# Healthcare — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/healthcare
> Sources are cited per item. Verify against the official texts before relying on them.

Processing in healthcare and medical context

## Overview

## Legal Framework

Health data receives heightened protection under Article 9(1) GDPR, which prohibits processing of personal data concerning health unless an Article 9(2) exception applies. Recital 35 defines health data broadly: it encompasses all data revealing past, present, or future physical or mental health status, including information collected during registration for or provision of healthcare services, as well as identifiers assigned for health purposes. This sweeping definition captures everything from clinical records to medical registration numbers.

The primary legal bases for healthcare processing typically arise under Article 9(2)(a) (explicit consent), Article 9(2)(h) (medical diagnosis, treatment, or health service management), and Article 9(2)(i) (public health). A separate Article 6 basis is always required alongside the Article 9 condition. The AI Act Recital 4 further signals that AI deployment in healthcare—spanning diagnostics, resource allocation, and personalized treatment—will face additional scrutiny, particularly where health data trains or operates AI systems.

## Key Developments

The *V v. European Parliament* decision establishes that transferring medical data between institutions constitutes an interference with Article 8 ECHR rights regardless of the recipient's purpose. Critically, even where a legitimate employment-law obligation exists to assess fitness for duty, the transfer must be *necessary*—the institution must demonstrate that no less intrusive alternative was available. In that case, the Parliament could have verified fitness without receiving the full medical file, rendering the transfer unlawful.

The Rotterdam District Court (ROT 20/3286) awarded immaterial damages for unlawful retention and processing of medical reports, confirming that violations of health-data provisions trigger not only administrative fines but also civil liability. The same court's detailed psychiatric examination framework in the childcare benefits scandal illustrates how medical data processing in litigation contexts requires proportionality: requests for anamnesis, treatment history, and ADL limitations must be scoped to the specific legal question at issue.

Enforcement confirms regulators' focus on healthcare sector compliance. The Irish DPC fined Midlands Regional Hospital Tullamore €300,000 for violations spanning Articles 5(1)(f), 28, 30, 32(1), and 34 GDPR—covering integrity, processor contracts, records of processing, security measures, and breach notification. The Italian Garante's action against Copacabana s.r.l. reinforces that insufficient legal basis remains a foundational enforcement trigger even at lower fine levels.

## Practical Guidance

- **Map each processing purpose to a specific Article 9(2) condition and a corresponding Article 6 basis.** Healthcare providers relying on Article 9(2)(h) must confirm processing genuinely relates to health service management, not administrative convenience.

- **Apply the necessity test from *V v. European Parliament* to all inter-institutional transfers.** Before sharing medical data with any third party—including employers, insurers, or other care providers—document why no less intrusive measure suffices.

- **Maintain executed Article 28 agreements with all processors and keep Article 30 records current.** The Tullamore fine demonstrates that processor governance and processing inventories are independently enforceable in healthcare settings.

- **Implement Article 32 security measures calibrated to health data sensitivity and establish Article 34 breach notification protocols.** The Dutch DPA's Woo-decision on healthcare data leaks signals active monitoring of breach response timelines.

- **Scope medical examinations and data requests in litigation to the specific legal question.** The Rotterdam court's structured questionnaire approach shows that proportionality in data collection is judicially enforceable and excess collection risks damages liability.

## Legislation (full text of key provisions)

### Recital 35 — health personal data definition scope

*Source: GDPR, gdpr-rec-35-en, 2016-04-27 — https://overview.legal/posts/91585*

Personal data concerning health should include all data pertaining to the health status of a data subject which reveal information relating to the past, current or future physical or mental health status of the data subject. This includes information about the natural person collected in the course of the registration for, or the provision of, health care services as referred to in Directive 2011/24/EU of the European Parliament and of the Council (9) to that natural person; a number, symbol or particular assigned to a natural person to uniquely identify the natural person for health purposes; information derived from the testing or examination of a body part or bodily substance, including from genetic data and biological samples; and any information on, for example, a disease, disability, disease risk, medical history, clinical treatment or the physiological or biomedical state of the data subject independent of its source, for example from a physician or other health professional, a hospital, a medical device or an in vitro diagnostic test.

### Recital 58 — AI essential public services access

*Source: AI Act, aiact-rec-58-en, 2024-06-12 — https://overview.legal/posts/93798*

Another area in which the use of AI systems deserves special consideration is the access to and enjoyment of certain essential private and public services and benefits necessary for people to fully participate in society or to improve one’s standard of living. In particular, natural persons applying for or receiving essential public assistance benefits and services from public authorities namely healthcare services, social security benefits, social services providing protection in cases such as maternity, illness, industrial accidents, dependency or old age and loss of employment and social and housing assistance, are typically dependent on those benefits and services and in a vulnerable position in relation to the responsible authorities. If AI systems are used for determining whether such benefits and services should be granted, denied, reduced, revoked or reclaimed by authorities, including whether beneficiaries are legitimately entitled to such benefits or services, those systems may have a significant impact on persons’ livelihood and may infringe their fundamental rights, such as the right to social protection, non-discrimination, human dignity or an effective remedy and should therefore be classified as high-risk. Nonetheless, this Regulation should not hamper the development and use of innovative approaches in the public administration, which would stand to benefit from a wider use of compliant and safe AI systems, provided that those systems do not entail a high risk to legal and natural persons. In addition, AI systems used to evaluate the credit score or creditworthiness of natural persons should be classified as high-risk AI systems, since they determine those persons’ access to financial resources or essential services such as housing, electricity, and telecommunication services. AI systems used for those purposes may lead to discrimination between persons or groups and may perpetuate historical patterns of discrimination, such as that based on racial or ethnic origins, gender, disabilities, age or sexual orientation, or may create new forms of discriminatory impacts. However, AI systems provided for by Union law for the purpose of detecting fraud in the offering of financial services and for prudential purposes to calculate credit institutions’ and insurance undertakings’ capital requirements should not be considered to be high-risk under this Regulation. Moreover, AI systems intended to be used for risk assessment and pricing in relation to natural persons for health and life insurance can also have a significant impact on persons’ livelihood and if not duly designed, developed and used, can infringe their fundamental rights and can lead to serious consequences for people’s life and health, including financial exclusion and discrimination. Finally, AI systems used to evaluate and classify emergency calls by natural persons or to dispatch or establish priority in the dispatching of emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems, should also be classified as high-risk since they make decisions in very critical situations for the life and health of persons and their property.

### Recital 50 — high-risk classification of safety-related AI systems

*Source: AI Act, aiact-rec-50-en, 2024-06-12 — https://overview.legal/posts/93782*

As regards AI systems that are safety components of products, or which are themselves products, falling within the scope of certain Union harmonisation legislation listed in an annex to this Regulation, it is appropriate to classify them as high-risk under this Regulation if the product concerned undergoes the conformity assessment procedure with a third-party conformity assessment body pursuant to that relevant Union harmonisation legislation. In particular, such products are machinery, toys, lifts, equipment and protective systems intended for use in potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft equipment, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, automotive and aviation.

### Recital 96 — fundamental rights impact assessment deployers

*Source: AI Act, aiact-rec-96-en, 2024-06-12 — https://overview.legal/posts/93874*

In order to efficiently ensure that fundamental rights are protected, deployers of high-risk AI systems that are bodies governed by public law, or private entities providing public services and deployers of certain high-risk AI systems listed in an annex to this Regulation, such as banking or insurance entities, should carry out a fundamental rights impact assessment prior to putting it into use. Services important for individuals that are of public nature may also be provided by private entities. Private entities providing such public services are linked to tasks in the public interest such as in the areas of education, healthcare, social services, housing, administration of justice. The aim of the fundamental rights impact assessment is for the deployer to identify the specific risks to the rights of individuals or groups of individuals likely to be affected, identify measures to be taken in the case of a materialisation of those risks. The impact assessment should be performed prior to deploying the high-risk AI system, and should be updated when the deployer considers that any of the relevant factors have changed. The impact assessment should identify the deployer’s relevant processes in which the high-risk AI system will be used in line with its intended purpose, and should include a description of the period of time and frequency in which the system is intended to be used as well as of specific categories of natural persons and groups who are likely to be affected in the specific context of use. The assessment should also include the identification of specific risks of harm likely to have an impact on the fundamental rights of those persons or groups. While performing this assessment, the deployer should take into account information relevant to a proper assessment of the impact, including but not limited to the information given by the provider of the high-risk AI system in the instructions for use. In light of the risks identified, deployers should determine measures to be taken in the case of a materialisation of those risks, including for example governance arrangements in that specific context of use, such as arrangements for human oversight according to the instructions of use or, complaint handling and redress procedures, as they could be instrumental in mitigating risks to fundamental rights in concrete use-cases. After performing that impact assessment, the deployer should notify the relevant market surveillance authority. Where appropriate, to collect relevant information necessary to perform the impact assessment, deployers of high-risk AI system, in particular when AI systems are used in the public sector, could involve relevant stakeholders, including the representatives of groups of persons likely to be affected by the AI system, independent experts, and civil society organisations in conducting such impact assessments and designing measures to be taken in the case of materialisation of the risks. The European Artificial Intelligence Office (AI Office) should develop a template for a questionnaire in order to facilitate compliance and reduce the administrative burden for deployers.

### Recital 64 — mandatory requirements for high-risk AI systems

*Source: AI Act, aiact-rec-64-en, 2024-06-12 — https://overview.legal/posts/93810*

To mitigate the risks from high-risk AI systems placed on the market or put into service and to ensure a high level of trustworthiness, certain mandatory requirements should apply to high-risk AI systems, taking into account the intended purpose and the context of use of the AI system and according to the risk-management system to be established by the provider. The measures adopted by the providers to comply with the mandatory requirements of this Regulation should take into account the generally acknowledged state of the art on AI, be proportionate and effective to meet the objectives of this Regulation. Based on the New Legislative Framework, as clarified in Commission notice ‘The “Blue Guide” on the implementation of EU product rules 2022’, the general rule is that more than one legal act of Union harmonisation legislation may be applicable to one product, since the making available or putting into service can take place only when the product complies with all applicable Union harmonisation legislation. The hazards of AI systems covered by the requirements of this Regulation concern different aspects than the existing Union harmonisation legislation and therefore the requirements of this Regulation would complement the existing body of the Union harmonisation legislation. For example, machinery or medical devices products incorporating an AI system might present risks not addressed by the essential health and safety requirements set out in the relevant Union harmonised legislation, as that sectoral law does not deal with risks specific to AI systems. This calls for a simultaneous and complementary application of the various legislative acts. To ensure consistency and to avoid an unnecessary administrative burden and unnecessary costs, providers of a product that contains one or more high-risk AI system, to which the requirements of this Regulation and of the Union harmonisation legislation based on the New Legislative Framework and listed in an annex to this Regulation apply, should have flexibility with regard to operational decisions on how to ensure compliance of a product that contains one or more AI systems with all the applicable requirements of that Union harmonised legislation in an optimal manner. That flexibility could mean, for example a decision by the provider to integrate a part of the necessary testing and reporting processes, information and documentation required under this Regulation into already existing documentation and procedures required under existing Union harmonisation legislation based on the New Legislative Framework and listed in an annex to this Regulation. This should not, in any way, undermine the obligation of the provider to comply with all the applicable requirements.

### Recital 63 — data subject right of access

*Source: GDPR, gdpr-rec-63-en, 2016-04-27 — https://overview.legal/posts/91641*

A data subject should have the right of access to personal data which have been collected concerning him or her, and to exercise that right easily and at reasonable intervals, in order to be aware of, and verify, the lawfulness of the processing. This includes the right for data subjects to have access to data concerning their health, for example the data in their medical records containing information such as diagnoses, examination results, assessments by treating physicians and any treatment or interventions provided. Every data subject should therefore have the right to know and obtain communication in particular with regard to the purposes for which the personal data are processed, where possible the period for which the personal data are processed, the recipients of the personal data, the logic involved in any automatic personal data processing and, at least when based on profiling, the consequences of such processing. Where possible, the controller should be able to provide remote access to a secure system which would provide the data subject with direct access to his or her personal data. That right should not adversely affect the rights or freedoms of others, including trade secrets or intellectual property and in particular the copyright protecting the software. However, the result of those considerations should not be a refusal to provide all information to the data subject. Where the controller processes a large quantity of information concerning the data subject, the controller should be able to request that, before the information is delivered, the data subject specify the information or processing activities to which the request relates.

### Recital 53 — special health data processing conditions

*Source: GDPR, gdpr-rec-53-en, 2016-04-27 — https://overview.legal/posts/91621*

Special categories of personal data which merit higher protection should be processed for health-related purposes only where necessary to achieve those purposes for the benefit of natural persons and society as a whole, in particular in the context of the management of health or social care services and systems, including processing by the management and central national health authorities of such data for the purpose of quality control, management information and the general national and local supervision of the health or social care system, and ensuring continuity of health or social care and cross-border healthcare or health security, monitoring and alert purposes, or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, based on Union or Member State law which has to meet an objective of public interest, as well as for studies conducted in the public interest in the area of public health. Therefore, this Regulation should provide for harmonised conditions for the processing of special categories of personal data concerning health, in respect of specific needs, in particular where the processing of such data is carried out for certain health-related purposes by persons subject to a legal obligation of professional secrecy. Union or Member State law should provide for specific and suitable measures so as to protect the fundamental rights and the personal data of natural persons. Member States should be allowed to maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health. However, this should not hamper the free flow of personal data within the Union when those conditions apply to cross-border processing of such data.

### Recital 84 — Third parties becoming high-risk AI providers

*Source: AI Act, aiact-rec-84-en, 2024-06-12 — https://overview.legal/posts/93850*

To ensure legal certainty, it is necessary to clarify that, under certain specific conditions, any distributor, importer, deployer or other third-party should be considered to be a provider of a high-risk AI system and therefore assume all the relevant obligations. This would be the case if that party puts its name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are allocated otherwise. This would also be the case if that party makes a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in a way that it remains a high-risk AI system in accordance with this Regulation, or if it modifies the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service, in a way that the AI system becomes a high-risk AI system in accordance with this Regulation. Those provisions should apply without prejudice to more specific provisions established in certain Union harmonisation legislation based on the New Legislative Framework, together with which this Regulation should apply. For example, Article 16(2) of Regulation (EU) 2017/745, establishing that certain changes should not be considered to be modifications of a device that could affect its compliance with the applicable requirements, should continue to apply to high-risk AI systems that are medical devices within the meaning of that Regulation.

### Recital 29 — prohibition of manipulative AI systems

*Source: AI Act, aiact-rec-29-en, 2024-06-12 — https://overview.legal/posts/93740*

AI-enabled manipulative techniques can be used to persuade persons to engage in unwanted behaviours, or to deceive them by nudging them into decisions in a way that subverts and impairs their autonomy, decision-making and free choices. The placing on the market, the putting into service or the use of certain AI systems with the objective to or the effect of materially distorting human behaviour, whereby significant harms, in particular having sufficiently important adverse impacts on physical, psychological health or financial interests are likely to occur, are particularly dangerous and should therefore be prohibited. Such AI systems deploy subliminal components such as audio, image, video stimuli that persons cannot perceive, as those stimuli are beyond human perception, or other manipulative or deceptive techniques that subvert or impair person’s autonomy, decision-making or free choice in ways that people are not consciously aware of those techniques or, where they are aware of them, can still be deceived or are not able to control or resist them. This could be facilitated, for example, by machine-brain interfaces or virtual reality as they allow for a higher degree of control of what stimuli are presented to persons, insofar as they may materially distort their behaviour in a significantly harmful manner. In addition, AI systems may also otherwise exploit the vulnerabilities of a person or a specific group of persons due to their age, disability within the meaning of Directive (EU) 2019/882 of the European Parliament and of the Council (16), or a specific social or economic situation that is likely to make those persons more vulnerable to exploitation such as persons living in extreme poverty, ethnic or religious minorities. Such AI systems can be placed on the market, put into service or used with the objective to or the effect of materially distorting the behaviour of a person and in a manner that causes or is reasonably likely to cause significant harm to that or another person or groups of persons, including harms that may be accumulated over time and should therefore be prohibited. It may not be possible to assume that there is an intention to distort behaviour where the distortion results from factors external to the AI system which are outside the control of the provider or the deployer, namely factors that may not be reasonably foreseeable and therefore not possible for the provider or the deployer of the AI system to mitigate. In any case, it is not necessary for the provider or the deployer to have the intention to cause significant harm, provided that such harm results from the manipulative or exploitative AI-enabled practices. The prohibitions for such AI practices are complementary to the provisions contained in Directive 2005/29/EC of the European Parliament and of the Council (17), in particular unfair commercial practices leading to economic or financial harms to consumers are prohibited under all circumstances, irrespective of whether they are put in place through AI systems or otherwise. The prohibitions of manipulative and exploitative practices in this Regulation should not affect lawful practices in the context of medical treatment such as psychological treatment of a mental disease or physical rehabilitation, when those practices are carried out in accordance with the applicable law and medical standards, for example explicit consent of the individuals or their legal representatives. In addition, common and legitimate commercial practices, for example in the field of advertising, that comply with the applicable law should not, in themselves, be regarded as constituting harmful manipulative AI-enabled practices.

### Recital 33 — law enforcement biometric identification exceptions

*Source: AI Act, aiact-rec-33-en, 2024-06-12 — https://overview.legal/posts/93748*

The use of those systems for the purpose of law enforcement should therefore be prohibited, except in exhaustively listed and narrowly defined situations, where the use is strictly necessary to achieve a substantial public interest, the importance of which outweighs the risks. Those situations involve the search for certain victims of crime including missing persons; certain threats to the life or to the physical safety of natural persons or of a terrorist attack; and the localisation or identification of perpetrators or suspects of the criminal offences listed in an annex to this Regulation, where those criminal offences are punishable in the Member State concerned by a custodial sentence or a detention order for a maximum period of at least four years and as they are defined in the law of that Member State. Such a threshold for the custodial sentence or detention order in accordance with national law contributes to ensuring that the offence should be serious enough to potentially justify the use of ‘real-time’ remote biometric identification systems. Moreover, the list of criminal offences provided in an annex to this Regulation is based on the 32 criminal offences listed in the Council Framework Decision 2002/584/JHA (18), taking into account that some of those offences are, in practice, likely to be more relevant than others, in that the recourse to ‘real-time’ remote biometric identification could, foreseeably, be necessary and proportionate to highly varying degrees for the practical pursuit of the localisation or identification of a perpetrator or suspect of the different criminal offences listed and having regard to the likely differences in the seriousness, probability and scale of the harm or possible negative consequences. An imminent threat to life or the physical safety of natural persons could also result from a serious disruption of critical infrastructure, as defined in Article 2, point (4) of Directive (EU) 2022/2557 of the European Parliament and of the Council (19), where the disruption or destruction of such critical infrastructure would result in an imminent threat to life or the physical safety of a person, including through serious harm to the provision of basic supplies to the population or to the exercise of the core function of the State. In addition, this Regulation should preserve the ability for law enforcement, border control, immigration or asylum authorities to carry out identity checks in the presence of the person concerned in accordance with the conditions set out in Union and national law for such checks. In particular, law enforcement, border control, immigration or asylum authorities should be able to use information systems, in accordance with Union or national law, to identify persons who, during an identity check, either refuse to be identified or are unable to state or prove their identity, without being required by this Regulation to obtain prior authorisation. This could be, for example, a person involved in a crime, being unwilling, or unable due to an accident or a medical condition, to disclose their identity to law enforcement authorities.

## Case law

### NSS - 1 As 183/2023-62

*Source: Supreme Administrative Court, 2026-08-04 — https://overview.legal/posts/184683 — original: https://gdprhub.eu/index.php?title=NSS_-_1_As_183/2023-62*

Facts — OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free Access to Information, it requested information from the General Health Insurance Company of the Czech Republic concerning the treatment of patients with iron deficiency and related conditions for the period from 1 January 2010 to 31 October 2017. The request covered 183 types of diagnoses, 18 types of medical procedures, 96 DRG codes and 13 types of medications. The company stated that it wished to analyse how specific diagnoses were treated, the number of patients treated, and the frequency of related medical procedures, in order to compare clinical practice against the relevant theoretical background. The public health insurer rejected the request on the grounds that granting it would require the creation of new information. Following an appeal by the company, the Prague Municipal Court overturned the decision. The public health insurer provided then the company with five separate tables regarding the diagnoses, diagnoses in conjunction with medical procedures, the DRG codes and prescribed medications. It aggregated the parameters of the provided data as follows: five-year age groups, dates were given only at the monthly level, and healthcare providers were classified into broad geographic regions. However, it refused to add a unique random identifier which would allow linking the individual records and tables pertaining to the same patient. The public health insurer considered that providing the code would result in the disclosure of special categories of personal data. The company lodged a complaint with the Czech DPA (UOOU), which rejected it. The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4(1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case (C-582/14), according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in Case T-557/20 (SRB v. EDPS), which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety. The company filed a cassation appeal with the Supreme Administrative Court, arguing that the information had been anonymised. It alleged that the addition of a random code with no independent meaning would not alter their anonymous nature. It claimed that the Municipal Court had not explained what specific additional information could be used to identify the patients and had relied on hypothetical scenarios. The company stated that it was objectively impossible to obtain such data through other requests in a detailed and non-aggregated form. It also argued that iron deficiency was not a rare disease, but was associated with a large number of patients and various conditions and that the data had undergone both randomisation and generalisation so the risk of identification was therefore low. Finally, the company emphasized that the tables without the random identifier could not be used effectively for the intended analysis. It further argued that the DPA and the Municipal Court had not adequately balanced the right of access to information against the right to the protection of personal data. The DPA argued that the random identifier constituted personal data when considered in conjunction with the health data to which it would be linked. It stated that the concept of personal data was not limited to information that directly identifies an individual nor did it require that all necessary additional information be held by the same entity. Replacing direct identifiers with a code did not anonymise the data, but made it pseudonymised. Moreover, it argued that certain categories contained a relatively small number of records and that combining them with other data could make it possible to select and identify a specific insured person and their treatment history. It further argued that, even if identifiability was relative, it should be assessed in relation to all potential information applicants and their ability to obtain contextual information. The Supreme Administrative Court stayed the proceedings in the case pending the CJEU’s decision in Case C-413/23 P (EDPS v. SRB). After the judgment was issued, the company argued that whether the data were pseudonymised or anonymised should be assessed in relation to the specific recipient of the data and the means that it could reasonably use. It stated that it did not have any means of re-identification and that only specific and practically available cross-referencing possibilities should be taken into account. Holding — The court relied on Case C-413/23 and noted that pseudonymised data under Article 4(5) GDPR does not automatically constitute personal data in relation to every person. Therefore, it examined whether the company had lawful means that could reasonably be expected to be used to identify the patients directly or indirectly. The court found that the tables, without the random identifier, did not allow for the identification of specific insured individuals. It held that the requested random identifier would link the records from the different tables and allow for the aggregation of information on the diagnoses, medical procedures, hospitalizations, and medications for the same patient during the eight-year period. Certain combinations of these data, along with age group, gender, and region, could be unique and allow for the identification of patients using information from public sources. It pointed out that although iron deficiency was a very common diagnosis and some tables contained a very large number of entries, other categories were not sufficiently generalised. According to the court, in certain cases, such as rare diseases, unusual treatment combinations, or particularly young or old age, knowing even a few details about a person could make it possible to identify the corresponding record. The risk was not negligible, given that information about a person’s age, gender, hospitalization, diagnosis, or treatment could be available in the media or on social media. Consequently, the court held that adding the random identifier, in conjunction with the data already provided, would make the dataset personal data in relation to the company under Article 4(1) GDPR, including health data falling under Article 9 GDPR. The court clarified that classifying the information as personal data was not sufficient in itself to reject the request. It noted that the right of access to the information must also be balanced against patients’ right to privacy through an assessment of suitability, necessity and proportionality. It determined that the decision not to provide the random identifier was appropriate for the protection of privacy, because without it, it was impossible to link the tables and identify individual patients. It was also deemed necessary because the company insisted on receiving that specific code along with the existing tables and there was no other procedure that would constitute a lesser infringement of its right to information. The court also recognized the public interest in accessing information related to the operation of the healthcare system, but ruled that this did not outweigh the need to protect the detailed health data of potentially hundreds of thousands of insured individuals. It concluded that the refusal to provide the code was therefore proportionate. The Supreme Administrative Court therefore upheld the Municipal Court’s ruling, but partially corrected its reasoning regarding the relative nature of identifiability and the need to conduct a proportionality review. It dismissed the appeal.

### Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal

*Source: Court of Justice of the European Union, C-667/21, 2023-12-21 — https://overview.legal/posts/132276 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0667*

The CJEU (Third Chamber) ruled on a preliminary reference from the Bundesarbeitsgericht in a case where ZQ sought compensation from his employer, Medizinischer Dienst der Krankenversicherung Nordrhein, for allegedly unlawful processing of his health data in connection with an assessment of his working capacity. The Court addressed the conditions under which a health insurance medical service may lawfully process special categories of health data of its own employees under GDPR Articles 6(1) and 9(2)(h)/(3), and clarified the scope of the right to compensation for non-material damage under Article 82(1), including the relevance of the controller's negligence. No fine was imposed, as the ruling concerns the interpretation of GDPR provisions for the referring court's application.

### CJEU - C-667/21 - Krankenversicherung Nordrhein

*Source: GDPRhub, 2023-12-21 — https://overview.legal/posts/156362 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-667/21_-_Krankenversicherung_Nordrhein*

Facts — The Medical Service of Health Insurance (the controller) is Germany's public health insurance medical review service. It provides expert reports when people say they are unable to work, as well as for its own staff. Before becoming unable to work, the data subject worked for the controller. The insurance company that was paying their benefits requested an expert opinion from the controller. The controller obtained health information from the data subject's doctor in the form of a medical report, which was then distributed to the data subject's coworkers. The data subject believed that their medical data had been unlawfully processed and sought €20,000 in damages from the controller, who rejected the claims. According to the data subject, the evaluation should have been performed by another organisation in order to prevent coworkers from accessing their medical data. Furthermore, they considered the security procedures around their medical report's archiving to be inadequate. After being rejected at first and second (Landesarbeitsgericht Düsseldorf) instance, the the data subject appealed to the Federal Labour Court, who referred the case to the CJEU with the following questions: On the topic of health data 1) Does Article 9(2)(h) GDPR prohibit a medical service of a health insurance fund from processing its employee’s health data when it is a prerequisite for the assessment of that employee’s working capacity? 2) If the Court answers Question 1 in the negative (with the consequence that an exception to the prohibition on the processing of data concerning health laid down in Article 9(1) GDPR is possible under Article 9(2)(h) GDPR) in a case such as the present one, are there further data protection requirements, beyond the conditions set out in Article 9(3) GDPR, that must be complied with, and, if so, which ones? 3) If the Court answers Question 1 in the negative, does the permissibility or lawfulness of the processing of data concerning health depend on the fulfilment of at least one of the conditions set out in Article 6(1) GDPR? On the topic of non-material damages 4) Does Article 82(1) GDPR have a specific or general preventive character, and must that be taken into account in the assessment of the amount of non-material damage to be compensated at the expense of the controller or processor on the basis of Article 82(1) GDPR? 5) Is the degree of fault on the part of the controller or processor a decisive factor in the assessment of the amount of non-material damage to be compensated on the basis of Article 82(1) GDPR? In particular, can non-existent or minor fault on the part of the controller or processor be taken into account in their favour? Advocate General Opinion — Advocate General Manuel Sánchez Bordona requested that the Court answer that Articles 9(2)(h) and (3) of the GDPR, as well as Articles 82(1) and (3), be understood as: Not barring a medical service of a health insurance fund from processing data about the health of an employee of such service, when those data are required for determining that employee's working capacity. Allowing an exception to the prohibition on processing personal data relating to health where such processing is required for the purposes of assessing the employee's working capacity and complies with the principles outlined in Article 5 GDPR as well as one of the conditions for lawfulness outlined in Article 6 GDPR. Making the degree of fault on the part of the controller or processor have no bearing on establishing the liability of either of them or quantifying the amount of non-material damage to be compensated on the basis of Article 82(1) GDPR. Allowing the data subject's participation in the incident that gave rise to the compensation duty to trigger, (depending on the circumstances) an exemption from liability for the controller or processor provided for in Article 82(3) GDPR. Holding — On the topic of health data On the first question, the exception under Article 9(2)(h) GDPR applies to situations where a public organisation for medical expertise processes health data of one of its employees not as employer but as a medical service, under the condition that the concerned processing fulfils the expressly prescribed preconditions and guarantees in subparagraph (h) and Article 9(3) GDPR. The purpose of Article 9 GDPR is to ensure a high level of protection in case of processing personal data whose level of sensitivity is especially high, involving an especially strong intrusion into the fundamental rights guaranteed by Articles 7 and 8 of the Charter. Therefore, the list in Article 9(2) is exhaustive and among others Article 9(3) prescribes a number of guarantees in the case of processing based on subparagraph (h). However, there is no reason to assume that subparagraph (h) is limited to cases of processing by independent third parties. This is supported by Recital 52 which states that derogation from Article 9 is permitted when it is in the public interest to do so. The quality and cost-effectiveness of the procedures used for settling claims for benefits and services in the health-insurance system can be said to be in the public interest. On the second question, it was held that because the exemption applies, the controller can share the health data to other colleagues. When health data is processed under subparagraph (h) it also has to be processed according to Article 9(3) GDPR. Article 9(3) requirements cannot be read widely as it is explicit in its requirements. Therefore, there is no legal ground to require that colleagues of the data subject should be excluded from the processing. Having said this, member states can derogate from this rule and create higher national standards under the opening clause provided in Article 9(4) GDPR. If a Member State would do this, the CJEU recommends using the principles of intergrity and confidentiality outlined in Article 5(1)(f) and 32(1)(a) and (b) to justify it. These higher standards should be proportionate to allow the relevant organisations outlined in Article 9(2), who may not have the technical and organisational resources to fulfil these conditions, to process health data. It is for a national court to determine whether the technical and organisational measures, according to Article 32 GDPR, are satisfactory and sufficient. On the third question, if 9(2)(h) applies, it must not only comply with the provisions set out in the article, but also fulfill at least one legal bases from Article 6(1) to be considered lawful processing. This can be inferrred from Articles 5, 6 and 9 GDPR which are all included in the Chapter titled “Principles” and concern “Principles relating to processing of personal data”, “Lawfulness of processing” and “Processing of special categories of personal data”. Recital 51 GDPR expressly mentions that “the general principles and other rules of this Regulations should apply, in particular as regards the condition for lawful processing". The Court has also decided multiple times that the all processing of personal data has to comply with the preconditions of lawfulness in Article 6 and that all preconditions of Chapter II GDPR have to be complied with. On the topic of non-material damages On the fourth question, Article 82(1) GDPR has a compensatory instead of deterrant or penalising function. Compensation should fully compensate the damage suffered caused by the infraction of the GDPR. The Court reffered to the established case law that compensation can only be required based on Article 82 GDPR, when all of three cumulative conditions are fulfilled; 1) the existence of a damage, 2) an infringement of the Regulation, 3) a causal relationship exists between the infringement and the damage. The GDPR does not contain rules to define the amount of damages. National courts have to apply domestic rules of the individual Member States as far as the principles of equivalence and effectivity are complied with. Based on Recital 146, the Court states that the objective of this rule is to provide for “full and effective for the damage they have suffered”. Different from the sanctions in Articles 83 and 84, this sanction has not a penalising, but a compensating function. It has nevertheless an effect to deter from repeating the unlawful behaviour as well. On the fifth question, Article 82 GDPR needs causation (which is presumed unless the controller can prove otherwise) and does not require an assesment as to the degree of the controller's responsibility when calculating the amount of compensation awarded for a non-material damage. A controller has to compensate for a damage which arose as the consequence of an infringement of the GDPR. Recitals 4 to 8 GDPR indicate that the aim of the Regulation is to establish a balance between the rights of the controller and of the data subject. On one hand the responsibility of the controller depends on the existence on an infringement which is to be attributable to it. On the other, this is to be assumed unless the controller can prove that they have not caused it. An obligation to pay damages without causation would contradict the principle of legal certainty. However, once the existence of a damage is ascertained, Article 82 does not require national courts to take into account the gravity of the infringement or the extent of the controller's responsibility to quantify damages. Instead, the amount should be calculated to compensate fully the damage suffered.

### Personvernnemnda (Norway) - 2018-14 (15/01355)

*Source: PVN, 2019-01-21 — https://overview.legal/posts/125646 — original: https://gdprhub.eu/index.php?title=Personvernnemnda_(Norway)_-_2018-14_(15/01355)*

Facts — In 2017, the Norwegian DPA Datatilsynet found that a company "Legelisten", running an anonymous review website of healthcare personnel, lacked a legal basis for processing and instructed them to allow said personnel to opt out of being listed and reviewed, in addition to several other instructions. Both the initial complainant and Legelisten responded to the DPA's decision with complaints. The DPA considered both complaints, but did not find any grounds to change their decision. Consequently, the case was submitted to the Norwegian Privacy Appeals Board, who considered comments from the initial complainant, Legelisten, the Norwegian Consumer Council, and the DPA. The Board focused their assessment on the lawfulness of processing of personal data on the website Legelisten.no. First, they considered the applicable law, as the GDPR had entered into force since the initial complaints dating back to 2012. They found that the GDPR would indeed apply. Holding — The Board reviewed several aspects relating to the case in question, summarised below. Controller responsibility — The Board agreed with the DPA's finding that Legelisten is the controller for all processing of personal data related to their site (as listed above), for both users and the healthcare personnel, because they in all these instances determine how the personal data will be processed (the purpose) and the means (technical platform, layout, which processors to use). The relationship to freedom of speach and processing for journalistic purposes — The Board agreed with the DPA's finding that there were no exemptions or derogations for processing carried out for journalistic purposes in this case. Legal grounds for processing personal data about the users — The DPA found that Legelisten lacked a legal basis for processing contact information (email address) of users submitting reviews, because they could not rely on consent as this was not found to have been provided voluntarily. The Board agreed that email addresses will often reveal the identity of a person and is, as such, personal data, and that information related to visits to or contact with specialist healthcare personnel, will reveal special category personal data and thus requires a legal ground for processing as per Article 9(2) GDPR, in addition to Article 6(1). However, the Board were split in their view of consent being a valid legal basis for processing in this specific case. The majority disagreed with the DPA and found that Legelisten could rely on consent for processing contact information of users, because they provided sufficient sufficient information in their terms and privacy notice, and required users to provide their consent through a clear affirmative act. The Board's decision here effectively reverted the DPA's initial decision item 8. Legal grounds for processing personal data about healthcare personnel — Processing of personal data about healthcare personnel on Legelisten relates to two categories: objective vs. subjective personal data. The Board noted that the relevant legal basis in both cases is Article 6(1)(f), legitimate interest, and made a thorough assessment relating to the three-part test (the purpose test, the necessity test and the balancing test). The Board first assessed the legal basis relating to the users' subjective reviews of healthcare personnel. In the balancing test, the Board were split in their views. First, the majority found that the subjective expressions of the individual patient in principle are expressions protected by the right of freedom of speech, cf. the Norwegian Constitution § 100 and the European Convention on Human Rights Article 10, and that most healthcare personnel on Legelisten can be seen as public figures, cf. the Article 29 Data Protection Working Party guidelines 225, number 2: «Does the data subject play a role in public life? Is the data subject a public figure?». Next, the majority emphasised that patients' subjective reviews of their experiences with healthcare personnel is of public interest and Legelisten's services contributes to safeguarding important consumer interests. Hence, they concluded that a general right to opt out of being reviewed on the website, would reduce the value of Legelisten as a source of information on the quality of health-related services in Norway. They pointed to the almost immediate reservation requests from about 20% of general practicioners following the DPA's decision. In conclusion, the majority of the Board held that the various legitimate interests of Legelisten outweighed the rights and freedoms of the healthcare personnel, that the processing of their personal data is necessary for the purpose and, consequently, lawful as per Article 6(1)(f). For the objective personal data, an unanimous Board agreed that Legelisten had a legitimate interest in processing these. The Board's decision — Legelisten is the controller for all personal data published on their website. Legelisten's publishing of reviews of healthcare personnel is not subject to the exemptions or derogations for processing carried out for journalistic purposes. Legelisten has legal grounds for processing user contact information, cf. Article 6(1)(a), cf. Article 9(2)(a). Legelisten is not instructed to publish the identity of the users submitting reviews of healthcare personnel. Legelisten has legal grounds for collecting and publishing subjective reviews of healthcare personnel, cf. Article 6(1)(f), and does not have to provide healthcare personnel with the right to opt out. Legelisten has legal grounds for collecting and publishing objective personal data of healthcare personnel, cf. Article 6(1)(f), and does not have to provide healthcare personnel with the right to opt out.

### CJEU - C‑474/24 - NADA Austria and Others

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/108989 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑474/24_-_NADA_Austria_and_Others*

Facts — Several data subjects were subject to suspension proceedings by the Austrian Anti-Doping Legal Commission (ÖADR). Under Austrian law, the National Anti-Doping Agency (“NADA”) publishes the names of persons who have been suspended on its website. For the duration of the suspension, the website includes information such as the athlete’s name, sport practised, infringement of anti-doping rules, and the duration of the penalty. The ÖADR publishes the same information in a press release, with the addition of the prohibited substances involved. For this summary, both authorities are referred to as the controllers. The data subjects filed a complaint with the DPA on the grounds that the controllers refused their request to cease displaying their names and practised sports. They also argued that the controllers were processing sensitive data within the meaning of Article 9 and 10 GDPR, and that the undifferentiated publication system was incompatible with Article 6(3) GDPR. The DPA dismissed the complaint. In particular, one of the data subjects’ complaints was rejected on the grounds that the relevant data had not been published yet. The data subjects appealed the decision to the Federal Administrative Court (BVwG). The controllers argued that publishing the information in their website was lawful, as it was based on the legal bases of legal obligation (Article 6(1)(c) GDPR) and public interest (Article 6(1)(e) GDPR). The BVwG stayed proceedings and requested a preliminary ruling from the CJEU. The BVwG referred the following questions: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? If yes: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? Does the GDPR preclude national legislation from publishing the information mentioned above, if it does not make it possible to infer health data of the person concerned? Does the GDPR require a balancing test between the interests of the data subject and the interest of the general public of being informed of anti-doping violations every time anti-doping violations will be published? Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR? If yes, must the decisions of the authority processing this data be subject to judicial review? Is filing a complaint before the processing takes place (but was processed during the proceedings) permissible? Or does it become permissible provided that at the time of the complaint there were specific indications that the processing was imminent or would take place in the near future? Advocate General Opinion — The AG gave his opinion on each question separately, with the exception of the third and fourth questions that were answered together. Question 1: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? — The AG first considered that the GDPR was applicable to this case. Under Article 2(2)(d) GDPR a situation falls outside of the scope of the GDPR when data is processed for the prevention, detection or prosecution of criminal offenses. This is because the Law Enforcement Directive (LED) applies. According to the AG, the GDPR may apply even if personal data relating to criminal convictions is processed if the controllers are not “competent authorities” within the meaning of Article 3(7) LED. If the controllers were competent authorities, the referring court would have to decide if the GDPR applies. The main question the AG addressed is whether the exception under Article 2(2)(a) GDPR applies, meaning the processing falls outside the scope of Union law; here, the AG noted that the exceptions are interpreted narrowly, and may only apply to activities intended to safeguard national security or activities classified in the same category. The AG concluded that the aim of combating anti-doping is not related to national security. The exception did not apply even if the activity fell under the competence of a Member State. Therefore, the GDPR was applicable. Question 2: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? — The AG first highlighted the sensitive nature of Article 9 GDPR data, which must be interpreted broadly. The AG also noted that the legal basis of the controller does not influence whether the data falls under the scope of health data. Beyond a medical context, the AG opined that the determining factor is whether it is possible to draw inferences about the health status of the data subject. In this case, the AG agreed with the reasoning of the DPA that only specific information relating to the infringements should be considered health data. This is because not all data revealed information related to the data subjects’ health. Specifically, the information regarding the anti-doping tests and its analysis should be considered health data. The AG noted that, while the name of the substance itself may not reveal information on health status, it may be possible to make indirect inferences. However, if the name is not included, the link to the health status of the data subject would be too indirect to fall under the scope of health data. Questions 5 and 6: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR, and must the decisions of the authority processing this data be subject to judicial review? — The AG first noted that the GDPR does not prohibit processing this data, but rather subjects it to enhanced scrutiny. The AG assessed whether the processing fell under the scope of Article 10 GDPR based on the three “Engel” criteria in ECtHR case Engel and Others v. the Netherlands. Anti-doping offenses under national law do not fall under the “criminal” classification according to Article 10 GDPR. However, the AG opined that article 10 GDPR applies if the convictions have a punitive purpose and have a degree of severity equivalent to a criminal penalty. This is a matter for the BVwG to decide. In terms of judicial review, the AG stated that the authority at issue is an “official authority” within the meaning of Article 10 GDPR. The wording itself of Article 10 GDPR does not provide for judicial review. However, the AG opined that it must be possible for an act following a decision by an official authority to be subject to judicial review. This is in light of Article 79(1) GDPR and a contextual interpretation of Article 10 GDPR. Questions 3 and 4: Does the GDPR preclude national legislation from publishing the information mentioned in the facts, and does it require a balancing test every time anti-doping violations will be published? — The AG considered, in essence, whether Articles 5(1)(a) and (c), and Article 6(3) GDPR precluded the controllers to publish the data concerned under legal obligation. The AG also considered whether the GDPR requires a case-by-case balancing of interests, or whether the proportionality test provided by the legislator is sufficient. The AG noted that the aim to deter athletes and prevent circumventing of anti-doping rules are legitimate public interest objectives in the context of combating doping in sport. Making this information public online is appropriate in order to achieve the public interest aims, with the exception of referring to the prohibited substance in question. According to the AG, this was not expressly provided for by national law, and is not required to achieve the public interests involved. However, the AG considered the publication of the personal data involved a serious interference with the fundamental rights of the data subjects. While national law provided exceptions on the publication of data (e.g. amateur athletes or vulnerable persons), the AG opined that the publication of personal data for an unlimited amount of time could be considered excessive. Therefore, the AG concluded that making this information publicly accessible is only permitted as long as it is proportionate. Finally, the AG opined that a case-by-case analysis is necessary, as the controllers must comply with data minimisation and accountability principles under the GDPR even if they are designated by national law. Question 7: Is filing a complaint before the processing takes place permissible? — Here, the AG stated that the wording of the GDPR does not seem to preclude a priori a precautionary or preventative approach by the supervisory authorities in handling complaints. Restricting the powers of a DPA to decide on cases involving processing that has already taken place would go against the objectives of the GDPR. Nonetheless, the alleged infringement of the GDPR must be appropriate, and the processing in question cannot be purely hypothetical. In this case, it would be impossible for a controller to erase data that has not been disclosed yet, unless the complaint is interpreted as seeking to prevent the data from being published. The AG stated that it is a matter for the BVwG to decide. The AG noted that the complaint would be inadmissible if it was based on Article 17 GDPR even if the processing is imminent. However, the AG opined that a complaint requesting injunctive relief is potentially admissible under the GDPR and Austrian law in the event of a threat of imminent unlawful interference with data subjects’ rights under the GDPR. This includes requesting the DPA to review a restriction of processing based on Article 18 GDPR before the start of the processing or if the processing has started, as long as the processing is not purely hypothetical. Finally, the AG considered whether a complaint could become admissible a posteriori. Here, the AG opined that it is a matter of the national law system to settle the question, while complying with the principles of effectiveness and equivalence. Holding — The Court held that the GDPR applied to the publication of information concerning anti-doping infringements. Such processing did not fall within the exception under Article 2(2)(a) GDPR, even if anti-doping policy primarily falls within Member State competence. Information that a data subject infringed anti-doping rules and was banned from competitions does not, in principle, constitute health data under Article 9 GDPR. However, it may do so where the publication identifies a prohibited substance or method and, together with other information, allows conclusions to be drawn about the data subject’s health. The Court accepted that combating doping and protecting the fairness and integrity of sport constitute objectives of general interest. Nevertheless, publishing athletes’ identities and sanctions online constitutes a serious interference with their rights. National legislation may therefore require such publication only where the controller can assess, in each case, whether the content and duration of the publication are necessary and proportionate. Publication should not continue longer than strictly necessary and may be disproportionate where a sanction is lengthy or lifelong. The Court also held that Article 10 GDPR did not apply, as the anti-doping infringements formed part of a disciplinary regime and were not criminal in nature. Finally, Article 77 GDPR allows a data subject to lodge a complaint before processing takes place where there are specific indications that the processing is imminent and not merely hypothetical. The DPA must assess the substance of such a preventive complaint.

### Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t

*Source: Court of Justice of the European Union, C-169/23, 2024-11-28 — https://overview.legal/posts/132158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0169*

In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan Government Office, as controller issuing COVID-19 immunity certificates, was required to provide information to data subjects under Article 14 GDPR where the personal data was not collected directly from them. The Court held that data generated by the controller in the context of its own processes falls within the Article 14(5)(c) exemption from the obligation to provide information, provided that Member State law ensures appropriate measures to protect the data subject's legitimate interests, including data security measures under Article 32. The Court also confirmed that supervisory authorities retain competence to handle complaints under Article 77(1) even where the Article 14(5)(c) exemption applies.

### CJEU - C-101/01 - Lindqvist

*Source: GDPRhub, C-101/01, 2003-11-06 — https://overview.legal/posts/125585 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-101/01_-_Lindqvist*

Facts — The case is about Mrs. Lindqvist who worked as a catechist in the Alseda Parish (Sweden). At the end of 1998, she set up internet pages on her personal computer in order to allow parishioners preparing for their confirmation to obtain any information they needed. She requested the administrator of the Swedish Church’s website to set up a link between those pages and the website. The pages she had set up contained information about Mrs. Lindqvist and 18 of her colleagues in the parish. The pages contained information including their full names, first names, jobs held, hobbies, telephone numbers and medical information on one of her colleagues. She had not informed her colleagues of those pages, obtain their consent or sought approval from the supervisory authority to process the personal data and sensitive personal data. The public prosecutor brought a proceeding against her, that she was in breach of the PUL on grounds that she processed personal data automatically without giving prior written notice to the Supervisory Authority (Datainspektionen). In addition, she processed sensitive personal data and transferred personal data to a third country without authorization or consent from the data subjects. The Royal Court (Göta hovrätt) stayed the national proceedings and referred some question of law to the CJEU. Dispute — The questions brought before the CJEU were: Whether a self-made list, with personal data of others, published on the internet constitute processing of personal data wholly or partly by automatic means as defined under Article 3(1) Directive 95/46/EC. Whether the act of setting up internet home pages for 15 people with links between the pages which make it possible to search the pages using the first name be considered processing of personal data which forms part of a filing system within the meaning under Article 3(1) Directive 95/46/EC? Whether the processing of personal data is covered under the exception to processing under a household activity under Article 3(1) Directive 95/46/EC? Whether the reference made to the health condition of Mrs. Lindqvist colleague amounts to processing of health/medical data under Article 8(1) Directive 95/46/EC? Whether publication of information on the internet, which can be viewed by anyone in the world, amount to transfer of personal data according to Article 25 Directive 95/46/EC. Whether the provisions of Directive 95/46/EC are in conflict with the general principles of freedom of expression under Article 10 ECHR. Lastly, whether a member state can provide more extensive protection for personal data than that provided under Article 13 Directive 95/46/EC. Holding — On the first and second question, the CJEU held that the term personal data defined under Article 2(b) Directive 95/46/EC includes any information relating to an identified or identifiable natural person. Hence, the term covers the name of a person, his telephone number or information relating to his working conditions or hobbies. Regarding the question whether Mrs. Lindqvist was processing personal data using internet pages, the court referred to Article 3(1) Directive 95/46/EC and observed that, according to the definition, the term processing of personal data covers any operation performed on personal data whether or not by automatic means. Thus, the court held that the operation of loading personal data on an internet page must be considered to be processing of personal data. The court also considered the third question, whether the processing falls under the exception stipulated under Article 3(2) Directive 95/46/EC as argued by Mrs. Lindqvist. On this, the court critically examined the exceptions stipulated which include processing by a natural person in the course of a purely household or personal activity. The court interpreted the exception to mean that the exception covers only activities which are carried out in the course of purely private or family life of individuals which clearly is not the case here since the activities carried out by Mrs. Lindqvist were or charitable or religious nature. On the fourth question, the court interpreted widely Article 3(1) Directive 95/46/EC to include information concerning all aspects of physical and mental health state of an individual. Hence, Mrs. Lindqvist's reference to her colleagues health condition constitutes processing of personal data concerning health in line with Article 8(1) Directive 95/46/EC. On the fifth question, the court noted that the term transfer was not defined by Directive 95/46/EC. Hence, in order to determine whether loading personal data on an internet page constitutes transfer within the meaning of transfer envisioned under Article 25 Directive 95/46/EC, the court took into account the technical nature of the internet pages operations. The court noted that, in order for internet users to have access to the internet pages containing the personal data, they had to first connect to the internet and then proceed to carry out a search. Thus, the technical operations in question did not contain the technical means to send that information automatically to people who did not seek to access those pages. The court held that Mrs. Lindqvist did not transfer personal data as enumerated under Article 25 Directive 95/46/EC. On the sixth question, the court noted that Member states have an obligation to ensure that national laws are harmonized to ensure free flow of information between member states and also safeguard individuals’ rights and freedoms. Thus, there must be balancing of rights of individuals and economic and social integration. Mrs. Lindqvist's freedom of expression in her work to contribute to religious life had to be weighed against the protection of individual rights. To balance these two, the court emphasized on the importance of respecting the principle of proportionality that means taking into account all the circumstances of the case before it before making a decision. The court held that the provisions of Directive 95/46/EC do not necessarily bring a restriction which conflicts with the general principles of freedom of expression, but it is up to the national courts to ensure a fair balance between the rights and interests in question. On the seventh question, the court addressed the question with reference to the provisions of Recital 8 Directive 95/46/EC and Recital 10 Directive 95/46/EC. In the harmonization of laws by member states, the court reiterated the importance of having a complete harmonization of laws. The court noted that Directive 95/46 allows room for manoeuvres in certain cases, but such manoeuvres should ensure that there is a balance between the free movement of personal data and protection of private life. In conclusion, the court held that measures taken by member states to ensure the protection of personal data must be consistent with the provisions of Directive 95/46/EC. However, nothing prevents a member state from extending the scope of national legislation to areas not included in the scope of Directive 95/46/EC.

### SG Nürnberg - S 5 SF 65/24 DS

*Source: Social Court Nuremberg, 2026-06-10 — https://overview.legal/posts/122874 — original: https://gdprhub.eu/index.php?title=SG_Nürnberg_-_S_5_SF_65/24_DS*

Facts — The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network. On 16 June 2023, the processor informed the controller about the incident. On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents. On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant. Holding — The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles: First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities. Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded. Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take. Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.

### CJEU - T‑384/20 RENV - OC v Commission

*Source: GDPRhub, 2025-10-01 — https://overview.legal/posts/122865 — original: https://gdprhub.eu/index.php?title=CJEU_-_T‑384/20_RENV_-_OC_v_Commission*

Facts — An academic researcher (the data subject) received EU funding for a project. The European Commission was initially a party to the funding agreement, but was later replaced by the European Research Council Executive Agency (ERCEA). The ERCEA later carried out a financial audit and informed the European Anti-Fraud Office (OLAF) of the results. OLAF alleged that the data subject had fraudulently claimed part of the funding for personal expenses, and published a press release on its website. The data subject brought an action to the General Court, requesting compensation from the Commission for the damage caused by the press release. The General Court dismissed the action, and stated that there was no violation of the data subject’s rights. According to the General Court, whether the data subject is identifiable depends on the ‘means reasonably likely to be used’ to identify the applicant as well as whether the ‘average or likely reader’ of said press release would be able to identify them. The General Court did not take into account the journalist that identified the data subject, as it did not fall under the definition of "average reader" . The data subject appealed the decision to the CJEU. The CJEU held that the General Court had misinterpreted the EUDPR and GDPR; the CJEU dismissed the General Court’s reasoning of the “average reader”, and stated that the information in the press release (such as the data subject’s gender, nationality, grant amount and father’s occupation) allow the data subject to be identifiable. The CJEU referred the case back to the General Court. The Commission argued that the press release is anonymous, does not disclose any personal data of the data subject and does not contain inaccurate data. Therefore, the press release cannot cause the data subject any harm. Holding — The Court first clarified that there are three cumulative conditions for the EU to incur non-contractual liability: a sufficiently serious breach of law, damage to the data subject, and a causal link between them. Sufficient breach of law — The Court first held that OLAF had processed the data subject’s data unlawfully, in accordance with Articles 4(1)(a), 5(1)(a), and 6(c) to (e) EUDPR. The Court considered that including information beyond the funding granted was unnecessary. Furthermore, the purpose of including the data in the press release was incompatible with the initial purpose of investigating fraud. Second, the Court held that OLAF violated the principle of the presumption of innocence in accordance with Articles 9(1) and 10 of Regulation 883/2013. This is because OLAF used the term “fraud” in its press release, which implied guilt of the data subject even if national proceedings were ongoing. Finally, the Court held that OLAF violated the right to good administration under Article 41 of the EU Charter of Fundamental Rights (CFREU), and Article 10(5) of Regulation 883/2013. Under Article 10(5) Regulation 883/3013, OLAF has the obligation to provide information to the public in a neutral and impartial manner. This is also linked to the duty to act diligently. OLAF did not meet these requirements, as it also included inaccurate information in its press release. Furthermore, the use of the term “fraud” was not neutral, as it implied guilt of the data subject. The Court considered the violations above sufficiently serious breaches capable of giving rise to liability. Damage to the data subject and causal link — The Court then assessed the damage to the data subject, and the causal link with the serious breaches of OLAF’s obligations. The Court first referred to CJEU case C‑300/21 (Österreichische Post) to state that the mere infringement of the EUDPR is not sufficient to confer a right to compensation. The Court divided the non-material damage into three groups, and assessed the link to the OLAF violations separately: damage to the data subject’s honour and reputation, damage to the data subject’s professional career, and damage linked to the data subject’s health. Damage to the data subject’s reputation — The Court first stated that OLAF damaged the data subject's reputation due to the unlawful processing, the use of the term "fraud", and the inaccuracies of the press release. The Court then noted a specific requirement for reputation damages; the right to compensation does not depend on the data subject's standing, however, a person's reputation may only be taken into account if disclosing the information (particularly through the press) has a greater impact compared to an ordinary citizen. The data subject had a distinguished academic career and international reputation. The Court concluded that there was a causal link between the press release and the damage to the data subject's reputation. This was the case even if third parties (journalists) published articles on the matter. Damage to the data subject’s professional career — The Court considered that it was unclear how the OLAF investigations and press release had affected their professional career and opportunities. Specifically, the absence of a promotion did not have a sufficiently direct causal link to the press release. The Court also considered the risk of dismissal as purely hypothetical. However, according to the Court, there was a clear link between the OLAF investigations and specific career opportunities. For example, the data subject demonstrated through e-mail exchanges that the withdrawal of a formal offer for a job position was linked to the OLAF investigations. Damage to the data subject’s health — The Court took into consideration the medical certificate presented by the data subject, which showed that the data subject suffered from intense psychological distress after the press release was published. The Court considered this sufficient to link the damage to the violations by OLAF, even other factors (such as OLAF's investigations and prosecution by national authorities) may have also contributed to the deterioration of the data subject's health. The Court ordered the Commission to pay the data subject €50,000 in damages.

### PHR - 22/01253

*Source: Supreme Court of the Netherlands, 2022-08-26 — https://overview.legal/posts/125598 — original: https://gdprhub.eu/index.php?title=PHR_-_22/01253*

Facts — A patient (the data subject) was treated in a hospital. Because she believed that an error had been made, she held the hospital liable. The hospital involved its liability insurer. On behalf of this liability insurer, a doctor from another hospital assessed the data subject's medical file. He checked whether the treatment had been carried out correctly. This doctor did not see the data subject nor was she involved in the investigation in any other way. The data subject found out that this other doctor had made an assessment of the treatment and tried to get access to the findings. The doctor who made the assessment refused her access. The data subject then filed a disciplinary complaint against this doctor with the Regional Medical Disciplinary Tribunal. The Regional Tribunal declared the complaint unfounded. The data subject appealed against this decision to the Central Medical Disciplinary Tribunal. The data subject argued that she should get access to the medical assessment based on the inspection rights from the Medical Treatment Contracts Act (MTCA) laid down in the Dutch Civil Code (article 7:456 BW). However, the Central Tribunal held that the data subject could not appeal to these rights, as an exception in the MTCA was applicable (article 7:464 BW). According to the Central Tribunal, the nature of the legal relationship (the trial) between the data subject and the hospital opposed this. It explained that the hospital had the right to prepare their defence against the data subject's liability claim 'in freedom and seclusion'. In that context, they must also be able to call in another doctor to assess the course of treatment, without the data subject being able to inspect the findings. The Central Tribunal therefore held that there was no obligation to make the medical assessment available to the data subject and declared the complaint unfounded. As a rule, decisions of the Central Tribunal cannot be appealed. However, cassation is possible if it is in the interests of the law at the Procurator General (PG) of the Supreme Court. This is what happened in the present case. Holding — The PG of the Supreme Court agreed with the Central Tribunal that the patient had no right of access. However, it held that the legal grounds used to substitute the decision were incorrect. According to the PG, the Central Tribunal misapplied various provisions of the MTCA. The PG noted that for the MTCA to be applicable, there must be an 'act in the field of medicine'. An assessment by a doctor solely based on a medical file, as in this case, did not involve such an act. To this end, the PG considered it important that the doctor did not treat, assess or examine the data subject, but only carried out a 'paper exercise' on her medical data. The PG thus held that the MTCA was, contrary to what the Central Tribunal had assumed, not applicable. Consequently, the data subject could not derive a right to inspect from the MTCA (and the hospital could not have appealed to the exception). Next, the PG examined whether the data subject may be entitled to access the medical assessment on the basis of a different regulation. In doing so, the PR looked at the GDPR. It held that a medical assessment qualifies as personal data and is thus subject to the GDPR. In principle, the data subject had a right to access her personal data in that assessment pursuant to Article 15(1) GDPR. However, Article 23(1)(i) GDPR and Article 41 UAVG provide the possibility of a restriction to protect the rights and freedoms of others. In the present case, this is the right to prepare for the defence against a legal claim in freedom and seclusion. The PG argued that such a right exists based on Article 6(1) ECHR. The PG followed that the corresponding interest can be found in the GDPR. Notably, the PG referenced Recital 52 and Article 9 GDPR. Recital 52 GDPR states that a derogation from the prohibition on processing special categories of personal data should be provided for the defence of legal claims. Article 9(1) GDPR and Article (2)(f) GDPR contain an exception to the prohibition of processing special categories of personal data when processing is necessary for the establishment, exercise or defence of legal claims. While this concerned the prohibition of processing personal data and not the exercise of the right of access, the PG argued it was still meaningful for the case at hand. It showed that while the drafting the GDPR, the need to process personal data for the defence against a legal claim was taken into consideration. Last, the PG stated that the data subject's interest (keeping track of the processing of her personal data) was only affected to a limited extent. The data subject could (1) still access her medical file pursuant to the MTCA and her personal data pursuant to Article 15(1) GDPR, insofar it did not restrict the hospital's interest to prepare its defence in freedom and privacy. In addition, (2) making the medical assessment involved no collection of any new personal data. The restriction was therefore proportionate. The PG therefore concluded that in a situation like the present case, a patient will usually not be able to demand access to the medical assessment based on Article 15 GDPR. Such an assessment qualifies as personal data, but that the hospital can object based on Article 23 GDPR to prepare its defence in freedom and privacy.

### Council of State: Tax Authority satisfied GDPR access request on FSV fraud registration

*Source: Council of State, 2026-08-05 — https://overview.legal/posts/187482 — original: https://gdprhub.eu/index.php?title=RVS_-_202307578/1/A3*

Facts — The personal data of an individual was stored in the Fraud Detection System (FSV), an application used by the Dutch Tax Authority between 2012 and 2020 to record potential indicators of tax fraud. The Minister of Finance was the controller. The data subject submitted an access request under Article 15 GDPR. In particular, she requested information about the personal data processed, the purposes of the processing, the recipients of the data, its source and retention period, and any automated decision-making concerning her. The controller provided an overview of the personal data stored in the FSV and answered the data subject’s questions. The data subject objected to the decision, claiming that the controller had not disclosed all information relating to her registration. The controller rejected the objection. It explained that the data subject had been selected for a manual review of her tax return under Project 1043, an anti-fraud initiative launched by the Dutch Tax, and was consequently registered in the FSV. It also stated that the data was accessible only to employees of the Tax Authority and had not been disclosed to other organisations. The District Court of Amsterdam dismissed the data subject’s appeal. It held that the proceedings concerned compliance with the GDPR access request and not the lawfulness of her inclusion in the FSV or any alleged resulting damage. The data subject appealed this judgment before the Council of State. Holding — The Council of State dismissed the appeal and upheld the judgment of the District Court. The Court held that there was no evidence that the controller had incorrectly applied Article 15 GDPR. The controller had provided an overview of all personal data concerning the data subject processed in the FSV, explained the purposes of the processing and clarified the circumstances of her registration under Project 1043. Although the data subject suspected that the controller held additional information, she did not provide concrete evidence supporting this claim. The Court also found no indication that she had been classified as a fraudster or that her personal data had been disclosed to other organisations. The Court further clarified that the lawfulness of the data subject’s registration in the FSV, the deletion of her data and any claim for compensation fell outside the scope of the access proceedings. Consequently, the Court confirmed the contested judgment and did not award litigation costs.

### CJEU - C-247/23 - Deldits

*Source: GDPRhub, C-247/23, 2025-03-13 — https://overview.legal/posts/125591 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-247/23_-_Deldits*

Facts — The data subject is a trans person who was granted refugee status in Hungary. When applying for this status, they pointed out that they identified as male and relied on their transsexuality as the ground for their recognition as a refugee. However, the Hungarian National Directorate-General for Immigration Policing (Országos Idegenrendészeti Főigazgatóság, the controller) recorded them in the register as female. In 2022, the data subject, pursuant to Article 16 GDPR, submitted a request to the controller to rectify the asylum register in two particulars: a change of the name under which they had been registered and a change of gender from female to male. On 11 October 2022, the controller rejected the request, arguing that the documents provided by the data subject did not prove that they had undergone gender reassignment surgery and that the applicant’s gender had changed. Therefore, the data subject brought proceedings before the Budapest High Court (Fővárosi Törvényszék). This court, having doubts regarding the interpretation of Article 16 GDPR, stayed the proceedings and referred the following questions to the CJEU: Must Article 16 GDPR be interpreted as meaning that, in connection with the exercise of the rights of the data subject, the authority responsible for keeping registers under national law is required to rectify the personal data relating to the gender of that data subject recorded by that authority, where those data have changed after they were entered in the register and therefore do not comply with the principle of accuracy established in Article 5(1)(d) GDPR? If the answer to the first question referred is in the affirmative, must Article 16 GDPR be interpreted as meaning that it requires the person requesting rectification of the data relating to his or her gender to provide evidence in support of the request for rectification? If the answer to the second question referred is in the affirmative, must Article 16 GDPR be interpreted as meaning that the person making the request is required to prove that he or she has undergone gender reassignment surgery?’ The data subject argued that, pursuant to Article 5(1)(d) GDPR, the accuracy of data must be assessed having regard to the purposes for which they are processed. In this case, the purpose of the asylum register is to identify refugees. On this point, the data subject pointed out that where the gender of a transgender person as recorded does not reflect the identity by which they are recognised in public, that record does not facilitate their identification and may even expose them to discrimination and harassment. The Hungarian Government submitted that, according to Article 6(2) GDPR and Article 6(3) GDPR, the data subject’s right to have an entry in an official record, such as the asylum register, rectified may be exercised under the law of a Member State only and not by direct reliance upon Article 16 GDPR. Advocate General Opinion — First question First, Advocate General Collins (AG) noted that the question asked by the referring court does not reflects the facts if the case. While the question seems to imply that the data subject’s change of gender identity occurred after the recognition of their refugee status in 2014, facts suggest that this occurred prior to it, since the change of gender identity appears to have been the basis upon which Hungary recognised the data subject’s refugee status. Therefore, the AG suggested the CJEU to take these facts into account and consider that the rectification request aimed at correcting an original error and not to amend that record in order to reflect a change in circumstances. Secondly, the AG recalled that the right to rectification is enshrined both in Article 16 GDPR but also in Article 8(2) CFR. Thirdly, the AG pointed out that since the accuracy of personal data may vary depending on the context in which it is processed, the purpose of the collection of data has a direct bearing upon an assessment of its accuracy. In the case at hand, one of the purposes of the asylum register is to identify a person and gender is considered to be one of the identifiers. On this point, the AG noted that when Hungary recognised the data subject’s refugee status, they identified as a transgender male. Therefore, the AG opined that the entry of the data subject’s gender as “female” in the asylum register thus appears to have been inaccurate for the purposes of Article 5(1)(d) GDPR. Fourthly, the AG acknowledged that the right to rectification is not absolute and could be limited under certain conditions, according to Article 23 GDPR. In particular, Article 23(1)(e) GDPR relates to the “keeping of public registers kept for reasons of general public interest”. Therefore, according to the AG, a Member State could theoretically rely on Article 23(1)(e) GDPR to partially restrict the right to rectification in order to ensure the reliability and consistency of public records, including records of civil status. However, nothing in the case at hand suggests that such a law has been implemented in Hungary. Moreover, this cannot on itself be an obstacle to granting an application to rectify the gender in an asylum register so as to record their gender identity as it was at the time it was entered therein, since this type of application only serves to enhance the reliability of that register and the accuracy of the data recorded therein. Therefore, the AG advised the Court to answer that Article 16 GDPR, read in the light of Article 5(1)(d) GDPR, is to be interpreted as meaning that a national authority responsible for keeping a register of refugees is, upon application, required to rectify personal data on the gender of a refugee which that authority had incorrectly recorded at the time they were entered in that register. Second and third questions According to the AG, the second and third questions seek to know which evidence a data subject should submit in support to their gender rectification request under Article 16 GDPR and whether that person may be required to furnish proof of having undergone gender reassignment surgery. First, the AG noted that Article 16 GDPR does not specify anything about the evidence a data subject should provide. Therefore, this needs to be assessed on a case-by-case basis. This means that, in certain cases, the data subject might be required to produce evidence that may be reasonably necessary to establish the inaccuracy of that data in the light of the purposes for which they were collected or processed. However, the AG emphasised that the data subject does not have to claim or to demonstrate a particular interest in the rectification of inaccurate data or that the alleged inaccuracy causes any harm. In the case at hand, the AG opined that it is sufficient for the data subject to prove that Hungary recognised their refugee status in 2014 on the basis of their pre-existing transgender identity and that the asylum register does not accurately record that identity. Finally, as for the necessity to have undergone gender reassignment surgery, the AG noted that the European Court of Human Rights has repeatedly hold that imposing this requirement goes against the ECHR. Therefore, imposing such a requirement would have the effect of negating the right to rectify inaccurate data on the gender of a transgender data subject. Therefore, the AG suggested the CJEU to answer that a national authority responsible for keeping a register of refugees may require a data subject requesting rectification of data to produce evidence to establish the inaccuracy of that data in the light of the purposes for which they were collected or processed but may not be required to prove they have undergone gender reassignment surgery. Holding — First question: Article 16 GDPR demands rectification of data on gender identity — The Court observed that under Article 16 GDPR in conjunction with the principle of accuracy (Article 5(1)(d) GDPR) and Article 8(2) CFR, the data subject has the right to obtain from the controller, without undue delay, the rectification of inaccurate personal data concerning him or her. The court recalled that it had laid out in Nowak that the purpose for which data were collected, was to be considered when assessing the accuracy of data. Thus, the court indicated, that if the purpose of collecting those data was to identify the data subject, those data would appear to refer to that person’s lived gender identity, and not to the identity assigned to them at birth. In that context, the court clarified that a Member State cannot limit the exercise of the right to rectification based on the absence of a national procedure to proof a transgender identity but only on legislative measures adopted under Article 23 GDPR. However, even if such a legislative measure existed, the court held, that although EU law does not detract from the Member States’ competence in the legal recognition of person's gender identity, those States must comply with EU law, including the GDPR, read in the light of the CFR. The court held, that national legislation preventing a transgender person from fulfilling a requirement which must be met to rectify their data on gender identity by not recognizing such identity must be regarded as being incompatible with Article 8(2) CFR and its specific expression in Article 16 GDPR. Consequently, the Court concluded that Article 16 GDPR must be interpreted as requiring a national authority responsible for keeping a public register to rectify the personal data relating to the gender identity where those data are inaccurate. Second and third question: No requirement to proof of gender reassignment surgery — The court found that, for the purposes of exercising their right to rectification under Article 16 GDPR, a person may be required to provide relevant and sufficient evidence that may reasonably be required in order to establish that those data are inaccurate. The court further stated, that any limitation of the rights under the GDPR pursuant to Article 23 GDPR must respect the essence of the fundamental rights and freedoms and be laid down by law. First, the court found that the evidential requirement for rectification limiting Article 16 GDPR seems to have no basis in Hungarian law. Secondly, the court found, that Article 8 ECHR (corresponding to Article 7 CFR) includes the right of transgender persons to personal development and physical and moral integrity, as well as to respect for and recognition of their gender identity. Additionally, the court referenced the European Court of Human Right's ruling, that recognition of a transgender identity could not be made conditional on the performance of surgical treatment not desired by that person. Thirdly, the court held, that in any event, a requirement of evidence of gender reassignment surgery is neither necessary nor proportionate to ensure the reliability and consistency of a public register such as the asylum register, since a medical certificate, including a psychiatric diagnosis, may constitute relevant and sufficient evidence in that regard. Thus, the court held, that a Member State may never make the exercise of the right to rectification conditional upon the production of evidence of gender reassignment surgery because such a requirement would undermine the essence of the right to the integrity of the person and the right to respect for private life, referred to in Article 3 CFR and Article 7 CFR.

## Guidance

### EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space

*Source: EDPB, edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on-en, 2022-07-12 — https://overview.legal/posts/125922 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on_en*

Adopted 1 EDPB - EDPS Joint Opinion 03 /2022 on the Proposal for a Regulation on the European Health Data Space Adopted on 12 July 2022 Adopted 2 Adopted 3 Executive Summary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on the European Health Data Space and urge the co - legislature to take decisive action. The EDPB and the EDPS note that the Proposal ai ms at supporting individuals to take control of their own health…

### EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)

*Source: EDPB, edpb-edps-joint-opinion-22022-on-the-proposal-of-the-european-en, 2022-05-04 — https://overview.legal/posts/125945 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-22022-on-the-proposal-of-the-european_en*

1 Adopted EDPB - EDP S Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act) Adopted on 4 May 2022 2 Adopted Executive s ummary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on Data Act and urge the co - legislature to take decisive action. The EDPB and EDPS note that the Proposal would apply to a broad range of products and…

### Guidelines 01/2021

*Source: EDPB, edpb-guidelines-on-examples-regarding-personal-data-breach-notification, 2022-01-03 — https://overview.legal/posts/38047 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012021-on-examples-regarding-personal-data-breach-notification_en*

The European Data Protection Board (EDPB) adopted Guidelines 01/2021 on December 14, 2021, providing practical examples and analysis regarding personal data breach notification obligations under Articles 33 and 34 of the GDPR. The guidelines present hypothetical scenarios covering ransomware attacks and data exfiltration incidents, illustrating how controllers should assess risk to determine whether notification to supervisory authorities and communication to data subjects are required. The document serves as interpretive guidance for controllers evaluating breach severity, appropriate mitigation measures, and notification decisions, and does not impose any fines or sanctions.

### EDPB Document on response to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research

*Source: EDPB, edpb-document-on-response-to-the-request-from-the-european-commission-for-en, 2021-02-02 — https://overview.legal/posts/126069 — original: https://www.edpb.europa.eu/documents/other-guidance/edpb-document-on-response-to-the-request-from-the-european-commission-for_en*

EDPB Document on r esponse to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research Adopted on 2 February 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 70.1.b of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak

*Source: EDPB, guidelines-032020-on-the-processing-of-data-concerning-health-for-the-purpose-en, 2020-04-21 — https://overview.legal/posts/126170 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032020-on-the-processing-of-data-concerning-health-for-the-purpose_en*

Adopted 1 Guidelines 03 /2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID - 19 outbreak Adopted on 21 April 2020 Adopted 2 Version history Version 1.1 30 April 2020 Minor corrections Version 1. 0 21 April 2020 Adoption of the Guidelines Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1) (e) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the…

### EDPB-EDPS Joint Opinion 1/2019 on the processing of patients’ data and the role of the European Commission within the eHealth Digital Service Infrastructure (eHDSI)

*Source: EDPB, edpb-edps-joint-opinion-12019-on-the-processing-of-patients-data-and-en, 2019-07-12 — https://overview.legal/posts/126222 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-12019-on-the-processing-of-patients-data-and_en*

1 EDPB - EDPS Joint Opinion 1/2019 on the processing of patients’ data and the role of the European Commission within the eHealth Digital Service Infrastructure (eHDSI) 2 TABLE OF CO NTENTS 1 Background ................................ ................................ ................................ ................................ ..... 3 2 Scope of the opinion ................................ ................................ ................................ ...................... 4 3…

### Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)

*Source: EDPB, opinion-32019-concerning-the-questions-and-answers-on-the-interplay-en, 2019-01-23 — https://overview.legal/posts/126252 — original: https://www.edpb.europa.eu/documents/legislative-opinion/opinion-32019-concerning-the-questions-and-answers-on-the-interplay_en*

1 Opinion 3/ 2 019 c oncerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR) (art. 70. 1. b)) Adopted on 23 January 2019 2 3 The European Data Protection Board Having regard to Article 70.1.b of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data,…

### Opinion 12/2024 on the draft decision of the French Supervisory Authority regarding the “Code of Conduct for Service Providers in Clinical Research” submitted by EUCROF

*Source: EDPB, opinion-122024-on-the-draft-decision-of-the-french-en, 2024-06-18 — https://overview.legal/posts/125740 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-122024-on-the-draft-decision-of-the-french_en*

1 Adopted Opinion 12 /202 4 on the draft decision of the French Supervisory Authority regarding the “ Code of Conduct for Service Providers in Clinical Research” submitted by EUCROF Adopted on 18 June 2024 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)( b ) and Article 4 0 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal…

## Enforcement decisions

### DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis

*Source: DSB (Austria), 2026-01-12 — https://overview.legal/posts/96832 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2026-0.016.479*

Facts — A medical student (the controller) worked as a ward attendant at a hospital. Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the nursing staff immediately when necessary. While assigned to a patient with dementia (the data subject), she recorded a video of him wearing a hospital gown and throwing a newspaper to the floor. She subsequently sent the video to a fellow student through a messaging service. The recording lasted about eleven seconds. Holding — The DPA treated the medical student as the controller of the relevant processing pursuant to Article 4(7) GDPR because she decided to record the data subject and disclose the video to a third party. It found that the context of the video, the data subject’s clothing and behaviour revealed information concerning his health within the meaning of Article 4(15) GDPR. The video therefore contained special categories of personal data. The DPA noted that an applicable condition under Article 9(2) GDPR was required for the processing. The DPA found that the controller lacked a legal basis for the relevant processing. It emphasized that the controller could not rely on Article 6(1)(f) GDPR since Article 9(2) GDPR restricts processing based on legitimate interest. The DPA pointed out that no scientific purpose was apparent for this recording and disclosure. It further noted that the video recording of the data subject was made for the purpose of exchanging comments with a fellow student. It therefore held that the processing also lacked a legitimate purpose under Article 5(1)(b) GDPR. The DPA concluded that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(b) GDPR, Article 6(1) GDPR and Article 9(2) GDPR. It found that she had acted intentionally, as she had knowingly recorded and transmitted the video and was aware that the processing was unlawful. It imposed a fine of €200, with twelve hours’ substitute imprisonment if the fine proved uncollectible.

### VDAI (Lithuania) - 3R-1143

*Source: VDAI (Lithuania), 2026-06-19 — https://overview.legal/posts/53896 — original: https://gdprhub.eu/index.php?title=VDAI_(Lithuania)_-_3R-1143*

Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other personal data of patients (the data subjects). The first breach potentially concerned 63 data subjects, whereas the latter breach affected approximately 10,000 employees and 383,000 data subjects. The DPA initiated two separate investigations against the controllers in September 2024 and November 2025 respectively and later combined the cases. Holding — The DPA imposed a fine of €450,000 on the first controller it investigated as this company was also the legal successor of the other controller. It held that the controllers had failed to implement appropriate technical and organisational measures to ensure the security of processing and compliance with the principles of integrity and confidentiality. The controller had violated Articles 5(1)(f), 24(1), and 32(1)(b) GDPR. When assessing the GDPR infringements, the DPA took into account that the controllers processed sensitive categories of personal data. The DPA held the controllers lacked adequate security measures for protecting against unauthorised access to an IT system, such as access control and authentication. For instance, passwords used by employees did not reach a certain level of complexity, and multi-factor authentication was not used.

### Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray

*Source: Garante per la protezione dei dati personali (Italy), 2026-05-28 — https://overview.legal/posts/53884 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_385/2026*

Facts — A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised, they received their food tray with a note stating their full name and medical condition as a patient with HIV. The data subject had also contacted the health directorate of the hospital, but had not received a response. During the DPA’s investigations, the controller stated that it included information on patients’ conditions to alert the kitchen staff on protective measures needed. The controller later modified the form alerting the staff to replace the patient’s medical condition with specific requests (e.g. to use disposable tableware). Holding — The DPA found a violation of Article 9 GDPR. The DPA highlighted that under national law, the controller has additional responsibilities in ensuring the confidentiality of data subjects that have HIV or AIDS. National law also requires medical facilities to implement protective measures to prevent the transmission of HIV. However, this requirement does not justify including the data subject’s full name and condition in the context of meal service. Therefore, the controller did not have a legal basis to process the data subject’s personal data in the context of disclosing the data subject’s HIV status while providing meals. This was the case for both including the patient's medical information in the form to the kitchen staff and disclosing the data through the note in the meal tray. The DPA also found a violation of Articles 5(1)(c) and (f) GDPR. The DPA considered that the processing activity violated the principle of data minimisation. The controller also failed to ensure security of processing by disclosing the data subject’s medical condition. Finally, the DPA found a violation of Article 157 of the Code, as the controller had not complied with its obligation to provide information to the DPA during its investigations. The DPA fined the controller €700. The DPA took into account that the controller had implemented measures to prevent future incidents from happening, such as raising awareness among staff.

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### DSB Austria: sharing medical assessment with municipality lacked Art. 9(2) legal basis

*Source: DSB (Austria), 2021-08-05 — https://overview.legal/posts/184543 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2021-0.518.795*

Facts — Person A is employed at a municipality and has been on sick leave for several weeks in 2013 and 2014. In September 2014, the municipality concluded that Person A's sickness had been caused by another individual (Person B) who was then asked for damages. In another proceeding between Person A and Person B, the latter obtained a medical assessment concerning Person A's state of health. According to Person B's view, this document would have proved the municipality's claim wrong. The document was therefore shared with the municipality (even though no further steps had been taken following the initial claim). For this reasons, Person B is considered controller of Person A's personal data. Holding — The DPA held that there was no legal basis under Article 9(2) GDPR for sending the medical assessment, which contained health data under Article 14 GDPR#15Article 4(15) GDPR, to the municipality. In particular, the controller could not invoke Article 9(2)(f) GDPR ("necessary for the establishment, exercise or defence of legal claims") because i) the municipality had taken no further steps to claim damages from the controller since September 2014 and ii) the claim had already been time-barred under § 1489 General Civil Code (Allgemeines Bürgerliches Gesetzbuch - ABGB) since more than three years had passed since the event that allegedly caused the damage (harming behaviour towards the data subject). Consequently, the DPA held that the disclosure of the data subject's health data were not necessary "for the establishment, exercise or defence of legal claims". To lawfully disclose the data, the data subject's explicit consent would have been required. When deciding on the amount of the administrative fine, the DSB took into account the sensitive nature of the data and wilful conduct of the controller but also the controller's low income and the fact that the controller collaborated with the DSB in the course of the procedure.

### Ospedaliero-Universitaria Careggi: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen.

*Source: Italian Data Protection Authority (Garante), 2025-08-04 — https://overview.legal/posts/52171*

De Italiaanse autoriteit voor gegevensbescherming (DPA) heeft een boete van 80.000 euro opgelegd aan het universitaire ziekenhuis Careggi. De verantwoordelijke, een universitair ziekenhuis, gebruikte software waarmee medisch personeel de medische dossiers van patiënten kon doorzoeken, zelfs als deze informatie niet relevant was voor de specifieke medische behandeling.

### UODO (Poland) - DKN.5131.12.2022

*Source: UODO (Poland), 2026-06-11 — https://overview.legal/posts/144031 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.12.2022*

Facts — The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor). The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022. Holding — The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated Article 28(1) GDPR: while the controller had concluded a data processing agreement with the processor, it had failed to verify whether the processor provided sufficient guarantees to implement appropriate technical and organisational measures. Second, the DPA found that the controller had infringed Articles 24(1), 25(1), and 32(1) and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of processing via the email system. The DPA took into account that the controller had not taken any measures to minimise the risks identified. In addition, the DPA pointed out that the breach involved sensitive health data, and the passwords used by the controller did not meet the usual security requirements. As a consequence of the previous violations, the controller had infringed the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR as well. Finally, the DPA found a violation of Article 35(1) GDPR in conjunction with Article 35(3) GDPR due to the controller’s failure to conduct a data protection impact assessment. The DPA also reprimanded the processor for the failure to implement appropriate technical and organisational measures to ensure the security of processing – the processor had failed to conduct a risk analysis and to implement adequate security measures, such as blocking a user’s account after a certain amount of login attempts. The DPA held that the processor had violated Articles 32(1) and 32(2) GDPR in conjunction with Article 28(3)(c) GDPR.

### APARELLS ORTOPEDICS CURTO, S.L: Onvoldoende naleving van de rechten van betrokkenen.

*Source: Spanish Data Protection Authority (aepd), 2025-10-28 — https://overview.legal/posts/51988*

De Spaanse autoriteit voor gegevensbescherming heeft APARELLS ORTOPEDICS CURTO, S.L. een boete van 6.000 euro opgelegd. De verantwoordelijke partij was niet in staat om de gegevens te bewaren die nodig waren om de beschikbaarheid ervan te garanderen, wat resulteerde in het feit dat de verantwoordelijke partij niet adequaat kon reageren op een verzoek van een betrokkene om haar rechten uit te oefenen. De oorspronkelijke boete van 10.000 euro is verlaagd tot 6.000 euro vanwege de onmiddellijke betaling en de erkenning van verantwoordelijkheid door de verantwoordelijke partij.

## Recent developments

### Court of Audit points out obstacles in implementation of GDPR in Netherlands in letter to Chamber

*Source: IT en Recht, 2023-04-04 — https://overview.legal/posts/6219 — original: https://www.itenrecht.nl/artikelen/algemene-rekenkamer-wijst-in-brief-aan-kamer-op-obstakels-bij-de-uitvoering-van-de-avg-in-nederland#entry-4294*

The Court of Audit has sent a letter to the House of Representatives pointing out obstacles in the implementation of the General Data Protection Regulation (AVG) in the Netherlands. Implementing organizations are struggling with the AVG and this can lead to negative consequences for citizens. Recommendations are made to enable data sharing and pay attention to data sharing between implementers to prevent zoonoses and address healthcare fraud. The AVG provides room to process personal data, but t

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

### EU-wetgeving inzake datagovernance definitief vastgesteld

*Source: NL EU Court Expert, 2022-06-08 — https://overview.legal/posts/6302 — original: https://ecer.minbuza.nl/-/eu-wetgeving-inzake-datagovernance-definitief-vastgesteld?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-303*

The new data governance regulation sets out the conditions for the reuse of certain government data. In addition, the regulation provides a notification and oversight framework for the provision of data mediation services. Furthermore, the regulation contains a framework for the voluntary registration of entities that collect and process data made available for altruistic purposes. The rules will apply from September 2023.

### Collection and retention, by the French blood donation service (EFS), of personal data reflecting applicant’s presumed sexual orientation without proven factual basis: violation of Article 8 of the Convention

*Source: ECHR, 2022-09-08 — https://overview.legal/posts/6283 — original: https://hudoc.echr.coe.int/eng-press#entry-367*

In today’s Chamber judgment1 in the case of Drelon v. France (application no. 3153/16) the
European Court of Human Rights held, unanimously, that there had been:
a violation of Article 8 (right to respect for private and family life) of the European Convention on
Human Rights.

The applications concerned, first, the collection and retention, by the French blood donation service
(EFS) of personal data reflecting the applicant’s presumed sexual orientation – together with the
rejection of his criminal complaint for discrimination – and, second, the refusal of his offers to
donate blood, together with the dismissal by the Conseil d’État of his judicial review application
challenging an order of 5 April 2016 which amended the selection criteria for blood donors.
Addressing the first application, the Court found that the collection and retention of sensitive
personal data constituted an interference with the applicant’s right to respect for his private life.
That interference had a foreseeable legal basis as the authorities’ discretionary power to set up a
health database for such purpose was sufficiently regulated by the then applicable Law of 6 January
1978. Whilst the collection and

### De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming).

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/51791*

De GDPR-risicoanalyse is bedoeld om controllers en verwerkers te helpen bij het identificeren van de risicofactoren voor de rechten en vrijheden van de betrokkenen, wiens gegevens worden verwerkt. Het doel is om een eerste inschatting te maken van het inherente risico, inclusief de noodzaak om een Privacy Impact Assessment (DIA) uit te voeren, en om het resterende risico te schatten als maatregelen en beveiligingsmechanismen worden gebruikt om specifieke risicofactoren te verminderen.

## Literature

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation”

*Source: Athens Journal of Law, 2025-01-02 — https://overview.legal/posts/132443 — original: https://doi.org/10.30958/ajl.11-1-3*

The recent Regulation that sets down harmonised rules on Artificial Intelligence in the European Union, known as the "AI Act," includes a significant requirement for human oversight in high-risk AI systems during their use (art. 14). This requirement embodies the "human-in-command" approach, ensuring both legal and ethical compliance. The AI Act is intended to complement the General Data Protection Regulation (hereinafter GDPR), thereby forming a consistent and comprehensive legal framework. Thi

### ‘Leading by Science’ through Covid-19: the GDPR Automated Decision-Making

*Source: International Journal of Population Data Science, 2021-02-24 — https://overview.legal/posts/132597 — original: https://doi.org/10.23889/ijpds.v5i4.1402*

The UK government announced in March 2020 that it would create an NHS Covid-19 ‘Data Store’ from information routinely collected as part of the health service. This ‘Store’ would use a number of sources of population data to provide a ‘single source of truth’ about the spread of the coronavirus in England. The initiative illustrates the difficulty of relying on automated processing when making healthcare decisions under the General Data Protection Regulation (GDPR). The end-product of the store,

### Health AI Governance, Medical Devices Health Data

*Source: Open Science Framework, 2026-07-17 — https://overview.legal/posts/132112 — original: https://doi.org/10.17605/osf.io/kpxn7*

This AGRIR-Lab component develops an interdisciplinary research programme on the governance, regulation, clinical safety, cybersecurity and ethical deployment of artificial intelligence in healthcare. It examines the EU Artificial Intelligence Act, the Medical Devices Regulation and In Vitro Diagnostic Medical Devices Regulation, the European Health Data Space, GDPR, NIS2, Medical Device Software, clinical and performance evaluation, health-data governance, anonymisation, predictive analytics, h

### Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132504 — original: https://doi.org/10.21552/edpl/2022/4/8*

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Health Data** — https://overview.legal/topics/health-data
  Processing of health and medical data
- **Healthcare** — https://overview.legal/topics/zorg
  Processing of health data and medical information
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

---
Generated by overview.legal · https://overview.legal/topics/healthcare · 2026-08-22
