# Health Data — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/health-data
> Sources are cited per item. Verify against the official texts before relying on them.

Processing of health and medical data

## Overview

## Legal Framework

Article 9 GDPR establishes the general prohibition on processing special categories of personal data, including health data, which encompasses physical and mental health status, medical history, and treatment records. This prohibition reflects the heightened risk that misuse of health data poses to fundamental rights, particularly the right to privacy under Article 8 ECHR, which the Court has confirmed extends to the secrecy of one's medical condition.

The prohibition is not absolute. Article 9(2) GDPR enumerates ten exceptions, with consent under Article 9(2)(a) and public interest in public health under Article 9(2)(i) being the most relevant for health data processing. Recital 53 clarifies that special categories may be processed for health purposes where necessary to serve the interests of individuals and society as a whole, particularly in managing healthcare systems and social services. Recital 54 reinforces that public health grounds may justify processing without consent, provided appropriate and specific safeguards protect individuals' rights and freedoms.

Member states may also create national-law exceptions under Article 9(2) for reasons of substantial public interest, subject to the adoption of suitable protective measures. National implementing legislation, such as the Dutch UAVG Article 23, operationalizes these exceptions for compliance with international obligations and other public interest grounds.

Article 24 GDPR imposes accountability obligations on controllers, requiring them to implement data protection policies and demonstrate compliance with the processing principles. Controllers bear direct responsibility for adherence, including when engaging processors under Article 28. Approved codes of conduct under Article 40 and certification mechanisms under Article 42 serve as admissible evidence of compliance.

## Key Developments

In *V & EDPS v. European Parliament*, the Court confirmed that medical data processing is prohibited in principle, with exceptions narrowly construed. The transfer of medical data to a third party constitutes interference with the right to private life regardless of the recipient's intended use, and absent the data subject's consent, such transfer requires a specific legal basis.

In *Dennekamp v. European Parliament*, the Court established that access-to-information rights and data protection rights carry equal weight, requiring full application of both regimes without automatic primacy for either.

The Dutch DPA has actively enforced health data rules, imposing fines of €25,000 on multiple municipalities including Ede and Eindhoven for unlawful processing of personal data in the context of government services. The Rotterdam District Court's rulings in the childcare benefits affair illustrate how medical and psychiatric data may be ordered disclosed in judicial proceedings, but only through structured expert examination with clearly defined questions.

## Practical Guidance

- **Establish a specific Article 9(2) legal basis before any health data processing.** Rely on consent only where it is genuinely freely given, as the *V v. European Parliament* ruling confirms that absence of consent renders processing unlawful absent an alternative ground.

- **Implement appropriate and specific safeguards as required by Article 9(1) and Recital 54.** These must be proportionate to the sensitivity of health data and the processing context, including pseudonymization, access controls, and encryption.

- **Document accountability measures under Article 24 GDPR.** Maintain internal policies, conduct DPIAs for high-risk health data processing, and ensure processor agreements under Article 28 impose equivalent obligations.

- **Treat any transfer of medical data to third parties as a separate processing operation requiring its own legal basis.** The *V v. European Parliament* judgment makes clear that onward transfer constitutes distinct interference with fundamental rights.

- **Monitor national implementing legislation for sector-specific health data rules.** Member states may impose additional conditions or exceptions beyond the GDPR baseline, as reflected in Dutch legislative amendments to healthcare data processing provisions.

## Legislation (full text of key provisions)

### Recital 53 — special health data processing conditions

*Source: GDPR, gdpr-rec-53-en, 2016-04-27 — https://overview.legal/posts/91621*

Special categories of personal data which merit higher protection should be processed for health-related purposes only where necessary to achieve those purposes for the benefit of natural persons and society as a whole, in particular in the context of the management of health or social care services and systems, including processing by the management and central national health authorities of such data for the purpose of quality control, management information and the general national and local supervision of the health or social care system, and ensuring continuity of health or social care and cross-border healthcare or health security, monitoring and alert purposes, or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, based on Union or Member State law which has to meet an objective of public interest, as well as for studies conducted in the public interest in the area of public health. Therefore, this Regulation should provide for harmonised conditions for the processing of special categories of personal data concerning health, in respect of specific needs, in particular where the processing of such data is carried out for certain health-related purposes by persons subject to a legal obligation of professional secrecy. Union or Member State law should provide for specific and suitable measures so as to protect the fundamental rights and the personal data of natural persons. Member States should be allowed to maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health. However, this should not hamper the free flow of personal data within the Union when those conditions apply to cross-border processing of such data.

### Recital 54 — public interest health data processing safeguards

*Source: GDPR, gdpr-rec-54-en, 2016-04-27 — https://overview.legal/posts/91623*

The processing of special categories of personal data may be necessary for reasons of public interest in the areas of public health without consent of the data subject. Such processing should be subject to suitable and specific measures so as to protect the rights and freedoms of natural persons. In that context, ‘public health’ should be interpreted as defined in Regulation (EC) No 1338/2008 of the European Parliament and of the Council (11), namely all elements related to health, namely health status, including morbidity and disability, the determinants having an effect on that health status, health care needs, resources allocated to health care, the provision of, and universal access to, health care as well as health care expenditure and financing, and the causes of mortality. Such processing of data concerning health for reasons of public interest should not result in personal data being processed for other purposes by third parties such as employers or insurance and banking companies.

### Recital 68 — data access for high-risk AI development

*Source: AI Act, aiact-rec-68-en, 2024-06-12 — https://overview.legal/posts/93818*

For the development and assessment of high-risk AI systems, certain actors, such as providers, notified bodies and other relevant entities, such as European Digital Innovation Hubs, testing experimentation facilities and researchers, should be able to access and use high-quality data sets within the fields of activities of those actors which are related to this Regulation. European common data spaces established by the Commission and the facilitation of data sharing between businesses and with government in the public interest will be instrumental to provide trustful, accountable and non-discriminatory access to high-quality data for the training, validation and testing of AI systems. For example, in health, the European health data space will facilitate non-discriminatory access to health data and the training of AI algorithms on those data sets, in a privacy-preserving, secure, timely, transparent and trustworthy manner, and with an appropriate institutional governance. Relevant competent authorities, including sectoral ones, providing or supporting the access to data may also support the provision of high-quality data for the training, validation and testing of AI systems.

### Recital 63 — data subject right of access

*Source: GDPR, gdpr-rec-63-en, 2016-04-27 — https://overview.legal/posts/91641*

A data subject should have the right of access to personal data which have been collected concerning him or her, and to exercise that right easily and at reasonable intervals, in order to be aware of, and verify, the lawfulness of the processing. This includes the right for data subjects to have access to data concerning their health, for example the data in their medical records containing information such as diagnoses, examination results, assessments by treating physicians and any treatment or interventions provided. Every data subject should therefore have the right to know and obtain communication in particular with regard to the purposes for which the personal data are processed, where possible the period for which the personal data are processed, the recipients of the personal data, the logic involved in any automatic personal data processing and, at least when based on profiling, the consequences of such processing. Where possible, the controller should be able to provide remote access to a secure system which would provide the data subject with direct access to his or her personal data. That right should not adversely affect the rights or freedoms of others, including trade secrets or intellectual property and in particular the copyright protecting the software. However, the result of those considerations should not be a refusal to provide all information to the data subject. Where the controller processes a large quantity of information concerning the data subject, the controller should be able to request that, before the information is delivered, the data subject specify the information or processing activities to which the request relates.

## Case law

### Judgment of the Court (Grand Chamber) of 4 October 2024.#ND v DR.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Chapter VIII – Remedies – Medicinal products marketed by a pharmacist on an online platform – Action brought before the national civil courts by a competitor of that pharmacist on the basis of the prohibition of unfair commercial practices for infringement by the pharmacist of t

*Source: Court of Justice of the European Union, C-21/23, 2024-10-04 — https://overview.legal/posts/132163 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0021*

In Case C-21/23, the Court of Justice of the European Union (Grand Chamber) ruled on a preliminary reference from the German Bundesgerichtshof in proceedings between two competing pharmacists (ND v DR) concerning whether a competitor has standing under GDPR Article 80(2) to bring a civil action against a rival for unfair commercial practices based on alleged GDPR violations involving health data processed through an online medicinal products platform. The Court addressed the interpretation of Article 9(1) GDPR and the concept of "data concerning health," clarifying the conditions for lawful processing of such special category data in the context of online pharmacy sales. No fine was imposed, as the ruling solely provides interpretative guidance on GDPR provisions regarding remedies, standing, and health data processing.

### CJEU - C-667/21 - Krankenversicherung Nordrhein

*Source: GDPRhub, 2023-12-21 — https://overview.legal/posts/156362 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-667/21_-_Krankenversicherung_Nordrhein*

Facts — The Medical Service of Health Insurance (the controller) is Germany's public health insurance medical review service. It provides expert reports when people say they are unable to work, as well as for its own staff. Before becoming unable to work, the data subject worked for the controller. The insurance company that was paying their benefits requested an expert opinion from the controller. The controller obtained health information from the data subject's doctor in the form of a medical report, which was then distributed to the data subject's coworkers. The data subject believed that their medical data had been unlawfully processed and sought €20,000 in damages from the controller, who rejected the claims. According to the data subject, the evaluation should have been performed by another organisation in order to prevent coworkers from accessing their medical data. Furthermore, they considered the security procedures around their medical report's archiving to be inadequate. After being rejected at first and second (Landesarbeitsgericht Düsseldorf) instance, the the data subject appealed to the Federal Labour Court, who referred the case to the CJEU with the following questions: On the topic of health data 1) Does Article 9(2)(h) GDPR prohibit a medical service of a health insurance fund from processing its employee’s health data when it is a prerequisite for the assessment of that employee’s working capacity? 2) If the Court answers Question 1 in the negative (with the consequence that an exception to the prohibition on the processing of data concerning health laid down in Article 9(1) GDPR is possible under Article 9(2)(h) GDPR) in a case such as the present one, are there further data protection requirements, beyond the conditions set out in Article 9(3) GDPR, that must be complied with, and, if so, which ones? 3) If the Court answers Question 1 in the negative, does the permissibility or lawfulness of the processing of data concerning health depend on the fulfilment of at least one of the conditions set out in Article 6(1) GDPR? On the topic of non-material damages 4) Does Article 82(1) GDPR have a specific or general preventive character, and must that be taken into account in the assessment of the amount of non-material damage to be compensated at the expense of the controller or processor on the basis of Article 82(1) GDPR? 5) Is the degree of fault on the part of the controller or processor a decisive factor in the assessment of the amount of non-material damage to be compensated on the basis of Article 82(1) GDPR? In particular, can non-existent or minor fault on the part of the controller or processor be taken into account in their favour? Advocate General Opinion — Advocate General Manuel Sánchez Bordona requested that the Court answer that Articles 9(2)(h) and (3) of the GDPR, as well as Articles 82(1) and (3), be understood as: Not barring a medical service of a health insurance fund from processing data about the health of an employee of such service, when those data are required for determining that employee's working capacity. Allowing an exception to the prohibition on processing personal data relating to health where such processing is required for the purposes of assessing the employee's working capacity and complies with the principles outlined in Article 5 GDPR as well as one of the conditions for lawfulness outlined in Article 6 GDPR. Making the degree of fault on the part of the controller or processor have no bearing on establishing the liability of either of them or quantifying the amount of non-material damage to be compensated on the basis of Article 82(1) GDPR. Allowing the data subject's participation in the incident that gave rise to the compensation duty to trigger, (depending on the circumstances) an exemption from liability for the controller or processor provided for in Article 82(3) GDPR. Holding — On the topic of health data On the first question, the exception under Article 9(2)(h) GDPR applies to situations where a public organisation for medical expertise processes health data of one of its employees not as employer but as a medical service, under the condition that the concerned processing fulfils the expressly prescribed preconditions and guarantees in subparagraph (h) and Article 9(3) GDPR. The purpose of Article 9 GDPR is to ensure a high level of protection in case of processing personal data whose level of sensitivity is especially high, involving an especially strong intrusion into the fundamental rights guaranteed by Articles 7 and 8 of the Charter. Therefore, the list in Article 9(2) is exhaustive and among others Article 9(3) prescribes a number of guarantees in the case of processing based on subparagraph (h). However, there is no reason to assume that subparagraph (h) is limited to cases of processing by independent third parties. This is supported by Recital 52 which states that derogation from Article 9 is permitted when it is in the public interest to do so. The quality and cost-effectiveness of the procedures used for settling claims for benefits and services in the health-insurance system can be said to be in the public interest. On the second question, it was held that because the exemption applies, the controller can share the health data to other colleagues. When health data is processed under subparagraph (h) it also has to be processed according to Article 9(3) GDPR. Article 9(3) requirements cannot be read widely as it is explicit in its requirements. Therefore, there is no legal ground to require that colleagues of the data subject should be excluded from the processing. Having said this, member states can derogate from this rule and create higher national standards under the opening clause provided in Article 9(4) GDPR. If a Member State would do this, the CJEU recommends using the principles of intergrity and confidentiality outlined in Article 5(1)(f) and 32(1)(a) and (b) to justify it. These higher standards should be proportionate to allow the relevant organisations outlined in Article 9(2), who may not have the technical and organisational resources to fulfil these conditions, to process health data. It is for a national court to determine whether the technical and organisational measures, according to Article 32 GDPR, are satisfactory and sufficient. On the third question, if 9(2)(h) applies, it must not only comply with the provisions set out in the article, but also fulfill at least one legal bases from Article 6(1) to be considered lawful processing. This can be inferrred from Articles 5, 6 and 9 GDPR which are all included in the Chapter titled “Principles” and concern “Principles relating to processing of personal data”, “Lawfulness of processing” and “Processing of special categories of personal data”. Recital 51 GDPR expressly mentions that “the general principles and other rules of this Regulations should apply, in particular as regards the condition for lawful processing". The Court has also decided multiple times that the all processing of personal data has to comply with the preconditions of lawfulness in Article 6 and that all preconditions of Chapter II GDPR have to be complied with. On the topic of non-material damages On the fourth question, Article 82(1) GDPR has a compensatory instead of deterrant or penalising function. Compensation should fully compensate the damage suffered caused by the infraction of the GDPR. The Court reffered to the established case law that compensation can only be required based on Article 82 GDPR, when all of three cumulative conditions are fulfilled; 1) the existence of a damage, 2) an infringement of the Regulation, 3) a causal relationship exists between the infringement and the damage. The GDPR does not contain rules to define the amount of damages. National courts have to apply domestic rules of the individual Member States as far as the principles of equivalence and effectivity are complied with. Based on Recital 146, the Court states that the objective of this rule is to provide for “full and effective for the damage they have suffered”. Different from the sanctions in Articles 83 and 84, this sanction has not a penalising, but a compensating function. It has nevertheless an effect to deter from repeating the unlawful behaviour as well. On the fifth question, Article 82 GDPR needs causation (which is presumed unless the controller can prove otherwise) and does not require an assesment as to the degree of the controller's responsibility when calculating the amount of compensation awarded for a non-material damage. A controller has to compensate for a damage which arose as the consequence of an infringement of the GDPR. Recitals 4 to 8 GDPR indicate that the aim of the Regulation is to establish a balance between the rights of the controller and of the data subject. On one hand the responsibility of the controller depends on the existence on an infringement which is to be attributable to it. On the other, this is to be assumed unless the controller can prove that they have not caused it. An obligation to pay damages without causation would contradict the principle of legal certainty. However, once the existence of a damage is ascertained, Article 82 does not require national courts to take into account the gravity of the infringement or the extent of the controller's responsibility to quantify damages. Instead, the amount should be calculated to compensate fully the damage suffered.

### CJEU - C‑474/24 - NADA Austria and Others

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/108989 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑474/24_-_NADA_Austria_and_Others*

Facts — Several data subjects were subject to suspension proceedings by the Austrian Anti-Doping Legal Commission (ÖADR). Under Austrian law, the National Anti-Doping Agency (“NADA”) publishes the names of persons who have been suspended on its website. For the duration of the suspension, the website includes information such as the athlete’s name, sport practised, infringement of anti-doping rules, and the duration of the penalty. The ÖADR publishes the same information in a press release, with the addition of the prohibited substances involved. For this summary, both authorities are referred to as the controllers. The data subjects filed a complaint with the DPA on the grounds that the controllers refused their request to cease displaying their names and practised sports. They also argued that the controllers were processing sensitive data within the meaning of Article 9 and 10 GDPR, and that the undifferentiated publication system was incompatible with Article 6(3) GDPR. The DPA dismissed the complaint. In particular, one of the data subjects’ complaints was rejected on the grounds that the relevant data had not been published yet. The data subjects appealed the decision to the Federal Administrative Court (BVwG). The controllers argued that publishing the information in their website was lawful, as it was based on the legal bases of legal obligation (Article 6(1)(c) GDPR) and public interest (Article 6(1)(e) GDPR). The BVwG stayed proceedings and requested a preliminary ruling from the CJEU. The BVwG referred the following questions: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? If yes: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? Does the GDPR preclude national legislation from publishing the information mentioned above, if it does not make it possible to infer health data of the person concerned? Does the GDPR require a balancing test between the interests of the data subject and the interest of the general public of being informed of anti-doping violations every time anti-doping violations will be published? Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR? If yes, must the decisions of the authority processing this data be subject to judicial review? Is filing a complaint before the processing takes place (but was processed during the proceedings) permissible? Or does it become permissible provided that at the time of the complaint there were specific indications that the processing was imminent or would take place in the near future? Advocate General Opinion — The AG gave his opinion on each question separately, with the exception of the third and fourth questions that were answered together. Question 1: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? — The AG first considered that the GDPR was applicable to this case. Under Article 2(2)(d) GDPR a situation falls outside of the scope of the GDPR when data is processed for the prevention, detection or prosecution of criminal offenses. This is because the Law Enforcement Directive (LED) applies. According to the AG, the GDPR may apply even if personal data relating to criminal convictions is processed if the controllers are not “competent authorities” within the meaning of Article 3(7) LED. If the controllers were competent authorities, the referring court would have to decide if the GDPR applies. The main question the AG addressed is whether the exception under Article 2(2)(a) GDPR applies, meaning the processing falls outside the scope of Union law; here, the AG noted that the exceptions are interpreted narrowly, and may only apply to activities intended to safeguard national security or activities classified in the same category. The AG concluded that the aim of combating anti-doping is not related to national security. The exception did not apply even if the activity fell under the competence of a Member State. Therefore, the GDPR was applicable. Question 2: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? — The AG first highlighted the sensitive nature of Article 9 GDPR data, which must be interpreted broadly. The AG also noted that the legal basis of the controller does not influence whether the data falls under the scope of health data. Beyond a medical context, the AG opined that the determining factor is whether it is possible to draw inferences about the health status of the data subject. In this case, the AG agreed with the reasoning of the DPA that only specific information relating to the infringements should be considered health data. This is because not all data revealed information related to the data subjects’ health. Specifically, the information regarding the anti-doping tests and its analysis should be considered health data. The AG noted that, while the name of the substance itself may not reveal information on health status, it may be possible to make indirect inferences. However, if the name is not included, the link to the health status of the data subject would be too indirect to fall under the scope of health data. Questions 5 and 6: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR, and must the decisions of the authority processing this data be subject to judicial review? — The AG first noted that the GDPR does not prohibit processing this data, but rather subjects it to enhanced scrutiny. The AG assessed whether the processing fell under the scope of Article 10 GDPR based on the three “Engel” criteria in ECtHR case Engel and Others v. the Netherlands. Anti-doping offenses under national law do not fall under the “criminal” classification according to Article 10 GDPR. However, the AG opined that article 10 GDPR applies if the convictions have a punitive purpose and have a degree of severity equivalent to a criminal penalty. This is a matter for the BVwG to decide. In terms of judicial review, the AG stated that the authority at issue is an “official authority” within the meaning of Article 10 GDPR. The wording itself of Article 10 GDPR does not provide for judicial review. However, the AG opined that it must be possible for an act following a decision by an official authority to be subject to judicial review. This is in light of Article 79(1) GDPR and a contextual interpretation of Article 10 GDPR. Questions 3 and 4: Does the GDPR preclude national legislation from publishing the information mentioned in the facts, and does it require a balancing test every time anti-doping violations will be published? — The AG considered, in essence, whether Articles 5(1)(a) and (c), and Article 6(3) GDPR precluded the controllers to publish the data concerned under legal obligation. The AG also considered whether the GDPR requires a case-by-case balancing of interests, or whether the proportionality test provided by the legislator is sufficient. The AG noted that the aim to deter athletes and prevent circumventing of anti-doping rules are legitimate public interest objectives in the context of combating doping in sport. Making this information public online is appropriate in order to achieve the public interest aims, with the exception of referring to the prohibited substance in question. According to the AG, this was not expressly provided for by national law, and is not required to achieve the public interests involved. However, the AG considered the publication of the personal data involved a serious interference with the fundamental rights of the data subjects. While national law provided exceptions on the publication of data (e.g. amateur athletes or vulnerable persons), the AG opined that the publication of personal data for an unlimited amount of time could be considered excessive. Therefore, the AG concluded that making this information publicly accessible is only permitted as long as it is proportionate. Finally, the AG opined that a case-by-case analysis is necessary, as the controllers must comply with data minimisation and accountability principles under the GDPR even if they are designated by national law. Question 7: Is filing a complaint before the processing takes place permissible? — Here, the AG stated that the wording of the GDPR does not seem to preclude a priori a precautionary or preventative approach by the supervisory authorities in handling complaints. Restricting the powers of a DPA to decide on cases involving processing that has already taken place would go against the objectives of the GDPR. Nonetheless, the alleged infringement of the GDPR must be appropriate, and the processing in question cannot be purely hypothetical. In this case, it would be impossible for a controller to erase data that has not been disclosed yet, unless the complaint is interpreted as seeking to prevent the data from being published. The AG stated that it is a matter for the BVwG to decide. The AG noted that the complaint would be inadmissible if it was based on Article 17 GDPR even if the processing is imminent. However, the AG opined that a complaint requesting injunctive relief is potentially admissible under the GDPR and Austrian law in the event of a threat of imminent unlawful interference with data subjects’ rights under the GDPR. This includes requesting the DPA to review a restriction of processing based on Article 18 GDPR before the start of the processing or if the processing has started, as long as the processing is not purely hypothetical. Finally, the AG considered whether a complaint could become admissible a posteriori. Here, the AG opined that it is a matter of the national law system to settle the question, while complying with the principles of effectiveness and equivalence. Holding — The Court held that the GDPR applied to the publication of information concerning anti-doping infringements. Such processing did not fall within the exception under Article 2(2)(a) GDPR, even if anti-doping policy primarily falls within Member State competence. Information that a data subject infringed anti-doping rules and was banned from competitions does not, in principle, constitute health data under Article 9 GDPR. However, it may do so where the publication identifies a prohibited substance or method and, together with other information, allows conclusions to be drawn about the data subject’s health. The Court accepted that combating doping and protecting the fairness and integrity of sport constitute objectives of general interest. Nevertheless, publishing athletes’ identities and sanctions online constitutes a serious interference with their rights. National legislation may therefore require such publication only where the controller can assess, in each case, whether the content and duration of the publication are necessary and proportionate. Publication should not continue longer than strictly necessary and may be disproportionate where a sanction is lengthy or lifelong. The Court also held that Article 10 GDPR did not apply, as the anti-doping infringements formed part of a disciplinary regime and were not criminal in nature. Finally, Article 77 GDPR allows a data subject to lodge a complaint before processing takes place where there are specific indications that the processing is imminent and not merely hypothetical. The DPA must assess the substance of such a preventive complaint.

### X - BA-6S/221/2019

*Source: Regional Administrative Court Bratislava, 2025-06-25 — https://overview.legal/posts/132105 — original: https://gdprhub.eu/index.php?title=X_-_BA-6S/221/2019*

Facts — Sociálna poisťovňa, the social insurance agency (the controller), processes applications for foreign invalidity pensions and forwards related documents to the social insurance institutions of other EU Member States. A data subject applied for a Danish invalidity pension. On 22 October 2018, the controller sent the data subject's sensitive personal data (including health data, personal identification number and a Danish personal identifier) to the Danish social insurance institution by ordinary (uninsured, untracked) second-class mail rather than by registered mail. The data subject could not confirm delivery and, in November 2018, filed a request with the Slovak DPA alleging that sending sensitive data by ordinary mail, without any proof of dispatch or protection against loss, violated their data protection rights. The controller resent the documents by the same method in December 2018. The DPA's first-instance decision (13 June 2019) found that the controller had violated Article 24(1) in conjunction with Article 32(1) and (2) GDPR, because sending sensitive personal data by ordinary rather than registered mail did not ensure a level of security appropriate to the risk. The DPA ordered the controller to use registered mail for such dispatches going forward and imposed a fine of €50,000. The controller's appeal was rejected, and the Slovak DPA president upheld the first-instance decision. The controller then brought an action before the Regional Administrative Court Bratislava, arguing among other things that: the parcel had in fact been delivered (as confirmed by the Danish institution by email), registered mail offers no greater protection against loss of confidentiality than ordinary mail, only one data subject was concerned and no damage had occurred and the decision's operative part improperly referred to the data of pension applicants generally, not just the individual data subject who had filed the complaint. Holding — The court did not rule on the substance of the security measures dispute, since it found the DPA's decision unreviewable on procedural grounds. First, the court held that the operative part of the DPA's decision was contradictory and imprecise. The administrative proceedings had been triggered by, and the evidence had concerned, an alleged violation of rights of one specific data subject (loss of their parcel). However, the decision extended the finding of violation to the controller's general practice of sending all pension applicants' data by ordinary mail. The court noted that a systemic pattern affecting other data subjects could, at most, be taken into account as an aggravating circumstance when setting the fine, but it could not itself form part of the sanctioned conduct in a proceeding limited to one individual's complaint. Second, the court found that the DPA had failed to properly assess evidence submitted by the controller showing that the parcel had actually been delivered to the Danish institution. The DPA only addressed this evidence for the first time in its written observations in the court proceedings, not in the administrative decision itself, even though the decision's entire reasoning rested on the (contested) premise that the parcel had been lost. Third, the court observed that the fine had been imposed under a provision of the national Data Protection Act that only permits fines for breaches of Articles 25 to 32 GDPR, whereas the DPA's decision had also relied on Article 24(1) GDPR, which is not covered by that provision. Because of these defects, the court annulled the DPA's decision and remanded the case for further proceedings, without addressing the parties' remaining arguments on the merits . The court instructed the DPA to first clearly establish the specific conduct underlying the alleged offence and then decide the case again, addressing all evidence submitted by the controller. The court awarded the controller full reimbursement of costs.

### Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal

*Source: Court of Justice of the European Union, C-667/21, 2023-12-21 — https://overview.legal/posts/132276 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0667*

The CJEU (Third Chamber) ruled on a preliminary reference from the Bundesarbeitsgericht in a case where ZQ sought compensation from his employer, Medizinischer Dienst der Krankenversicherung Nordrhein, for allegedly unlawful processing of his health data in connection with an assessment of his working capacity. The Court addressed the conditions under which a health insurance medical service may lawfully process special categories of health data of its own employees under GDPR Articles 6(1) and 9(2)(h)/(3), and clarified the scope of the right to compensation for non-material damage under Article 82(1), including the relevance of the controller's negligence. No fine was imposed, as the ruling concerns the interpretation of GDPR provisions for the referring court's application.

### CE - 439360

*Source: CE, 2021-04-13 — https://overview.legal/posts/125663 — original: https://gdprhub.eu/index.php?title=CE_-_439360*

Facts — In February 2020 the French minister of the interior enacted the Decree No. 2020-151 of 20 February 2020 authorising the automated processing of personal data known as "mobile note-taking application" (Décret n° 2020-151 du 20 février 2020 portant autorisation d'un traitement automatisé de données à caractère personnel dénommé «application mobile de prise de notes» (GendNotes)). The app should be used on the occasion of preventive actions, investigations or interventions necessary for the exercise of judicial or administrative police missions. Among the data that can be collected is information relating to alleged racial or ethnic origin, political, philosophical or religious opinions, trade union membership, health or sexual activities or orientation. A group of human rights organisations filed a complaint with the French Constitutional Court. Dispute — Is the "GendNotes" App of the French national police force (Gendarmerie nationale) unlawfully processing special category personal data? Holding — The French Highest Administrative Court held that the decree infringed Article 4 of the Law of 6 January 1978, implementing GDPR in France, the Council of Europe Convention No. 108 for the Protection of Individuals with regard to Automatic Processing of Personal Data and Article 8 CFR, as it excessively infringed upon the right to respect for private life and the correlative right to protection of personal data, without providing appropriate safeguards for their protection in terms of the purpose of the processing and the nature of the data collected, as well as excessive data retention period, data sharing and data security. The Court discussed whether the decree violated Article 4 (a) GDPR, Article 4 (b) GDPR, Article 4 (c) GDPR, and Article 4 (e) GDPR and Article 9 GDPR. According to the Court, the processing of data did not comply with the principle of purpose limitation, as data is collected for future investigations or proceedings. However, the Court did not find a violation on the collect of special category data, given the fact that the decree establishes that this data can only be processed in case of "absolute necessity". Additionally, the Court noted that, even if the decree provides a limitation for the storage of the data, in practice this can be ignored, as the data may be used in different or further investigations, that would impede its erasure. However, they found that the decree was lawful in this regard, given that it clearly stated a retention period of 3 months to 1 year. Taken the above-mentioned into account, the French Highest Administrative Court decided that the data processed by the French national police force can no longer be used "in other data processing, in particular by means of a pre-information system". Therefore, the Court held: In Article 1° of the decree, the words "in other data processing, in particular by means of a pre-information system," are cancelled out. The State will pay €3,000 to every claimant. The rest of the application is rejected. The allowance to collect special category data is not overruled, as the Court argues that the decree only allows it when it is "absolutely necessary". This decision will be notified to the claimants: the Ligue des droits de l'homme, the associations Homosexualités et socialismes and Internet Society France, the associations Mousse, Stop Homophobie, Adheos and Familles A, the association AIDES, the Syndicat de la magistrature, the Syndicat des avocats de France, the Conseil national des barreaux, the Quadrature du Net and the International League against Racism and Anti-Semitism, the Prime Minister and the Minister of the Interior.

### CJEU - C-101/01 - Lindqvist

*Source: GDPRhub, C-101/01, 2003-11-06 — https://overview.legal/posts/125585 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-101/01_-_Lindqvist*

Facts — The case is about Mrs. Lindqvist who worked as a catechist in the Alseda Parish (Sweden). At the end of 1998, she set up internet pages on her personal computer in order to allow parishioners preparing for their confirmation to obtain any information they needed. She requested the administrator of the Swedish Church’s website to set up a link between those pages and the website. The pages she had set up contained information about Mrs. Lindqvist and 18 of her colleagues in the parish. The pages contained information including their full names, first names, jobs held, hobbies, telephone numbers and medical information on one of her colleagues. She had not informed her colleagues of those pages, obtain their consent or sought approval from the supervisory authority to process the personal data and sensitive personal data. The public prosecutor brought a proceeding against her, that she was in breach of the PUL on grounds that she processed personal data automatically without giving prior written notice to the Supervisory Authority (Datainspektionen). In addition, she processed sensitive personal data and transferred personal data to a third country without authorization or consent from the data subjects. The Royal Court (Göta hovrätt) stayed the national proceedings and referred some question of law to the CJEU. Dispute — The questions brought before the CJEU were: Whether a self-made list, with personal data of others, published on the internet constitute processing of personal data wholly or partly by automatic means as defined under Article 3(1) Directive 95/46/EC. Whether the act of setting up internet home pages for 15 people with links between the pages which make it possible to search the pages using the first name be considered processing of personal data which forms part of a filing system within the meaning under Article 3(1) Directive 95/46/EC? Whether the processing of personal data is covered under the exception to processing under a household activity under Article 3(1) Directive 95/46/EC? Whether the reference made to the health condition of Mrs. Lindqvist colleague amounts to processing of health/medical data under Article 8(1) Directive 95/46/EC? Whether publication of information on the internet, which can be viewed by anyone in the world, amount to transfer of personal data according to Article 25 Directive 95/46/EC. Whether the provisions of Directive 95/46/EC are in conflict with the general principles of freedom of expression under Article 10 ECHR. Lastly, whether a member state can provide more extensive protection for personal data than that provided under Article 13 Directive 95/46/EC. Holding — On the first and second question, the CJEU held that the term personal data defined under Article 2(b) Directive 95/46/EC includes any information relating to an identified or identifiable natural person. Hence, the term covers the name of a person, his telephone number or information relating to his working conditions or hobbies. Regarding the question whether Mrs. Lindqvist was processing personal data using internet pages, the court referred to Article 3(1) Directive 95/46/EC and observed that, according to the definition, the term processing of personal data covers any operation performed on personal data whether or not by automatic means. Thus, the court held that the operation of loading personal data on an internet page must be considered to be processing of personal data. The court also considered the third question, whether the processing falls under the exception stipulated under Article 3(2) Directive 95/46/EC as argued by Mrs. Lindqvist. On this, the court critically examined the exceptions stipulated which include processing by a natural person in the course of a purely household or personal activity. The court interpreted the exception to mean that the exception covers only activities which are carried out in the course of purely private or family life of individuals which clearly is not the case here since the activities carried out by Mrs. Lindqvist were or charitable or religious nature. On the fourth question, the court interpreted widely Article 3(1) Directive 95/46/EC to include information concerning all aspects of physical and mental health state of an individual. Hence, Mrs. Lindqvist's reference to her colleagues health condition constitutes processing of personal data concerning health in line with Article 8(1) Directive 95/46/EC. On the fifth question, the court noted that the term transfer was not defined by Directive 95/46/EC. Hence, in order to determine whether loading personal data on an internet page constitutes transfer within the meaning of transfer envisioned under Article 25 Directive 95/46/EC, the court took into account the technical nature of the internet pages operations. The court noted that, in order for internet users to have access to the internet pages containing the personal data, they had to first connect to the internet and then proceed to carry out a search. Thus, the technical operations in question did not contain the technical means to send that information automatically to people who did not seek to access those pages. The court held that Mrs. Lindqvist did not transfer personal data as enumerated under Article 25 Directive 95/46/EC. On the sixth question, the court noted that Member states have an obligation to ensure that national laws are harmonized to ensure free flow of information between member states and also safeguard individuals’ rights and freedoms. Thus, there must be balancing of rights of individuals and economic and social integration. Mrs. Lindqvist's freedom of expression in her work to contribute to religious life had to be weighed against the protection of individual rights. To balance these two, the court emphasized on the importance of respecting the principle of proportionality that means taking into account all the circumstances of the case before it before making a decision. The court held that the provisions of Directive 95/46/EC do not necessarily bring a restriction which conflicts with the general principles of freedom of expression, but it is up to the national courts to ensure a fair balance between the rights and interests in question. On the seventh question, the court addressed the question with reference to the provisions of Recital 8 Directive 95/46/EC and Recital 10 Directive 95/46/EC. In the harmonization of laws by member states, the court reiterated the importance of having a complete harmonization of laws. The court noted that Directive 95/46 allows room for manoeuvres in certain cases, but such manoeuvres should ensure that there is a balance between the free movement of personal data and protection of private life. In conclusion, the court held that measures taken by member states to ensure the protection of personal data must be consistent with the provisions of Directive 95/46/EC. However, nothing prevents a member state from extending the scope of national legislation to areas not included in the scope of Directive 95/46/EC.

### NSS - 1 As 183/2023-62

*Source: Supreme Administrative Court, 2026-08-04 — https://overview.legal/posts/184683 — original: https://gdprhub.eu/index.php?title=NSS_-_1_As_183/2023-62*

Facts — OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free Access to Information, it requested information from the General Health Insurance Company of the Czech Republic concerning the treatment of patients with iron deficiency and related conditions for the period from 1 January 2010 to 31 October 2017. The request covered 183 types of diagnoses, 18 types of medical procedures, 96 DRG codes and 13 types of medications. The company stated that it wished to analyse how specific diagnoses were treated, the number of patients treated, and the frequency of related medical procedures, in order to compare clinical practice against the relevant theoretical background. The public health insurer rejected the request on the grounds that granting it would require the creation of new information. Following an appeal by the company, the Prague Municipal Court overturned the decision. The public health insurer provided then the company with five separate tables regarding the diagnoses, diagnoses in conjunction with medical procedures, the DRG codes and prescribed medications. It aggregated the parameters of the provided data as follows: five-year age groups, dates were given only at the monthly level, and healthcare providers were classified into broad geographic regions. However, it refused to add a unique random identifier which would allow linking the individual records and tables pertaining to the same patient. The public health insurer considered that providing the code would result in the disclosure of special categories of personal data. The company lodged a complaint with the Czech DPA (UOOU), which rejected it. The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4(1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case (C-582/14), according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in Case T-557/20 (SRB v. EDPS), which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety. The company filed a cassation appeal with the Supreme Administrative Court, arguing that the information had been anonymised. It alleged that the addition of a random code with no independent meaning would not alter their anonymous nature. It claimed that the Municipal Court had not explained what specific additional information could be used to identify the patients and had relied on hypothetical scenarios. The company stated that it was objectively impossible to obtain such data through other requests in a detailed and non-aggregated form. It also argued that iron deficiency was not a rare disease, but was associated with a large number of patients and various conditions and that the data had undergone both randomisation and generalisation so the risk of identification was therefore low. Finally, the company emphasized that the tables without the random identifier could not be used effectively for the intended analysis. It further argued that the DPA and the Municipal Court had not adequately balanced the right of access to information against the right to the protection of personal data. The DPA argued that the random identifier constituted personal data when considered in conjunction with the health data to which it would be linked. It stated that the concept of personal data was not limited to information that directly identifies an individual nor did it require that all necessary additional information be held by the same entity. Replacing direct identifiers with a code did not anonymise the data, but made it pseudonymised. Moreover, it argued that certain categories contained a relatively small number of records and that combining them with other data could make it possible to select and identify a specific insured person and their treatment history. It further argued that, even if identifiability was relative, it should be assessed in relation to all potential information applicants and their ability to obtain contextual information. The Supreme Administrative Court stayed the proceedings in the case pending the CJEU’s decision in Case C-413/23 P (EDPS v. SRB). After the judgment was issued, the company argued that whether the data were pseudonymised or anonymised should be assessed in relation to the specific recipient of the data and the means that it could reasonably use. It stated that it did not have any means of re-identification and that only specific and practically available cross-referencing possibilities should be taken into account. Holding — The court relied on Case C-413/23 and noted that pseudonymised data under Article 4(5) GDPR does not automatically constitute personal data in relation to every person. Therefore, it examined whether the company had lawful means that could reasonably be expected to be used to identify the patients directly or indirectly. The court found that the tables, without the random identifier, did not allow for the identification of specific insured individuals. It held that the requested random identifier would link the records from the different tables and allow for the aggregation of information on the diagnoses, medical procedures, hospitalizations, and medications for the same patient during the eight-year period. Certain combinations of these data, along with age group, gender, and region, could be unique and allow for the identification of patients using information from public sources. It pointed out that although iron deficiency was a very common diagnosis and some tables contained a very large number of entries, other categories were not sufficiently generalised. According to the court, in certain cases, such as rare diseases, unusual treatment combinations, or particularly young or old age, knowing even a few details about a person could make it possible to identify the corresponding record. The risk was not negligible, given that information about a person’s age, gender, hospitalization, diagnosis, or treatment could be available in the media or on social media. Consequently, the court held that adding the random identifier, in conjunction with the data already provided, would make the dataset personal data in relation to the company under Article 4(1) GDPR, including health data falling under Article 9 GDPR. The court clarified that classifying the information as personal data was not sufficient in itself to reject the request. It noted that the right of access to the information must also be balanced against patients’ right to privacy through an assessment of suitability, necessity and proportionality. It determined that the decision not to provide the random identifier was appropriate for the protection of privacy, because without it, it was impossible to link the tables and identify individual patients. It was also deemed necessary because the company insisted on receiving that specific code along with the existing tables and there was no other procedure that would constitute a lesser infringement of its right to information. The court also recognized the public interest in accessing information related to the operation of the healthcare system, but ruled that this did not outweigh the need to protect the detailed health data of potentially hundreds of thousands of insured individuals. It concluded that the refusal to provide the code was therefore proportionate. The Supreme Administrative Court therefore upheld the Municipal Court’s ruling, but partially corrected its reasoning regarding the relative nature of identifiability and the need to conduct a proportionality review. It dismissed the appeal.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

### CJEU - C-205/21 - Ministerstvo na vatreshnite raboti

*Source: GDPRhub, 2023-01-26 — https://overview.legal/posts/158437 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-205/21_-_Ministerstvo_na_vatreshnite_raboti*

Facts — A data subject was accused of a criminal offence and refused to consent to the collection of her genetic and biometric data (Photographs and fingerprints), which the Bulgarian Police required to create a record. The data subject also refused to let the police take a sample for the purpose of creating a DNA profile. In the end, the police did not collect this data. The police went to a Bulgarian Criminal court (Spetsializiran nakazatelen sad), which was also the referring court in this case. Here, the police asked the court to authorise the forced collection of the genetic and biometric data, considering there was enough evidence to convict the data subject of the crime. The police position was mostly based on Bulgatian law (ZMVR, Law of the ministry of Home affairs) authorising the collection of biometric and genetic data for, among the others, law and order purposes. However, the referring court had doubts whether the such law was actually compliant with EU law. This Bulgarian law did refer to Article 9 GDPR, but did not refer to EU directive 2016/680. The latter is an EU directive which concerns the protection of personal data regarding processing of competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. This directive states that the processing of certain special category data, including genetic and biometric data, can be lawful if this is compliant with EU law or national law. The Bulgarian law had even taken over some of the wording from Article 10(a) of this directive for its national provision. The court determined that there were two problems resulting from the fact that this national law contained a reference to the GDPR, but did not mention the aforementioned directive. The first problem was the fact that the GDPR was not applicable to the processing of personal data with regard to criminal investigations, pursuant to Article 2(2)(d) GDPR. The second problem was the fact that Article 9 GDPR prohibited the processing of genetic and biometric data. The court also reiterated that a law enforcement purpose could not fall under one of the exceptions under Article 9(2) GDPR. The referring court referred several questions to the CJEU. The main issue was to know whether the processing of genetic and biometric data for purposes of criminal investigations in this case was permissible under the national law, despite the mention of Article 9 GDPR, and despite the fact that EU directive 2016/680 was not mentioned in the national law. Holding — First, The CJEU determined that both Article 9 GDPR and Article 10 of the directive contain provisions regarding the processing of special categories of personal data, including biometric en genetic data. Second, The CJEU determined that processing of biometric and genetic data by the police authorities could be permissible, as long as this processing fell under Article 10(a) of the directive. This meant that the processing had to be strictly necessary, with adequate safeguards and was provided for in national / EU law, pursuant to Article 52 CFR. However, it could still be unlawful to process this data, when this processing also fell within the scope of the GDPR. Third, The court stated that the requirement of authorised by Union or Member State' law in Article 10a of the directive must be interpreted pursuant to Article 52(1) CFR, which states that any limitation on the exercise of a fundamental right "must be ‘provided for by law". The legal basis which is used for this limitation (in this case, the legal basis was the Bulgarian law), must define the scope of the limitation sufficiently clearly and precisely. This meant that there should not be any uncertainty about the laws concerning - or the conditions of the processing of genetic and biometric data. However, The CJEU also noted that these conditions of processing could vary between the GDPR and the directive. In this context, The CJEU determined that the member states were free to organise their processing operations under either the GDPR or the aforementioned directive. However, member states would have to make sure that there would be no uncertainty about the fact which law would be applicable to different kinds of processing of biometric/genetic data. Fourth, The court also determined that member states were not obligated to cite the directive in the national law itself when they were transposing this directive into national law. It was therefore not necessary for the Bulgarian legislature to mention directive 2016/680 in its transposed national provisions. Fifth, the CJEU noted that national courts had the obligation to explain the national law. For this explanation, the national court had to consider the wording of the directive and the context of the directive. This was an obligation pursuant to Article 288 TFEU, which was applicable to all public bodies of a member state, including national courts. In the present case, where there was an obvious conflict between the GDPR and the directive, the national court had to provide an explanation which would keep the useful working of the directive intact. The CJEU stated that it was up to the national court to determine if the reference to Article 9 GDPR in the Bulgarian law was even correct. The court concluded that it was up to the national court to assess the case. In summary, the Court noted that the processing of the biometric and genetic data by the police could be lawful in this case if it fell under Article 10(a) of the directive. Also, the national implementation of the directive needed to have a sufficiently clear and precise legal basis for the processing of biometric/genetic data by the Bulgarian police. The fact that Article 9 GDPR was mentioned in this law was of no consequence for the legality of this processing, nor was the fact that the directive was not mentioned in the national implementation. However, the explanation by the national court of this Bulgarian law had to be sufficiently precise and clear. Also, this explanation of the national court should state in an unequivocal manner whether certain processing of biometric and genetic data would fall under the directive, or would fall under the GDPR.

### SO Warszawa - III C 904/23

*Source: Regional Court in Warsaw, 2026-02-16 — https://overview.legal/posts/53100 — original: https://gdprhub.eu/index.php?title=SO_Warszawa_-_III_C_904/23*

Facts — The Financial Ombudsman’s office (the controller) sent a letter containing the name, the address, and the case reference number of a customer (the data subject) to 28,366 public institutions and entities registered on an official government platform in February 2021. The data subject demanded compensation for the unauthorised disclosure of his personal data from the controller in November 2021. The controller refused to accept liability for the incident. The supervisory authority issued the controller a reprimand in September 2022 for disclosure of personal data in violation of Article 6(1) GDPR. The data subject brought a lawsuit for damages under Article 82 GDPR before the Regional Court in Warsaw in August 2023. The data subject stated that they had experienced severe stress and lost the sense of security and control over their data as a result of the unauthorised disclosure of the letter. The controller argued it was not at fault for the incident as it was caused by a temporary IT system failure that the controller could not have foreseen. Holding — The Regional Court in Warsaw held that the controller was undoubtedly liable for the unauthorised disclosure of the data subject’s personal data pursuant to Article 82 GDPR: the controller was an administrator for the government platform and had not taken adequate measures to secure the data. Second, the court held that the data subject had suffered non-material damage in connection with the aforementioned incident. It took into account that the data had been disclosed to numerous entities. In addition, the deterioration of the data subject’s mental state was confirmed by a witness. The court awarded the data subject PLN 40,000 in damages. It considered the data subject’s claim of PLN 50,000 to be excessive in light of established case law.

### BVwG - W211 2281442-1

*Source: Federal Administrative Court, 2024-06-12 — https://overview.legal/posts/187484 — original: https://gdprhub.eu/index.php?title=BVwG_-_W211_2281442-1*

Facts — The data subject and the controller both worked as nurses at the same hospital, on different wards. Over ten years before the events in question, the data subject had been hospitalised as a patient on the ward where the controller worked as a nurse. The controller's daughter, a school classmate of the data subject at the time, had visited her in hospital and the data subject's hospitalisation had briefly been discussed once in a social-skills class at school, without any diagnosis being disclosed. The data subject only told her closest friends about the hospitalisation itself. The data subject was later employed as a nurse at the same hospital, on a different ward, from October to April of a subsequent year. She and the controller belonged to a shared WhatsApp group used by both wards. Around Christmas, the controller's daughter recognised the data subject from her WhatsApp profile picture and reminded the controller that the data subject had once been her patient, the controller herself had not previously made this connection. The data subject resigned from her position, with her last working day followed by sick leave through the end of her notice period. On her first day back from holiday, the controller, deputy head of her ward, discussed recent events with the ward manager, including the data subject's resignation. In the course of this conversation, the controller mentioned that her daughter had gone to school with the data subject and asked the ward manager whether she had known that the data subject had been hospitalised on the relevant ward over ten years earlier. That same day, the ward manager told the data subject that staff at the hospital were aware of her earlier hospitalisation, intending to prepare her for the possibility that colleagues might raise it. The data subject later learned, from the site manager, that it was the controller who had disclosed this information to the ward manager. The data subject alleged that this disclosure led to her being bullied in the workplace. The controller denied any obligation on employees to disclose past hospitalisations to the employer and stated she had no other motive for the disclosure. The data subject lodged a complaint with the Austrian DPA, alleging a violation of her right to secrecy. The DPA upheld the complaint, finding that although the GDPR did not directly apply to this oral disclosure, the national constitutional right to secrecy under Section 1 DSG did apply, that the disclosed health data warranted heightened protection and that the controller had not shown sufficiently weighty grounds to justify the disclosure. The controller appealed to the Federal Administrative Court, arguing that the information was already publicly available (since it had once been mentioned at school) and that the disclosure was justified as processing of manifestly public data, as processing by a professional subject to confidentiality obligations, or as necessary for assessing an employee's fitness for work. Holding — The court dismissed the appeal and confirmed the DPA's decision in full. First, the court held that the GDPR's substantive scope did not apply to this case, since it concerned a purely oral disclosure of personal data, not automated or file-based processing. The applicable standard was instead the national constitutional right to secrecy under §1 DSG, interpreted in light of GDPR principles. The court noted that the disclosed information, the fact of a past hospitalisation, qualified as health data under Article 4(15) GDPR, given the broad interpretation the CJEU applies to that concept. Second, the court held that the information was not "generally available" within the meaning of §1(1) DSG, which would have excluded any protectable secrecy interest. It reasoned that data are only "generally available" if accessible to an indeterminate group of people, not merely to a limited circle of confidants. Since the data subject had only shared her hospitalisation with a small group of close friends and even the one classroom discussion of it involved only a defined group of classmates (not the public), the general-availability exception did not apply and the data subject retained a protectable secrecy interest. Third, addressing the controller's justification arguments in turn, the court held Article 9(2)(e) GDPR (data manifestly made public by the data subject) did not apply, for the same reasons the data was not "generally available“, Article 9(2)(a) GDPR (explicit consent) did not apply, since no explicit consent to this specific disclosure had ever been given and Article 9(2)(h) GDPR (processing necessary for assessing an employee's working capacity, among other health-related purposes) did not apply, because the disclosure was not shown to be necessary. The employer had no policy of taking such hospitalisations into account, the data subject had no duty to disclose them and no concrete workplace measures were linked to the disclosure. The court emphasised that health data attracts a particularly high level of protection, meaning that even if the controller's interest had been considered on a par with the data subject's, this would not have been sufficient to justify disclosure, given that the data subject was already leaving employment within a short period, her interest in confidentiality clearly outweighed any interest of the controller. The court accordingly confirmed that the controller had violated the data subject's right to secrecy under §1 DSG and declared an appeal on points of law (Revision) inadmissible, since the case turned on an individual assessment of undisputed facts and raised no question of fundamental legal importance.

## Guidance

### EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space

*Source: EDPB, edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on-en, 2022-07-12 — https://overview.legal/posts/125922 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on_en*

Adopted 1 EDPB - EDPS Joint Opinion 03 /2022 on the Proposal for a Regulation on the European Health Data Space Adopted on 12 July 2022 Adopted 2 Adopted 3 Executive Summary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on the European Health Data Space and urge the co - legislature to take decisive action. The EDPB and the EDPS note that the Proposal ai ms at supporting individuals to take control of their own health…

### Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak

*Source: EDPB, guidelines-032020-on-the-processing-of-data-concerning-health-for-the-purpose-en, 2020-04-21 — https://overview.legal/posts/126170 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032020-on-the-processing-of-data-concerning-health-for-the-purpose_en*

Adopted 1 Guidelines 03 /2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID - 19 outbreak Adopted on 21 April 2020 Adopted 2 Version history Version 1.1 30 April 2020 Minor corrections Version 1. 0 21 April 2020 Adoption of the Guidelines Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1) (e) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the…

### EDPB-EDPS Joint Opinion 1/2019 on the processing of patients’ data and the role of the European Commission within the eHealth Digital Service Infrastructure (eHDSI)

*Source: EDPB, edpb-edps-joint-opinion-12019-on-the-processing-of-patients-data-and-en, 2019-07-12 — https://overview.legal/posts/126222 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-12019-on-the-processing-of-patients-data-and_en*

1 EDPB - EDPS Joint Opinion 1/2019 on the processing of patients’ data and the role of the European Commission within the eHealth Digital Service Infrastructure (eHDSI) 2 TABLE OF CO NTENTS 1 Background ................................ ................................ ................................ ................................ ..... 3 2 Scope of the opinion ................................ ................................ ................................ ...................... 4 3…

### EDPB Document on response to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research

*Source: EDPB, edpb-document-on-response-to-the-request-from-the-european-commission-for-en, 2021-02-02 — https://overview.legal/posts/126069 — original: https://www.edpb.europa.eu/documents/other-guidance/edpb-document-on-response-to-the-request-from-the-european-commission-for_en*

EDPB Document on r esponse to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research Adopted on 2 February 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 70.1.b of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Statement on the processing of personal data in the context of reopening of borders following the COVID-19 outbreak

*Source: EDPB, statement-on-the-processing-of-personal-data-in-the-context-of-reopening-of-en, 2020-06-16 — https://overview.legal/posts/126144 — original: https://www.edpb.europa.eu/documents/statement/statement-on-the-processing-of-personal-data-in-the-context-of-reopening-of_en*

1 Statement on the processing of personal data in the context of reopening of borders following the COVID - 19 outbreak Adopted on 16 June 2020 The European Data Protection Board has adopted the following statement: 1. In the Communication from the Commission on the third assessment of the application of the temporary restriction on non - essential travel to the EU from 11 June 2020, the Schengen Member States and Schengen Associated State s are invited to lift internal border controls by 15…

### Statement on the processing of personal data in the context of the COVID-19 outbreak

*Source: EDPB, statement-on-the-processing-of-personal-data-in-the-context-of-the-covid-19-en, 2020-03-19 — https://overview.legal/posts/126176 — original: https://www.edpb.europa.eu/documents/statement/statement-on-the-processing-of-personal-data-in-the-context-of-the-covid-19_en*

1 Statement on the processing of personal data in the context of the COVID - 19 outbreak . Adopted on 19 March 2020 The European Data Protection Board has adopted the following statement: Governments, p ublic and private organisations throughout Europe are taking measures to contain and mitigate COVID - 19. This can involve the processing of different types of personal data. Data protection rules ( such as the GDPR ) do not hinder measures taken in the fight against the coronavirus pandemic.…

### Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)

*Source: EDPB, opinion-32019-concerning-the-questions-and-answers-on-the-interplay-en, 2019-01-23 — https://overview.legal/posts/126252 — original: https://www.edpb.europa.eu/documents/legislative-opinion/opinion-32019-concerning-the-questions-and-answers-on-the-interplay_en*

1 Opinion 3/ 2 019 c oncerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR) (art. 70. 1. b)) Adopted on 23 January 2019 2 3 The European Data Protection Board Having regard to Article 70.1.b of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data,…

### Opinion 2/2018 on the draft list of the competent supervisory authority of Belgium regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-22018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126274 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-22018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 2 /2018 on the draft list of the competent supervisory authority of Belgium regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

## Enforcement decisions

### Italian DPA: Justice Ministry unlawful disclosure of employee health data in service order

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-20 — https://overview.legal/posts/144019 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10254256*

Facts — The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who certified that the data subject was fit for service but had to be exempted from wearing a duty belt and could not hold fixed postures for long periods, the facility issued a service order assigning him to a specific operational unit. The service order referred to the data subject's "physical conditions", his "health needs" and the need for an "alternation of posture". The service order itself provided that a copy would be posted on the institute's noticeboard for publicity purposes. Copies were displayed on the noticeboard located in the bar/canteen area and in the TV/relax area, both accessible to all staff on duty but not to outsiders. Further copies were sent to the head of department, the services office, the coordinator of the records office and the penitentiary police secretariat, as well as to the trade unions, and the document was filed in the official collection of service orders. The data subject filed a complaint with the DPA. During the investigation, the controller argued that the reference to the alternation of posture did not disclose any sensitive data and merely justified the assignment decision to other staff. It also argued that, as an administrative act, the service order had to state the reasons of fact and law behind it under Article 3 of Law 241/1990, that its display and communication to the trade unions followed from transparency rules on administrative acts and from the National Framework Agreement for Penitentiary Police Personnel, and that the data subject had been notified of the order and had not objected at the time. The controller added that the order was replaced on the noticeboard after a short period and that all internal recipients were instructed and authorised to process personal data. Holding — First, the DPA held that the information in the service order constituted health data under Article 4(15) GDPR. The references to the data subject's physical conditions, health needs and the need to alternate his posture related unequivocally to his overall psychophysical state, even without any express diagnosis, and the order had been issued precisely to implement the measures prescribed by the occupational health physician under Article 42 of Legislative Decree 81/2008. The DPA also noted that the reference to the alternation of posture allowed anyone to infer the nature of the data subject's condition. Second, the DPA recalled that an employer may access the fitness-for-duty assessment and the working conditions prescribed by the occupational health physician, but only through staff specifically appointed and authorised to process such data. Making data available to persons who are not authorised to process it, even where they belong to the controller's own organisation, amounts to a communication of personal data that requires a legal basis under Article 2-ter of the Italian Data Protection Code and, for health data, under Article 9 GDPR. The DPA found that the display of the order on a noticeboard accessible to all staff, and its transmission to the trade unions, made the data available to colleagues and third parties who had no need to know it. Access should have been restricted, on strict proportionality grounds, to the staff responsible for actually implementing the measures in the exercise of managerial and organisational functions. Therefore, the DPA found a violation of Articles 5(1)(a), 6 and 9 GDPR and Article 2-ter of the Italian Data Protection Code. Third, the DPA rejected the controller's justification based on the duty to give reasons for an administrative act. The document remained in full in the administration's files and was accessible to anyone demonstrating a direct, concrete and current interest under Articles 22 of Law 241/1990 and Articles 59 and 60 of the Italian Data Protection Code. A generic reference to transparency rules on administrative acts was not sufficient either, since those rules do not provide for disclosure by way of noticeboard display. Fourth, the DPA held that collective agreements cannot constitute an appropriate legal basis for a communication of personal data. Collective agreements may only specify, in favour of employees, a framework already laid down by national legislation and cannot introduce a new processing operation not provided for by law. The DPA added that, even where union prerogatives do entail communications to trade unions, these must comply with the necessity principle and be accompanied by specific safeguards, all the more so where the data concern the most intimate sphere of the person. Finally, the DPA classified the gravity of the violation as medium. It considered that the case concerned a single data subject and that the order remained on the noticeboard for a very short time, but also that the conduct reflected an ordinary practice based on collective agreements. The violation was negligent, as the controller had acted in the mistaken belief that it was complying with the applicable rules. As mitigating factors, the DPA took into account the controller's full cooperation during the investigation and the absence of relevant previous violations at the facility concerned. On these grounds, the DPA fined the controller €12,000.

### VDAI (Lithuania) - 3R-1143

*Source: VDAI (Lithuania), 2026-06-19 — https://overview.legal/posts/53896 — original: https://gdprhub.eu/index.php?title=VDAI_(Lithuania)_-_3R-1143*

Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other personal data of patients (the data subjects). The first breach potentially concerned 63 data subjects, whereas the latter breach affected approximately 10,000 employees and 383,000 data subjects. The DPA initiated two separate investigations against the controllers in September 2024 and November 2025 respectively and later combined the cases. Holding — The DPA imposed a fine of €450,000 on the first controller it investigated as this company was also the legal successor of the other controller. It held that the controllers had failed to implement appropriate technical and organisational measures to ensure the security of processing and compliance with the principles of integrity and confidentiality. The controller had violated Articles 5(1)(f), 24(1), and 32(1)(b) GDPR. When assessing the GDPR infringements, the DPA took into account that the controllers processed sensitive categories of personal data. The DPA held the controllers lacked adequate security measures for protecting against unauthorised access to an IT system, such as access control and authentication. For instance, passwords used by employees did not reach a certain level of complexity, and multi-factor authentication was not used.

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### Austrian DSB: sharing ADHD diagnosis from public forum post did not breach Art. 9 GDPR

*Source: DSB (Austria), 2025-12-03 — https://overview.legal/posts/108990 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-0.968.031*

Facts — A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data subject and had previously been in personal contact with them, knew that the pseudonym belonged to the data subject. The controller subsequently sent a WhatsApp message to a mutual acquaintance stating that the data subject had received an ADHD diagnosis and included a link to the forum post. The data subject lodged a complaint with the Austrian DPA (DSB), arguing that their health data had been disclosed to a third party. They alleged that the controller by forwarding the pseudonymous forum profile, had unequivocally linked it to their real identity. Holding — The DPA held that the data subject was identifiable to the controller as regards the publication of the forum post under her profile name. Since the post also included information concerning her gender, age and diagnosis, it concluded that it constituted her personal data under Article 4(1) GDPR. The DPA further held that the prohibition on processing special categories of personal data under Article 9(1) GDPR did not apply because the data subject had manifestly made their health data public within the meaning of Article 9(2)(e) GDPR. It reasoned that actively disclosing the ADHD diagnosis in a publicly accessible forum constituted an unambiguous and conscious act by which the data subject made the information available to the public. The DPA therefore dismissed the complaint as unfounded.

### APARELLS ORTOPEDICS CURTO, S.L: Onvoldoende naleving van de rechten van betrokkenen.

*Source: Spanish Data Protection Authority (aepd), 2025-10-28 — https://overview.legal/posts/51988*

De Spaanse autoriteit voor gegevensbescherming heeft APARELLS ORTOPEDICS CURTO, S.L. een boete van 6.000 euro opgelegd. De verantwoordelijke partij was niet in staat om de gegevens te bewaren die nodig waren om de beschikbaarheid ervan te garanderen, wat resulteerde in het feit dat de verantwoordelijke partij niet adequaat kon reageren op een verzoek van een betrokkene om haar rechten uit te oefenen. De oorspronkelijke boete van 10.000 euro is verlaagd tot 6.000 euro vanwege de onmiddellijke betaling en de erkenning van verantwoordelijkheid door de verantwoordelijke partij.

### Menarini Silicon Biosystems SpA: Niet-naleving van de algemene principes voor gegevensverwerking.

*Source: Italian Data Protection Authority (Garante), 2025-05-21 — https://overview.legal/posts/52267*

De Italiaanse gegevensbeschermingsautoriteit heeft Menarini Silicon Biosystems SpA een boete van 21.000 euro opgelegd. De verantwoordelijke organisatie voert oncologisch onderzoek uit en heeft een software ontwikkeld die in staat is om menselijke cellen te classificeren. De verantwoordelijke organisatie heeft gebruik gemaakt van geanonimiseerde gezondheidsgegevens van een Amerikaans bedrijf dat deel uitmaakt van dezelfde groep. De verantwoordelijke organisatie heeft nagelaten ervoor te zorgen dat de betrokkenen voldoende informatie ontvingen en dat er voldoende beperkingen werden aangebracht met betrekking tot de opslag van gegevens. De verantwoordelijke organisatie heeft ook niet aangetoond dat zij voldoet aan de geografische beperkingen.

### Chief Commander of the Police: Insufficient legal basis for data processing

*Source: Polish National Personal Data Protection Office (UODO), 2025-03-24 — https://overview.legal/posts/48703 — original: https://www.enforcementtracker.com/ETid-2588*

The Polish DPA has fined the Chief Commander of the Polish Police EUR 17,600. During a press conference, the Chief Commander of the Police disclosed the personal and medical data of an individual who had had an abortion which had been the subject of an investigation by the Polish police. The disclosure was specific enough to allow a third party to identify the person. This resulted in the specific danger of discrimination, loss of reputation and loss of control over their own data. Therefore, th

### Primary Health Care in the Capital Area: Insufficient legal basis for data processing

*Source: Icelandic data protection authority ('Persónuvernd'), 2025-02-17 — https://overview.legal/posts/48717 — original: https://www.enforcementtracker.com/ETid-2602*

The Icelandic DPA has imposed a fine of EUR 34,300 on the Primary Health Care in the Capital Area. The controller processed personal and health data in shared medical record systems by merging its medical records with those of other parties and granting them access to its patients' records.

## Recent developments

### DPC (Ireland) - IN-19-9-4

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291263 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_IN-19-9-4*

The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR.The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR. English Summary. English Summary On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the

### EU Commission internal draft would wreck core principles of the GDPR

*Source: noyb - European Center for Digital Rights, 2025-11-10 — https://overview.legal/posts/49184 — original: https://noyb.eu/en/eu-commission-about-wreck-core-principles-gdpr*

GDPR Policy As gradually leaked the last days by various news outlets, the EU Commission has secretly set in motion a potentially massive reform of the GDPR. If internal drafts become reality, this would have significant impact on people's fundamental right to privacy and data protection. The reform would be part of the so-called "Digital Omnibus" which was supposed to only bring targeted adjustments to simplify compliance for businesses. Now, the Commission proposes changes to core elements lik

### Health data and use of cookies: DOCTISSIMO fined €380,000

*Source: CNIL, 2023-05-17 — https://overview.legal/posts/6202 — original: https://www.cnil.fr/en/health-data-and-use-cookies-doctissimo-fined-eu380000#entry-5237*

Background information
Following a complaint by the PRIVACY INTERNATIONAL association, the CNIL carried out four investigations into DOCTISSIMO. The doctissimo.fr website mainly offers articles, tests, quizzes and discussion forums related to health and well-being for the general public.
During its investigations, the CNIL noted several infringements, in particular concerning the duration of data retention, the collection of health data via online tests, the security of data as well as the wayco

### Court of Audit points out obstacles in implementation of GDPR in Netherlands in letter to Chamber

*Source: IT en Recht, 2023-04-04 — https://overview.legal/posts/6219 — original: https://www.itenrecht.nl/artikelen/algemene-rekenkamer-wijst-in-brief-aan-kamer-op-obstakels-bij-de-uitvoering-van-de-avg-in-nederland#entry-4294*

The Court of Audit has sent a letter to the House of Representatives pointing out obstacles in the implementation of the General Data Protection Regulation (AVG) in the Netherlands. Implementing organizations are struggling with the AVG and this can lead to negative consequences for citizens. Recommendations are made to enable data sharing and pay attention to data sharing between implementers to prevent zoonoses and address healthcare fraud. The AVG provides room to process personal data, but t

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

## Literature

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### Criminal Offence and Health Condition Information as Special Categories of Data, and the Legal Aspects of Processing in Labor Relations under GDPR and Georgian Law

*Source: ORBELIANI LAW REVIEW, 2025-03-11 — https://overview.legal/posts/132538 — original: https://doi.org/10.52340/olr.2024.03.01.05*

71 Orbeliani Law Review  Vol. 3, No. 1, 2024 Simoni Takashvili* ORCID: 0000-0001-8608-170X Criminal Offence and Health Condition Information as Special Categories of Data, and the Legal Aspects of Processing in Labor Relations under GDPR and Georgian Law ABSTRACT Criminal offence and health condition information as special categories of data present significant legal challenges in labor relations. The new Personal Data Protection Law outlines the general regulations regarding criminal offence and health condition information as special categories of personal data. The prin - ciples governing the processing of this personal information are very specific, and depend on several factors, especially in employment contexts. Employers have access to private data related to candidates during the pre-contractual phase, and to employees during the contractual relationship. This access car - ries a high risk of breaching the principles of processing special categories of personal data. This article provides a comprehensive analysis of the processing of criminal of - fence and health condition information as special categories of data by the em - ployer. This issue is analyzed within the cont

### LEGAL REGULATION OF THE PROTECTION OF PERSONAL DATA OF EMPLOYEES UNDER THE GDPR

*Source: Law and Society, 2023-01-01 — https://overview.legal/posts/132610 — original: https://doi.org/10.32842/2078-3736/2023.2.2.20*

134 ПРАВО І СУСПІЛЬСТВО № 2 / 2023. Т. 2 ЛУЦЕНКО О. Є., кандидатка юридичних наук, доцентка кафедри трудового права права (Національний юридичний університет імені Ярослава Мудрого) УДК 349.2:[342.721:004.056.5] DOI https://doi.org/10.32842/2078-3736/2023.2.2.20 ПРАВОВЕ РЕГУЛЮВАННЯ ЗАХИСТУ ПЕРСОНАЛЬНИХ ДАНИХ ПРАЦІВНИКІВ ЗА GDPR У статті висвітлюється, що Регламент GDPR діє екстериторіально, оскільки поширюється на суб’єктів, що отримують та обробляють персональні дані гро - мадян та резидентів ЄС незалежно від свого місцезнаходження. GDPR не вима - гає, аби національні уряди розробляли спеціальні акти для його впровадження, і є безпосередньо обов’язковим до виконання. Авторка встановила, що відповідно до GDPR, працівник повинен мати можливість чітко розрізняти дані, на обробку/зберігання яких він/вона вільно погоджується та знати цілі, для яких зберігаються його/її дані. Співробітники також повинні бути проінформованими про свої права та тривалість часу, про - тягом якого дані зберігатимуться, перш ніж можна буде надати згоду. Якщо порушення персональних даних може призвести до високого ризику для прав і свобод фізичних осіб, то роботодавець повинен сповістити про це працівника. GD

### ‘Leading by Science’ through Covid-19: the GDPR Automated Decision-Making

*Source: International Journal of Population Data Science, 2021-02-24 — https://overview.legal/posts/132597 — original: https://doi.org/10.23889/ijpds.v5i4.1402*

The UK government announced in March 2020 that it would create an NHS Covid-19 ‘Data Store’ from information routinely collected as part of the health service. This ‘Store’ would use a number of sources of population data to provide a ‘single source of truth’ about the spread of the coronavirus in England. The initiative illustrates the difficulty of relying on automated processing when making healthcare decisions under the General Data Protection Regulation (GDPR). The end-product of the store,

### Recommendations for Creating Codes of Conduct for Processing Personal Data in Biobanking Based on the GDPR art.40

*Source: Frontiers in Genetics, 2021-11-12 — https://overview.legal/posts/132560 — original: https://doi.org/10.3389/fgene.2021.711614*

Personal data protection has become a fundamental normative challenge for biobankers and scientists researching human biological samples and associated data. The General Data Protection Regulation (GDPR) harmonises the law on protecting personal data throughout Europe and allows developing codes of conduct for processing personal data based on GDPR art. 40. Codes of conduct are a soft law measure to create protective standards for data processing adapted to the specific area, among others, to bi

## Related topics

- **Healthcare** — https://overview.legal/topics/zorg
  Processing of health data and medical information
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Healthcare** — https://overview.legal/topics/healthcare
  Processing in healthcare and medical context
- **Special Categories of Data** — https://overview.legal/topics/bijzondere-persoonsgegevens
  Sensitive data requiring enhanced protection (health, biometric, etc.)
- **Types of Special Categories of Personal Data** — https://overview.legal/topics/special-categories-data-types
  A dedicated topic is needed to comprehensively cover the specific types and definitions of special categories of personal data, including racial/ethnic origin, 
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data

---
Generated by overview.legal · https://overview.legal/topics/health-data · 2026-08-22
