

## Guidance

### EU-US Data Privacy Framework FAQ for European individuals

*Source: EDPB, eu-us-data-privacy-framework-faq-for-european-individuals-en, 2024-07-16 — https://overview.legal/posts/125730 — original: https://www.edpb.europa.eu/documents/other-guidance/eu-us-data-privacy-framework-faq-for-european-individuals_en*

Adopted EU - U.S. DATA PRIVACY FRAMEWORK F.A.Q. FOR EUROPEAN INDIVIDUALS 1 Adopted on 16 July 2024 1 In this context, European individuals means any natural person, regardless of their nationality, whose personal data have been transferred to a U . S . company under the EU - U . S . Data Privacy Framework . A dopted 2 A dopted 3 Q1. WHAT IS THE EU - U.S. DATA PRIVACY FRAMEWORK? The EU - U.S. Data Privacy Framework (“DPF”) is a self - certification mechanism for companies in the U.S. The…

### Article 29 Working Party - Guidelines on transparency under Regulation 2016/679

*Source: EDPB, article-29-working-party-guidelines-on-transparency-under-regulation-2016679-en, 2018-04-11 — https://overview.legal/posts/126340 — original: https://www.edpb.europa.eu/documents/guideline/article-29-working-party-guidelines-on-transparency-under-regulation-2016679_en*

ARTICLE 29 DATA PROTECTION WORKING PARTY This Working Party was set up under Article 29 of Directive 95/46/EC. It is an independent European advisory body on data protection and privacy. Its tasks are descr bed in Article 30 of Directive 95/46/EC and Article 15 of Directive 2002/58/EC. The secretariat is provided by Directorate C (Fundamental Rights and Union Citizenship) of the Europe an Commission, Directorate General Justice, B - 1049 Brussels, Belgium, Office No MO - 59 02/013. Website:…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Opinion 16/2025 regarding the draft decision of the German North Rhine Westphalia Supervisory Authority regarding Trusted Site Data Privacy (TÜV IT) certification criteria

*Source: EDPB, edpb-opinion-202516-tuv-certificationcriteria-en-0, 2025-07-14 — https://overview.legal/posts/51080 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-162025-regarding-the-draft-decision-of-the-german_en*

Adopted 1 Opinion 16 /2025 regarding the draft decision of the German North Rhine Westphalia Supervisory Authority regarding Trusted Site Data Privacy (TÜV IT) certification criteria Adopted on 8 July 2025 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data…

### Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH

*Source: EDPB, edpb-opinion-202515-dbo-certificationcriteria-en, 2025-07-14 — https://overview.legal/posts/51079 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-152025-on-the-draft-decision-of-the-austrian_en*

Adopted 1 Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority ( AT SA) regarding the certificat ion criteria of BDO Consulting GmbH Adopted on 8 July 2025 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of…

### Opinion 3/2025 on the draft decision of the French Supervisory Authority (FR SA) regarding the “Lexing GDPR certification criteria”

*Source: EDPB, edpb-opinion-202523-lexingcertificationcriteria-en, 2025-04-14 — https://overview.legal/posts/50756 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-32025-on-the-draft-decision-of-the-french-supervisory_en*

EDPB, Opinion 3/2025 on the draft decision of the French Supervisory Authority (FR SA) regarding the “Lexing GDPR certification criteria”, 2025.

### Opinion 18/2024 on the draft decision of the Austrian Supervisory Authority regarding DSGVO-zt GmbH certification criteria

*Source: EDPB, opinion-182024-on-the-draft-decision-of-the-austrian-en, 2024-07-18 — https://overview.legal/posts/125721 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-182024-on-the-draft-decision-of-the-austrian_en*

Adopted 1 Opinion 18/2024 on the draft decision of the Austrian Supervisory Authority regarding DSGV O - zt GmbH certification criteria Adopted on 16 July 2024 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free mo vement of such data, and…

### Guidelines 03/2021 on the application of Article 65(1)(a) GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-651a-gdpr, 2023-05-24 — https://overview.legal/posts/38137 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032021-on-the-application-of-article-651a-gdpr_en*

The European Data Protection Board (EDPB) adopted Guidelines 03/2021 to clarify the dispute resolution mechanism under Article 65(1)(a) GDPR, which governs the EDPB's authority to issue binding decisions when a Lead Supervisory Authority receives relevant and reasoned objections from Concerned Supervisory Authorities that it does not follow. The Guidelines address the procedural framework, the threshold for "relevant and reasoned" objections, the scope of the EDPB's substantive competence, and applicable procedural safeguards including the right to be heard, access to the file, and available judicial remedies.

## Enforcement decisions

### Italian DPA: Enna Health Authority violated GDPR by publishing judicial data

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-18 — https://overview.legal/posts/109000 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_471/2026*

Facts — The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial records). The data subject contacted the controller and requested the controller to remove or redact the data. The controller responded that it would remove it promptly, however, the data subjects’ data remained in a separate page of the controller’s website. The data subject later brought a complaint to the DPA. The controller stated that it completely removed the data subject’s personal data after the DPA requested it, including data that was accidentally included in its website. Holding — The DPA found a violation of Articles 5, 6 and 10 GDPR. The DPA first clarified that the controller processed data related to the commission of crimes or pending criminal proceedings involving the data subject. This data fell under the scope of Article 10 GDPR, meaning the controller had specific obligations for the processing activity to be lawful. The DPA considered that the controller had processed this data unlawfully by publishing it, and had failed to comply with the principle of lawfulness (Article 5(1)(a) GDPR) and data minimisation (Article 5(1)(c) GDPR). The DPA also found a violation of Article 17 GDPR. The DPA stated that the controller failed to adequately respond to the data subject’s request for erasure by not recognising that the data remained visible in a different section of its website. The DPA fined the controller €20,000.

### Italian Garante: OPI of Pisa must remove residential addresses from public register

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-16 — https://overview.legal/posts/122839 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10192784*

Facts — The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the residential address, information not necessary for the purposes of the Register [Note: the OPI is a governance body for registered nurses]. The OPI (the controller), when asked by the DPA to provide further clarification, initially stated that, in accordance with the applicable local regulation (DPR 221/1950), the public register included residential addresses to provide employers with accurate information and to avoid identity confusion in cases of identical names. During the investigation, the National Federation of Nursing Professional Orders (the “Federation”), the representative body entrusted with functions of guidance, coordination and administrative support to the territorial Orders, indicated that the residential address was not required for the functioning or the purpose of the register, expressly referring to Article 6(3) GDPR to confirm that no legal provision required the publication of such data. The controller subsequently revised its position, explaining that it routinely maintained two databases: a complete version and a reduced one containing only minimal information. The publication in which the residential address of a single data subject appeared resulted from an employee’s mistake during the update following a meeting of the Directive Council. Holding — The DPA upheld the complaint and found violations of Article 5(1)(a) GDPR, Article 6(1)(e) GDPR, Article 6(2) GDPR and Article 6(3) GDPR. The publication, through the internet, of personal data that exceeds the main purpose of the professional public registry, without a proper legal basis, breached the Article 6(1). The DPA rejected the controller’s argument that the disclosure resulted merely from an employee’s mistake, noting that the controller did not act promptly to prevent continued access through search engine caching and that such circumstances could not justify the unlawful disclosure. It also clarified that the version of the Register published online contained the residential addresses of all registered professionals, not only that of the complainant, as later confirmed by the DPA. It was mandatory for the the controller to comply with the principles governing data protection, including the principles of lawfulness, fairness and transparency, as well as data minimisation. In accordance with this principles, the data processing should had been processed lawfully, fairly and in a transparent manner in relation to the data subject, and adequate, relevant and limited to what was strictly necessary in relation to the purposes. Following this, the DPA imposed a €16,000 fine. In defining the amount, the DPA took into account that the violation was produced due to the negligence of the Controller (art. 83, par. 2, lett. b.) and its lack of cooperation.

### Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-03 — https://overview.legal/posts/184557 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_483/2026*

Facts — Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas contracts with them because its checks had resulted in a negative risk assessment. The controller had used a credit-check procedure to assess the creditworthiness of prospective customers before entering into such contracts. The credit-check procedure consisted of an internal and an external assessment. During the internal assessment, Hera S.p.A. (processor A) checked whether the prospective customer had outstanding debts towards the controller or EstEnergy S.p.A., another energy supplier within the same corporate group. The assessment returned an OK or KO result. The controller’s privacy notice stated that customer data could be disclosed to other companies within the Hera Group and to third parties contractually linked to the Group. Where the internal assessment returned an OK result, an external assessment was carried out using software called “CGS-X”, provided by Major 1 S.r.l. (processor B). Through the software, databases operated by Experian Italia S.p.A. (the credit-information provider) and Cerved Group S.p.A. (the commercial-information provider) were consulted. The software combined the scores supplied by the two external data providers to generate an integrated creditworthiness score, which was transmitted to systems operated by processor A. Those systems applied the criteria established under the controller’s group credit policy and returned a final OK or KO result. The data subjects alleged that the refusal of their applications resulted from the external creditworthiness assessment. When they subsequently contacted the two external data providers, the providers stated that their systems did not contain negative information or adverse events concerning them. The data subjects then submitted access requests to the controller. The controller replied that their risk profiles were based on automated scoring using information obtained from external databases and directed them to the two external data providers for further details. The replies did not identify the CGS-X score and did not explain the logic or criteria used in the assessment. At the time of the inspection, the controller had not set a specific retention period for the external-assessment data and instead applied a general ten-year period used for accounting documentation. It also reused credit-check data, including information from external providers and previous debts, for analyses aimed at refining its group’s rating system. Between 2022 and March 2024, this processing concerned 1,003,657 individuals. During the proceedings, the controller and the other energy supplier entered into a joint-controller arrangement under Article 26 GDPR concerning the internal assessment and updated the relevant privacy information. Under that arrangement, the two joint controllers also undertook to appoint processor A for the processing carried out as part of the internal assessment. The controller subsequently adopted a five-year retention period for creditworthiness data and discontinued the analyses concerning the refinement of the rating system. Holding — The DPA considered that the information provided by the controller did not describe the intra-group sharing and use of data concerning previous debts with sufficient specificity. It found that the general references to disclosures within the corporate group did not provide information about the processing operations connected with the internal assessment. The DPA also found that the instructions provided to processor A did not cover the processing of information concerning debts owed by customers to the other energy supplier. It therefore found infringements of Article 5(1)(a) GDPR, Article 13 GDPR, Article 14 GDPR and Article 28 GDPR. The DPA noted that, under the joint-controller arrangement, the internal assessment was carried out jointly by the two energy suppliers on the basis of Article 6(1)(f) GDPR. However, it found that the processing carried out before the conclusion of that arrangement was unlawful. The DPA also found that the responses to the access requests did not meet the requirements of Article 12 GDPR and Article 15 GDPR. It noted that the access requests had been submitted to the controller which was required to provide all personal data and information relating to the processing. It pointed out additionally that the information to be provided should include the integrated score, the contributing scores, and meaningful information about the logic and criteria applied. Moreover, referring to the CJEU’s judgment in Case C-203/22 (Dun & Bradstreet Austria), the DPA stated that the requirement to provide meaningful information about the logic involved could not be satisfied merely by disclosing a complex mathematical formula or by providing a detailed description of every stage of the automated process. It emphasized that the controller was required to describe the procedure and principles actually applied in a concise and understandable manner, enabling the data subject to understand which personal data were used and how they contributed to the result. The DPA considered that the information provided did not enable the data subjects fully to assess the lawfulness of the processing or the accuracy of the data used. It also limited their ability to request rectification, obtain human intervention, express their views and contest the decision. The DPA further found that the application of a general ten-year retention period to the credit-check data had not been sufficiently justified in relation to the purpose of assessing a specific contractual application. The controller had not demonstrated the necessity of retaining the scores and related reports for that period. The DPA concluded that the controller violated Article 5(1)(e) GDPR. Furthermore, the DPA considered that the use of data obtained from the credit-information provider and the commercial-information provider for analyses concerning the refinement of the controller’s group rating model pursued a further purpose incompatible with the original purpose for which those data had been collected. It also found that retaining and subsequently reusing data obtained from the two external providers created a risk that the information would no longer be up to date. It therefore found infringements of Article 5(1)(b) GDPR and Article 5(1)(d) GDPR. The DPA imposed a fine of €5,800,000. It also ordered the controller to define a new response template for access requests, including the relevant scores and meaningful information about the logic and criteria applied, and to provide the revised response to the complainants. The controller was further required to establish a procedure enabling data subjects to request the rectification of inaccurate or incomplete data, obtain human intervention, express their views and contest the decision.

### Italian DPA: Vasto municipality breached transparency duties over traffic cameras

*Source: Garante per la protezione dei dati personali (Italy), 2026-06-18 — https://overview.legal/posts/144036 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_457/2026*

Facts — The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A data subject filed a complaint against the controller after being fined for running a red light. The data subject argued that there were no signs or warnings near the cameras installed to detect violations, and that the controller did not obscure the windows to make data subjects unrecognisable. The controller argued that it provided warning signs of the presence of cameras. In addition, the cameras only capture data subjects’ license plates to comply with the principle of data minimisation (Article 5(1)(c) GDPR), and that the case of the data subject was a technical error. Holding — The DPA first noted that, in principle, a public entity can process this data if it is necessary to fulfil a legal obligation or for the public interest (Article 6(1)(c) and (e) GDPR). However, the controller still has the obligation to provide information to data subjects regarding the processing, in accordance with the principle of transparency (Article 5(1)(a) GDPR). The DPA found that, at the time of the complaint, the controller had not included any information near the cameras. In addition, the first level privacy policy did not comply with the requirements of Article 13 GDPR and were not provided in concise and transparent manner. Therefore, the DPA found a violation of Articles 5(1)(a), 12(1) and 13 GDPR. The DPA also found a violation of Article 5(1)(c) GDPR, as the controller failed to comply with the principle of data minimisation. The DPA stated that the controller had failed to ensure that the cameras only captured the vehicles’ license plates, and had therefore processed more data than necessary. Finally, the DPA found a violation of Article 35 GDPR, as the controller had prepared a data protection impact assessment (DPIA) only after the processing activities began. The DPA noted that the DPIA was also not specific enough. The DPA fined the controller €5,000. In addition, the DPA ordered the controller to adopt appropriate measures to provide data subjects with adequate information and update its DPIA.

### UODO (Poland) - DKE.561.4.2026

*Source: UODO (Poland), 2026-05-22 — https://overview.legal/posts/108997 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKE.561.4.2026*

Facts — The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending beyond the boundary of their property to include public roads and the data subjects’ properties. The DPA decided that the controller had unlawfully processed data subjects’ data. The DPA held that the controller had the obligation to erase the data, and prohibited the controller from future monitoring. The DPA later requested the controller to provide evidence of compliance with the decision, but did not receive a response from the controller. The DPA received a complaint from one of the data subjects, stating that the controller continued to violate the GDPR despite the DPA’s decision. The DPA found that the controller had reinstalled the cameras and continued to cover areas outside their property, even after the cameras were removed by police officers. Holding — The DPA found a violation of Article 5(2) GDPR, as the controller had failed to demonstrate compliance with the DPA’s decision. The DPA stated that the obligation to demonstrate compliance with the principle of lawfulness (Article 5(1)(a) GDPR) extended to complying with decisions from the DPA. The DPA reiterated that the controller processed data subjects’ personal data unlawfully through their surveillance camera. The DPA took into account the small size of the local community and the number of data subjects affected, and concluded that the controller’s continuous monitoring disrupted the community’s functioning by deeply interfering with data subjects’ lives. In addition, the DPA stated that the manner in which the controller used the surveillance footage suggested that the processing purpose was to harass data subjects. The DPA fined the controller PLN 26,711 (approximately €6,174).

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

### NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations

*Source: NAIH (Hungary), 2026-05-12 — https://overview.legal/posts/184727 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-450-7-2026*

Facts — The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The period under review extended from January 2020 to November 2025. During this time, the company had multiple privacy notices in force, as well as other documents that contained relevant information on the processing of personal data. Holding — The DPA found the controller guilty of multiple GDPR violations and issued it a fine of HUF 15,000,000 (€41,500). In addition, it ordered the controller to bring its processing operations in compliance with the GDPR by amending the information system used on its website, in particular the data processing provisions of the general terms and conditions and the data processing notices related to prize contests. First, the DPA held that the controller had violated the principle of transparency laid down in Article 5(1)(a) GDPR: several separate documents contained partially conflicting, irrelevant, and incomplete information regarding the processing of personal data. The information was not organised within a uniform, transparent system. Second, the DPA determined that the controller had failed to provide concise, transparent, and intelligible information regarding the purposes and the legal basis for each processing activity and therefore infringed Article 12(1) GDPR. Finally, the DPA found infringements of Articles 13(1) and 13(2) GDPR – the controller had not provided the data subjects all information necessary when personal data is collected from data subjects. In particular, the controller had failed to adequately distinguish the purposes and the legal bases for each processing operation, recipients of personal data, and retention periods. The controller’s website also contained contradictory information on whether or not personal data was transferred to the United States.

### NAIH fines online store HUF 10M for missing and inadequate privacy notice

*Source: NAIH (Hungary), 2026-04-30 — https://overview.legal/posts/262255 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-4462-5-2026*

Facts — The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The controller’s main business activity was the wholesale distribution of beverages. The personal data of the data subjects was processed on the website of the online store for registration, placing orders, billing, communication, delivery, creation of user accounts, and newsletter subscription. During the period under review, i.e. between January 2020 and October 2025, no standalone privacy notice was available on the website. The previously archived privacy notice and the data processing section included in the general terms and conditions described the processing operations in a rather brief and general manner. The controller argued that the inaccessibility of the privacy notice followed from a technical error that was corrected upon discovery. Holding — The DPA found that the controller had violated Articles 5(1)(a), 5(2), 12(1), 13(1)(a), (c), and (e) as well as 13(2)(a)–(e) GDPR and issued it a fine of HUF 10,000,000 (€27,300). When issuing the fine, the DPA took into account that the identified infringements followed from systemic inadequacies of the privacy notice and were of continuous nature. In addition, the DPA ordered the controller to develop and publish a uniformly structured privacy notice that is aligned with its actual processing operations. First, the DPA identified a violation of the principle of transparency laid down in Article 5(1)(a) GDPR: the information provided to data subjects about the processing of their personal data was either incomplete or completely absent, and changes could not be tracked. Second, the DPA held that the controller had violated the principle of accountability set forth in Article 5(2) GDPR, as it had failed to submit appropriate documentation covering the period under review. In addition, the controller’s data processing practices could not be continuously monitored or subsequently verified based on the documentation it had provided. Finally, the DPA confirmed that the controller had not complied with the requirements laid down in Articles 12(1), 13(1)(a), (c) and (e), and 13(2)(a)–(e) GDPR. Due to the lack of a privacy notice, the controller could not demonstrate that it had provided data subjects with the information required under Article 13 GDPR apart from brief, general statements in the archived privacy notice and the general terms and conditions. The controller had thus failed to provide the data subjects clear and differentiated information regarding the purpose and legal basis for each processing operation. Furthermore, the controller had not adequately identified the recipients or the storage period of personal data or information on the data subjects' rights. Due to the form and scope of the information provided, the controller had also infringed Article 12(1) GDPR.

## Recent developments

### Coordinated Enforcement Framework: EDPB selects topic for 2026

*Source: EDPB, 2025-10-14 — https://overview.legal/posts/49129 — original: https://www.edpb.europa.eu/news/news/2025/coordinated-enforcement-framework-edpb-selects-topic-2026_en*

Brussels, 14 October - During its October plenary, the European Data Protection Board (EDPB) picked the topic for its fifth coordinated enforcement action, which will concern compliance with the obligations of transparency and information under the General Data Protection Regulation (GDPR). The GDPR ensures that individuals are informed when their data is being processed (under Art. 12, 13 and 14). This right to be informed is a core element of transparency and ensures that individuals have more

### Next Steps for users & FAQs

*Source: noyb - European Center for Digital Rights, 2020-07-24 — https://overview.legal/posts/53354 — original: https://noyb.eu/en/next-steps-users-faqs*

Data Transfers On this page we have summarized the options for users that want to stop their data being transferred to the United States after the CJEU judgment in C-311/18 ("Schrems II") on the Privacy Shield and Standard Contractual Clauses ("SCCs"). In addition we added a couple of FAQs that may help you identify cases where you have a right to request a stop to data transfers. What can I do now? FAQs for users What can I do now? The GDPR gives you strong rights to get information on your dat

### Gecoördineerd handhavingskader: Het EDPB selecteert een onderwerp voor 2026.

*Source: EDPB, 2025-10-14 — https://overview.legal/posts/51738*

Brussel, 14 oktober - Tijdens de plenaire vergadering van oktober heeft het Europees Comité voor de bescherming van de persoonlijke levenssfeer (EDPB) het onderwerp gekozen voor zijn vijfde gecoördineerde handhavingsactie. Deze actie zal betrekking hebben op de naleving van de verplichtingen met betrekking tot transparantie en informatieverstrek onder de Algemene Verordening Gegevensbescherming (AVG). De AVG zorgt ervoor dat individuen worden geïnformeerd wanneer hun gegevens worden verwerkt (zoals vastgelegd in artikel 12, 13 en 14). Dit recht op informatie is een essentieel onderdeel van transparantie en zorgt ervoor dat individuen meer...

### Court rules on Experian appeal of ICO enforcement notice

*Source: IAPP, 2023-02-21 — https://overview.legal/posts/6241 — original: https://iapp.org/news/a/court-rules-on-experian-appeal-of-ico-enforcement-notice#entry-3894*

> 
																						The First-Tier Tribunal overturned portions of a 2020 enforcement notice by the U.K. Information Commissioner's Office against Experian, confirming the company's reliance on legitimate interests as a legal basis for processing credit reference agency information for direct marketing purposes. Deputy Commissioner Stephen Bonner, CIPP/E, CIPM, said marketing processes "must happen in line with the law and in an open and honest way" and the ICO noted it will consider an app

### Greek SA fines Clearview AI for EUR 20M

*Source: IAPP, 2022-10-20 — https://overview.legal/posts/6252 — original: https://iapp.org/news/a/greek-dpa-imposes-20m-euro-fine-on-clearview-ai-for-unlawful-processing-of-personal-data#entry-1098*

A rundown of the fine on IAPP: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings

## Literature

### Is the GDPR efficient in protecting EU citizens against the privacy risks raised by social media?

*Source: Journal of Data Protection Privacy, 2025-06-01 — https://overview.legal/posts/132556 — original: https://doi.org/10.69554/xact2373*

The General Data Protection Regulation (GDPR) was adopted for a noble cause: protecting European Union (EU) citizens’ privacy and the EU social model founded on the values of dignity, freedom, democracy, equality, the rule of law and respect for human rights. Thanks to the magnitude of its fines, the GDPR attracted much attention from media, companies and legislators far beyond the EU and greatly helped expand the protection of personal data worldwide. Seven years after coming into force, howeve

### The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how

*Source: Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza, 2023-12-30 — https://overview.legal/posts/132546 — original: https://doi.org/10.14746/ppuam.2023.15.09*

The data subject’s right to access information on data processing has a very broad meaning. Considering the latest developments in this field (mainly the CJEU ruling on Austrian posts and EDPB guidelines) one can draw the conclusion that the controller’s right to protect its confidential in-formation is limited and less valuable than the data subject’s rights. However, this may lead to unfair and unequal treatment of companies and data subjects. When looking at this right in a more systematic pe

### Recommendations for Creating Codes of Conduct for Processing Personal Data in Biobanking Based on the GDPR art.40

*Source: Frontiers in Genetics, 2021-11-12 — https://overview.legal/posts/132560 — original: https://doi.org/10.3389/fgene.2021.711614*

Personal data protection has become a fundamental normative challenge for biobankers and scientists researching human biological samples and associated data. The General Data Protection Regulation (GDPR) harmonises the law on protecting personal data throughout Europe and allows developing codes of conduct for processing personal data based on GDPR art. 40. Codes of conduct are a soft law measure to create protective standards for data processing adapted to the specific area, among others, to bi

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

### GDPR - General Data Protection Regulation on Sites Requiring Accessibility

*Source: Innovative STEM Education, 2021-06-29 — https://overview.legal/posts/132420 — original: https://doi.org/10.55630/stem.2021.0305*

The paper describes what GDPR - General Data Protection Regulation is and why it matters for business, institutions and other legal entities, who need to collect personal data in order to provide and deliver services or products. They have to apply and describe to consumers’ principles and general rules to protect their data. Rules include reasons why personal data collection is necessary, transparency how and by who it will be used and stored and for how long, as well as safety measures to not

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Transparency** — https://overview.legal/topics/transparantie
  Openness about data processing activities
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data

---
Generated by overview.legal · https://overview.legal/topics/fairness-transparency-principle · 2026-08-22
