# Legitimate Interest — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/gerechtvaardigd-belang
> Sources are cited per item. Verify against the official texts before relying on them.

Processing necessary for legitimate interests pursued by controller or third party

## Overview

## Legal Framework

The primary legal basis for legitimate interests processing is [Article 6(1)(f) GDPR](/laws/gdpr/art-6#par-1-pnt-f), which permits processing when it is "necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child." This provision creates a three-part balancing test: a legitimate interest must exist, the processing must be necessary for that interest, and the data subject's rights must not override it. Crucially, Article 6(1)(f) does not apply to processing by public authorities in the performance of their tasks.

Transparency obligations attach directly to this basis. Under [Article 13(1)(d)](/laws/gdpr/art-13#par-1-pnt-d), where data is collected from the subject, the controller must inform them of "the legitimate interests pursued by the controller or by a third party." Where data is not obtained from the subject, [Article 14(2)(b)](/laws/gdpr/art-14#par-2-pnt-b) imposes the same disclosure requirement.

## Key Developments

The CJEU has established that the legitimate interests basis imposes three cumulative conditions. In *Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde v. Rīgas pašvaldības SIA 'Rīgas satiksme'*, the Court held:

> "Article 7(f) of Directive 95/46 lays down three cumulative conditions so that the processing of personal data is lawful, namely, first, the pursuit of a legitimate interest by the data controller or by the third party or parties to whom the data are disclosed; second, the need to process personal data for the purposes of the legitimate interests pursued; and third, that the fundamental rights and freedoms of the person concerned by the data protection do not take precedence."
> — [CJEU, *Rīgas satiksme* ¶28](/posts/5953#seg-28)

The Court also clarified that this provision creates a possibility, not an obligation — controllers have discretion whether to rely on it, but must satisfy all three limbs. In *RYNES*, the CJEU recognised that legitimate interests can include tangible, concrete concerns such as "the protection of the property, health and life of his family and himself," confirming that the concept extends beyond purely commercial interests.

Enforcement actions reinforce the necessity limb. The Italian Garante fined the Calabrian Regional Agency €50,000 over remote-work monitoring, illustrating that vague security justifications fail when less intrusive alternatives exist. The AEPD's intervention against the University of Navarra on vaccination-status collection further shows that legitimate interests cannot override data subject autonomy where consent is the more appropriate basis.

## Status of the Debate

This topic is actively contested in court. The three-part test from *Rīgas satiksme* provides the structural framework, but courts and DPAs diverge on how to calibrate the balancing limb — particularly the weight assigned to data subject rights relative to controller interests in employment, surveillance, and commercial profiling contexts. The EDPB's consent guidance signals that power imbalances (employment, public authority contexts) make legitimate interests harder to sustain, yet the precise boundary between legitimate-interests processing and required consent remains unsettled. What would resolve the open question is CJEU guidance on the proportionality assessment within the third limb — specifically, whether a categorical rule should exclude certain processing types (e.g., employee monitoring) from the legitimate interests basis, or whether the case-by-case approach should prevail.

## Practical Guidance

- **Document a three-part assessment before processing begins**: Identify the specific legitimate interest, demonstrate necessity (no less intrusive alternative), and record the balancing analysis weighing data subject rights against that interest.
- **Be specific in transparency notices**: Under [Article 13(1)(d)](/laws/gdpr/art-13#par-1-pnt-d) and [Article 14(2)(b)](/laws/gdpr/art-14#par-2-pnt-b), articulate the actual interest pursued — not a generic "business operations" statement — so data subjects can understand and, where applicable, object.
- **Avoid legitimate interests where power imbalances exist**: In employment and public-authority contexts, the EDPB's consent guidance and enforcement trends indicate that the balancing test will frequently fail; prefer consent, contract, or legal obligation bases.
- **Consider data subject expectations and vulnerability**: The express reference to children in Article 6(1)(f) signals that the balancing test must account for the data subject's position; processing involving minors or sensitive contexts carries a higher override risk.
- **Re-assess periodically**: The balancing test is not static — changes in processing scope, new case law, or shifts in data subject expectations can tip the balance, requiring renewed justification.

## Legislation (full text of key provisions)

### Recital 47 — legitimate interests as processing legal basis

*Source: GDPR, gdpr-rec-47-en, 2016-04-27 — https://overview.legal/posts/91609*

The legitimate interests of a controller, including those of a controller to which the personal data may be disclosed, or of a third party, may provide a legal basis for processing, provided that the interests or the fundamental rights and freedoms of the data subject are not overriding, taking into consideration the reasonable expectations of data subjects based on their relationship with the controller. Such legitimate interest could exist for example where there is a relevant and appropriate relationship between the data subject and the controller in situations such as where the data subject is a client or in the service of the controller. At any rate the existence of a legitimate interest would need careful assessment including whether a data subject can reasonably expect at the time and in the context of the collection of the personal data that processing for that purpose may take place. The interests and fundamental rights of the data subject could in particular override the interest of the data controller where personal data are processed in circumstances where data subjects do not reasonably expect further processing. Given that it is for the legislator to provide by law for the legal basis for public authorities to process personal data, that legal basis should not apply to the processing by public authorities in the performance of their tasks. The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned. The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.

### Recital 69 — data subject right to object

*Source: GDPR, gdpr-rec-69-en, 2016-04-27 — https://overview.legal/posts/91653*

Where personal data might lawfully be processed because processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or on grounds of the legitimate interests of a controller or a third party, a data subject should, nevertheless, be entitled to object to the processing of any personal data relating to his or her particular situation. It should be for the controller to demonstrate that its compelling legitimate interest overrides the interests or the fundamental rights and freedoms of the data subject.

### Recital 121 — lawful personal data processing for cybersecurity

*Source: NIS2, nis2-rec-121-en, 2022-12-14 — https://overview.legal/posts/96770*

The processing of personal data, to the extent necessary and proportionate for the purpose of ensuring security of network and information systems by essential and important entities, could be considered to be lawful on the basis that such processing complies with a legal obligation to which the controller is subject, in accordance with the requirements of Article 6(1), point (c), and Article 6(3) of Regulation (EU) 2016/679. Processing of personal data could also be necessary for legitimate interests pursued by essential and important entities, as well as providers of security technologies and services acting on behalf of those entities, pursuant to Article 6(1), point (f), of Regulation (EU) 2016/679, including where such processing is necessary for cybersecurity information-sharing arrangements or the voluntary notification of relevant information in accordance with this Directive. Measures related to the prevention, detection, identification, containment, analysis and response to incidents, measures to raise awareness in relation to specific cyber threats, exchange of information in the context of vulnerability remediation and coordinated vulnerability disclosure, the voluntary exchange of information about those incidents, and cyber threats and vulnerabilities, indicators of compromise, tactics, techniques and procedures, cybersecurity alerts and configuration tools could require the processing of certain categories of personal data, such as IP addresses, uniform resources locators (URLs), domain names, email addresses and, where they reveal personal data, time stamps. Processing of personal data by the competent authorities, the single points of contact and the CSIRTs, could constitute a legal obligation or be considered to be necessary for carrying out a task in the public interest or in the exercise of official authority vested in the controller pursuant to Article 6(1), point (c) or (e), and Article 6(3) of Regulation (EU) 2016/679, or for pursuing a legitimate interest of the essential and important entities, as referred to in Article 6(1), point (f), of that Regulation. Furthermore, national law could lay down rules allowing the competent authorities, the single points of contact and the CSIRTs, to the extent that is necessary and proportionate for the purpose of ensuring the security of network and information systems of essential and important entities, to process special categories of personal data in accordance with Article 9 of Regulation (EU) 2016/679, in particular by providing for suitable and specific measures to safeguard the fundamental rights and interests of natural persons, including technical limitations on the re-use of such data and the use of state-of-the-art security and privacy-preserving measures, such as pseudonymisation, or encryption where anonymisation may significantly affect the purpose pursued.

### Recital 52 — harmonised notice and action mechanisms

*Source: DSA, dsa-rec-52-en, 2022-10-19 — https://overview.legal/posts/95501*

The rules on such notice and action mechanisms should be harmonised at Union level, so as to provide for the timely, diligent and non-arbitrary processing of notices on the basis of rules that are uniform, transparent and clear and that provide for robust safeguards to protect the right and legitimate interests of all affected parties, in particular their fundamental rights guaranteed by the Charter, irrespective of the Member State in which those parties are established or reside and of the field of law at issue. Those fundamental rights include but are not limited to: for the recipients of the service, the right to freedom of expression and of information, the right to respect for private and family life, the right to protection of personal data, the right to non-discrimination and the right to an effective remedy; for the service providers, the freedom to conduct a business, including the freedom of contract; for parties affected by illegal content, the right to human dignity, the rights of the child, the right to protection of property, including intellectual property, and the right to non-discrimination. Providers of hosting services should act upon notices in a timely manner, in particular by taking into account the type of illegal content being notified and the urgency of taking action. For instance, such providers can be expected to act without delay when allegedly illegal content involving a threat to life or safety of persons is being notified. The provider of hosting services should inform the individual or entity notifying the specific content without undue delay after taking a decision whether or not to act upon the notice.

### Recital 97 — researcher data access framework

*Source: DSA, dsa-rec-97-en, 2022-10-19 — https://overview.legal/posts/95591*

This Regulation therefore provides a framework for compelling access to data from very large online platforms and very large online search engines to vetted researchers affiliated to a research organisation within the meaning of Article 2 of Directive (EU) 2019/790, which may include, for the purpose of this Regulation, civil society organisations that are conducting scientific research with the primary goal of supporting their public interest mission. All requests for access to data under that framework should be proportionate and appropriately protect the rights and legitimate interests, including the protection of personal data, trade secrets and other confidential information, of the very large online platform or of the very large online search engine and any other parties concerned, including the recipients of the service. However, to ensure that the objective of this Regulation is achieved, consideration of the commercial interests of providers should not lead to a refusal to provide access to data necessary for the specific research objective pursuant to a request under this Regulation. In this regard, whilst without prejudice to Directive (EU) 2016/943 of the European Parliament and of the Council (32), providers should ensure appropriate access for researchers, including, where necessary, by taking technical protections such as through data vaults. Data access requests could cover, for example, the number of views or, where relevant, other types of access to content by recipients of the service prior to its removal by the providers of very large online platforms or of very large online search engines.

### Recital 47 — Non-arbitrary intermediary rights-respecting restrictions

*Source: DSA, dsa-rec-47-en, 2022-10-19 — https://overview.legal/posts/95491*

When designing, applying and enforcing those restrictions, providers of intermediary services should act in a non-arbitrary and non-discriminatory manner and take into account the rights and legitimate interests of the recipients of the service, including fundamental rights as enshrined in the Charter. For example, providers of very large online platforms should in particular pay due regard to freedom of expression and of information, including media freedom and pluralism. All providers of intermediary services should also pay due regard to relevant international standards for the protection of human rights, such as the United Nations Guiding Principles on Business and Human Rights.

### Recital 63 — safeguards against platform misuse

*Source: DSA, dsa-rec-63-en, 2022-10-19 — https://overview.legal/posts/95523*

The misuse of online platforms by frequently providing manifestly illegal content or by frequently submitting manifestly unfounded notices or complaints under the mechanisms and systems, respectively, established under this Regulation undermines trust and harms the rights and legitimate interests of the parties concerned. Therefore, there is a need to put in place appropriate, proportionate and effective safeguards against such misuse, that need to respect the rights and legitimate interests of all parties involved, including the applicable fundamental rights and freedoms as enshrined in the Charter, in particular the freedom of expression. Information should be considered to be manifestly illegal content and notices or complaints should be considered manifestly unfounded where it is evident to a layperson, without any substantive analysis, that the content is illegal or, respectively, that the notices or complaints are unfounded.

### Recital 113 — non repetitive limited data transfers

*Source: GDPR, gdpr-rec-113-en, 2016-04-27 — https://overview.legal/posts/91741*

Transfers which can be qualified as not repetitive and that only concern a limited number of data subjects, could also be possible for the purposes of the compelling legitimate interests pursued by the controller, when those interests are not overridden by the interests or rights and freedoms of the data subject and when the controller has assessed all the circumstances surrounding the data transfer. The controller should give particular consideration to the nature of the personal data, the purpose and duration of the proposed processing operation or operations, as well as the situation in the country of origin, the third country and the country of final destination, and should provide suitable safeguards to protect fundamental rights and freedoms of natural persons with regard to the processing of their personal data. Such transfers should be possible only in residual cases where none of the other grounds for transfer are applicable. For scientific or historical research purposes or statistical purposes, the legitimate expectations of society for an increase of knowledge should be taken into consideration. The controller should inform the supervisory authority and the data subject about the transfer.

### Recital 111 — conditional personal data transfer exceptions

*Source: GDPR, gdpr-rec-111-en, 2016-04-27 — https://overview.legal/posts/91737*

Provisions should be made for the possibility for transfers in certain circumstances where the data subject has given his or her explicit consent, where the transfer is occasional and necessary in relation to a contract or a legal claim, regardless of whether in a judicial procedure or whether in an administrative or any out-of-court procedure, including procedures before regulatory bodies. Provision should also be made for the possibility for transfers where important grounds of public interest laid down by Union or Member State law so require or where the transfer is made from a register established by law and intended for consultation by the public or persons having a legitimate interest. In the latter case, such a transfer should not involve the entirety of the personal data or entire categories of the data contained in the register and, when the register is intended for consultation by persons having a legitimate interest, the transfer should be made only at the request of those persons or, if they are to be the recipients, taking into full account the interests and fundamental rights of the data subject.

### Recital 48 — intra-group personal data transfers

*Source: GDPR, gdpr-rec-48-en, 2016-04-27 — https://overview.legal/posts/91611*

Controllers that are part of a group of undertakings or institutions affiliated to a central body may have a legitimate interest in transmitting personal data within the group of undertakings for internal administrative purposes, including the processing of clients' or employees' personal data. The general principles for the transfer of personal data, within a group of undertakings, to an undertaking located in a third country remain unaffected.

## Case law

### CJEU - C‑209/23 - RRC Sports

*Source: GDPRhub, 2026-07-16 — https://overview.legal/posts/144028 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑209/23_-_RRC_Sports*

Facts — Fédération internationale de football association (FIFA) is a Switzerland-based non-profit that acts as the global governing body for football. A large number of football clubs and national football associations are member of FIFA and bound by its regulations. In January FIFA published the FIFA Football Agent Regulations (FFAR). FFAR regulated the conduct of player’s agents. In particular, FFAR provided maximum limits to agents’ remuneration and prohibited specific types of contractual arrangements between clubs, agents, and agencies. In order to ensure compliance with these rules, Article 12 FFAR required agents to disclose certain information to FIFA. In particular, agents had to disclose: Information about any agreement with a client, other than a representation agreement; Information on any arrangement between agents to cooperate in the provision of their services, or to share the revenue or profits of their services; Information about their relationship with agencies, including the names of all of the agency’s employees. Additionally, FIFA would make the information available to a number of stakeholders including agents, players, and football clubs. Three applicants (an agent, a company acting as a players’ agent, and the Vice-President of a players’ agents’ associations) challenged FFAR in the Regional Court of Mainz (Germany). The Court referred four questions to the CJEU for a preliminary ruling. In essence, the Court asked the CJEU whether the FFAR was compatible with Articles 101 TFEU (prohibition on cartels), 102 TFEU (prohibition on abuse of a dominant position), 56 TFEU (freedom to provide services), and 6 GDPR (legal bases for processing personal data). With regards to Article 6 GDPR specifically, the referring court essentially asked whether there was a lawful basis under the GDPR for a collection of personal data, such as required under the FFAR’s mandatory disclosure rules. Advocate General Opinion — The referring question did not specify what legal basis had to be examined in order to assess the compatibility of FFAR disclosures with the GDPR. However, the AG opined that interest under Article 6(1)(f) was the relevant legal basis, based on the nature of the FFAR rules and on other information on the order for reference. Therefore, the AG focused on the legal basis of legitimate interest exclusively. The AG recalled that the mandatory disclosure under FFAR were compatible with the GDPR if they met three cumulative requirements: They genuinely pursued an interest worthy of protection; They were limited to what was strictly necessary to that end; They did not place an intolerable burden on the data subjects as regards their right to privacy and their financial interests. The AG opined that in the case at hand, the processing of personal data pursued an interest worthy of protection (that is, FIFA’s interest in ensuring that the conduct of agents was consistent with the core objective of the football transfer systems, and other objectives related to the good functioning of the player market). However, the AG was more cautious about the other two requirements. With regards to the requirement of necessity, the AG noted that FFAR required the collection of a substantial amount of personal data, including delicate data about agents’ remuneration and contractual agreements. Additionally, FIFA would not only receive the data but also make it available to stakeholders such as clubs, players, and player’s agents. The AG opined that such a broad collection and disclosure of personal data could, to some extent, exceed what was strictly necessary to pursue FIFA’s legitimate interest. In that regard, the AG stressed that FIFA should explain to the referring court why the collection and disclosure of the data were necessary, in relation to each type of information. With regards to the balancing of interests, the AG opined that agents operate within a regulatory framework and, therefore, have a reasonable expectation that FIFA would process their data as a regulatory body. In the AG’s view, this expectation could weight favorably on the balancing of legitimate interest. At the same time, the AG opined that the availability of agents’ personal data to both competitors and potential clients, could financially harm agents and erode trust in agent-client relationships. Holding — The CJEU held that processing based on Article 6(1)(f) GDPR is lawful only where three cumulative conditions are met. First, the controller or a third party must pursue a legitimate interest. Second, the processing must be necessary for that interest. Third, the interests or fundamental rights and freedoms of the data subject must not override the legitimate interest pursued. Regarding the information agents were required to submit through the controller’s digital platform under Article 16 FFAR, the Court considered that ensuring compliance with the regulatory framework governing football agents could constitute a legitimate interest. This was conditional on the underlying obligations being compatible with EU and national law. The Court found that the information required under Article 16 FFAR appeared capable of identifying attempts to circumvent rules on representation, remuneration and conflicts of interest. The processing could therefore be adequate, relevant and limited to what was necessary. However, the referring court had to determine whether equally effective but less intrusive measures were available and assess any additional information requested through the platform whose precise scope was not defined in the regulations. The processing under Article 16 FFAR could therefore be compatible with Article 6(1)(f) GDPR, subject to verification by the referring court. Regarding Article 19 FFAR, the Court distinguished between the different categories of information disclosed by the controller. The publication of agents’ names and contact details, the identity of their clients, the duration and exclusivity of representation agreements and the services provided could pursue legitimate interests such as establishing professional and ethical standards, protecting clients from unethical conduct and improving transparency. Since the information concerned professional activities within a regulatory framework known to the persons involved, this processing could satisfy the balancing test under Article 6(1)(f) GDPR. By contrast, publishing detailed information about every transaction involving an agent, including the service fees paid, was not limited sufficiently. The Court held that agents and clients did not need access to detailed information about all transactions involving their competitors to comply with the regulations. The indiscriminate disclosure of this information therefore infringed the data minimisation principle under Article 5(1)(c) GDPR and was not necessary under Article 6(1)(f) GDPR. The Court also examined the publication of sanctions imposed on agents and clients. It accepted that publication could, in certain circumstances, deter misconduct, restore confidence in the market and allow persons harmed by an infringement to become aware of it. Nevertheless, Article 19 FFAR required the publication of every sanction without considering its seriousness, the harm caused, its relevance to market confidence or the time elapsed since the infringement. The regulation also did not provide for the information to cease being available after a defined period. The blanket publication obligation therefore did not appropriately balance the controller’s interests against the data subjects’ rights under Articles 7 and 8 CFR. Moreover, where a sanction contained personal data relating to criminal convictions or offences, Article 10 GDPR applied. In the absence of authorisation under EU or Member State law and supervision by a public authority, the controller could not process such data. The Court consequently held that Article 6(1)(f) GDPR precluded regulations adopted by an international sports federation insofar as they required the disclosure and publication of: every sanction imposed on agents or their clients; and detailed information concerning all transactions involving agents. The Court did not impose a fine or order any specific corrective measure. It provided an interpretation of EU law for the referring court, which remained responsible for resolving the underlying dispute and verifying the relevant factual and legal conditions.

### USR - Us I-755/2025-8

*Source: Administrative Court in Rijeka, 2025-11-11 — https://overview.legal/posts/49225 — original: https://gdprhub.eu/index.php?title=USR_-_Us_I-755/2025-8*

Facts — The data subject was a member of the management board of Zagrebački holding, a company owned by the City of Zagreb, from 3 September 2021 until 31 March 2023. A television broadcaster published several pieces, including a video on its YouTube channel, reporting on the data subject’s resignation. The publications mentioned his name, role, employer, salary, and information on the brand of his private car. The data subject filed a complaint with the Croatian Personal Data Protection Agency (AZOP), claiming that the publication constituted unlawful processing under the GDPR because the media lacked a valid legal basis under Article 6, the reporting was inaccurate and excessive, and it did not serve any genuine public interest. He latter further claimed during the lawsuit against AZOP's decision that the authority had incorrectly and incompletely established the facts, misapplied substantive law, and breached procedural rules. He emphasized that the published personal data was unrelated to transparency in public administration, that he was neither a public figure nor a political actor, and that any public interest ended once he left office on 31 March 2023. He invoked his right to erasure under Article 17 GDPR and sought removal of the content, annulment of AZOP’s decision, or alternatively, a remittal for a new procedure. AZOP contested the lawsuit in full, maintaining that it had acted in accordance with Article 34 of the Croatian GDPR Implementation Act and Article 77 GDPR. It argued that the publication fell within a justified public interest under Article 8 of the Croatian Media Act and that it had properly carried out a balancing test between privacy (Article 8 ECHR) and freedom of expression (Article 10 ECHR). According to AZOP, the reporting was necessary, proportionate, and not sensationalistic, and did not excessively intrude on the data subject’s privacy. It added that consent was not required because the processing relied on legitimate interest under Article 6(1)(f) GDPR. Holding — The Administrative Court dismissed the action and upheld AZOP’s decision. Because Zagrebački holding is a city-owned and publicly funded company, the court considered information about the data subject’s salary, compensation for using his private vehicle in official duties, and his managerial role to be directly connected to the use of public resources. This placed the publication within the legitimate public interest in transparency recognised by Article 8 of the Media Act. In its proportionality assessment, the court accepted AZOP's application of Article 5 and 6 GDPR, emphasizing that the published data did not touch upon the data subject’s family or intimate life but related solely to his public functions. Publication was therefore limited to what was necessary to inform the public about the management of a publicly owned company. The data subject’s claims that the publication was false or harmful to his reputation did not alter the outcome, as AZOP is not empowered to determine the truthfulness or tone of journalistic content, particularly under the journalistic exemption in Article 85 GDPR. Issues of accuracy or reputational harm must instead be pursued through media-law mechanisms such as requests for correction or civil actions. On the erasure request, the court held that the right to be forgotten under Article 17 GDPR cannot override freedom of expression and information where media reporting is involved. Although the data subject no longer served on the board, the publication continued to contribute to public understanding of how a major public entity was run during his tenure, thus the public interest persisted and erasure was not justified. Finally, the court reiterated that consent was not required because Article 6 GDPR offers alternative lawful bases for processing. Since Article 6(1)(f) was satisfied, the absence of consent was irrelevant. Concluding that AZOP had properly applied the law and that the interference with the data subject’s privacy was proportionate, the court upheld the decision and denied the data subject’s claim and costs.

### Judgment of the Court (Ninth Chamber) of 4 October 2024.#Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens.#Request for a preliminary ruling from the Rechtbank Amsterdam.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Lawfulness of processing – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interest

*Source: Court of Justice of the European Union, C-621/22, 2024-10-04 — https://overview.legal/posts/132160 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0621*

The CJEU ruled on a preliminary reference from the Amsterdam District Court in proceedings between the Koninklijke Nederlandse Lawn Tennisbond (KNLTB) and the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) concerning whether a sports federation may rely on Article 6(1)(f) GDPR to disclose members' personal data to sponsors for commercial purposes without their consent. The Court held that a controller's commercial interest can constitute a "legitimate interest" under Article 6(1)(f), but that sharing members' data with sponsors without consent is unlawful where members could not reasonably expect such processing, as the necessity and balancing tests are not satisfied. The underlying AP fine against KNLTB was imposed for violating GDPR rules in connection with this practice.

### VwGH - Ro 2022/04/0026

*Source: Austrian Administrative Supreme Court, 2024-05-17 — https://overview.legal/posts/187377 — original: https://gdprhub.eu/index.php?title=VwGH_-_Ro_2022/04/0026*

Facts — The data subjects, joint operators of a hotel and restaurant business, ran their establishment through a family business. The controller operates an online travel platform accessible in Austria, on which registered users can post reviews and experience reports about listed establishments, in addition to general information. The data subjects' business was listed on the platform without their consent and was reviewed by users a few times per month, in comments that identified the data subjects by name, including both positive and negative reviews. On 27 June 2019, the data subjects requested that the controller erase all their personal data from the platform. The controller did not comply. On 28 August 2019, the data subjects lodged a complaint with the Austrian DPA, alleging unlawful processing and a violation of their right to erasure under Article 17(1)(d) GDPR. The DPA rejected the complaint on 18 September 2020, relying on Article 6(1)(f) GDPR (legitimate interests) as the legal basis for the processing. The data subjects appealed to the Federal Administrative Court (BVwG), which held an oral hearing and dismissed the appeal on 13 May 2022. The BVwG found that the platform's processing served a legitimate interest in freedom of expression and information that the reviews concerned the data subjects' social andprofessional sphere rather than their private sphere, that it was reasonable to expect the data subjects to monitor the platform for unjustified criticism and that the controller had taken adequate measures against abusive reviews. The BVwG declared an appeal on points of law (Revision) admissible, citing the absence of Supreme Administrative Court case-law on the principles governing the balancing of interests for review platforms under Article 6(1)(f) GDPR. The data subjects appealed to the Supreme Administrative Court. Holding — The court dismissed the appeal as unfounded, addressing each contested element of the three-part test under Article 6(1)(f) GDPR (legitimate interest, necessity, no overriding interest of the data subject). On legitimate interest: The court held that the exercise of freedom of expression and information can constitute a legitimate interest under Article 6(1)(f) GDPR. It reasoned that both service recipients' freedom to express opinions about service quality and the conduct of those providing the service and prospective recipients' freedom to access such opinions, were protected by this provision and that the platform served this purpose by enabling reviews and structured searches. The court held that the controller's pursuit of commercial interests alongside this function did not undermine the legitimate interest, since Article 6(1)(f) GDPR expressly covers interests of the controller "or a third party" and the data subjects had not substantiated their claim that the controller had abandoned a neutral intermediary role. It also rejected the argument that the public's interest was too narrow to qualify as legitimate merely because the hotel's clientele was limited, holding that such considerations belong to the separate balancing-of-interests stage, not to the threshold question of whether a legitimate interest exists at all. On the sphere of privacy affected: The court agreed with the lower court that the reviews concerned the data subjects' social sphere (specifically, their professional sphere as hotel operators) rather than their private sphere, since the criticised conduct occurred in public in the course of providing services to third parties. It held that this classification does not change merely because the business could hypothetically be sold to a third party in future, such a change of circumstances could be considered if and when it actually occurred, but did not retroactively reclassify the current processing. On the reasonableness of monitoring the platform: The court held that requiring the data subjects to check the platform for reviews was not excessive, given the low frequency of reviews, the availability of an email notification service and the fact that hotel operators offering services to the public must accept a degree of observation and criticism. The court limited the relevant comparison to the controller's own platform, not all review platforms on which the business might be listed, since only a claim against this controller was at issue. On protection against abuse: The court held that the absence of identity verification for reviewers was a relevant factor in the balancing exercise, but that a blanket requirement for reviewers to identify themselves would be disproportionate, given the recognised value of anonymous expression online. It held that the controller's existing measures allowing establishment representatives to report abusive reviews for removal, were sufficient, although it criticised the lower court's findings on this point as underdeveloped. However, since the data subjects failed to show that any specific personal data would have been removed had a stricter verification system existed, this shortcoming did not establish unlawfulness in the specific case. On the second data subject's claim of heightened risk as a former political figure: The court held that a data subject wishing to invoke a "particular situation" under Article 21 GDPR must lodge an actual objection to processing on that basis; simply mentioning a past political role during proceedings did not amount to such an objection and the erasure request had in fact been based solely on unlawful processing under Article 17(1)(d) GDPR, not the objection-based ground under Article 17(1)(c) GDPR. Finally, the court declined the data subjects' request for a preliminary reference to the CJEU, noting that the CJEU has already made clear that the case-specific balancing of interests under Article 6(1)(f) GDPR is a matter for the national court. (C-252/21)

### LG Rostock - 3 O 762/19

*Source: LG Rostock, 2020-09-15 — https://overview.legal/posts/122848 — original: https://gdprhub.eu/index.php?title=LG_Rostock_-_3_O_762/19*

Facts — The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit against advocado GmbH (advocado, the defendant), a German-based company that runs an online platform where attorneys can offer their services. The defendant's website had used a cookie banner with pre-ticked boxes for the use of marketing and analytics cookies. This included the use of tools such as Google Analytics that entail a data transfer to third countries. The claimant argued that the data processing in connection with the placed cookies was unlawful under Article 6(1) GDPR: A user's consent under Article 6(1)(a) GDPR could not be considered valid under Articles 4(11) and 7 GDPR, especially since the boxes were pre-ticked. Moreover, the claimant claimed that the defendant had violated Articles 5(1)(a), 13/14, 26 and 44 et seqq. GDPR as it had failed to properly inform users of the scope of intended processing activities, joint controllers and international data transfers in connection with the use of cookies. The defendant stated that it had based the use of cookies on legitimate interests under Article 6(1)(f) GDPR until the CJEU issued its decision C-673/17 on 01.10.2019 ("Planet 49"). Afterwards, the defandent argued that they changed the legal basis for processing to consent under Article 6(1)(a) GDPR, which it considered valid under Articles 4(11) and 7 GDPR. The defendant also stated that it was the sole controller for the processing activities - there were no joint controllers involved, only processors. (Furthermore, the claimant had also argued that some provisions in the defendant's general terms and conditions were unlawful from a civil law / consumer protection law perspective. This will not be discussed further in this summary.) Dispute — Was it necessary to ask for the users' consent under Article 6(1)(a) GDPR or could the processing activities in connection with the use of marketing and analytics cookies be based on legitimate interest under Artilce 6(1)(f)? Was the consent given by users' when interacting with the defendant's cookie banner valid under Articles 6(1)(a), 4(11) and 7 GDPR? Did the defendant violate GDPR provisions on transparency? Was the defendant the sole controller regarding the processing activities in connection with the use of marketing and analytics cookies or were there any joint controllers? Holding — Legal basis and validity of consent — The court held that the marketing and analytics cookies used by the defendant c an only be placed with the users' consent under Article 6(1)(a) GDPR : § 15(3) Telemediengesetz that deals with such cookies must be interpreted in light of Article 5(3) e-Privacy Directive, which requires consent for cookies not strictly necessary for technical reasons. Taking into consideration the design of the cookie banner and the lack of information provided to a website user, the court held that consent given could not be considered valid under Articles 6(1)(a), 4(11) and 7 GDPR. The banner featured pre-ticked boxes and a big "OK" button. The option "use only necessary cookies" was designed to not look like an interactive button but rather a link. Consent could therefore not be considered "freely given" and was invalid. Transparency — The court further held that the defendant violated Article 13 GDPR by mentioning an incorrect transfer mechanism under Articles 44 et seqq. GDPR for data transfers in connection with the use of cookies. Sole or joint controllership when using Google Analytics? — Lastly, the court held that the use of Google Analytics results in joint controllership of the website provider using this tool and Google . Google does not qualify as the website provider's processor under Article 4(7). This is because Google does not process the data solely for the purpose of use by the website provider. Rather, Google, like other third-party providers, expressly reserves the right to process the data for its own purposes as well. The fact that the defendant and Google entered into a data processing agreement under Article 28 GDPR does not change this assessment. The court's legal view is in line with the official opinion of the "Datenschutzkonferenz", a gathering of all German DPAs.

### GHARL - 200.256.426

*Source: GHARL, 2019-11-05 — https://overview.legal/posts/122859 — original: https://gdprhub.eu/index.php?title=GHARL_-_200.256.426*

Facts — DFW (a Dutch movie distributor) applies a protocol to its processing of personal data which was approved by the Dutch DPA before the GDPR came into force. DFW asked Ziggo (an internet service provider) to provide IP addresses of customers who according to DFW shared movies illegally. Ziggo refused to provide this information. Dispute — Τhe Court had to assess whose interests prevail in this case: DFW's interest in the protection of its intellectual property rights or Ziggo's interest in the protection of the personal data of its customers. Holding — The Court found that any processing needed to be based on legitimate interests according to Article 6(1)(f) GDPR and that Ziggo had to comply with Article 6(4)(d) GDPR. The Court found that DFW had a legitimate interest and that the processing was necessary. However, the Court pursued a balancing exercise between the interests of DFW and the interests of the data subjects and found that the approved protocol was not transparent enough. Thus, the possible consequences for the data subjects of providing their data to DFW could not be estimated. DFW failed to make clear which action it would take, under which circumstances and in which manner it would inform the data subjects of their rights. The Court is of the opinion that the interests of Ziggo's customers are still insufficiently safeguarded, and it, therefore, rejected DFW’s claims confirming the ruling of the Court of First Instance. The Court based its ruling on the national civil code, Articles 4(2) and 6 GDPR, Articles 17 and 47 of the Charter of Fundamental Rights (CFR), and Articles 8 and 13 ECHR.

### Personvernnemnda (Norway) - 2018-14 (15/01355)

*Source: PVN, 2019-01-21 — https://overview.legal/posts/125646 — original: https://gdprhub.eu/index.php?title=Personvernnemnda_(Norway)_-_2018-14_(15/01355)*

Facts — In 2017, the Norwegian DPA Datatilsynet found that a company "Legelisten", running an anonymous review website of healthcare personnel, lacked a legal basis for processing and instructed them to allow said personnel to opt out of being listed and reviewed, in addition to several other instructions. Both the initial complainant and Legelisten responded to the DPA's decision with complaints. The DPA considered both complaints, but did not find any grounds to change their decision. Consequently, the case was submitted to the Norwegian Privacy Appeals Board, who considered comments from the initial complainant, Legelisten, the Norwegian Consumer Council, and the DPA. The Board focused their assessment on the lawfulness of processing of personal data on the website Legelisten.no. First, they considered the applicable law, as the GDPR had entered into force since the initial complaints dating back to 2012. They found that the GDPR would indeed apply. Holding — The Board reviewed several aspects relating to the case in question, summarised below. Controller responsibility — The Board agreed with the DPA's finding that Legelisten is the controller for all processing of personal data related to their site (as listed above), for both users and the healthcare personnel, because they in all these instances determine how the personal data will be processed (the purpose) and the means (technical platform, layout, which processors to use). The relationship to freedom of speach and processing for journalistic purposes — The Board agreed with the DPA's finding that there were no exemptions or derogations for processing carried out for journalistic purposes in this case. Legal grounds for processing personal data about the users — The DPA found that Legelisten lacked a legal basis for processing contact information (email address) of users submitting reviews, because they could not rely on consent as this was not found to have been provided voluntarily. The Board agreed that email addresses will often reveal the identity of a person and is, as such, personal data, and that information related to visits to or contact with specialist healthcare personnel, will reveal special category personal data and thus requires a legal ground for processing as per Article 9(2) GDPR, in addition to Article 6(1). However, the Board were split in their view of consent being a valid legal basis for processing in this specific case. The majority disagreed with the DPA and found that Legelisten could rely on consent for processing contact information of users, because they provided sufficient sufficient information in their terms and privacy notice, and required users to provide their consent through a clear affirmative act. The Board's decision here effectively reverted the DPA's initial decision item 8. Legal grounds for processing personal data about healthcare personnel — Processing of personal data about healthcare personnel on Legelisten relates to two categories: objective vs. subjective personal data. The Board noted that the relevant legal basis in both cases is Article 6(1)(f), legitimate interest, and made a thorough assessment relating to the three-part test (the purpose test, the necessity test and the balancing test). The Board first assessed the legal basis relating to the users' subjective reviews of healthcare personnel. In the balancing test, the Board were split in their views. First, the majority found that the subjective expressions of the individual patient in principle are expressions protected by the right of freedom of speech, cf. the Norwegian Constitution § 100 and the European Convention on Human Rights Article 10, and that most healthcare personnel on Legelisten can be seen as public figures, cf. the Article 29 Data Protection Working Party guidelines 225, number 2: «Does the data subject play a role in public life? Is the data subject a public figure?». Next, the majority emphasised that patients' subjective reviews of their experiences with healthcare personnel is of public interest and Legelisten's services contributes to safeguarding important consumer interests. Hence, they concluded that a general right to opt out of being reviewed on the website, would reduce the value of Legelisten as a source of information on the quality of health-related services in Norway. They pointed to the almost immediate reservation requests from about 20% of general practicioners following the DPA's decision. In conclusion, the majority of the Board held that the various legitimate interests of Legelisten outweighed the rights and freedoms of the healthcare personnel, that the processing of their personal data is necessary for the purpose and, consequently, lawful as per Article 6(1)(f). For the objective personal data, an unanimous Board agreed that Legelisten had a legitimate interest in processing these. The Board's decision — Legelisten is the controller for all personal data published on their website. Legelisten's publishing of reviews of healthcare personnel is not subject to the exemptions or derogations for processing carried out for journalistic purposes. Legelisten has legal grounds for processing user contact information, cf. Article 6(1)(a), cf. Article 9(2)(a). Legelisten is not instructed to publish the identity of the users submitting reviews of healthcare personnel. Legelisten has legal grounds for collecting and publishing subjective reviews of healthcare personnel, cf. Article 6(1)(f), and does not have to provide healthcare personnel with the right to opt out. Legelisten has legal grounds for collecting and publishing objective personal data of healthcare personnel, cf. Article 6(1)(f), and does not have to provide healthcare personnel with the right to opt out.

### OLG München - 36 U 1054/25 e

*Source: Higher Regional Court Munich, 2026-06-26 — https://overview.legal/posts/184545 — original: https://gdprhub.eu/index.php?title=OLG_München_-_36_U_1054/25_e*

Facts — The data subject had used a social media platform operated by the controller, an Irish company, since 2013. The controller provided “Business Tools” to third-party website operators and app providers. These tools enabled the controller to obtain data concerning how users interacted with third-party websites and apps, including information about page visits, purchases and advertisements clicked. In November 2023, the data subject requested that the controller recognize that the processing of his personal data was contrary to the parties’ contract, erase or anonymize the personal data, provide access to the personal data and pay compensation. The data subject subsequently brought an action before the Regional Court of Munich II, seeking a declaration that the parties’ user contract did not permit the processing, cessation of the processing of personal data collected through the Business Tools on third-party websites and apps, restriction of further processing, erasure or anonymization of previously collected data and at least €5,000 in non-material damages. The relevant data included direct and indirect identifiers, such as his name, contact details, IP address and internal identifiers, as well as website URLs, visit times, app names and information about his interactions with websites and apps. The Regional Court of Munich II dismissed the action, holding that the declaratory and erasure or anonymization claims were inadmissible, the cessation claims were legally unavailable and the damages claim had not been sufficiently substantiated. In relation to the damages claim, it found that the data subject had not identified specific third-party websites or apps through which his personal data had been processed. The data subject accordingly appealed to the Higher Regional Court of Munich. Holding — The Higher Regional Court of Munich partially upheld the appeal. First, the court held that the Controller processed the data subject’s personal data under Articles 4(1) and 4(2) GDPR by receiving data transmitted through its Business Tools, associating it with a user account and storing it. The data subject was not required to identify every website, app or individual transmission because the relevant information was principally within the controller’s knowledge and it was sufficiently probable that he had been affected. Second, referring to CJEU C‑40/17 concerning the broad interpretation of “controller”, the court held that the controller was a joint controller under Articles 4(7) and 26 GDPR for the collection and transmission of the personal data. It controlled the programming of the Business Tools and participated in determining the purposes and means of processing. Allocating certain obligations to third-party website and app operators did not remove its responsibility. Third, referring to CJEU C‑252/21, the court held that the controller had not established a lawful basis for the processing of the personal data. The processing was not justified by consent under Article 6(1)(a), contractual necessity under Article 6(1)(b), a legal obligation under Article 6(1)(c), a public-interest task under Article 6(1)(e), or legitimate interests under Article 6(1)(f) GDPR. Accordingly, the court held that the controller's processing infringed Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. Relying on CJEU C‑655/23, the court granted an injunction against future unlawful processing under German law. It also ordered restriction pending erasure under Article 18(1)(b) and erasure under Article 17(1)(d) GDPR. The court upheld the dismissal of the separate declaratory claim and also rejected anonymization of the website and app interaction data. Finally, relying on BGH VI ZR 10/24, the court awarded €1,500 in non-material damages under Article 82(1) GDPR for the data subject’s loss of control over his personal data.

### BVwG - W137 2327171-1

*Source: Federal Administrative Court, 2026-07-08 — https://overview.legal/posts/184712 — original: https://gdprhub.eu/index.php?title=BVwG_-_W137_2327171-1*

Facts — The controller, an assistant professor at a private university (the appellant), was engaged in an employment dispute with her university employer before a labour and social court. The data subject, a senior legal counsel employed by the university gave testimony as a witness in that employment proceeding. On 23 January 2025, the labour and social court ruled in the controller's favour, finding that her employment relationship continued beyond the university's purported termination date. The judgment referred to the data subject several times by her academic title and surname in connection with her witness testimony. In April 2025, the controller published the unredacted judgment in full, including the data subject's title and surname on social media. She shared a downloadable link (first via Dropbox, later via Adobe) on her public Facebook profile and in a closed Facebook group of around 230 members connected to the university community. The files were later removed by Dropbox and Adobe after the data subject reported them. The data subject's full first name and additional details could also be found by combining her academic title and surname with the university's name in a Google search, which surfaced her LinkedIn profile. The data subject filed a complaint with the Austrian DPA, arguing that the controller had no justification for naming her and had drawn her into a public dispute with her employer. The controller argued that the judgment concerned matters of wider relevance to university staff, that the Facebook group was closed and that the data subject's name and role were already public via the university directory and LinkedIn. On 15 October 2025, the DPA upheld the complaint, finding that the controller had violated the data subject's right to secrecy under §1(1) of the Austrian Data Protection Act (DSG) by publishing the judgment without a legal basis. The DPA found that a legitimate interest existed in principle, but that both publications were excessive as the judgment was made accessible to an uninvolved and disproportionately wide audience and that disclosing the data subject's name was not necessary to achieve the controller's stated purpose of informing colleagues in similar situations. The DPA noted that publishing the judgment with the data subject's name redacted would have been an equally effective, less intrusive alternative. The controller appealed, arguing that the data subject had no protectable secrecy interest because she had participated in the proceeding in a public professional capacity and had made comparable information about herself public on LinkedIn and that the DPA had failed to weigh her freedom of expression rights under Article 10 ECHR against the data subject's secrecy interest. Holding — The court dismissed the appeal in full and confirmed the DPA's decision. First, the court rejected the controller's argument that no protectable secrecy interest existed because the data subject had acted in a professional capacity. It held that, under settled national case-law, appearing in a professional role does not by itself remove a person's right to secrecy under §1(1) DSG. Second, applying the three-part test for legitimate interest under Article 6(1)(f) GDPR, the court accepted that the controller had, in principle, a legitimate interest in informing colleagues in comparable employment situations about the judgment. However, it held that publishing the data subject's surname failed the necessity requirement under this test and therefore also breached the data minimisation principle under Article 5(1)(c) GDPR. The court noted that the data subject was a witness testifying about legal matters, not the person responsible for the controller's employment contract and that naming her added nothing to the comprehensibility or persuasive value of the information the controller sought to share. Because necessity was lacking, the court found it unnecessary to conduct any further balancing of the parties' respective rights. Third, the court rejected the controller’s argument that her freedom of expression justified the full disclosure of the judgment, for which she relied on the CJEU’s judgment in Case C-345/17 (Buivids). The court held that Buivids concerned whether processing could be regarded as being carried out solely for journalistic purposes, whereas there was no indication of journalistic activity in the present case. It further held that §9 DSG, which implements Article 85 GDPR in relation to journalistic activity, was therefore inapplicable. In any event, the court stated that §9 DSG does not entirely override the principle of proportionality but establishes a different standard for balancing the competing interests. Finally, the court agreed with the DPA that redacting the data subject's name and title would have been an equally effective and only minimally burdensome alternative that would not have undermined the controller's informational purpose and held that the controller had not plausibly explained why such redaction would have been insufficient. The court accordingly found no unlawfulness in the DPA's decision and dismissed the appeal. It declared that an appeal on points of law (Revision) was not admissible, since the case did not raise a legal question of fundamental importance and was consistent with existing case-law.

### OLG Köln - 15 W 55/26

*Source: Higher Regional Court Cologne, 2026-06-12 — https://overview.legal/posts/53657 — original: https://gdprhub.eu/index.php?title=OLG_Köln_-_15_W_55/26*

Facts — The data subject, a doctor, sought an injunction against the Controller, the operator of an online review platform, requiring the removal of, and prohibiting the future publication of, a notice stating that between six and ten reviews concerning his medical practice had been removed during the previous year following complaints relating to defamation under German law. The Regional Court of Cologne dismissed the application, following which the data subject lodged an immediate appeal before the Higher Regional Court of Cologne. The data subject argued that the notice was inaccurate because the reviews had been challenged on the basis that no genuine patient relationship existed, rather than on the ground of defamation. He submitted that the notice therefore created the false impression that he had complained of defamatory reviews, rendering the processing of his personal data unlawful. The Controller argued that complaints alleging the absence of a genuine customer or patient relationship fell within its internal category of complaints concerning defamation under German law and that publishing the number of removed reviews promoted transparency regarding its review moderation process. Holding — The court held that where a data subject seeks not only the erasure of personal data but also an injunction preventing its future publication, Article 17(1) GDPR provides a basis for both forms of relief. It further held that the journalistic exemption under Article 85(2) GDPR did not apply because the Controller's review platform, including the automated notices relating to removed reviews, did not process data for journalistic purposes. The court also held that the displayed number of removed reviews constituted personal data within the meaning of Article 4(1) GDPR because it related to an identified natural person. By storing and disclosing that information, the Controller processed personal data within the meaning of Article 4(2) GDPR. In assessing the accuracy of the notice under Article 5(1)(d) GDPR, the court considered how an average user would understand the information. It held that a prominently linked information page entitled "Defamation under German law" explained that the platform categorised not only false or reputation-damaging reviews, but also complaints alleging that the reviewer was not a genuine customer, as complaints concerning defamation. As the data subject did not dispute that he had successfully requested the removal of between six and ten reviews on the basis that the reviewers had not been genuine patients, the court concluded that users could readily understand the platform's use of the term and that the notice was factually accurate. The court also rejected the data subject's reliance on the Festzins Plus judgment (BGH, judgment of 21 September 2017 – I ZR 53/16), distinguishing that case because the corrective information there appeared only at the end of a lengthy and unclear text, whereas the notice in the present case contained a clearly highlighted hyperlink directing users to explanatory information specifically addressing the platform's categorisation of review removals. The court held that the Controller had legitimate interests in promoting transparency regarding its handling of review-removal requests and that publication of the notice was necessary for that purpose. These interests outweighed the data subject's rights because the notice related only to his professional activity, was presented in a factual manner, contained no criticism of his behavior and was not prominently displayed, appearing only after users selected the "Reviews" tab. Accordingly, the court concluded that the processing was lawful under Article 6(1)(f) GDPR and that the data subject was not entitled to erasure or an injunction preventing the future publication of the notice under Article 17(1) GDPR.

### Judgment of the Court (First Chamber) of 7 December 2023.#UF and AB v Land Hessen.#Requests for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Principle of ‘lawfulness’ – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interests pursued by the controller or by

*Source: Court of Justice of the European Union, C-26/22, 2023-12-07 — https://overview.legal/posts/132278 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0026*

The Court of Justice of the European Union (First Chamber) ruled on preliminary references from the Verwaltungsgericht Wiesbaden in joined cases C-26/22 and C-64/22, concerning UF and AB's challenge to the Hessischer Beauftragter für Datenschutz und Informationsfreiheit's refusal to order SCHUFA Holding AG to delete data regarding the discharge of their remaining debts. The core issue was whether storage of such data by a credit information agency was lawful under GDPR Article 6(1)(f) and whether the supervisory authority's dismissal of the complaints satisfied Article 78's right to an effective judicial remedy. The Court held that the legitimate interests of credit agencies in assessing creditworthiness may justify retention of remaining-debt-discharge data, but the three-year storage period presumptively lawful under German law must be assessed against GDPR necessity and proportionality requirements, and that national courts must conduct full judicial review of supervisory authority decisions rather than limited deferential review. No fine was imposed.

### BVwG - W256 2227693-1

*Source: Federal Administrative Court, 2023-09-28 — https://overview.legal/posts/125664 — original: https://gdprhub.eu/index.php?title=BVwG_-_W256_2227693-1*

Facts — On 05.09.2019, the Austrian DPA (DSB) notified the controller of a customer loyalty program that they were initiating an ex officio investigation. The controller responded by answering the provided questionnaire and submitting further documents. On 23.10.2019, the DPA ruled that the investigation was justified and that the declaration of consent for profiling using certain registration methods (website, app, partner company store, flyer) did not comply with the requirements of Article 4(11) GDPR and Article 7 GDPR, nor were they provided in an intelligible way. If a contract covers several aspects, the declaration of consent must be clearly distinguishable. Regarding the website and flyer, the following was found: The website says 'Enjoy your personal benefits' without providing clear information that 'personal benefits' involves profiling. In an embedded box, the relevant points were merely referred to. Information regarding profiling was only accessible by scrolling down further. Concerning the flyer, the following information was provided under the signature field: 'This signature only applies to the declaration of consent and is voluntary. Your registration [...] is also valid without a signature.' Thus, it conveyed the impression that a signature was required to confirm the registration. Consequently, the controller was required to amend the declaration and to cease using any obtained consents for the purpose of profiling prior to 01.05.2020. The controller lodged a complaint. In addition to other information, the controller stated that the data processing was in accordance with Article 6(1)(a) GDPR, and that they had a legitimate interest under Article 6(1)(f) GDPR. The DPA ruled a preliminary decision on the complaint, thereby changing the ruling that the website and flyer did not meet the requirements under Article 6(1)(a) GDPR, and thus, the processing of personal data, collected in that cases, was forbidden. The other methods ensured that the consent was clearly separated from the rest of the registration process. The controller then filed a request for referral to the court, arguing that the DPA had exceeded their corrective powers by prohibiting the processing of the data. Furthermore, the data processing for profiling would be used to manage customer memberships under Article 6(1)(b) GDPR. Following their view, processing under Article 6(4) GDPR was applicable. Additionally, the controller denied the DPA's view that a violation of the principle of good faith would foreclose a weighing of interests under Article 6(1)(f) GDPR. The court quashed the preliminary decision as the DPA had not examined the other grounds of justification for data processing under Article 6(1) GDPR in their initial decision. The DPA then lodged an appeal to the Austrian Supreme Administrative Court (Verwaltungsgerichtshof), which overturned the court's ruling (VwGH 08.02.2022, Ro 2021/04/0033). It was the court's responsibility to examine the potential legal bases, rather than overturning the DPA's decision. Therefore, the case was returned to the court. In the meantime, the controller complied with the preliminary decision by deleting the affected personal data in 2021 and changing their registration process in 2020. Holding — First, the court found that they had to formally rule on whether the DPA's decision was lawful at the time it was ruled. It is not to be considered that the controller complied with the administrative decision and fulfilled the required steps (VwGH 28.04.2022, Ra 2022/06/0056). Second, the court held that the controller did not comply with the transparency requirements regarding the layout of their declaration of consent under Article 7(2) GDPR in both cases (website, flyer). Third, the court ruled that they could not agree with DPA's view, that an invalid declaration of consent always constitutes unlawful data processing and that a review of other grounds of justification would not be necessary (CLEU in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537). Further on, the Supreme Administrative Court ruled that both, the DPA and the court are required to examine the presence of other grounds (VwGH 08.02.2022, Ro 2021/04/0033). Fourth, the court held that the controller could not base their appeal on Article 6(4) GDPR as the data processing did not satisfy the grounds of justification, nor were other grounds apparent. Inter alia, following the CLEU's preliminary ruling in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537, three cumulative requirements must be met for data processing under Article 6(1)(f) GDPR: (1) The controller or a third party must have a legitimate interest, (2) which requires the processing of that personal data, (3) and 'the fundamental rights and freedoms of the data subject' must not outweigh those interests. There were no doubts about the controller's legitimate interest in processing the personal data in question for targeted marketing purposes, as this was both necessary and reasonable. However, the data subject should have been notified about profiling. The wording 'only if the member consents' did not constitute such a notification, and therefore the data subjects were not to be expected that their personal data was used for profiling purposes. Furthermore, the controller explicitly excluded it in their general terms and conditions. Hence, the data subject's right to secrecy overrode the controller's legitimate interest. In summary, the court dismissed the controller's complaint. Last, the court held that an appeal to the Supreme Administrative Court was admissible under Article 133(4) B-VG, as no prevailing case law concerning the implementation of a declaration of consent existed. Hence, the decision relied on a legal question of fundamental importance.

## Guidance

### Guidelines 3/2019 on processing of personal data through video devices

*Source: EDPB, edpb-guidelines-on-processing-of-personal-data-through-video-devices, 2020-01-30 — https://overview.legal/posts/38059 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-32019-on-processing-of-personal-data-through-video-devices_en*

The European Data Protection Board (EDPB) adopted Guidelines 3/2019 to provide comprehensive guidance on the processing of personal data through video devices,including CCTV and smart camera systems, under the GDPR. The guidelines address key issues such as the scope of application, the household exemption, lawfulness of processing under Article 6(1)(f) GDPR (legitimate interests), data subjects' rights, and obligations of controllers, while also clarifying the boundary with the Law Enforcement Directive (EU 2016/680). The guidelines were adopted on 29 January 2020 following public consultation and do not impose fines but serve as interpretative guidance for controllers and supervisory authorities.

### Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

*Source: EDPB, opinion-282024-on-certain-data-protection-aspects-related-to-en, 2024-12-18 — https://overview.legal/posts/125697 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en*

Adopted 1 Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models Adopted on 17 December 2024 Adopted 2 Executive summary AI technologies create many opportunities and benefits across a wide range of sectors and social activities. By protecting the fundamental right to data protection, GDPR supports these opportunities and promotes other EU fundamental rights, including the right to freedom of thought, expression and information,…

### Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-derogations-of-article-49, 2018-05-25 — https://overview.legal/posts/38057 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22018-on-derogations-of-article-49-under-regulation-2016679_en*

The European Data Protection Board (EDPB) issued Guidelines 2/2018 to provide interpretive guidance on the application of Article 49 derogations for international transfers of personal data under the GDPR. The guidelines emphasize that derogations under Article 49 are exceptions to the general rule requiring an adequacy decision or appropriate safeguards, and that controllers must first exhaust transfer mechanisms under Articles 45 and 46 before resorting to these derogations. The document details specific conditions and limitations for each derogation, including explicit consent, contractual necessity, public interest, vital interests, public registers, and compelling legitimate interests.

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom

*Source: EDPB, edpb-opinion-202527-united-kingdom-adequacy-led-en, 2025-10-16 — https://overview.legal/posts/51407 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-272025-regarding-the-european-commission-draft-implementing-decision_en*

Adopted 1 Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom Adopted 16 October 2025 Adopted 2 Executive summary The European Commission endorsed its draft implementing decision on the adequate protection of personal data by the United Kingdom pursuant to the Law Enforcement Directive on 22 July 2025. On the same date, as part of the procedure towards the formal…

### Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation

*Source: EDPB, joint-guidelines-interplay-between-digital-en, 2025-10-13 — https://overview.legal/posts/51268 — original: https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2025/joint-guidelines-interplay-between-digital_en*

Executive summary The Digital Markets Act (DMA) and the General Data Protection Regulation (GDPR) pursue different purposes and objectives and have different scopes. While the GDPR aims to protect natural persons with regard to the processing of personal data and ensure the free flow of personal data in the U nion covering all data controllers and processors, the DMA aims to tackle unfair prac tices, and their potential harmful effects for business users, by laying down harmonised rules…

### Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms

*Source: EDPB, opinion-082024-on-valid-consent-in-the-context-of-consent-or-en, 2024-04-17 — https://overview.legal/posts/125765 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-082024-on-valid-consent-in-the-context-of-consent-or_en*

A dopted 1 Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms Adopted on 17 April 2024 Adopted 2 Adopted 3 Executive summary The Dutch, Norwegian and German (Hamburg) supervisory authorities requested the EDPB to issue an opinion on the question of under which circumstances and conditions ’consent or pay’ models relating to behavioural advertising can be implemented by large online platforms in a way that constitutes valid, and in…

### Recommendations 02/2021 on the legal basis for the storage of credit card data for the sole purpose of facilitating further online transactions

*Source: EDPB, recommendations-022021-on-the-legal-basis-for-the-storage-of-credit-card-en, 2021-05-19 — https://overview.legal/posts/126030 — original: https://www.edpb.europa.eu/documents/recommendation/recommendations-022021-on-the-legal-basis-for-the-storage-of-credit-card_en*

adopted 1 Recommendations 02/2021 on the legal basis for the storage of credit card data for the sole purpose of facilitating further online transactions Adopted on 19 May 2021 adopted 2 The European Data Protection Board Having regard to Article 70(1)(e) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the fre e movement of such data, and repealing Directive…

## Enforcement decisions

### Austrian DSB: Marketing agency violated GDPR by recording phone interviews without valid

*Source: DSB (Austria), 2026-01-19 — https://overview.legal/posts/184689 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-1.049.138*

Facts — The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted and interviewed by telephone. A former employee of the controller was examined as a witness by the Austrian DPA (DSB) and provided evidence concerning the recordings. The telephone interviews generally followed a particular pattern. The employees contacted data subjects in the name of the relevant client, stated that their application appeared interesting, presented the position, asked about their qualifications and professional experience and, where appropriate, arranged an in-person interview. The calls were recorded from beginning to end and stored for an indefinite period. In some cases, data subjects were not informed that the call was being recorded. In other cases, the employee asked during the call whether recording would be acceptable. In one such call, the data subject responded, “Uh, yeah.” Moreover, a superior employee had encouraged other employees through an intranet message to record and store interviews for training purposes, including without obtaining the data subject's consent. The controller argued that it had been unaware of the recording practice. It submitted that the employee who had instructed the others to make the recordings was neither a managing director nor an authorised signatory and had no authority to issue such instructions. According to the controller, the statement that interviews could be recorded “even without consent” resulted from personal overzealousness and legal recklessness and did not reflect the controller’s internal procedures. As legal bases for the processing, the controller stated that it relied on consent under Article 6(1)(a) GDPR and legitimate interests under Article 6(1)(f) GDPR. It claimed that data subjects had been expressly asked for consent at the beginning of the application process and that the recordings served the legitimate interest of improving employee performance. Holding — The DPA relied on the CJEU’s judgment in Case C-807/21 (Deutsche Wohnen) and held that a legal entity may be liable not only for infringements committed by its representatives, managers or executives, but also for infringements committed by any person acting within the scope of its business activities and on its behalf. It acknowledged that an exception may apply where an employee acts outside that framework and exclusively for personal purposes. The DPA determined that the supervising employee had ordered the processing within the scope of their employment relationship and in the controller’s interest. It pointed out that the controller could therefore not avoid responsibility by claiming that it had been unaware of the practice or that the employee lacked formal authority to issue instructions. The DPA held that no consent had been obtained in some cases and that, where consent had been sought, it was neither timely nor valid. It stated that consent must be obtained before processing begins. However, it noted that the recordings had already been activated before the calls began, due to the fact that the recordings included the opening greetings. It held that asking for consent during the recorded call was too late. The DPA further held that one data subject’s response, “Uh, yeah,” did not constitute an unambiguous affirmative act. It also considered that a job interview, similarly to an existing employment relationship, is characterised by a structural imbalance of power. Moreover, it emphasised that the data subjects had not been informed of the true identity of the controller, because its employees presented themselves as acting for the client companies. It concluded that the data subject could therefore not have given valid consent and that processing could not be based on Article 6(1)(a) GDPR. Furthermore, the DPA examined whether the recordings could be justified by legitimate interests. It underlined that a controller relying on Article 6(1)(f) GDPR must comply with the corresponding transparency obligations. Specifically, pursuant to Article 13(1)(d) GDPR, the legitimate interests pursued must be communicated when the personal data is collected. Referring to Case C-394/23 (Mousse) the DPA held that the collection could not be based on Article 6(1)(f) GDPR where that information had not been provided in time. It found that the data subjects had either not been informed at all of the legitimate interest pursued or had been informed only after the collection of their personal data had begun. It held accordingly that the processing could not be based on Article 6(1)(f) GDPR. The DPA concluded that the recording and storage of the interviews lacked a legal basis and infringed Article 6(1) GDPR in conjunction with Article 5(1)(a) GDPR. In addition, the DPA held that the recordings were not necessary for the training purpose as less intrusive alternatives, such as simulated interviews between employees, could have achieved the same objective. It therefore found a violation of the principle of data minimisation under Article 5(1)(c) GDPR. It further found that the indefinite retention of the recordings was also unnecessary and violated the principle of storage limitation under Article 5(1)(e) GDPR. The DPA also found that the controller had failed to comply with its transparency obligations. In some cases, data subjects received no information about the processing. In others, information was provided only after the processing had begun. The data subjects were also not informed of the identity of the actual controller, because the employees presented themselves as representatives of the client companies. It therefore found an infringement of Article 5(1)(a) GDPR in conjunction with Article 12 GDPR and Article 13 GDPR. The DPA found that the controller had acted at least negligently. It imposed a fine of €25,500 for the infringements.

### AEPD sanctions Tiger Media Inc. for installing advertising cookies without user consent

*Source: AEPD (Spain), 2025-11-14 — https://overview.legal/posts/158452 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00480-2025*

Facts — Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting publishers offering advertising space with advertisers seeking to display ads on those websites. Through this platform, the controller processed personal data of users visiting publishers’ websites where its ads were displayed. This included IP addresses, device and browser information, website URLs, referral URLs, clicks, impressions and cookie identifiers. According to the controller, the data were processed for ad delivery, fraud prevention, frequency capping, performance measurement and service improvement. The controller argued that it did not carry out behavioural advertising or profiling. It claimed that any targeting was limited to contextual factors, such as country and language. The controller relied mainly on legitimate interest as a legal basis and argued that publishers, as independent controllers of their own websites, were responsible for obtaining any consent required for cookies. The DPA investigated the controller’s platform and several Spanish websites using it. It found that cookies linked to the controller’s platform were installed on users’ devices without prior consent. These cookies were used for advertising-related purposes, including measuring ad performance, improving ad relevance, limiting frequency and detecting fraud. The AEPD also noted that the controller was not established in the EU. Although the controller stated that it had appointed a representative in Northern Ireland and was in the process of changing representative, the DPA considered that it did not have a valid representative established in the Union. Holding — The AEPD held that the controller violated Article 6 GDPR by processing personal data without a valid legal basis. The DPA emphasised that the LSSI, the Spanish law implementing the ePrivacy Directive require prior consent for storing or accessing information on a user’s device through cookies, unless an exemption applies. The DPA distinguished between the placement or reading of cookies, which is governed by the cookie rules, and the subsequent processing of personal data obtained through those cookies, which must comply with the GDPR. Since the cookies were installed without consent, the subsequent processing of the data collected through them could not be considered lawful. The AEPD rejected the controller’s reliance on legitimate interest under Article 6(1)(f) GDPR. It found that users had not received clear information and had not consented to the use of cookies. Moreover, users of the affected websites did not have a reasonable expectation that their browsing-related data would be processed by a third-party advertising network for advertising purposes. Therefore, the processing did not pass the balancing test required under Article 6(1)(f) GDPR. The DPA also held that the controller violated Article 27 GDPR. Since the controller was not established in the EU but processed personal data of users in Spain in connection with its advertising services, it was required to appoint a representative established in an EU Member State. A representative in Northern Ireland did not meet this requirement. The AEPD fined the controller €120,000 in total: €70,000 for the violation of Article 6 GDPR and €50,000 for the violation of Article 27 GDPR. Pursuant to Article 85 of the Spanish administrative Law 39/2015, the notice of initiation informed the controller of the possibility of acknowledging liability and making a voluntary payment of the proposed penalty, which would entail two cumulative reductions of 20% each. With the application of these two reductions, the final penalty was set at €72,000, and its payment resulted in the termination of the proceedings. The AEPD also ordered the controller to adopt corrective measures within three months. In particular, the controller had to ensure compliance with Article 6 GDPR, ensure compliance with the Spanish cookie rules by the service providers using its cookies, appoint an EU representative and notify the AEPD of the measures adopted.

### LfD (Lower Saxony) - Fine EUR 900,000 against bank

*Source: LfD (Lower Saxony), 2022-09-28 — https://overview.legal/posts/6319 — original: https://gdprhub.eu/index.php?title=LfD_(Lower_Saxony)_-_Fine_EUR_900,000_against_bank*

Facts — A commercial bank (controller) used personal data of current and former customers (data subjects) to identify customers with an affinity for digital media usage, in order to address them more intensely through electronic communication channels for further commercial communication (advertisement). A service provider analyzed digital usage behavior on behalf of the controller, including the total amount of app-store purchases, the usage frequency of bank statement printers as well as the total amount of transfers in online banking system (in comparison to the offline usage in their local branch offices). The results were compared and further enriched with data from a commercial credit reporting agency. Most customers were informed in advance, but no consent under Article 6(1)(a) GDPR was obtained. The controller based the data analysis, data enrichment and the subsequent creation of customer profiles on legitimate interest as per Article 6(1)(f) GDPR. Holding — The DPA found that the analysis of large amounts of data to create customer profiles could not be based on Article 6(1)(f). It followed that processing based on a legitimate interest requires a balancing act between the interest of the controller and the fundamental rights and freedoms if the data subject. The controller had to consider the reasonable expectations of the data subjects. The DPA argued that a data subject could not reasonably expect large amounts of its personal data to be analyzed by the controller to better target its advertising. Third-party data enrichment, like the use of commercial credit reporting agency data, further overrides the interest of the controller and tips the balancing test in favor of the data subject. The DPA held that in addition, data enrichment from a third-party source and linking it to profiles could also not be based on legitimate interest. This could potentially link data from all areas of life to an accurate customer profile, which could also not be reasonably expected by a customer. Customer consent (see Article 6(1)(a)) is required. The controller cooperated with the DPA throughout the process. For the violation, the DPA fined the controller €900,000.

### DSB (Austria) - 2021-0.698.184

*Source: DSB (Austria), 2021-10-08 — https://overview.legal/posts/262252 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2021-0.698.184*

Facts — The data subject was a shareholder and managing director of two companies. The controller operated a free online search platform that allowed users to look up companies registered in the Austrian companies register and see, for a given company, which natural persons held positions such as shareholder or managing director, as well as an overlay showing what other companies those persons were connected to. The controller obtained the underlying data from a commercial information provider, which in turn sourced it from the Federal Ministry of Justice under a data-reuse agreement covering companies register documents. The controller funded the free service through advertising displayed on the platform. The data subject had no contractual relationship with the controller. A direct name search for the data subject on the controller's platform returned no results, however, searching for a company in which he held a position returned his name together with his role (managing director, sole shareholder with a 100% stake) and through an „i“ icon, an overlay listing his positions in other companies. The data subject complained to the Austrian DPA, arguing that the controller published his name without any contract between them and without any identifiable legitimate interest justifying the publication. The controller argued that its processing pursued a legitimate commercial interest, enabling business participants to research potential contractual partners and pointed out that companies register data was already public and accessible to anyone under national law, including via other commercial and official information services. Holding — First, the DPA rejected the controller's argument that the data was already available and therefore outside the scope of a secrecy interest altogether. It held, citing CJEU case-law C-73/07, that a blanket assumption that lawfully published data cannot be subject to a legitimate secrecy interest is incompatible with EU law requirements. Second, the DPA held that the controller's processing constituted a new form of data use requiring independent justification, because the controller did not merely reproduce publicly accessible companies register data, but recombined and cross-linked it, thereby creating additional informational value beyond what a simple companies register search would reveal. Third, applying the balancing test under Article 6(1)(f) GDPR and Section 1(2) DSG, the DPA found that the controller had a legitimate interest in operating its platform, both a commercial interest of its own (generating advertising revenue) and a legitimate interest of platform users and market participants generally in being able to assess a business partner's other company affiliations. The DPA weighed this against the data subject's interest in secrecy and concluded that the balance favoured the controller, for three reasons: 1. the underlying data's general availability in the companies register reduced (though did not eliminate) its protection-worthiness 2. the data related exclusively to the data subject's professional sphere as someone who had voluntarily chosen to participate in commercial life as a shareholder and managing director 3. the resulting interference with his data protection rights was accordingly of low intensity. The DPA therefore rejected the complaint as unfounded.

### Belgian DPA: Political campaign email without consent violates GDPR and ePrivacy

*Source: APD/GBA (Belgium), 2024-05-16 — https://overview.legal/posts/158448 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_74/2024*

Facts — On 30 January 2024, the data subject received an email from a candidate in the June 2024 regional elections (‘controller’), promoting their programme. On 3 January 2024, the data subject responded to the email indicating that Belgian law prohibits political spamming practices. He also indicated that he no longer wished for the controller to use his data, and made an access request, in particular to understand where the controller collected his personal data. On 5 February 2024, the controller responded to the access request by explaining that the data subject’s personal data was probably already in his address book, although it was possible that friends had given it to him. On 5 April 2024, the data subject lodged a complaint with the Belgian DPA (‘APD’). Holding — First, regarding the use of the data subject’s email address for electoral propaganda purposes, Article 6(1)(a) GDPR establishes that the processing of personal data is lawful if the data subject has consented to the processing. Article 13(1) ePrivacy directive states that the use of an email for the purposes of direct marketing may be authorised only if the targeted subscribers have given consent. Furthermore, the APD published a note on the processing of personal data in the context of elections in which it established that the targeting people with political propaganda on the basis of voters’ personal data must be considered direct marketing within the meaning of the GDPR and ePrivacy Directive. In the present case, the APD noted that the data subject did not give consent to the processing of his email address for direct marketing purposes. Therefore, the DPA held that the controller may have breached Article 6(1)(a) GDPR as well as Article 13(1) ePrivacy directive. The DPA examined the possibility of invoking legitimate interest under Article 6(1)(f) GDPR as a legal basis. This article establishes that the processing of personal data is lawful if it is necessary for the purposes of the legitimate interests pursued by the controller, unless the interests or fundamental rights and freedoms of the data subject prevail. Recital 47 GDPR states that the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest. In CJEU, 4 May 2017, Rigas, C-13/16, the Court of Justice held that Article 6(1)(f) GDPR lays down three cumulative conditions. (i) the pursuit of a legitimate interest by the controller, (ii) the necessity of the processing in order to achieve the legitimate interest pursued and (iii) the fundamental rights and freedoms of the data subject must not prevail. Regarding the pursuit of a legitimate interest, Belgian law provides that candidates in elections may promote their programme through communications. Moreover, the APD described the controller’s interest as ‘sending direct marketing communications to promote the electoral programme for the regional elections in June 2024’. Thus, the controller’s interest is sufficiently specific that it represents a real and present interest. The APD considered that the controller is pursuing a legitimate interest. Regarding the necessity of the processing in order to achieve the legitimate interest, the APD took into account the existence of less intrusive means to attain the objective. The DPA considered that an election programme can be promoted by means of flyers placed in people’s mailboxes for example, which is far less intrusive, even if It may require some extra effort. Therefore, the APD held that the direct marketing was not strictly necessary to the legitimate interest pursued, namely the promotion of its electoral programme. Thus, the APD concluded that the controller may have committed a potential breach of Article 6 GDPR. Second, regarding the access request in order to discover the source of the data used, the APD considered that the controller sent vague and imprecise information about the source of the data subject’s personal data. Therefore, the APD concluded that there may have been a breach of Articles 5(1)(a) and 12(1) GDPR. Hence, the APD issued a prima facie warning to the controller.

### NAIH fines online store HUF 2M for unclear and incomplete privacy notice

*Source: NAIH (Hungary), 2026-07-22 — https://overview.legal/posts/156361 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-11443-3/2026*

Facts — The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The processing activities in question included, inter alia, cookies, registration, billing, shipping, consumer complaint, and processing of orders. The privacy notice of the company operating the online store had been in force unchanged from May 2018 to May 2025, and the period under investigation extended from 1 January 2020 to 27 June 2025. Holding — The DPA held that the controller had violated Articles 12(1), 13(1)(c), (d) and (f), and 13(2)(a) GDPR and issued the controller a fine of HUF 2,000,000 (€5,500). In addition, the DPA ordered the controller to bring its data processing operations into compliance with the GDPR and to amend the content of its privacy notice. First, the DPA found an infringement of Article 12(1) GDPR: the structure of the privacy notice was confusing and difficult to follow. The privacy notice also contained incomplete, incorrect, and unnecessary information as well as repetitive details. Based on this, the DPA concluded that the controller had failed to provide data subjects with information regarding the processing of personal data that was sufficiently concise, transparent, intelligible and easily accessible. Second, the DPA held that the controller had also violated Articles 13(1)(c), (d) and (f) GDPR by failing to specify a legal basis for certain processing operations such as the use of cookies, not specifying its legitimate interests when relying on Article 6(1)(f) GDPR as a legal basis, and not providing detailed information regarding the safeguards ensuring the lawfulness of data transfers to the United States. Finally, the DPA found a violation of Article 13(2)(a) GDPR as the controller had also failed to provide the data subjects information on the period for which the personal data processed would be stored.

### APD/GBA (Belgium) - 113/2024

*Source: APD/GBA (Belgium), 2024-09-06 — https://overview.legal/posts/122855 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_113/2024*

Facts — A data subject visited four website operated by MediaHuis, namely: Gazet van Antwerpen; De Standaard; Het Nieuwsblad; Het Belang van Limburg. On each website there was a cookie banner which: Didn’t contain a reject button within its first layer;Buttons colours were misleading; It was not as easy to withdraw consent as it was to give it; Contained a reference to the legal basis of legitimate interest. The data subject filed four complaints referring to abovementioned cookie banners with the Belgian DPA (ADP/GBA). noyb was appointed by the data subject as their representative under Article 80(1) GDPR. MediaHuis was assigned the role of data controller. According to the controller, the law, especially Article 7(3) GDPR or Article 4(11) GDPR, didn’t prescribe the controller to implement reject button within the first layer of the cookie banner or to use different colours for the buttons or to implement consent withdrawal option in a particular way. The fact that the cookie banners were not in line with the guidelines of different data protection authorities and the EDPB, as mentioned by the data subject, did not amount to violation of the GDPR. Moreover, the data subject gave their consent for processing activities of the controller and, for that reason, they had no interest to bring a case before the DPA. Holding — The DPA found the controller violated the Article 5(1)(a) GDPR, Article 6(1)(a) GDPR, Article 7(3) GDPR. Firstly, the DPA clarified that for the consent to be freely and unambiguously given under Article 6(1)(a) GDPR and Article 5(3) ePrivacy Directive, the reject button had to be presented alongside the accept button. Otherwise, the data subject would have no real alternative to consenting for placing and processing cookies. Secondly, the buttons’ colours used by the controller were of deceptive nature. They inclined a data subject to give a consent for the cookies processing. Because of that, the controller was in breach of Article 5(1)(a) GDPR. Since the cookie banner was lacking of the reject button within its first layer, and the colours used were misleading, the DPA order the controller to bring the cookie banner into compliance with the GDPR within 45 days. The order was combined with a penalty of €25,000 per day and per each website concerned, due if the controller fails to implement the ordered changes. The maximum amount of total penalty was set on €10,000,000. Thirdly, the controller violated Article 7(3) GDPR. To withdraw the consent given, a data subject had to perform more actions - “click more” – whilst to give a consent only one click sufficed. Nevertheless, the controller updated their websites by adding the reject button to the first layer of cookie banner and the option to withdraw the consent, using the manage link at the bottom of each website. The violation was remedied, accordingly the DPA reprimanded the controller. Fourthly, the legitimate interest called upon by the controller covered placing and processing of the cookies, which were not “strictly necessary”. The controller’s cookies were of different kind, including the analytical cookies. Especially for the latter, the application of Article 6(1)(f) GDPR is per se excluded and the consent needed to be obtained. Furthermore, by adding the legitimate interest to be a “back-up” legal basis for the cookies related processing, the controller mislead the data subject. The controller violated then Article 6(1)(a) GDPR. Nonetheless, the DPA reprimanded the controller that the legal basis for placing and processing of analytical cookies and other cookies that were not “strictly necessary cookies only was a consent under Article 6(1)(a) GDPR. In answer to the controller’s claims, the DPA emphasised that: the fact that the data subject gave a consent didn’t deprive them from starting the case before the DPA; the guidelines of the EDPB were not legally binding, as pointed by the controller, but they played important role regarding the interpretation of the GDPR. In addition, the DPA excluded alleged pressure put on the data subject by noyb to initiate the proceedings. The controller argued the relationship between the data subject, being a trainee at noyb, was instructed to lodge the complaints with the DPA. Hence there was no legal interest of the data subject in the case at hand. However, for the DPA statements of that kind were unfounded, bearing in mind the facts of the case. In particular, the outcome of the data subject’s hearing before the DPA that proved the data subject’s interest being involved.

### Garante per la protezione dei dati personali (Italy) - 9788429

*Source: Garante per la protezione dei dati personali (Italy), 2022-07-07 — https://overview.legal/posts/122853 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9788429*

Facts — Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June 2022, the controller announced that a new privacy policy would come into effect on 13 July 2022. Under the new policy, the controller would only serve personalize advertising to users over 18 years of age and on the legal basis of the legitimate interest of the controller (Article 6(1)(f) GDPR). The Italian DPA started an investigation and found that personalized advertisement would likely involve the use of cookies or other tracking mechanisms. Holding — Regarding the competence of the Italian DPA, it should be noted that the Irish DPA is the lead supervisory authority for the controller’s data processing activities under the GDPR's "one-stop-shop" mechanism. The Italian DPA acknowledged the Irish DPA’s position in its decision. However, the Italian DPA held the ePrivacy Directive to be applicable to the processing of cookies by the controller and held itself competent to enforce the Directive. The DPA referenced Recital 173 GDPR and EDPB Opinion 05/2020 on this point. The DPA held that the controller’s new privacy policy violated Article 5(3) ePrivacy Directive 2002/58/EC. The Article only allows the controller to process cookies and use similar tracking mechanisms with the user’s consent . For this reason, legitimate interest under Article 6(1)(f) GDPR is not a valid legal basis for the processing of cookies. The Italian DPA also held that the controller violated Article 122 of the Italian Privacy Code (d. lgs. 30 giugno 2003, n. 196). Article 122 is a direct transposition of Article 5(3) ePrivacy Directive. The violation of the Code constitutes a direct consequence of the violation of the Directive. The DPA issued a warning against the controller.

## Recent developments

### VG Berlin - 42 K 51.25

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291291 — original: https://gdprhub.eu/index.php?title=VG_Berlin_-_42_K_51.25*

English Summary The data subject appealed the DPA decision in April 2025. He argued that there was no particular threat that would justify the installation of a video surveillance system. According to the data subject, an on-site investigation carried out by the Berlin police supported this view.The data subject appealed the DPA decision in April 2025. He argued that there was no particular threat that would justify the installation of a video surveillance system. According to the data subject,

### noyb survey: only 7% of users want Meta to use their personal data for AI

*Source: noyb - European Center for Digital Rights, 2025-08-07 — https://overview.legal/posts/53144 — original: https://noyb.eu/en/noyb-survey-only-7-users-want-meta-use-their-personal-data-ai*

Artificial Intelligence Meta has recently started using the personal data of Europeans for AI training. Contrary to its GDPR obligations, Meta hasn’t asked for consent in advance. Instead, the company claims to have a ‘legitimate interest’ outweighing the fundamental right to privacy. A key argument in favour of such a ‘legitimate interest’ is the reasonable expectations of users. This begs the question: do people want this to happen? To find out more, noyb has commissioned the Gallup Institute

### Bumble's AI icebreakers are mainly breaking EU law

*Source: noyb - European Center for Digital Rights, 2025-06-26 — https://overview.legal/posts/53148 — original: https://noyb.eu/en/bumbles-ai-icebreakers-are-mainly-breaking-eu-law*

Artificial Intelligence In December 2023, the dating platform Bumble introduced so-called AI Icebreakers to the “Bumble for Friends” section of the app. Powered by OpenAI’s ChatGPT, the feature is designed to help you start a conversation by providing an AI-generated message. In order to do this, your personal profile information is fed into the AI system without Bumble ever obtaining your consent. Although the company repeatedly shows you a banner designed to nudge you into clicking “Okay”, whi

### noyb sends Meta 'cease and desist' letter over AI training. European Class Action as potential next step

*Source: noyb - European Center for Digital Rights, 2025-05-14 — https://overview.legal/posts/53154 — original: https://noyb.eu/en/noyb-sends-meta-cease-and-desist-letter-over-ai-training-european-class-action-potential-next-step*

Forced Consent & Consent Bypass Meta has announced it will use EU personal data from Instagram and Facebook users to train its new AI systems from 27 May onwards. Instead of asking consumers for opt-in consent, Meta relies on an alleged 'legitimate interest' to just suck up all user data. The new EU Collective Redress Directive allows Qualified Entities such as noyb to issue EU-wide injunctions. As a first step, noyb has now sent a formal settlement proposal in the form of a so-called Cease and

### Verbraucherzentrale NRW requests Meta to cease and desist AI training in the EU

*Source: noyb - European Center for Digital Rights, 2025-05-06 — https://overview.legal/posts/53155 — original: https://noyb.eu/en/verbraucherzentrale-nrw-requests-meta-cease-and-desist-ai-training-eu*

Forced Consent & Consent Bypass On 14 April, Meta announced that it would use the personal data of European users for artificial intelligence (AI) training in the future. Starting on 27 May, the company will use all posts published on Instagram and Facebook for AI training. The company falsely claims to have a legitimate interest in this extensive data use – even though it should actually ask those affected for their consent. noyb filed a series of GDPR complaints against Meta's plans in 2024, p

## Literature

### Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU

*Source: Unio - EU Law Journal, 2025-06-18 — https://overview.legal/posts/53865 — original: https://doi.org/10.21814/unio.11.1.6632*

The Mousse ruling represents a pivotal moment in EU data protection law, reinforcing strict limitations on personal data processing and clarifying the legal standards under the General Data Protection Regulation (GDPR). The Court of Justice of the European Union (CJEU) reaffirmed that data collection must be objectively indispensable for a specified legal basis, rejecting broad interpretations of contractual necessity and legitimate interest. Additionally, the ruling confirms that the right to o

### Submission to the European Data Protection Board's Public Consultation on the 2024/01 guidelines on legitimate interest under the GDPR

*Source: SSRN Electronic Journal, 2025-01-01 — https://overview.legal/posts/132585 — original: https://doi.org/10.2139/ssrn.5029217*

### Commercial, but Legitimate Interest: The Court of Justice Calls the Dutch Data Protection Authority to Order

*Source: European Data Protection Law Review, 2025-01-01 — https://overview.legal/posts/132586 — original: https://doi.org/10.21552/edpl/2025/1/19*

### GDPR Glasnost: Spain’s AEPD raises the transparency bar and sanctions two banks

*Source: Journal of Data Protection Privacy, 2021-12-01 — https://overview.legal/posts/132536 — original: https://doi.org/10.69554/roid7095*

This paper is a commentary on two recent decisions issued by the Spanish data protection authority (DPA): the AEPD (Agencia Española de Protección de Datos). Both decisions — issued one month apart — developed similar motives and grievances primarily arising from the alleged lack of clarity in the two banks’ privacy notifications to their clients as well as in the consent-collection process and in the formulation of their legitimate interest in processing personal data. These two decisions combi

### Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – VI: Legitimate Interests

*Source: SSRN Electronic Journal, 2019-01-01 — https://overview.legal/posts/132470 — original: https://doi.org/10.2139/ssrn.3743576*

## Tools

### ICO lawful basis interactive guidance tool

*Source: ICO, 2026-07-17 — https://overview.legal/posts/125618 — original: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/lawful-basis-interactive-guidance-tool/*

Interactive questionnaire by the UK regulator that helps controllers identify the most appropriate lawful basis under Article 6 (and conditions under Articles 9–10) for a given processing operation, with tailored guidance for the outcome.

### GDPR.eu compliance checklist

*Source: GDPR.eu (Proton), 2026-07-17 — https://overview.legal/posts/125625 — original: https://gdpr.eu/checklist/*

Widely used plain-language GDPR compliance checklist covering lawful basis, data inventory, accountability documents, data subject rights, security and transfer requirements. Published by Proton as part of the GDPR.eu resource site (an unofficial but well-maintained companion to the Regulation).

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/gerechtvaardigd-belang · 2026-08-22
